"\37,bm?L*\270$%\17ev\305\334\0\360VS|\303\277\237\356\0S\331$o\212\306*\301\311\09n\370]i?=\31\177C\300\204 LF4\14Z\v^1\332.\345\17\7\367\263\327\270\325W\207\330\367]\261\335\34\236|:1HT\3\304Y~\36>vh\312\306\270\301\323\31\252b;\257\203\224\11\216\371q\356\265ZJ*\20Dw\323H\241-\262\325\312\326f\272\25\301*\14\375\333 B\331FC\226\30209h\26\225'\320\10\274\367\343y$\266\347=\2748\227\10\11\2137\364pr\14\242\373R\233\310\206I\335!\376=\344*'\345\3\241\356\222\337H\370J\214\7q\250\17\332S\37\257@\312eH~:iS\270\222R\13oY\333\2451G\21p\301k\236\274\3574\272\1x5\216kV:\315\241\323k\344'\33d\343\30\234_\363P\374\345\4\211, ) , ) == 0x0
00928 1740 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\235\372y\306\314\301\202.N\313;\6.@r\373:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\270!\300TW\323x\226\16\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ...
00929 1740 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0
00930 1740 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0
00931 1740 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0
00932 1740 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0
00933 1740 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0
00934 1740 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0
00935 1740 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH
00936 1740 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0
00937 1740 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "\227\325\353\12&\242\221\217VD\366\267[\33\20\253\224\345\3363\35\6\262\206\25*\341x\364\231\236\251\305l\337\247H\364v\222\263\301\277N;rH\23\20\335\300`\244\203\314\370\340\307*`\341\204\313\264\35\323!f\271{\305\360T\331\314h\246\324n\32", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "\227\325\353\12&\242\221\217VD\366\267[\33\20\253\224\345\3363\35\6\262\206\25*\341x\364\231\236\251\305l\337\247H\364v\222\263\301\277N;rH\23\20\335\300`\244\203\314\370\340\307*`\341\204\313\264\35\323!f\271{\305\360T\331\314h\246\324n\32", 80, ... ) , 80, ... ) == 0x0
00938 1740 NtClose (-2147482740, ... ) == 0x0
00928 1740 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, ")\302\270\11\260\346v\3377\253\376\305\261\237\303\315e\305\352\263\272;J\30i\244\5S\16"5rM\225\375\260d\311\231\213{^\230\5\364'\371\375*7\340\221\366\336#\276\207\232\252\274\331\231\231\374k\312\3K^\37\373\0\6\252\177\266\344\37\246\315~5\2\32\39\216\247\355\220\350\260\1\313\240L\333\300\206\22\266t\324\324\276\221\15\313\225\10\363\354q\315\2254\251O\300\313\224\37\331\333\215\257\240G\274\26\226Y\275\246x\275\354YUhV\272\224zW\341\261XE0\316\2114\332\373\321\34\245\331\36~\354\273\234A-]\314\301\371=\15\203\367h\4\27\274kZa\342\16\226\325\230(\313>\5\364U\251\1\317%\241\235:OC\337\305\1>\237\272\364\254=\340o\225O\2076@y@2\224\271\345\231\211J\250\327\266\352\0\317\271'P\234\11,\275;\264\365\334\13-\1\310\254\20\270\212a\347\317\212X", ) 5rM\225\375\260d\311\231\213{^\230\5\364'\371\375*7\340\221\366\336#\276\207\232\252\274\331\231\231\374k\312\3K^\37\373\0\6\252\177\266\344\37\246\315~5\2\32\39\216\247\355\220\350\260\1\313\240L\333\300\206\22\266t\324\324\276\221\15\313\225\10\363\354q\315\2254\251O\300\313\224\37\331\333\215\257\240G\274\26\226Y\275\246x\275\354YUhV\272\224zW\341\261XE0\316\2114\332\373\321\34\245\331\36~\354\273\234A-]\314\301\371=\15\203\367h\4\27\274kZa\342\16\226\325\230(\313>\5\364U\251\1\317%\241\235:OC\337\305\1>\237\272\364\254=\340o\225O\2076@y@2\224\271\345\231\211J\250\327\266\352\0\317\271'P\234\11,\275;\264\365\334\13-\1\310\254\20\270\212a\347\317\212X", ) == 0x0
00939 1740 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\235\372y\306\314\301\202.N\313;\6.@r\373:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\270!\300TW\323x\226\16\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ...
00940 1740 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0
00941 1740 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0
00942 1740 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0
00943 1740 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0
00944 1740 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0
00945 1740 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0
00946 1740 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH
00947 1740 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0
00948 1740 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "0\\355_\244\15\305\221\17\371\362\6\214e\301\211J^\14\204(\225\260\322\200\15\20\247\1\326\322\263\6\177\5\0\177\25\370\230\352\26V4\343\205q\205f\361\345\236\200zg\273\3057\307Lq_)7\265\272\02\307\226sK\220\224X\47\275\30$", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "0\\355_\244\15\305\221\17\371\362\6\214e\301\211J^\14\204(\225\260\322\200\15\20\247\1\326\322\263\6\177\5\0\177\25\370\230\352\26V4\343\205q\205f\361\345\236\200zg\273\3057\307Lq_)7\265\272\02\307\226sK\220\224X\47\275\30$", 80, ... ) , 80, ... ) == 0x0
00949 1740 NtClose (-2147482740, ... ) == 0x0
00939 1740 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\310D\256 a\69\302\6\356\277z.\363\316\307\246\207\374\361\253\2005\16Y\200\360=\235\264\235c\34G\214d\355\7\5\246\15\334\15\351\276:\27\236\350\362\233\36\342\353\330\354\24\352\226\373#\231]\25k\305\221\300,\321\307u\370\253YlX\2113?\4B\334\22\326\224\343\247\253o\201\275\262ET\340W\325"\346\7H#\333bU\254\246\257\301\34\341\206G\14\231a\372\320\25t:\7\233I\t\6\13\250\240\202\277\246\271\365\33\226i\2142E\231!RP-\365\202:\267\200\16\273q\225\322\257\11\254\225\374\313bZF\217\250\364\237O\360\250l\326n\34\223\373\254\341P\226\357w\17./H\36z\\355\324\226\320\342Z\233\260\262\354Cl\221:\31\312\334\216K\251ib\16\364\31R\304\200\320|V\24\230\242=\307\357KcA\337L6\207Q\32wg\312\375pL\11\351\230\3107l\266\207]'Kt", ) \346\7H#\333bU\254\246\257\301\34\341\206G\14\231a\372\320\25t:\7\233I\t\6\13\250\240\202\277\246\271\365\33\226i\2142E\231!RP-\365\202:\267\200\16\273q\225\322\257\11\254\225\374\313bZF\217\250\364\237O\360\250l\326n\34\223\373\254\341P\226\357w\17./H\36z\\355\324\226\320\342Z\233\260\262\354Cl\221:\31\312\334\216K\251ib\16\364\31R\304\200\320|V\24\230\242=\307\357KcA\337L6\207Q\32wg\312\375pL\11\351\230\3107l\266\207]'Kt", ) == 0x0
00950 1740 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\235\372y\306\314\301\202.N\313;\6.@r\373:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\270!\300TW\323x\226\16\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ...
00951 1740 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0
00952 1740 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0
00953 1740 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0
00954 1740 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0
00955 1740 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0
00956 1740 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0
00957 1740 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH
00958 1740 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0
00959 1740 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "hS}\350l\372\221\253\313\22\22\370\304m('\271\222$4iY\320\35771\236\357\341,?\16\14/\311*!\31\321^\220vw\344\205\25\5\240\250'l\373\324\10\0\237 \250R\334\267\343\255\25\214m\27\3714\222\201y\262Yt\\240\321nk", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "hS}\350l\372\221\253\313\22\22\370\304m('\271\222$4iY\320\35771\236\357\341,?\16\14/\311*!\31\321^\220vw\344\205\25\5\240\250'l\373\324\10\0\237 \250R\334\267\343\255\25\214m\27\3714\222\201y\262Yt\\240\321nk", 80, ... ) , 80, ... ) == 0x0
00960 1740 NtClose (-2147482740, ... ) == 0x0
00950 1740 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "$#\362H\274\306\360\25>\270\260\237\3455"Q\243\316V\337\\345\227\27{\372\216\2111<\223\275\341=\21\301r\251_\371\277\211v!\16\310A#\224\362\222\5\240\270t\242X\2269f\252\30\\314\224\24x\21\215)}\217\347"V\203\370\274\352\372v\13g\254.\30`W"C}T\324S\336\346\36k?\346qGu\327\232\2504\334\371\317\220\322!*\262\337&? \177-f\353Glw\320\314\25C[\342\314\324~\203\17\230#l\360DH\7v\344\344\372e\17U\274\5\1\350\300@\177/\24\367\372\364\241\273-\236?\217'1\343>xB\220\243}\350\235V\342~%\30vx\226\332``\227f>\32\377\235\204\314or\202\347\33)D0\305k\223\306\377\27c\33dx\335D\340\327{L\325~\362\252+\205\317\325DD\36&\211\267e\353\266\373$\36'\347\245\301~:\2476\316\247\232", ) Q\243\316V\337\\345\227\27{\372\216\2111<\223\275\341=\21\301r\251_\371\277\211v!\16\310A#\224\362\222\5\240\270t\242X\2269f\252\30\\314\224\24x\21\215)}\217\347 ... {status=0x0, info=256}, "$#\362H\274\306\360\25>\270\260\237\3455"Q\243\316V\337\\345\227\27{\372\216\2111<\223\275\341=\21\301r\251_\371\277\211v!\16\310A#\224\362\222\5\240\270t\242X\2269f\252\30\\314\224\24x\21\215)}\217\347"V\203\370\274\352\372v\13g\254.\30`W"C}T\324S\336\346\36k?\346qGu\327\232\2504\334\371\317\220\322!*\262\337&? \177-f\353Glw\320\314\25C[\342\314\324~\203\17\230#l\360DH\7v\344\344\372e\17U\274\5\1\350\300@\177/\24\367\372\364\241\273-\236?\217'1\343>xB\220\243}\350\235V\342~%\30vx\226\332``\227f>\32\377\235\204\314or\202\347\33)D0\305k\223\306\377\27c\33dx\335D\340\327{L\325~\362\252+\205\317\325DD\36&\211\267e\353\266\373$\36'\347\245\301~:\2476\316\247\232", ) C}T\324S\336\346\36k?\346qGu\327\232\2504\334\371\317\220\322!*\262\337&? \177-f\353Glw\320\314\25C[\342\314\324~\203\17\230#l\360DH\7v\344\344\372e\17U\274\5\1\350\300@\177/\24\367\372\364\241\273-\236?\217'1\343>xB\220\243}\350\235V\342~%\30vx\226\332``\227f>\32\377\235\204\314or\202\347\33)D0\305k\223\306\377\27c\33dx\335D\340\327{L\325~\362\252+\205\317\325DD\36&\211\267e\353\266\373$\36'\347\245\301~:\2476\316\247\232", ) == 0x0
00961 1740 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\235\372y\306\314\301\202.N\313;\6.@r\373:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\305\223:n/\274\207\270!\300TW\323x\226\16\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ...
