Summary:

NtAccessCheck(>) 1 NtUserGetThreadDesktop(>) 1 NtSetInformationFile(>) 5 NtQueryVirtualMemory(>) 15
NtCallbackReturn(>) 1 NtUserOpenWindowStation(>) 1 NtUserBuildHwndList(>) 5 NtDeviceIoControlFile(>) 16
NtCreateProcessEx(>) 1 NtUserSystemParametersInfo(>) 1 NtWriteVirtualMemory(>) 5 NtRequestWaitReplyPort(>) 16
NtCreateSemaphore(>) 1 NtConnectPort(>) 2 NtContinue(>) 6 NtOpenSection(>) 24
NtCreateThread(>) 1 NtCreateIoCompletion(>) 2 NtOpenProcessToken(>) 6 NtQueryDirectoryFile(>) 24
NtDuplicateToken(>) 1 NtGdiCreateSolidBrush(>) 2 NtQueryDefaultUILanguage(>) 6 NtSetInformationProcess(>) 25
NtGdiCreateBitmap(>) 1 NtGdiHfontCreate(>) 2 NtUserGetProcessWindowStation(>) 6 NtOpenProcessTokenEx(>) 28
NtGdiCreatePatternBrushInternal(>) 1 NtQueryInformationJobObject(>) 2 NtWaitForSingleObject(>) 6 NtOpenThreadTokenEx(>) 28
NtGdiInit(>) 1 NtReleaseMutant(>) 2 NtFsControlFile(>) 7 NtCreateSection(>) 29
NtGdiQueryFontAssocInfo(>) 1 NtTerminateProcess(>) 2 NtOpenThreadToken(>) 7 NtQueryInformationToken(>) 37
NtGdiSelectBitmap(>) 1 NtUserCloseWindowStation(>) 2 NtQueryInformationFile(>) 7 NtOpenFile(>) 41
NtOpenEvent(>) 1 NtUserGetObjectInformation(>) 2 NtWaitForMultipleObjects(>) 7 NtQueryInformationProcess(>) 44
NtOpenKeyedEvent(>) 1 NtGdiCreateCompatibleDC(>) 3 NtEnumerateKey(>) 8 NtQueryDefaultLocale(>) 48
NtOpenMutant(>) 1 NtGdiDeleteObjectApp(>) 3 NtSetValueKey(>) 8 NtUnmapViewOfSection(>) 48
NtQueryDebugFilterState(>) 1 NtOpenDirectoryObject(>) 3 NtUserCallNoParam(>) 9 NtAllocateVirtualMemory(>) 51
NtQueryInstallUILanguage(>) 1 NtOpenSymbolicLinkObject(>) 3 NtUserFindExistingCursorIcon(>) 9 NtQueryAttributesFile(>) 54
NtQueryObject(>) 1 NtQuerySymbolicLinkObject(>) 3 NtUserGetWindowDC(>) 10 NtFlushInstructionCache(>) 65
NtQueryPerformanceCounter(>) 1 NtReadVirtualMemory(>) 3 NtCreateKey(>) 11 NtMapViewOfSection(>) 69
NtQuerySystemTime(>) 1 NtSetEvent(>) 3 NtFreeVirtualMemory(>) 11 NtQuerySystemInformation(>) 76
NtRegisterThreadTerminatePort(>) 1 NtSetInformationObject(>) 3 NtUserCallOneParam(>) 11 NtQueryValueKey(>) 105
NtResumeThread(>) 1 NtUserOpenDesktop(>) 3 NtWriteFile(>) 11 NtUserValidateHandleSecure(>) 132
NtSecureConnectPort(>) 1 NtCreateMutant(>) 4 NtQuerySection(>) 12 NtOpenKey(>) 153
NtTestAlert(>) 1 NtDuplicateObject(>) 4 NtSetInformationThread(>) 13 NtProtectVirtualMemory(>) 156
NtUserBuildNameList(>) 1 NtQueryVolumeInformationFile(>) 4 NtCreateEvent(>) 14 NtUserQueryWindow(>) 160
NtUserCloseDesktop(>) 1 NtGdiGetStockObject(>) 5 NtCreateFile(>) 14 NtClose(>) 240
NtUserGetGUIThreadInfo(>) 1 NtReadFile(>) 5 NtUserRegisterClassExWOW(>) 14

Trace:

00001 464 NtOpenFile (0x80100000, {24, 0, 0x240, 0, 0, (0x80100000, {24, 0, 0x240, 0, 0, "\SystemRoot\Prefetch\PACKED.EXE-09ED06A1.pf"}, 0, 32, ... ) }, 0, 32, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00003 464 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00004 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00005 464 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1310720, 1048576, ) == 0x0 00006 464 NtAllocateVirtualMemory (-1, 1310720, 0, 4096, 4096, 4, ... 1310720, 4096, ) == 0x0 00007 464 NtAllocateVirtualMemory (-1, 1314816, 0, 8192, 4096, 4, ... 1314816, 8192, ) == 0x0 00008 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00009 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2359296, 65536, ) == 0x0 00010 464 NtAllocateVirtualMemory (-1, 2359296, 0, 24576, 4096, 4, ... 2359296, 24576, ) == 0x0 00011 464 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00012 464 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00013 464 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00014 464 NtClose (12, ... ) == 0x0 00015 464 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\C:\scripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00016 464 NtQueryVolumeInformationFile (12, 1243852, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00017 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 1243804, ... ) }, 1243804, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7c800000), 0x0, 1003520, ) == 0x0 00020 464 NtClose (16, ... ) == 0x0 00021 464 NtProtectVirtualMemory (-1, (0x7c801000), 1568, 4, ... (0x7c801000), 4096, 32, ) == 0x0 00022 464 NtProtectVirtualMemory (-1, (0x7c801000), 4096, 32, ... (0x7c801000), 4096, 4, ) == 0x0 00023 464 NtFlushInstructionCache (-1, 2088767488, 1568, ... ) == 0x0 00024 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00025 