00962 1740 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0
00963 1740 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0
00964 1740 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0
00965 1740 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0
00966 1740 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0
00967 1740 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0
00968 1740 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH
00969 1740 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0
00970 1740 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, ")\310\12\327\227~\323\356\211\225\233\223=\233\276\226\210\271n\320}h\276\15\17\326\U\345\10\326\32\316\345|\241\263\353%@\212\263\304\15\236C\277\375\334\320\222p'\371\312\177\330C\333\354\306\3368\340\253#\371\224Y, 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, ")\310\12\327\227~\323\356\211\225\233\223=\233\276\226\210\271n\320}h\276\15\17\326\U\345\10\326\32\316\345|\241\263\353%@\212\263\304\15\236C\277\375\334\320\222p'\371\312\177\330C\333\354\306\3368\340\253#\371\224Y, 80, ... ) , 80, ... ) == 0x0
00971 1740 NtClose (-2147482740, ... ) == 0x0
00961 1740 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "H~\237\14\213y\25\230\36\3062@\200I.\225\222\254\344\26s\313G\263\342\377\271b\340LvO\270\375\362\302\36\206WD\2437c\211?\3478\16Q0\16 U\245\226\177\315\233\342Z\324\205XO\205!\34\211l|\17\353\226\177\3\246\206&(\327*\344z\263\205s\357\377\237\376\2#\355zm\345N\321Dbu\264\215)\202\210\365\325\313P[%B\346o\313\23\210\32$f\324R&\301}u\352\322\270\312\376\342b\242\363\232\207\216/\274\324/`w\363\315l\337\33G\4\6\221l\365ryD\24\276\14D\276d~\37[A-\200-\37\322n\200\22\216\342\35e\237y\323!\2447\363\367\240c?\214\326\362s\320%\347\311?\16@\20S\347\252\244\24\334\34s%\14\241\241_E"\343o1\302\335\234t\20\377\351v\212~\334\344\232\3416tub\215\224#_$+\340T\17`\206M\312q\332\250", ) \343o1\302\335\234t\20\377\351v\212~\334\344\232\3416tub\215\224#_$+\340T\17`\206M\312q\332\250", ) == 0x0
00972 1740 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 124, ) == 0x0
00973 1740 NtConnectPort ( ("\RPC Control\IcaApi", {12, 2, 1, 0}, 0x0, 0x0, 1234748, 188, ... 128, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 0}, 0x0, 0x0, 1234748, 188, ... 128, 0x0, 0x0, 0x0, 188, ) == 0x0
00974 1740 NtRequestWaitReplyPort (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} "\0\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\08\232\24\0\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\234]a\364\310\367\16g\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\234q\4\307x\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 928, 1740, 57977, 0} "\7\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\234]a\364\310\367\16g\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\234q\4\307x\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ... {200, 224, reply, 0, 928, 1740, 57977, 0} (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} "\0\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\08\232\24\0\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\234]a\364\310\367\16g\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\234q\4\307x\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 928, 1740, 57977, 0} "\7\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\234]a\364\310\367\16g\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\234q\4\307x\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0
00975 1740 NtRequestWaitReplyPort (128, {32, 56, new_msg, 0, 0, 0, 0, 0} (128, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 928, 1740, 57978, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ... {124, 148, reply, 0, 928, 1740, 57978, 0} (128, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 928, 1740, 57978, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ) == 0x0
00976 1740 NtAllocateVirtualMemory (-1, 1351680, 0, 4096, 4096, 4, ... 1351680, 4096, ) == 0x0
00977 1740 NtRequestWaitReplyPort (128, {44, 68, new_msg, 56, 928, 1740, 57978, 0} (128, {44, 68, new_msg, 56, 928, 1740, 57978, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 928, 1740, 57979, 0} "\2\31\221|\4\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 928, 1740, 57979, 0} (128, {44, 68, new_msg, 56, 928, 1740, 57978, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 928, 1740, 57979, 0} "\2\31\221|\4\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\14\5\0\0\320\371\15\0" ) ) == 0x0
00978 1740 NtRequestWaitReplyPort (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 928, 1740, 57980, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 928, 1740, 57980, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 928, 1740, 57980, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0
00979 1740 NtRequestWaitReplyPort (128, {44, 68, new_msg, 56, 928, 1740, 57979, 0} (128, {44, 68, new_msg, 56, 928, 1740, 57979, 0} "\1\31\0\0B\2\5\0\200\300\227|p\31\221|\250$\12\0\330\0\0\0\377\377\377\377\0\300\372\177\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 928, 1740, 57981, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 928, 1740, 57981, 0} (128, {44, 68, new_msg, 56, 928, 1740, 57979, 0} "\1\31\0\0B\2\5\0\200\300\227|p\31\221|\250$\12\0\330\0\0\0\377\377\377\377\0\300\372\177\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 928, 1740, 57981, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ) == 0x0
00980 1740 NtRequestWaitReplyPort (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 928, 1740, 57982, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 928, 1740, 57982, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 928, 1740, 57982, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0
00981 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 132, ) }, ... 132, ) == 0x0
00982 1740 NtOpenKey (0x20019, {24, 132, 0x40, 0, 0, (0x20019, {24, 132, 0x40, 0, 0, "ActiveComputerName"}, ... 136, ) }, ... 136, ) == 0x0
00983 1740 NtQueryValueKey (136, (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0
00984 1740 NtClose (136, ... ) == 0x0
00985 1740 NtClose (132, ... ) == 0x0
00986 1740 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 132, ) == 0x0
00987 1740 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 136, ) == 0x0
00988 1740 NtDuplicateObject (-1, 132, -1, 0x0, 0, 2, ... 140, ) == 0x0
00989 1740 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN
00990 1740 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 144, ) == 0x0
00991 1740 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN
00992 1740 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0
00993 1740 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234784, (0xc0100080, {24, 0, 0x40, 0, 1234784, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 148, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 148, {status=0x0, info=1}, ) == 0x0
00994 1740 NtSetInformationFile (148, 1234840, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0
00995 1740 NtSetInformationFile (148, 1234828, 8, Completion, ... {status=0x0, info=0}, ) == 0x0
00996 1740 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0
00997 1740 NtWriteFile (148, 117, 0, 0, (148, 117, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0
00998 1740 NtReadFile (148, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (148, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0
00999 1740 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103
01000 1740 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , ) == 0x103
01001 1740 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103
01002 1740 NtClose (144, ... ) == 0x0
01003 1740 NtClose (148, ... ) == 0x0
01004 1740 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN
01005 1740 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 148, ) == 0x0
01006 1740 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN
01007 1740 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0
01008 1740 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234756, (0xc0100080, {24, 0, 0x40, 0, 1234756, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 144, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 144, {status=0x0, info=1}, ) == 0x0
01009 1740 NtSetInformationFile (144, 1234812, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0
01010 1740 NtSetInformationFile (144, 1234800, 8, Completion, ... {status=0x0, info=0}, ) == 0x0
01011 1740 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0
01012 1740 NtWriteFile (144, 117, 0, 0, (144, 117, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0
01013 1740 NtReadFile (144, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (144, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0
01014 1740 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\14\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\14\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103
01015 1740 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , ) == 0x103
01016 1740 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103
01017 1740 NtClose (148, ... ) == 0x0
01018 1740 NtClose (144, ... ) == 0x0
01019 1740 NtOpenProcessToken (-1, 0x20008, ... 144, ) == 0x0
01020 1740 NtQueryInformationToken (144, User, 0, ... ) == STATUS_BUFFER_TOO_SMALL
01021 1740 NtQueryInformationToken (144, User, 36, ... {token info, class 1, size 36}, 36, ) == 0x0
01022 1740 NtOpenDirectoryObject (0x2, {24, 0, 0x40, 0, 0, (0x2, {24, 0, 0x40, 0, 0, "\Windows\WindowStations"}, ... 148, ) }, ... 148, ) == 0x0
01023 1740 NtUserOpenWindowStation ({24, 148, 0x40, 0, 0, ({24, 148, 0x40, 0, 0, "winsta0"}, 0x37f, ... ) }, 0x37f, ... ) == 0x98
01024 1740 NtClose (148, ... ) == 0x0
01025 1740 NtUserCloseWindowStation (152, ...
01026 1740 NtClose (152, ... ) == 0x0
01025 1740 NtUserCloseWindowStation ... ) == 0x1
01027 1740 NtClose (144, ... ) == 0x0
01028 1740 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 144, ) == 0x0
01029 1740 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 152, ) == 0x0
01030 1740 NtCreateMutant (0x1f0001, {24, 0, 0x2, 0, 0, 0x0}, 0, ... 148, ) == 0x0
01031 1740 NtDuplicateObject (-1, -1, -1, 0x1f0fff, 2, 0, ... 156, ) == 0x0
01032 1740 NtCreateSection (0xf0007, {24, 0, 0x2, 0, 0, 0x0}, {7248, 0}, 4, 134217728, 0, ... 160, ) == 0x0
01033 1740 NtMapViewOfSection (160, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3d0000), {0, 0}, 8192, ) == 0x0
01034 1740 NtQueryDefaultUILanguage (1235448, ...
01035 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01036 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0
01037 1740 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01038 1740 NtClose (-2147482740, ... ) == 0x0
01039 1740 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0
01040 1740 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01041 1740 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0
01042 1740 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01043 1740 NtClose (-2147481328, ... ) == 0x0
01044 1740 NtClose (-2147482740, ... ) == 0x0
01034 1740 NtQueryDefaultUILanguage ... ) == 0x0
01045 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01046 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01047 1740 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0
01048 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233692, ... ) }, 1233692, ... ) == 0x0
01049 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232464, ... ) }, 1232464, ... ) == 0x0
01050 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01051 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01052 1740 NtCreateFile (0x10100080, {24, 0, 0x40, 0, 1234800, (0x10100080, {24, 0, 0x40, 0, 1234800, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\bce_appcompat.txt"}, 0x0, 128, 0, 2, 96, 0, 0, ... }, 0x0, 128, 0, 2, 96, 0, 0, ...
01053 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0
01054 1740 NtClose (-2147482740, ... ) == 0x0
01055 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0
01056 1740 NtClose (-2147482740, ... ) == 0x0
01057 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0
01058 1740 NtClose (-2147482740, ... ) == 0x0
01052 1740 NtCreateFile ... 164, {status=0x0, info=2}, ) == 0x0
01059 1740 NtClose (164, ... ) == 0x0
01060 1740 NtCreateSection (0xf001f, 0x0, {4194304, 0}, 4, 67108864, 0, ... 164, ) == 0x0
01061 1740 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 4194304, 2, 0, 4, ... (0xa90000), 0x0, 4194304, ) == 0x0
01062 1740 NtAllocateVirtualMemory (-1, 11075584, 0, 1, 4096, 4, ... 11075584, 4096, ) == 0x0
01063 1740 NtAllocateVirtualMemory (-1, 11079680, 0, 1968, 4096, 4, ... 11079680, 4096, ) == 0x0
01064 1740 NtCreateSection (0xf0007, 0x0, {22396, 0}, 4, 134217728, 0, ... 168, ) == 0x0
01065 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01066 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01067 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01068 1740 NtClose (164, ... ) == 0x0
01069 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01070 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01071 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01072 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01073 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01074 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01075 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01076 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01077 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01078 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01079 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01080 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01081 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01082 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01083 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01084 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01085 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01086 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01087 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01088 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01089 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01090 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01091 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01092 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01093 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01094 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01095 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01096 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01097 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01098 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01099 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01100 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01101 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01102 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01103 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01104 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01105 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01106 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01107 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01108 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01109 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01110 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01111 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01112 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01113 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0
01114 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01115 1740 NtClose (168, ... ) == 0x0
01116 1740 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0
01117 1740 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\u:"}, 3, 96, ... 168, {status=0x0, info=1}, ) }, 3, 96, ... 168, {status=0x0, info=1}, ) == 0x0
01118 1740 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\u:"}, ... 164, ) }, ... 164, ) == 0x0
01119 1740 NtQuerySymbolicLinkObject (164, ... (164, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0
01120 1740 NtClose (164, ... ) == 0x0
01121 1740 NtQueryVolumeInformationFile (168, 1234016, 8, Device, ... {status=0x0, info=8}, ) == 0x0
01122 1740 NtClose (168, ... ) == 0x0
01123 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1232812, ... ) }, 1232812, ... ) == 0x0
01124 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 168, {status=0x0, info=1}, ) }, 5, 96, ... 168, {status=0x0, info=1}, ) == 0x0
01125 1740 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 168, ... 164, ) == 0x0
01126 1740 NtClose (168, ... ) == 0x0
01127 1740 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x3e0000), 0x0, 126976, ) == 0x0
01128 1740 NtClose (164, ... ) == 0x0
01129 1740 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0
01130 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1233120, ... ) }, 1233120, ... ) == 0x0
01131 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 164, {status=0x0, info=1}, ) }, 5, 96, ... 164, {status=0x0, info=1}, ) == 0x0
01132 1740 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 164, ... 168, ) == 0x0
01133 1740 NtQuerySection (168, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0
01134 1740 NtClose (164, ... ) == 0x0
01135 1740 NtMapViewOfSection (168, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0
01136 1740 NtClose (168, ... ) == 0x0
01137 1740 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0
01138 1740 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0
01139 1740 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0
01140 1740 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01141 1740 NtAllocateVirtualMemory (-1, 1355776, 0, 12288, 4096, 4, ... 1355776, 12288, ) == 0x0
01142 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1234508, ... ) }, 1234508, ... ) == 0x0
01143 1740 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234516, (0x40100080, {24, 0, 0x40, 0, 1234516, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\bce_appcompat.txt"}, 0x0, 128, 0, 5, 96, 0, 0, ... }, 0x0, 128, 0, 5, 96, 0, 0, ...
01144 1740 NtClose (-2147482740, ... ) == 0x0
01145 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0
01146 1740 NtClose (-2147482740, ... ) == 0x0
01147 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0
01148 1740 NtClose (-2147482740, ... ) == 0x0
01149 1740 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0
01150 1740 NtClose (-2147482740, ... ) == 0x0
01143 1740 NtCreateFile ... 168, {status=0x0, info=3}, ) == 0x0
01151 1740 NtAllocateVirtualMemory (-1, 1368064, 0, 12288, 4096, 4, ... 1368064, 12288, ) == 0x0
01152 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 164, {status=0x0, info=1}, ) }, 3, 16417, ... 164, {status=0x0, info=1}, ) == 0x0
01153 1740 NtQueryDirectoryFile (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, "packed.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0
01154 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "\377\376", 2, 0x0, 0, ... {status=0x0, info=2}, ) , 2, 0x0, 0, ... {status=0x0, info=2}, ) == 0x0
01155 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \01\0.\00\0 (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \0U\0T\0F\0-\01\06\0 (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) , 106, 0x0, 0, ... {status=0x0, info=106}, ) == 0x0
01156 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) , 122, 0x0, 0, ... {status=0x0, info=122}, ) == 0x0
01157 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233600, ... ) }, 1233600, ... ) == 0x0
01158 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work"}, 3, 16417, ... 172, {status=0x0, info=1}, ) }, 3, 16417, ... 172, {status=0x0, info=1}, ) == 0x0
01159 1740 NtQueryDirectoryFile (172, 0, 0, 0, 1233212, 592, Directory, 1, (172, 0, 0, 0, 1233212, 592, Directory, 1, "packed.exe", 0, ... {status=0x0, info=84}, ) , 0, ... {status=0x0, info=84}, ) == 0x0
01160 1740 NtClose (172, ... ) == 0x0
01161 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01162 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01163 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232132, ... ) }, 1232132, ... ) == 0x0
01164 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1230904, ... ) }, 1230904, ... ) == 0x0
01165 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01166 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01167 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) == 0x0
01168 1740 NtQueryInformationFile (172, 1233688, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01169 1740 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 172, ... 176, ) == 0x0
01170 1740 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 188416, ) == 0x0
01171 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01172 1740 NtClose (176, ... ) == 0x0
01173 1740 NtClose (172, ... ) == 0x0
01174 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\08\05\03\04\04\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\01\03\08\07\07\0E\01\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \0W\0I\0N\03\02\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\02\09\04\0A\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\00\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\08\05\03\04\04\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... , 418, 0x0, 0, ...
01175 1740 NtContinue (-106648108, 0, ...
01174 1740 NtWriteFile ... {status=0x0, info=418}, ) == 0x0
01176 1740 NtQueryDirectoryFile (164, 0, 0, 0, 1371248, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES
01177 1740 NtClose (164, ... ) == 0x0
01178 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0", 16, 0x0, 0, ... {status=0x0, info=16}, ) , 16, 0x0, 0, ... {status=0x0, info=16}, ) == 0x0
01179 1740 NtClose (168, ... ) == 0x0
01180 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1234508, ... ) }, 1234508, ... ) == 0x0
01181 1740 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234516, (0x40100080, {24, 0, 0x40, 0, 1234516, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\bce_appcompat.txt"}, 0x0, 128, 0, 3, 96, 0, 0, ... 168, {status=0x0, info=1}, ) }, 0x0, 128, 0, 3, 96, 0, 0, ... 168, {status=0x0, info=1}, ) == 0x0
01182 1740 NtQueryInformationFile (168, 1234540, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01183 1740 NtSetInformationFile (168, 1234572, 8, Position, ... {status=0x0, info=0}, ) == 0x0
01184 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 164, {status=0x0, info=1}, ) }, 3, 16417, ... 164, {status=0x0, info=1}, ) == 0x0
01185 1740 NtQueryDirectoryFile (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, "kernel32.dll", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0
01186 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) , 126, 0x0, 0, ... {status=0x0, info=126}, ) == 0x0
01187 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1233572, ... ) }, 1233572, ... ) == 0x0
01188 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 3, 16417, ... 172, {status=0x0, info=1}, ) }, 3, 16417, ... 172, {status=0x0, info=1}, ) == 0x0
01189 1740 NtQueryDirectoryFile (172, 0, 0, 0, 1233212, 592, Directory, 1, (172, 0, 0, 0, 1233212, 592, Directory, 1, "kernel32.dll", 0, ... {status=0x0, info=88}, ) , 0, ... {status=0x0, info=88}, ) == 0x0
01190 1740 NtClose (172, ... ) == 0x0
01191 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01192 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01193 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232132, ... ) }, 1232132, ... ) == 0x0
01194 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230904, ... ) }, 1230904, ... ) == 0x0
01195 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01196 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01197 1740 NtQueryDefaultLocale (1, 1233092, ... ) == 0x0
01198 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01199 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01200 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232124, ... ) }, 1232124, ... ) == 0x0
01201 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230896, ... ) }, 1230896, ... ) == 0x0
01202 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01203 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01204 1740 NtQueryDefaultLocale (1, 1233084, ... ) == 0x0
01205 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) == 0x0
01206 1740 NtQueryInformationFile (172, 1233688, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01207 1740 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 172, ... 176, ) == 0x0
01208 1740 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 987136, ) == 0x0
01209 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01210 1740 NtClose (176, ... ) == 0x0
01211 1740 NtClose (172, ... ) == 0x0
01212 1740 NtQueryDefaultUILanguage (1233044, ...