464 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00026 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00027 464 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00028 464 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00029 464 NtClose (16, ... ) == 0x0 00030 464 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00031 464 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00032 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00033 464 NtQueryVirtualMemory (-1, 0x250000, Basic, 28, ... {BaseAddress=0x250000,AllocationBase=0x250000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00034 464 NtAllocateVirtualMemory (-1, 2424832, 0, 4096, 4096, 4, ... 2424832, 4096, ) == 0x0 00035 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6\31\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 1036, 464, 57955, 0} "`\375\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57955, 0} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6\31\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 1036, 464, 57955, 0} "`\375\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00036 464 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00037 464 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00038 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00039 464 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00040 464 NtClose (16, ... ) == 0x0 00041 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 16, ) }, ... 16, ) == 0x0 00042 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x260000), 0x0, 90112, ) == 0x0 00043 464 NtClose (16, ... ) == 0x0 00044 464 NtQueryDefaultLocale (0, 2089305000, ... ) == 0x0 00045 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 16, ) }, ... 16, ) == 0x0 00046 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x280000), 0x0, 249856, ) == 0x0 00047 464 NtClose (16, ... ) == 0x0 00048 464 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 16, ) }, ... 16, ) == 0x0 00049 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2c0000), 0x0, 266240, ) == 0x0 00050 464 NtQuerySection (16, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00051 464 NtClose (16, ... ) == 0x0 00052 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 16, ) }, ... 16, ) == 0x0 00053 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x310000), 0x0, 24576, ) == 0x0 00054 464 NtClose (16, ... ) == 0x0 00055 464 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00056 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00057 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00058 464 NtAllocateVirtualMemory (-1, 2428928, 0, 8192, 4096, 4, ... 2428928, 8192, ) == 0x0 00059 464 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6\31\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ... {24, 52, reply, 0, 1036, 464, 57956, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ) ... {24, 52, reply, 0, 1036, 464, 57956, 0} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6\31\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ... {24, 52, reply, 0, 1036, 464, 57956, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ) ) == 0x0 00060 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 1036, 464, 57957, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57957, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 1036, 464, 57957, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00061 464 NtProtectVirtualMemory (-1, (0x47c000), 155648, 4, ... (0x47c000), 155648, 128, ) == 0x0 00062 464 NtProtectVirtualMemory (-1, (0x47c000), 155648, 128, ... (0x47c000), 155648, 4, ) == 0x0 00063 464 NtFlushInstructionCache (-1, 4702208, 155648, ... ) == 0x0 00064 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00065 464 NtAllocateVirtualMemory (-1, 1323008, 0, 4096, 4096, 4, ... 1323008, 4096, ) == 0x0 00066 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.DLL"}, 1242572, ... ) }, 1242572, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00067 464 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... {status=0x0, info=0}, 0x0, ) == 0x0 00068 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2_32.DLL"}, 1242572, ... ) }, 1242572, ... ) == 0x0 00069 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2_32.DLL"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00070 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 16, ... 