01213 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01214 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0
01215 1740 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01216 1740 NtClose (-2147482740, ... ) == 0x0
01217 1740 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0
01218 1740 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01219 1740 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0
01220 1740 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01221 1740 NtClose (-2147481328, ... ) == 0x0
01222 1740 NtClose (-2147482740, ... ) == 0x0
01212 1740 NtQueryDefaultUILanguage ... ) == 0x0
01223 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \09\08\04\05\07\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \00\0x\0F\00\0B\03\03\01\0F\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) == 0x0
01224 1740 NtQueryDirectoryFile (164, 0, 0, 0, 1362544, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES
01225 1740 NtClose (164, ... ) == 0x0
01226 1740 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0<\0/\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 42, 0x0, 0, ... {status=0x0, info=42}, ) , 42, 0x0, 0, ... {status=0x0, info=42}, ) == 0x0
01227 1740 NtClose (168, ... ) == 0x0
01228 1740 NtUnmapViewOfSection (-1, 0x77b40000, ... ) == 0x0
01229 1740 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED
01230 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1231780, ... ) }, 1231780, ... ) == 0x0
01231 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1232516, ... ) }, 1232516, ... ) == 0x0
01232 1740 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 168, {status=0x0, info=1}, ) }, 5, 96, ... 168, {status=0x0, info=1}, ) == 0x0
01233 1740 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 168, ... 164, ) == 0x0
01234 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01235 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 172, ) }, ... 172, ) == 0x0
01236 1740 NtQueryValueKey (172, (172, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01237 1740 NtClose (172, ... ) == 0x0
01238 1740 NtQueryVolumeInformationFile (168, 1231792, 8, Device, ... {status=0x0, info=8}, ) == 0x0
01239 1740 NtOpenMutant (0x120001, {24, 48, 0x0, 0, 0, (0x120001, {24, 48, 0x0, 0, 0, "ShimCacheMutex"}, ... 172, ) }, ... 172, ) == 0x0
01240 1740 NtWaitForSingleObject (172, 0, {-1000000, -1}, ... ) == 0x0
01241 1740 NtOpenSection (0x2, {24, 48, 0x0, 0, 0, (0x2, {24, 48, 0x0, 0, 0, "ShimSharedMemory"}, ... 176, ) }, ... 176, ) == 0x0
01242 1740 NtMapViewOfSection (176, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 57344, ) == 0x0
01243 1740 NtReleaseMutant (172, ... 0x0, ) == 0x0
01244 1740 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0
01245 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1229724, ... ) }, 1229724, ... ) == 0x0
01246 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 180, {status=0x0, info=1}, ) }, 5, 96, ... 180, {status=0x0, info=1}, ) == 0x0
01247 1740 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 180, ... 184, ) == 0x0
01248 1740 NtClose (180, ... ) == 0x0
01249 1740 NtMapViewOfSection (184, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa90000), 0x0, 126976, ) == 0x0
01250 1740 NtClose (184, ... ) == 0x0
01251 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01252 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1230032, ... ) }, 1230032, ... ) == 0x0
01253 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 184, {status=0x0, info=1}, ) }, 5, 96, ... 184, {status=0x0, info=1}, ) == 0x0
01254 1740 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 184, ... 180, ) == 0x0
01255 1740 NtQuerySection (180, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0
01256 1740 NtClose (184, ... ) == 0x0
01257 1740 NtMapViewOfSection (180, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0
01258 1740 NtClose (180, ... ) == 0x0
01259 1740 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0
01260 1740 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0
01261 1740 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0
01262 1740 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01263 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 180, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 180, {status=0x0, info=1}, ) == 0x0
01264 1740 NtQueryInformationFile (180, 1230048, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01265 1740 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 180, ... 184, ) == 0x0
01266 1740 NtMapViewOfSection (184, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 1191936, ) == 0x0
01267 1740 NtQueryInformationFile (180, 1230148, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01268 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01269 1740 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0
01270 1740 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0
01271 1740 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01272 1740 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 188, ) }, ... 188, ) == 0x0
01273 1740 NtQueryValueKey (188, (188, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (188, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01274 1740 NtClose (188, ... ) == 0x0
01275 1740 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01276 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01277 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1227744, 616, BothDirectory, 1, (188, 0, 0, 0, 1227744, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0
01278 1740 NtClose (188, ... ) == 0x0
01279 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01280 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01281 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228120, ... ) }, 1228120, ... ) == 0x0
01282 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01283 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0
01284 1740 NtClose (188, ... ) == 0x0
01285 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01286 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0
01287 1740 NtClose (188, ... ) == 0x0
01288 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01289 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0
01290 1740 NtClose (188, ... ) == 0x0
01291 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01292 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01293 1740 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0
01294 1740 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01295 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01296 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0
01297 1740 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01298 1740 NtClose (188, ... ) == 0x0
01299 1740 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01300 1740 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01301 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228952, ... ) }, 1228952, ... ) == 0x0
01302 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01303 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01304 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227820, ... ) }, 1227820, ... ) == 0x0
01305 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 188, {status=0x0, info=1}, ) }, 5, 96, ... 188, {status=0x0, info=1}, ) == 0x0
01306 1740 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 188, ... 192, ) == 0x0
01307 1740 NtClose (188, ... ) == 0x0
01308 1740 NtMapViewOfSection (192, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xbc0000), 0x0, 180224, ) == 0x0
01309 1740 NtClose (192, ... ) == 0x0
01310 1740 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0
01311 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227416, ... ) }, 1227416, ... ) == 0x0
01312 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228160, (0x80100080, {24, 0, 0x40, 0, 1228160, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) == 0x0
01313 1740 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 192, ... 188, ) == 0x0
01314 1740 NtClose (192, ... ) == 0x0
01315 1740 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xbc0000), {0, 0}, 180224, ) == 0x0
01316 1740 NtClose (188, ... ) == 0x0
01317 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01318 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01319 1740 NtQueryDefaultLocale (1, 1228780, ... ) == 0x0
01320 1740 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0
01321 1740 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0
01322 1740 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0
01323 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01324 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01325 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227812, ... ) }, 1227812, ... ) == 0x0
01326 1740 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 188, {status=0x0, info=1}, ) }, 5, 96, ... 188, {status=0x0, info=1}, ) == 0x0
01327 1740 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 188, ... 192, ) == 0x0
01328 1740 NtClose (188, ... ) == 0x0
01329 1740 NtMapViewOfSection (192, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xbc0000), 0x0, 180224, ) == 0x0
01330 1740 NtClose (192, ... ) == 0x0
01331 1740 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0
01332 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227408, ... ) }, 1227408, ... ) == 0x0
01333 1740 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228152, (0x80100080, {24, 0, 0x40, 0, 1228152, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) == 0x0
01334 1740 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 192, ... 188, ) == 0x0
01335 1740 NtClose (192, ... ) == 0x0
01336 1740 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xbc0000), {0, 0}, 180224, ) == 0x0
01337 1740 NtClose (188, ... ) == 0x0
01338 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01339 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01340 1740 NtQueryDefaultLocale (1, 1228772, ... ) == 0x0
01341 1740 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0
01342 1740 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0
01343 1740 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01344 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01345 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0
01346 1740 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01347 1740 NtClose (188, ... ) == 0x0
01348 1740 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01349 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01350 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01351 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1229372, ... ) }, 1229372, ... ) == 0x0
01352 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01353 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0
01354 1740 NtClose (188, ... ) == 0x0
01355 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01356 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0
01357 1740 NtClose (188, ... ) == 0x0
01358 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01359 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0
01360 1740 NtClose (188, ... ) == 0x0
01361 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01362 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01363 1740 NtWaitForSingleObject (172, 0, {-1000000, -1}, ... ) == 0x0
01364 1740 NtReleaseMutant (172, ... 0x0, ) == 0x0
01365 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01366 1740 NtClose (184, ... ) == 0x0
01367 1740 NtClose (180, ... ) == 0x0
01368 1740 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN
01369 1740 NtOpenProcessToken (-1, 0xa, ... 180, ) == 0x0
01370 1740 NtQueryInformationToken (180, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0
01371 1740 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01372 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0
01373 1740 NtQueryValueKey (184, (184, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (184, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0
01374 1740 NtQueryValueKey (184, (184, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (184, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01375 1740 NtClose (184, ... ) == 0x0
01376 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01377 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0
01378 1740 NtQueryValueKey (184, (184, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01379 1740 NtClose (184, ... ) == 0x0
01380 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01381 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01382 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01383 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01384 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01385 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01386 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01387 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01388 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01389 1740 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0
01390 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 184, ) }, ... 184, ) == 0x0
01391 1740 NtEnumerateKey (184, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (184, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0
01392 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 188, ) }, ... 188, ) == 0x0
01393 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0
01394 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01395 1740 NtClose (188, ... ) == 0x0
01396 1740 NtEnumerateKey (184, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES
01397 1740 NtClose (184, ... ) == 0x0
01398 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 184, ) }, ... 184, ) == 0x0
01399 1740 NtEnumerateKey (184, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0
01400 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 188, ) }, ... 188, ) == 0x0
01401 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0
01402 1740 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0
01403 1740 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0
01404 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01405 1740 NtClose (188, ... ) == 0x0
01406 1740 NtEnumerateKey (184, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0
01407 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 188, ) }, ... 188, ) == 0x0
01408 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0
01409 1740 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0
01410 1740 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0
01411 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01412 1740 NtClose (188, ... ) == 0x0
01413 1740 NtEnumerateKey (184, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0
01414 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 188, ) }, ... 188, ) == 0x0
01415 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0
01416 1740 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0
01417 1740 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0
01418 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01419 1740 NtClose (188, ... ) == 0x0
01420 1740 NtEnumerateKey (184, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0
01421 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 188, ) }, ... 188, ) == 0x0
01422 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0
01423 1740 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0
01424 1740 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0
01425 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01426 1740 NtClose (188, ... ) == 0x0
01427 1740 NtEnumerateKey (184, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0
01428 1740 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 188, ) }, ... 188, ) == 0x0
01429 1740 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0
01430 1740 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0
01431 1740 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0
01432 1740 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01433 1740 NtClose (188, ... ) == 0x0
01434 1740 NtEnumerateKey (184, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES
01435 1740 NtClose (184, ... ) == 0x0
01436 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01437 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01438 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01439 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01440 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01441 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01442 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01443 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01444 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01445 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01446 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01447 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01448 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01449 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01450 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01451 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01452 1740 NtClose (184, ... ) == 0x0
01453 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01454 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01455 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01456 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01457 1740 NtClose (184, ... ) == 0x0
01458 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01459 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01460 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01461 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01462 1740 NtClose (184, ... ) == 0x0
01463 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01464 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01465 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01466 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01467 1740 NtClose (184, ... ) == 0x0
01468 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01469 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01470 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01471 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01472 1740 NtClose (184, ... ) == 0x0
01473 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01474 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01475 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01476 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01477 1740 NtClose (184, ... ) == 0x0
01478 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01479 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01480 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01481 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01482 1740 NtClose (184, ... ) == 0x0
01483 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01484 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01485 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01486 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01487 1740 NtClose (184, ... ) == 0x0
01488 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01489 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01490 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01491 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01492 1740 NtClose (184, ... ) == 0x0
01493 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01494 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01495 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01496 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01497 1740 NtClose (184, ... ) == 0x0
01498 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01499 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01500 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01501 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01502 1740 NtClose (184, ... ) == 0x0
01503 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01504 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01505 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01506 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01507 1740 NtClose (184, ... ) == 0x0
01508 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01509 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01510 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01511 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01512 1740 NtClose (184, ... ) == 0x0
01513 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01514 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01515 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01516 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01517 1740 NtClose (184, ... ) == 0x0
01518 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01519 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01520 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01521 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01522 1740 NtClose (184, ... ) == 0x0
01523 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01524 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0
01525 1740 NtQueryValueKey (184, (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0
01526 1740 NtClose (184, ... ) == 0x0
01527 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01528 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0