28, ) == 0x0 00071 464 NtQuerySection (28, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00072 464 NtOpenProcessToken (-1, 0x8, ... 32, ) == 0x0 00073 464 NtQueryInformationToken (32, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00074 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00075 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 36, ) }, ... 36, ) == 0x0 00076 464 NtQueryValueKey (36, (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00077 464 NtClose (36, ... ) == 0x0 00078 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00079 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 36, ) == 0x0 00080 464 NtQueryInformationToken (36, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00081 464 NtClose (36, ... ) == 0x0 00082 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00083 464 NtClose (32, ... ) == 0x0 00084 464 NtClose (16, ... ) == 0x0 00085 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 94208, ) == 0x0 00086 464 NtClose (28, ... ) == 0x0 00087 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "msvcrt.dll"}, ... 28, ) }, ... 28, ) == 0x0 00088 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 360448, ) == 0x0 00089 464 NtClose (28, ... ) == 0x0 00090 464 NtProtectVirtualMemory (-1, (0x77c11000), 632, 4, ... (0x77c11000), 4096, 32, ) == 0x0 00091 464 NtProtectVirtualMemory (-1, (0x77c11000), 4096, 32, ... (0x77c11000), 4096, 4, ) == 0x0 00092 464 NtFlushInstructionCache (-1, 2009141248, 632, ... ) == 0x0 00093 464 NtProtectVirtualMemory (-1, (0x71ab1000), 468, 4, ... (0x71ab1000), 4096, 32, ) == 0x0 00094 464 NtProtectVirtualMemory (-1, (0x71ab1000), 4096, 32, ... (0x71ab1000), 4096, 4, ) == 0x0 00095 464 NtFlushInstructionCache (-1, 1907036160, 468, ... ) == 0x0 00096 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00097 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 1241756, ... ) }, 1241756, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00098 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2HELP.dll"}, 1241756, ... ) }, 1241756, ... ) == 0x0 00099 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2HELP.dll"}, 5, 96, ... 28, {status=0x0, info=1}, ) }, 5, 96, ... 28, {status=0x0, info=1}, ) == 0x0 00100 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 28, ... 16, ) == 0x0 00101 464 NtQuerySection (16, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00102 464 NtClose (28, ... ) == 0x0 00103 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 00104 464 NtClose (16, ... ) == 0x0 00105 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00106 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 634880, ) == 0x0 00107 464 NtClose (16, ... ) == 0x0 00108 464 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00109 464 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00110 464 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00111 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 16, ) }, ... 16, ) == 0x0 00112 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e70000), 0x0, 593920, ) == 0x0 00113 464 NtClose (16, ... ) == 0x0 00114 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00115 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00116 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00117 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00118 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00119 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00120 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00121 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00122 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00123 464 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00124 464 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00125 464 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00126 464 NtProtectVirtualMemory (-1, (0x71aa1000), 352, 4, ... (0x71aa1000), 4096, 32, ) == 0x0 00127 464 NtProtectVirtualMemory (-1, (0x71aa1000), 4096, 32, ... (0x71aa1000), 4096, 4, ) == 0x0 00128 464 NtFlushInstructionCache (-1, 1906970624, 352, ... ) == 0x0 00129 464 NtProtectVirtualMemory (-1, (0x71ab1000), 468, 4, ... (0x71ab1000), 4096, 32, ) == 0x0 00130 464 NtProtectVirtualMemory (-1, (0x71ab1000), 4096, 32, ... (0x71ab1000), 4096, 4, ) == 0x0 00131 464 NtFlushInstructionCache (-1, 1907036160, 468, ... ) == 0x0 00132 464 NtProtectVirtualMemory (-1, (0x47c000), 155648, 4, ... (0x47c000), 155648, 64, ) == 0x0 00133 464 