01529 1740 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01530 1740 NtClose (184, ... ) == 0x0
01531 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01532 1740 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN
01533 1740 NtOpenProcessToken (-1, 0xa, ... 184, ) == 0x0
01534 1740 NtDuplicateToken (184, 0xc, {24, 0, 0x0, 0, 1231652, 0x0}, 0, 2, ... 188, ) == 0x0
01535 1740 NtClose (184, ... ) == 0x0
01536 1740 NtAccessCheck (1379984, 188, 0x1, 1231728, 1231780, 56, 1231760, ... (0x1), ) == 0x0
01537 1740 NtClose (188, ... ) == 0x0
01538 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 188, ) }, ... 188, ) == 0x0
01539 1740 NtQueryValueKey (188, (188, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (188, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0
01540 1740 NtClose (188, ... ) == 0x0
01541 1740 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 188, ) }, ... 188, ) == 0x0
01542 1740 NtQuerySymbolicLinkObject (188, ... (188, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0
01543 1740 NtClose (188, ... ) == 0x0
01544 1740 NtQueryVolumeInformationFile (168, 1229484, 8, Device, ... {status=0x0, info=8}, ) == 0x0
01545 1740 NtQueryInformationFile (168, 1229600, 528, Name, ... {status=0x0, info=58}, ) == 0x0
01546 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01547 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01548 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228772, ... ) }, 1228772, ... ) == 0x0
01549 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01550 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0
01551 1740 NtClose (188, ... ) == 0x0
01552 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01553 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0
01554 1740 NtClose (188, ... ) == 0x0
01555 1740 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0
01556 1740 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0
01557 1740 NtClose (188, ... ) == 0x0
01558 1740 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0
01559 1740 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01560 1740 NtQueryInformationFile (168, 1231640, 24, Standard, ... {status=0x0, info=24}, ) == 0x0
01561 1740 NtCreateSection (0xf0005, 0x0, {180224, 0}, 2, 134217728, 168, ... 188, ) == 0x0
01562 1740 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 180224, 1, 0, 2, ... (0xa90000), {0, 0}, 180224, ) == 0x0
01563 1740 NtClose (188, ... ) == 0x0
01564 1740 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN
01565 1740 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0
01566 1740 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0
01567 1740 NtClose (188, ... ) == 0x0
01568 1740 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 188, ) }, ... 188, ) == 0x0
01569 1740 NtOpenKey (0x20019, {24, 188, 0x40, 0, 0, (0x20019, {24, 188, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 184, ) }, ... 184, ) == 0x0
01570 1740 NtClose (188, ... ) == 0x0
01571 1740 NtQueryValueKey (184, (184, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW
01572 1740 NtQueryValueKey (184, (184, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (184, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0
01573 1740 NtClose (184, ... ) == 0x0
01574 1740 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0
01575 1740 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 4128768, 4096, ) == 0x0
01576 1740 NtAllocateVirtualMemory (-1, 4128768, 0, 4096, 4096, 4, ... 4128768, 4096, ) == 0x0
01577 1740 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0
01578 1740 NtQueryValueKey (184, (184, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01579 1740 NtClose (184, ... ) == 0x0
01580 1740 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01581 1740 NtQueryInformationToken (180, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0
01582 1740 NtQueryInformationToken (180, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0
01583 1740 NtClose (180, ... ) == 0x0
01584 1740 NtQuerySection (164, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0
01585 1740 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01586 1740 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0
01587 1740 NtCreateProcessEx (1233564, 2035711, 0, -1, 4, 164, 0, 0, 0, ... ) == 0x0
01588 1740 NtSetInformationProcess (180, PriorityClass, {process info, class 18, size 2}, 512, ... ) == 0x0
01589 1740 NtSetInformationProcess (180, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0
01590 1740 NtQueryInformationProcess (180, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffde000,AffinityMask=0x1,BasePriority=8,Pid=484,ParentPid=928,}, 0x0, ) == 0x0
01591 1740 NtReadVirtualMemory (180, 0x7ffde008, 4, ... (180, 0x7ffde008, 4, ... "\0\0\00", 0x0, ) , 0x0, ) == 0x0
01592 1740 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01593 1740 NtReadVirtualMemory (180, 0x30000000, 4096, ... (180, 0x30000000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0$\206\244\23`\347\312@`\347\312@`\347\312@9\304\331@b\347\312@`\347\313@d\347\312@\210\370\301@a\347\312@\343\373\304@j\347\312@\210\370\300@I\347\312@6\370\331@h\347\312@\272\304\326@i\347\312@\220\370\301@p\347\312@`\347\312@H\346\312@Rich`\347\312@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0N\23\216?\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\24\0\220\2\0\0\240\0\0\0\0\0\0\232t\0\0\0\20\0\0\0\320\3\0\0\0\00\0\20\0\0\0\20\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0@\3\0\0\20\0\0\237*\3\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\327\211\2\0z\1\0\0\00\3\0\244\12\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Z\236\2\08\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0`\2\0\0\370\0\0\0\0\20\0\0\270\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\222\216\2\0", 4096, ) , 4096, ) == 0x0
01594 1740 NtReadVirtualMemory (180, 0x30033000, 256, ... (180, 0x30033000, 256, ... "\0\0\0\0J\23\216?\0\0\0\0\0\0\3\0\5\0\0\0(\0\0\200\13\0\0\0@\0\0\200\20\0\0\0X\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0e\0\0\0p\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\210\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\240\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\270\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\310\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\330\0\0\0\3600\3\0\26\3\0\0\0\0\0\0\0\0\0\0\104\3\0\254\1\0\0\0\0\0\0\0\0\0\0\2645\3\0\360\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\0\310\200\0\0\0\0\14\0\0\0\0\0f\1", 256, ) , 256, ) == 0x0
01595 1740 NtQueryDebugFilterState (53, 2, ... ) == 0x0
01596 1740 NtQueryInformationProcess (180, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffde000,AffinityMask=0x1,BasePriority=8,Pid=484,ParentPid=928,}, 0x0, ) == 0x0
01597 1740 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 1232516, ... ) }, 1232516, ... ) == 0x0
01598 1740 NtAllocateVirtualMemory (-1, 0, 0, 2428, 4096, 4, ... 11075584, 4096, ) == 0x0
01599 1740 NtAllocateVirtualMemory (180, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0
01600 1740 NtWriteVirtualMemory (180, 0x10000, (180, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0
01601 1740 NtAllocateVirtualMemory (180, 0, 0, 2428, 4096, 4, ... 131072, 4096, ) == 0x0
01602 1740 NtWriteVirtualMemory (180, 0x20000, (180, 0x20000, "\0\20\0\0|\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\0\0\0\0\13\0\0\0&\0\10\2\220\2\0\0\16\0\0\0\364\3\366\3\230\4\0\0:\0<\0\220\10\0\0N\0P\0\314\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\0<\0\34\11\0\0\36\0 \0X\11\0\0\0\0\2\0x\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2428, ... 0x0, ) , 2428, ... 0x0, ) == 0x0
01603 1740 NtWriteVirtualMemory (180, 0x7ffde010, (180, 0x7ffde010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0
01604 1740 NtAllocateVirtualMemory (180, 0, 0, 388, 4096, 4, ... 196608, 4096, ) == 0x0
01605 1740 NtWriteVirtualMemory (180, 0x30000, (180, 0x30000, "S\0h\0i\0m\0E\0n\0g\0.\0d\0l\0l\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\1\0\0\253\355\15\254\210\255\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 388, ... 0x0, ) , 388, ... 0x0, ) == 0x0
01606 1740 NtWriteVirtualMemory (180, 0x7ffde1e8, (180, 0x7ffde1e8, "\0\0\3\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0
01607 1740 NtFreeVirtualMemory (-1, (0xa90000), 0, 32768, ... (0xa90000), 4096, ) == 0x0
01608 1740 NtAllocateVirtualMemory (180, 0, 0, 1048576, 8192, 4, ... 262144, 1048576, ) == 0x0
01609 1740 NtAllocateVirtualMemory (180, 1302528, 0, 8192, 4096, 4, ... 1302528, 8192, ) == 0x0
01610 1740 NtProtectVirtualMemory (180, (0x13e000), 4096, 260, ... (0x13e000), 4096, 4, ) == 0x0
01611 1740 NtCreateThread (0x1f03ff, 0x0, 180, 1233572, 1233236, 1, ... 184, {484, 748}, ) == 0x0
01612 1740 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\267\0\0\0\270\0\0\0\344\1\0\0\354\2\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 928, 1740, 57985, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\264\0\0\0\270\0\0\0\344\1\0\0\354\2\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ... {168, 196, reply, 0, 928, 1740, 57985, 0} (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\267\0\0\0\270\0\0\0\344\1\0\0\354\2\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 928, 1740, 57985, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\264\0\0\0\270\0\0\0\344\1\0\0\354\2\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ) == 0x0
01613 1740 NtResumeThread (184, ... 1, ) == 0x0
01614 1740 NtClose (168, ... ) == 0x0
01615 1740 NtClose (164, ... ) == 0x0
01616 1740 NtClose (184, ... ) == 0x0
01617 1740 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0
01618 1740 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x102
01619 1740 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0
01620 1740 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x102
01621 1740 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0
01622 1740 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x0
01623 1740 NtClose (180, ... ) == 0x0
01624 1740 NtUnmapViewOfSection (-1, 0x3d0000, ... ) == 0x0
01625 1740 NtClose (160, ... ) == 0x0
01626 1740 NtClose (144, ... ) == 0x0
01627 1740 NtClose (152, ... ) == 0x0
01628 1740 NtClose (148, ... ) == 0x0
01629 1740 NtClose (156, ... ) == 0x0
01630 1740 NtClose (100, ... ) == 0x0
01631 1740 NtClose (104, ... ) == 0x0
01632 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x7,}, 4, ... ) == 0x0
01633 1740 NtWaitForMultipleObjects (2, (64, 72, ), 1, 0, 0x0, ... ) == 0x1
01634 1740 NtClose (72, ... ) == 0x0
01635 1740 NtSetEvent (64, ... 0x0, ) == 0x0
01636 1740 NtClose (64, ... ) == 0x0
01637 1740 NtWaitForMultipleObjects (2, (76, 80, ), 1, 0, 0x0, ... ) == 0x1
01638 1740 NtClose (80, ... ) == 0x0
01639 1740 NtSetEvent (76, ... 0x0, ) == 0x0
01640 1740 NtClose (76, ... ) == 0x0
01641 1740 NtWaitForMultipleObjects (2, (84, 88, ), 1, 0, 0x0, ... ) == 0x1
01642 1740 NtClose (88, ... ) == 0x0
01643 1740 NtSetEvent (84, ... 0x0, ) == 0x0
01644 1740 NtClose (84, ... ) == 0x0
01645 1740 NtRequestWaitReplyPort (128, {88, 112, new_msg, 0, 928, 1740, 57981, 0} (128, {88, 112, new_msg, 0, 928, 1740, 57981, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 928, 1740, 58115, 0} "\2\376\255\201\1\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\210\300\310\0\0\0\3\1\0\0\3\1\0\0\10A\210\300\0@\250\300\220\276u\201\264;\350\371R\250S\200\304;\350\371\4\0\0\0\0\0\0\0\220\276u\201<(\255\201\7\0\0\0\304\277u\201]\0\0\0" ) ... {124, 148, reply, 0, 928, 1740, 58115, 0} (128, {88, 112, new_msg, 0, 928, 1740, 57981, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 928, 1740, 58115, 0} "\2\376\255\201\1\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\210\300\310\0\0\0\3\1\0\0\3\1\0\0\10A\210\300\0@\250\300\220\276u\201\264;\350\371R\250S\200\304;\350\371\4\0\0\0\0\0\0\0\220\276u\201<(\255\201\7\0\0\0\304\277u\201]\0\0\0" ) ) == 0x0
01646 1740 NtClose (124, ... ) == 0x0
01647 1740 NtClose (128, ... ) == 0x0
01648 1740 NtClose (68, ... ) == 0x0
01649 1740 NtUnmapViewOfSection (-1, 0x69450000, ... ) == 0x0
01650 1740 NtUnmapViewOfSection (-1, 0x77920000, ... ) == 0x0
01651 1740 NtUnmapViewOfSection (-1, 0x76f50000, ... ) == 0x0
01652 1740 NtUnmapViewOfSection (-1, 0x76360000, ... ) == 0x0
01653 1740 NtUnmapViewOfSection (-1, 0x5b860000, ... ) == 0x0
01654 1740 NtUnmapViewOfSection (-1, 0x769c0000, ... ) == 0x0
01655 1740 NtContinue (1242900, 0, ...
01656 1740 NtTerminateProcess (0, -1073741682, ... ) == 0x0
01657 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x8,}, 4, ... ) == 0x0
01658 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0
01659 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0
01660 1740 NtClose (92, ... ) == 0x0
01661 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0
01662 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0
01663 1740 NtUnmapViewOfSection (-1, 0x380000, ... ) == 0x0
01664 1740 NtClose (60, ... ) == 0x0
01665 1740 NtGdiDeleteObjectApp (1913653144, ... ) == 0x1
01666 1740 NtUserGetProcessWindowStation (... ) == 0x1c
01667 1740 NtUserBuildNameList (28, 522, 1379448, 1244228, ... ) == 0x0
01668 1740 NtUserGetProcessWindowStation (... ) == 0x1c
01669 1740 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x3c
01670 1740 NtUserBuildHwndList (60, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 52, ) == 0x0
01671 1740 NtUserValidateHandleSecure (327838, ... ) == 0x1
01672 1740 NtUserQueryWindow (327838, 0, ... ) == 0x6b8
01673 1740 NtUserQueryWindow (327838, 1, ... ) == 0x6d4
01674 1740 NtUserValidateHandleSecure (327838, ... ) == 0x1
01675 1740 NtUserValidateHandleSecure (262394, ... ) == 0x1
01676 1740 NtUserQueryWindow (262394, 0, ... ) == 0x6b8
01677 1740 NtUserQueryWindow (262394, 1, ... ) == 0x6d4
01678 1740 NtUserValidateHandleSecure (262394, ... ) == 0x1
01679 1740 NtUserBuildHwndList (0, 262394, 1, 0, 64, ... (0x80064, 0x60068, 0x6006c, 0x50094, 0x50096, 0x60066, 0x7006a, 0x90058, 0x6006e, 0x5008a, 0x50088, 0x500a0, 0x1, ), 13, ) == 0x0
01680 1740 NtUserValidateHandleSecure (524388, ... ) == 0x1
01681 1740 NtUserQueryWindow (524388, 0, ... ) == 0x6b8
01682 1740 NtUserQueryWindow (524388, 1, ... ) == 0x6d4
01683 1740 NtUserValidateHandleSecure (393320, ... ) == 0x1
01684 1740 NtUserQueryWindow (393320, 0, ... ) == 0x6b8
01685 1740 NtUserQueryWindow (393320, 1, ... ) == 0x6d4
01686 1740 NtUserValidateHandleSecure (393324, ... ) == 0x1
01687 1740 NtUserQueryWindow (393324, 0, ... ) == 0x6b8
01688 1740 NtUserQueryWindow (393324, 1, ... ) == 0x6d4
01689 1740 NtUserValidateHandleSecure (327828, ... ) == 0x1
01690 1740 NtUserQueryWindow (327828, 0, ... ) == 0x6b8
01691 1740 NtUserQueryWindow (327828, 1, ... ) == 0x6d4
01692 1740 NtUserValidateHandleSecure (327830, ... ) == 0x1
01693 1740 NtUserQueryWindow (327830, 0, ... ) == 0x6b8
01694 1740 NtUserQueryWindow (327830, 1, ... ) == 0x6d4
01695 1740 NtUserValidateHandleSecure (393318, ... ) == 0x1
01696 1740 NtUserQueryWindow (393318, 0, ... ) == 0x6b8
01697 1740 NtUserQueryWindow (393318, 1, ... ) == 0x6d4
01698 1740 NtUserValidateHandleSecure (458858, ... ) == 0x1
01699 1740 NtUserQueryWindow (458858, 0, ... ) == 0x6b8
01700 1740 NtUserQueryWindow (458858, 1, ... ) == 0x6d4
01701 1740 NtUserValidateHandleSecure (589912, ... ) == 0x1
01702 1740 NtUserQueryWindow (589912, 0, ... ) == 0x6b8
01703 1740 NtUserQueryWindow (589912, 1, ... ) == 0x6d4
01704 1740 NtUserValidateHandleSecure (393326, ... ) == 0x1
01705 1740 NtUserQueryWindow (393326, 0, ... ) == 0x6b8
01706 1740 NtUserQueryWindow (393326, 1, ... ) == 0x6d4
01707 1740 NtUserValidateHandleSecure (327818, ... ) == 0x1
01708 1740 NtUserQueryWindow (327818, 0, ... ) == 0x6b8
01709 1740 NtUserQueryWindow (327818, 1, ... ) == 0x6d4
01710 1740 NtUserValidateHandleSecure (327816, ... ) == 0x1
01711 1740 NtUserQueryWindow (327816, 0, ... ) == 0x6b8
01712 1740 NtUserQueryWindow (327816, 1, ... ) == 0x6d4
01713 1740 NtUserValidateHandleSecure (327840, ... ) == 0x1
01714 1740 NtUserQueryWindow (327840, 0, ... ) == 0x6b8
01715 1740 NtUserQueryWindow (327840, 1, ... ) == 0x6d4
01716 1740 NtUserValidateHandleSecure (65652, ... ) == 0x1
01717 1740 NtUserQueryWindow (65652, 0, ... ) == 0x6b8
01718 1740 NtUserQueryWindow (65652, 1, ... ) == 0x6d4
01719 1740 NtUserValidateHandleSecure (65652, ... ) == 0x1
01720 1740 NtUserValidateHandleSecure (65664, ... ) == 0x1
01721 1740 NtUserQueryWindow (65664, 0, ... ) == 0x6b8
01722 1740 NtUserQueryWindow (65664, 1, ... ) == 0x6d4
01723 1740 NtUserValidateHandleSecure (65664, ... ) == 0x1
01724 1740 NtUserValidateHandleSecure (65648, ... ) == 0x1
01725 1740 NtUserQueryWindow (65648, 0, ... ) == 0x6b8
01726 1740 NtUserQueryWindow (65648, 1, ... ) == 0x6d4
01727 1740 NtUserValidateHandleSecure (65648, ... ) == 0x1
01728 1740 NtUserValidateHandleSecure (65668, ... ) == 0x1
01729 1740 NtUserQueryWindow (65668, 0, ... ) == 0x6b8
01730 1740 NtUserQueryWindow (65668, 1, ... ) == 0x6d4
01731 1740 NtUserValidateHandleSecure (65668, ... ) == 0x1
01732 1740 NtUserValidateHandleSecure (196680, ... ) == 0x1
01733 1740 NtUserQueryWindow (196680, 0, ... ) == 0x6b8
01734 1740 NtUserQueryWindow (196680, 1, ... ) == 0x6d4
01735 1740 NtUserValidateHandleSecure (196680, ... ) == 0x1
01736 1740 NtUserValidateHandleSecure (65650, ... ) == 0x1
01737 1740 NtUserQueryWindow (65650, 0, ... ) == 0x6b8
01738 1740 NtUserQueryWindow (65650, 1, ... ) == 0x6d4
01739 1740 NtUserValidateHandleSecure (65650, ... ) == 0x1
01740 1740 NtUserValidateHandleSecure (131154, ... ) == 0x1
01741 1740 NtUserQueryWindow (131154, 0, ... ) == 0x6b8
01742 1740 NtUserQueryWindow (131154, 1, ... ) == 0x6d4
01743 1740 NtUserValidateHandleSecure (131154, ... ) == 0x1
01744 1740 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0
01745 1740 NtUserValidateHandleSecure (196670, ... ) == 0x1
01746 1740 NtUserQueryWindow (196670, 0, ... ) == 0x6b8
01747 1740 NtUserQueryWindow (196670, 1, ... ) == 0x6d4
01748 1740 NtUserValidateHandleSecure (196668, ... ) == 0x1
01749 1740 NtUserQueryWindow (196668, 0, ... ) == 0x6b8
01750 1740 NtUserQueryWindow (196668, 1, ... ) == 0x6d4
01751 1740 NtUserValidateHandleSecure (196672, ... ) == 0x1
01752 1740 NtUserQueryWindow (196672, 0, ... ) == 0x6b8
01753 1740 NtUserQueryWindow (196672, 1, ... ) == 0x6d4
01754 1740 NtUserValidateHandleSecure (196674, ... ) == 0x1
01755 1740 NtUserQueryWindow (196674, 0, ... ) == 0x6b8
01756 1740 NtUserQueryWindow (196674, 1, ... ) == 0x6d4
01757 1740 NtUserValidateHandleSecure (196676, ... ) == 0x1
01758 1740 NtUserQueryWindow (196676, 0, ... ) == 0x6b8
01759 1740 NtUserQueryWindow (196676, 1, ... ) == 0x6d4
01760 1740 NtUserValidateHandleSecure (196678, ... ) == 0x1
01761 1740 NtUserQueryWindow (196678, 0, ... ) == 0x6b8
01762 1740 NtUserQueryWindow (196678, 1, ... ) == 0x6d4
01763 1740 NtUserValidateHandleSecure (65654, ... ) == 0x1
01764 1740 NtUserQueryWindow (65654, 0, ... ) == 0x6b8
01765 1740 NtUserQueryWindow (65654, 1, ... ) == 0x6d4
01766 1740 NtUserValidateHandleSecure (65666, ... ) == 0x1
01767 1740 NtUserQueryWindow (65666, 0, ... ) == 0x6b8
01768 1740 NtUserQueryWindow (65666, 1, ... ) == 0x6d4
01769 1740 NtUserValidateHandleSecure (65658, ... ) == 0x1
01770 1740 NtUserQueryWindow (65658, 0, ... ) == 0x6b8
01771 1740 NtUserQueryWindow (65658, 1, ... ) == 0x6d4
01772 1740 NtUserValidateHandleSecure (65662, ... ) == 0x1
01773 1740 NtUserQueryWindow (65662, 0, ... ) == 0x6b8
01774 1740 NtUserQueryWindow (65662, 1, ... ) == 0x6d4
01775 1740 NtUserValidateHandleSecure (327836, ... ) == 0x1
01776 1740 NtUserQueryWindow (327836, 0, ... ) == 0x6b8
01777 1740 NtUserQueryWindow (327836, 1, ... ) == 0x6d4
01778 1740 NtUserValidateHandleSecure (327836, ... ) == 0x1
01779 1740 NtUserValidateHandleSecure (65680, ... ) == 0x1
01780 1740 NtUserQueryWindow (65680, 0, ... ) == 0x6b8
01781 1740 NtUserQueryWindow (65680, 1, ... ) == 0x6bc
01782 1740 NtUserValidateHandleSecure (65680, ... ) == 0x1
01783 1740 NtUserValidateHandleSecure (327842, ... ) == 0x1
01784 1740 NtUserQueryWindow (327842, 0, ... ) == 0x6b8
01785 1740 NtUserQueryWindow (327842, 1, ... ) == 0x6d4
01786 1740 NtUserValidateHandleSecure (327842, ... ) == 0x1
01787 1740 NtUserValidateHandleSecure (65744, ... ) == 0x1
01788 1740 NtUserQueryWindow (65744, 0, ... ) == 0x19c
01789 1740 NtUserQueryWindow (65744, 1, ... ) == 0x1a0
01790 1740 NtUserValidateHandleSecure (65744, ... ) == 0x1
01791 1740 NtUserValidateHandleSecure (131248, ... ) == 0x1
01792 1740 NtUserQueryWindow (131248, 0, ... ) == 0xa0
01793 1740 NtUserQueryWindow (131248, 1, ... ) == 0xe4
01794 1740 NtUserValidateHandleSecure (131248, ... ) == 0x1
01795 1740 NtUserValidateHandleSecure (65740, ... ) == 0x1
01796 1740 NtUserQueryWindow (65740, 0, ... ) == 0x19c
01797 1740 NtUserQueryWindow (65740, 1, ... ) == 0x1a0
01798 1740 NtUserValidateHandleSecure (65740, ... ) == 0x1
01799 1740 NtUserValidateHandleSecure (459012, ... ) == 0x1
01800 1740 NtUserQueryWindow (459012, 0, ... ) == 0x49c
01801 1740 NtUserQueryWindow (459012, 1, ... ) == 0x180
01802 1740 NtUserValidateHandleSecure (459012, ... ) == 0x1
01803 1740 NtUserValidateHandleSecure (459008, ... ) == 0x1
01804 1740 NtUserQueryWindow (459008, 0, ... ) == 0x5e8
01805 1740 NtUserQueryWindow (459008, 1, ... ) == 0x1dc
01806 1740 NtUserValidateHandleSecure (459008, ... ) == 0x1