NtProtectVirtualMemory (-1, (0x47c000), 155648, 64, ... (0x47c000), 155648, 4, ) == 0x0 00134 464 NtFlushInstructionCache (-1, 4702208, 155648, ... ) == 0x0 00135 464 NtQueryInformationProcess (-1, 37, 48, ... {process info, class 37, size 48}, 0x0, ) == 0x0 00136 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00137 464 NtReadFile (16, 0, 0, 0, 4, {166908, 0}, 0, ... {status=0x0, info=4}, (16, 0, 0, 0, 4, {166908, 0}, 0, ... {status=0x0, info=4}, "\300 \0\0", ) , ) == 0x0 00138 464 NtReadFile (16, 0, 0, 0, 8, {8380, 0}, 0, ... {status=0x0, info=8}, (16, 0, 0, 0, 8, {8380, 0}, 0, ... {status=0x0, info=8}, "\320J\233Dhs5\223", ) , ) == 0x0 00139 464 NtReadFile (16, 0, 0, 0, 8, {158516, 0}, 0, ... {status=0x0, info=8}, (16, 0, 0, 0, 8, {158516, 0}, 0, ... {status=0x0, info=8}, "\362;\213\12\257\312\207\325", ) , ) == 0x0 00140 464 NtClose (16, ... ) == 0x0 00141 464 NtSetInformationProcess (-1, 34, {process info, class 34, size 4}, 4, ... ) == 0x0 00142 464 NtOpenProcessToken (-1, 0x8, ... 16, ) == 0x0 00143 464 NtQueryInformationToken (16, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00144 464 NtClose (16, ... ) == 0x0 00145 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00146 464 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00147 464 NtClose (16, ... ) == 0x0 00148 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00149 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00150 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 3276800, 65536, ) == 0x0 00151 464 NtAllocateVirtualMemory (-1, 3276800, 0, 4096, 4096, 4, ... 3276800, 4096, ) == 0x0 00152 464 NtAllocateVirtualMemory (-1, 3280896, 0, 8192, 4096, 4, ... 3280896, 8192, ) == 0x0 00153 464 NtAllocateVirtualMemory (-1, 3289088, 0, 4096, 4096, 4, ... 3289088, 4096, ) == 0x0 00154 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 16, ) }, ... 16, ) == 0x0 00155 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x330000), 0x0, 12288, ) == 0x0 00156 464 NtClose (16, ... ) == 0x0 00157 464 NtAllocateVirtualMemory (-1, 3293184, 0, 4096, 4096, 4, ... 3293184, 4096, ) == 0x0 00158 464 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 00159 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00160 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00161 464 NtQueryVirtualMemory (-1, 0x0, Basic, 28, ... {BaseAddress=0x0,AllocationBase=0x0,AllocationProtect=0x0,RegionSize=0x10000,State=0x10000,Protect=0x1,Type=0x0,}, 28, ) == 0x0 00162 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00163 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00164 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00165 464 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00166 464 NtQueryValueKey (16, (16, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00167 464 NtClose (16, ... ) == 0x0 00168 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 16, ) }, ... 16, ) == 0x0 00169 464 NtQueryValueKey (16, (16, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00170 464 NtClose (16, ... ) == 0x0 00171 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 16, ) }, ... 16, ) == 0x0 00172 464 NtSetInformationObject (16, Handle, {Inherit=0,ProtectFromClose=1,}, 2011431168, ... ) == 0x0 00173 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00174 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00175 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2_32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00176 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00177 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00178 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00179 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00180 464 NtTestAlert (... ) == 0x0 00181 464 NtContinue (1244464, 1, ... 00182 464 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x47c17a,}, 4, ... ) == 0x0 00183 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 4096, 64, ... 3407872, 4096, ) == 0x0 00184 464 NtAllocateVirtualMemory (-1, 0, 0, 15980, 4096, 4, ... 3473408, 16384, ) == 0x0 00185 464 NtFreeVirtualMemory (-1, (0x350000), 0, 32768, ... (0x350000), 16384, ) == 0x0 00186 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 4096, ) == 0x0 00187 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 28, ) }, ... 28, ) == 0x0 00188 464 NtQueryValueKey (28, (28, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00189 464 NtClose (28, ... ) == 0x0 00190 464 NtAllocateVirtualMemory (-1, 1327104, 0, 4096, 4096, 4, ... 