01807 1740 NtUserValidateHandleSecure (131352, ... ) == 0x1
01808 1740 NtUserQueryWindow (131352, 0, ... ) == 0x6ac
01809 1740 NtUserQueryWindow (131352, 1, ... ) == 0x7f4
01810 1740 NtUserValidateHandleSecure (131352, ... ) == 0x1
01811 1740 NtUserValidateHandleSecure (196940, ... ) == 0x1
01812 1740 NtUserQueryWindow (196940, 0, ... ) == 0x4b4
01813 1740 NtUserQueryWindow (196940, 1, ... ) == 0x474
01814 1740 NtUserValidateHandleSecure (196940, ... ) == 0x1
01815 1740 NtUserValidateHandleSecure (65820, ... ) == 0x1
01816 1740 NtUserQueryWindow (65820, 0, ... ) == 0x22c
01817 1740 NtUserQueryWindow (65820, 1, ... ) == 0x220
01818 1740 NtUserValidateHandleSecure (65820, ... ) == 0x1
01819 1740 NtUserValidateHandleSecure (65766, ... ) == 0x1
01820 1740 NtUserQueryWindow (65766, 0, ... ) == 0x6b8
01821 1740 NtUserQueryWindow (65766, 1, ... ) == 0x13c
01822 1740 NtUserValidateHandleSecure (65766, ... ) == 0x1
01823 1740 NtUserValidateHandleSecure (65750, ... ) == 0x1
01824 1740 NtUserQueryWindow (65750, 0, ... ) == 0x6b8
01825 1740 NtUserQueryWindow (65750, 1, ... ) == 0x13c
01826 1740 NtUserValidateHandleSecure (65750, ... ) == 0x1
01827 1740 NtUserBuildHwndList (0, 65750, 1, 0, 64, ... (0x100da, 0x100dc, 0x100de, 0x100e0, 0x1, ), 5, ) == 0x0
01828 1740 NtUserValidateHandleSecure (65754, ... ) == 0x1
01829 1740 NtUserQueryWindow (65754, 0, ... ) == 0x6b8
01830 1740 NtUserQueryWindow (65754, 1, ... ) == 0x13c
01831 1740 NtUserValidateHandleSecure (65756, ... ) == 0x1
01832 1740 NtUserQueryWindow (65756, 0, ... ) == 0x6b8
01833 1740 NtUserQueryWindow (65756, 1, ... ) == 0x13c
01834 1740 NtUserValidateHandleSecure (65758, ... ) == 0x1
01835 1740 NtUserQueryWindow (65758, 0, ... ) == 0x6b8
01836 1740 NtUserQueryWindow (65758, 1, ... ) == 0x13c
01837 1740 NtUserValidateHandleSecure (65760, ... ) == 0x1
01838 1740 NtUserQueryWindow (65760, 0, ... ) == 0x6b8
01839 1740 NtUserQueryWindow (65760, 1, ... ) == 0x13c
01840 1740 NtUserValidateHandleSecure (65746, ... ) == 0x1
01841 1740 NtUserQueryWindow (65746, 0, ... ) == 0x6b8
01842 1740 NtUserQueryWindow (65746, 1, ... ) == 0x6d4
01843 1740 NtUserValidateHandleSecure (65746, ... ) == 0x1
01844 1740 NtUserValidateHandleSecure (65738, ... ) == 0x1
01845 1740 NtUserQueryWindow (65738, 0, ... ) == 0x19c
01846 1740 NtUserQueryWindow (65738, 1, ... ) == 0x1a0
01847 1740 NtUserValidateHandleSecure (65738, ... ) == 0x1
01848 1740 NtUserValidateHandleSecure (65736, ... ) == 0x1
01849 1740 NtUserQueryWindow (65736, 0, ... ) == 0xa0
01850 1740 NtUserQueryWindow (65736, 1, ... ) == 0xe4
01851 1740 NtUserValidateHandleSecure (65736, ... ) == 0x1
01852 1740 NtUserValidateHandleSecure (65722, ... ) == 0x1
01853 1740 NtUserQueryWindow (65722, 0, ... ) == 0x104
01854 1740 NtUserQueryWindow (65722, 1, ... ) == 0x108
01855 1740 NtUserValidateHandleSecure (65722, ... ) == 0x1
01856 1740 NtUserValidateHandleSecure (65710, ... ) == 0x1
01857 1740 NtUserQueryWindow (65710, 0, ... ) == 0x104
01858 1740 NtUserQueryWindow (65710, 1, ... ) == 0x108
01859 1740 NtUserValidateHandleSecure (65710, ... ) == 0x1
01860 1740 NtUserValidateHandleSecure (65708, ... ) == 0x1
01861 1740 NtUserQueryWindow (65708, 0, ... ) == 0x120
01862 1740 NtUserQueryWindow (65708, 1, ... ) == 0x124
01863 1740 NtUserValidateHandleSecure (65708, ... ) == 0x1
01864 1740 NtUserValidateHandleSecure (196774, ... ) == 0x1
01865 1740 NtUserQueryWindow (196774, 0, ... ) == 0xc4
01866 1740 NtUserQueryWindow (196774, 1, ... ) == 0xc8
01867 1740 NtUserValidateHandleSecure (196774, ... ) == 0x1
01868 1740 NtUserValidateHandleSecure (65656, ... ) == 0x1
01869 1740 NtUserQueryWindow (65656, 0, ... ) == 0x6b8
01870 1740 NtUserQueryWindow (65656, 1, ... ) == 0x6ec
01871 1740 NtUserValidateHandleSecure (65656, ... ) == 0x1
01872 1740 NtUserValidateHandleSecure (196706, ... ) == 0x1
01873 1740 NtUserQueryWindow (196706, 0, ... ) == 0x6b8
01874 1740 NtUserQueryWindow (196706, 1, ... ) == 0x6bc
01875 1740 NtUserValidateHandleSecure (196706, ... ) == 0x1
01876 1740 NtUserValidateHandleSecure (327734, ... ) == 0x1
01877 1740 NtUserQueryWindow (327734, 0, ... ) == 0x6b8
01878 1740 NtUserQueryWindow (327734, 1, ... ) == 0x6bc
01879 1740 NtUserValidateHandleSecure (327734, ... ) == 0x1
01880 1740 NtUserValidateHandleSecure (327772, ... ) == 0x1
01881 1740 NtUserQueryWindow (327772, 0, ... ) == 0x6b8
01882 1740 NtUserQueryWindow (327772, 1, ... ) == 0x6bc
01883 1740 NtUserValidateHandleSecure (327772, ... ) == 0x1
01884 1740 NtUserValidateHandleSecure (65726, ... ) == 0x1
01885 1740 NtUserQueryWindow (65726, 0, ... ) == 0x19c
01886 1740 NtUserQueryWindow (65726, 1, ... ) == 0x1a0
01887 1740 NtUserValidateHandleSecure (65726, ... ) == 0x1
01888 1740 NtUserValidateHandleSecure (262398, ... ) == 0x1
01889 1740 NtUserQueryWindow (262398, 0, ... ) == 0x6b8
01890 1740 NtUserQueryWindow (262398, 1, ... ) == 0x6d4
01891 1740 NtUserValidateHandleSecure (262398, ... ) == 0x1
01892 1740 NtUserValidateHandleSecure (65682, ... ) == 0x1
01893 1740 NtUserQueryWindow (65682, 0, ... ) == 0x6b8
01894 1740 NtUserQueryWindow (65682, 1, ... ) == 0x6bc
01895 1740 NtUserValidateHandleSecure (65682, ... ) == 0x1
01896 1740 NtUserValidateHandleSecure (65670, ... ) == 0x1
01897 1740 NtUserQueryWindow (65670, 0, ... ) == 0x6b8
01898 1740 NtUserQueryWindow (65670, 1, ... ) == 0x6bc
01899 1740 NtUserValidateHandleSecure (65670, ... ) == 0x1
01900 1740 NtUserBuildHwndList (0, 65670, 1, 0, 64, ... (0x1008c, 0x1008e, 0x1, ), 3, ) == 0x0
01901 1740 NtUserValidateHandleSecure (65676, ... ) == 0x1
01902 1740 NtUserQueryWindow (65676, 0, ... ) == 0x6b8
01903 1740 NtUserQueryWindow (65676, 1, ... ) == 0x6bc
01904 1740 NtUserValidateHandleSecure (65678, ... ) == 0x1
01905 1740 NtUserQueryWindow (65678, 0, ... ) == 0x6b8
01906 1740 NtUserQueryWindow (65678, 1, ... ) == 0x6bc
01907 1740 NtUserValidateHandleSecure (262196, ... ) == 0x1
01908 1740 NtUserQueryWindow (262196, 0, ... ) == 0x6b8
01909 1740 NtUserQueryWindow (262196, 1, ... ) == 0x6d4
01910 1740 NtUserValidateHandleSecure (262196, ... ) == 0x1
01911 1740 NtUserValidateHandleSecure (327760, ... ) == 0x1
01912 1740 NtUserQueryWindow (327760, 0, ... ) == 0x6b8
01913 1740 NtUserQueryWindow (327760, 1, ... ) == 0x6d4
01914 1740 NtUserValidateHandleSecure (327760, ... ) == 0x1
01915 1740 NtUserValidateHandleSecure (65852, ... ) == 0x1
01916 1740 NtUserQueryWindow (65852, 0, ... ) == 0x22c
01917 1740 NtUserQueryWindow (65852, 1, ... ) == 0x220
01918 1740 NtUserValidateHandleSecure (65852, ... ) == 0x1
01919 1740 NtUserValidateHandleSecure (65824, ... ) == 0x1
01920 1740 NtUserQueryWindow (65824, 0, ... ) == 0x22c
01921 1740 NtUserQueryWindow (65824, 1, ... ) == 0x220
01922 1740 NtUserValidateHandleSecure (65824, ... ) == 0x1
01923 1740 NtUserValidateHandleSecure (65730, ... ) == 0x1
01924 1740 NtUserQueryWindow (65730, 0, ... ) == 0xa0
01925 1740 NtUserQueryWindow (65730, 1, ... ) == 0xe4
01926 1740 NtUserValidateHandleSecure (65730, ... ) == 0x1
01927 1740 NtUserValidateHandleSecure (65724, ... ) == 0x1
01928 1740 NtUserQueryWindow (65724, 0, ... ) == 0xa0
01929 1740 NtUserQueryWindow (65724, 1, ... ) == 0xe4
01930 1740 NtUserValidateHandleSecure (65724, ... ) == 0x1
01931 1740 NtUserValidateHandleSecure (131406, ... ) == 0x1
01932 1740 NtUserQueryWindow (131406, 0, ... ) == 0x4b4
01933 1740 NtUserQueryWindow (131406, 1, ... ) == 0x474
01934 1740 NtUserValidateHandleSecure (131406, ... ) == 0x1
01935 1740 NtUserValidateHandleSecure (65752, ... ) == 0x1
01936 1740 NtUserQueryWindow (65752, 0, ... ) == 0x6b8
01937 1740 NtUserQueryWindow (65752, 1, ... ) == 0x13c
01938 1740 NtUserValidateHandleSecure (65752, ... ) == 0x1
01939 1740 NtUserValidateHandleSecure (65718, ... ) == 0x1
01940 1740 NtUserQueryWindow (65718, 0, ... ) == 0x104
01941 1740 NtUserQueryWindow (65718, 1, ... ) == 0x108
01942 1740 NtUserValidateHandleSecure (65718, ... ) == 0x1
01943 1740 NtUserValidateHandleSecure (65720, ... ) == 0x1
01944 1740 NtUserQueryWindow (65720, 0, ... ) == 0x120
01945 1740 NtUserQueryWindow (65720, 1, ... ) == 0x124
01946 1740 NtUserValidateHandleSecure (65720, ... ) == 0x1
01947 1740 NtUserValidateHandleSecure (65716, ... ) == 0x1
01948 1740 NtUserQueryWindow (65716, 0, ... ) == 0xc4
01949 1740 NtUserQueryWindow (65716, 1, ... ) == 0xc8
01950 1740 NtUserValidateHandleSecure (65716, ... ) == 0x1
01951 1740 NtUserValidateHandleSecure (65728, ... ) == 0x1
01952 1740 NtUserQueryWindow (65728, 0, ... ) == 0x19c
01953 1740 NtUserQueryWindow (65728, 1, ... ) == 0x1a0
01954 1740 NtUserValidateHandleSecure (65728, ... ) == 0x1
01955 1740 NtUserValidateHandleSecure (65690, ... ) == 0x1
01956 1740 NtUserQueryWindow (65690, 0, ... ) == 0x6b8
01957 1740 NtUserQueryWindow (65690, 1, ... ) == 0x6bc
01958 1740 NtUserValidateHandleSecure (65690, ... ) == 0x1
01959 1740 NtUserValidateHandleSecure (327774, ... ) == 0x1
01960 1740 NtUserQueryWindow (327774, 0, ... ) == 0x6b8
01961 1740 NtUserQueryWindow (327774, 1, ... ) == 0x6bc
01962 1740 NtUserValidateHandleSecure (327774, ... ) == 0x1
01963 1740 NtUserCloseDesktop (60, ... ) == 0x1
01964 1740 NtUserGetProcessWindowStation (... ) == 0x1c
01965 1740 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0
01966 1740 NtUserGetProcessWindowStation (... ) == 0x1c
01967 1740 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Winlogon"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0
01968 1740 NtGdiDeleteObjectApp (856294625, ... ) == 0x1
01969 1740 NtGdiDeleteObjectApp (1376388660, ... ) == 0x1
01970 1740 NtClose (56, ... ) == 0x0
01971 1740 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0
01972 1740 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 56, ) }, ... 56, ) == 0x0
01973 1740 NtQueryValueKey (56, (56, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND
01974 1740 NtClose (56, ... ) == 0x0
01975 1740 NtClose (44, ... ) == 0x0
01976 1740 NtFreeVirtualMemory (-1, (0x3f0000), 4096, 32768, ... (0x3f0000), 4096, ) == 0x0
01977 1740 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0
01978 1740 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0
01979 1740 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0
01980 1740 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} "\0\0\0\0\3\0\1\0\214\371\21\0\320\220\347w\216\0\0\300" ... {20, 48, reply, 0, 928, 1740, 58118, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\320\220\347w\216\0\0\300" ) ... {20, 48, reply, 0, 928, 1740, 58118, 0} (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} "\0\0\0\0\3\0\1\0\214\371\21\0\320\220\347w\216\0\0\300" ... {20, 48, reply, 0, 928, 1740, 58118, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\320\220\347w\216\0\0\300" ) ) == 0x0
01981 1740 NtTerminateProcess (-1, -1073741682, ...