1327104, 4096, ) == 0x0 00191 464 NtProtectVirtualMemory (-1, (0x40e860), -1662053999, -238816909, ... ) == STATUS_INVALID_PAGE_PROTECTION 00192 464 NtProtectVirtualMemory (-1, (0x3fff02), -1920137235, -2091057152, ... ) == STATUS_INVALID_PAGE_PROTECTION 00193 464 NtProtectVirtualMemory (-1, (0x141c600), 148100, 251738496, ... ) == STATUS_INVALID_PAGE_PROTECTION 00194 464 NtProtectVirtualMemory (-1, (0xfed68589), -362, -2060728949, ... ) == STATUS_INVALID_PAGE_PROTECTION 00195 464 NtProtectVirtualMemory (-1, (0xff4ab58d), -314, -2063466497, ... ) == STATUS_INVALID_PAGE_PROTECTION 00196 464 NtProtectVirtualMemory (-1, (0x500068), 1080710741, 100794367, ... ) == STATUS_INVALID_PAGE_PROTECTION 00197 464 NtProtectVirtualMemory (-1, (0xff6e95ff), 6946816, 268462080, ... ) == STATUS_INVALID_PAGE_PROTECTION 00198 464 NtProtectVirtualMemory (-1, (0x85c90000), 57246735, -1064960001, ... ) == STATUS_INVALID_PAGE_PROTECTION 00199 464 NtProtectVirtualMemory (-1, (0x67f95b00), 232, -322, ... ) == STATUS_INVALID_PAGE_PROTECTION 00200 464 NtProtectVirtualMemory (-1, (0x4002b0), -397192999, 50331651, ... ) == STATUS_INVALID_PAGE_PROTECTION 00201 464 NtProtectVirtualMemory (-1, (0x3ffe86), -1123811957, 915103070, ... ) == STATUS_INVALID_PAGE_PROTECTION 00202 464 NtProtectVirtualMemory (-1, (0xf904c7), -2096466688, 1065607051, ... ) == STATUS_INVALID_PAGE_PROTECTION 00203 464 NtProtectVirtualMemory (-1, (0x3b430000), 112918, -352321536, ... ) == STATUS_INVALID_PAGE_PROTECTION 00204 464 NtProtectVirtualMemory (-1, (0x33cb1301), 880017467, -2096839805, ... ) == STATUS_INVALID_PAGE_PROTECTION 00205 464 NtProtectVirtualMemory (-1, (0x3fff32), -1241558191, 1459911427, ... ) == STATUS_INVALID_PAGE_PROTECTION 00206 464 NtProtectVirtualMemory (-1, (0x85cbcf8b), -695468033, -13715969, ... ) == STATUS_INVALID_PAGE_PROTECTION 00207 464 NtProtectVirtualMemory (-1, (0x5c10ff00), 371205, -322, ... ) == STATUS_INVALID_PAGE_PROTECTION 00208 464 NtProtectVirtualMemory (-1, (0xc82b08c3), -2096794624, -108830887, ... ) == STATUS_INVALID_PAGE_PROTECTION 00209 464 NtProtectVirtualMemory (-1, (0x3ebeb5), -16750080, 8388712, ... ) == STATUS_INVALID_PAGE_PROTECTION 00210 464 NtProtectVirtualMemory (-1, (0x3ec6b5), -1912602625, 848691199, ... ) == STATUS_INVALID_PAGE_PROTECTION 00211 464 NtProtectVirtualMemory (-1, (0x843e8b36), -1961863539, 139365375, ... ) == STATUS_INVALID_PAGE_PROTECTION 00212 464 NtProtectVirtualMemory (-1, (0x77413ce8), 742852490, 1064567033, ... ) == STATUS_INVALID_PAGE_PROTECTION 00213 464 NtProtectVirtualMemory (-1, (0x385a8a14), 1946157434, -2146989065, ... ) == STATUS_INVALID_PAGE_PROTECTION 00214 464 NtProtectVirtualMemory (-1, (0xc10108e8), -1050278817, -1964411617, ... ) == STATUS_INVALID_PAGE_PROTECTION 00215 464 NtProtectVirtualMemory (-1, (0xc101c486), 73370122, -339442160, ... ) == STATUS_INVALID_PAGE_PROTECTION 00216 464 NtAllocateVirtualMemory (-1, 0, 0, 118784, 4096, 4, ... 3407872, 118784, ) == 0x0 00217 464 NtAllocateVirtualMemory (-1, 0, 0, 118784, 4096, 4, ... 3538944, 118784, ) == 0x0 00218 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 118784, ) == 0x0 00219 464 NtAllocateVirtualMemory (-1, 0, 0, 1350, 4096, 4, ... 3407872, 4096, ) == 0x0 00220 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 4096, ) == 0x0 00221 464 NtAllocateVirtualMemory (-1, 0, 0, 79872, 4096, 4, ... 3407872, 81920, ) == 0x0 00222 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 81920, ) == 0x0 00223 464 NtAllocateVirtualMemory (-1, 0, 0, 2048, 4096, 4, ... 3407872, 4096, ) == 0x0 00224 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 4096, ) == 0x0 00225 464 NtAllocateVirtualMemory (-1, 0, 0, 2560, 4096, 4, ... 3407872, 4096, ) == 0x0 00226 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 4096, ) == 0x0 00227 464 NtAllocateVirtualMemory (-1, 0, 0, 5120, 4096, 4, ... 3407872, 8192, ) == 0x0 00228 464 NtFreeVirtualMemory (-1, (0x340000), 0, 32768, ... (0x340000), 8192, ) == 0x0 00229 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "user32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00230 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7e410000), 0x0, 589824, ) == 0x0 00231 464 NtClose (28, ... ) == 0x0 00232 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00233 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77f10000), 0x0, 290816, ) == 0x0 00234 464 NtClose (28, ... ) == 0x0 00235 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00236 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00237 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00238 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00239 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00240 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00241 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00242 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00243 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00244 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00245 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00246 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00247 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00248 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00249 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00250 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00251 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00252 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00253 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00254 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\user32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00255 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00256 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089900645, 7274606, 2090320576, 1241608} (24, {28, 56, new_msg, 0, 2089900645, 7274606, 2090320576, 1241608} "\210\6\31\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 1036, 464, 57958, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57958, 0} (24, {28, 56, new_msg, 0, 2089900645, 7274606, 2090320576, 1241608} "\210\6\31\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 1036, 464, 57958, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00257 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239000, ... ) }, 1239000, ... ) == 0x0 00258 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 28, {status=0x0, info=1}, ) }, 5, 96, ... 28, {status=0x0, info=1}, ) == 0x0 00259 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 28, ... 32, ) == 0x0 00260 464 NtClose (28, ... ) == 0x0 00261 464 NtMapViewOfSection (32, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x340000), 0x0, 110592, ) == 0x0 00262 464 NtClose (32, ... ) == 0x0 00263 464 NtUnmapViewOfSection (-1, 0x340000, ... ) == 0x0 00264 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1238908, ... ) }, 1238908, ... ) == 0x0 00265 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 32, {status=0x0, info=1}, ) }, 5, 96, ... 32, {status=0x0, info=1}, ) == 0x0 00266 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 32, ... 28, ) == 0x0 00267 464 NtClose (32, ... ) == 0x0 00268 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x340000), 0x0, 110592, ) == 0x0 00269 464 NtClose (28, ... ) == 0x0 00270 464 NtUnmapViewOfSection (-1, 0x340000, ... ) == 0x0 00271 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239216, ... ) }, 1239216, ... ) == 0x0 00272 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 28, {status=0x0, info=1}, ) }, 5, 96, ... 28, {status=0x0, info=1}, ) == 0x0 00273 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 28, ... 32, ) == 0x0 00274 464 NtQuerySection (32, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00275 464 NtClose (28, ... ) == 0x0 00276 464 NtMapViewOfSection (32, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76390000), 0x0, 118784, ) == 0x0 00277 464 NtClose (32, ... ) == 0x0 00278 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00279 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00280 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00281 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00282 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00283 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00284 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00285 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00286 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00287 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00288 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00289 464 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00290 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1236132, ... ) }, 1236132, ... ) == 0x0 00291 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239536, ... ) }, 1239536, ... ) == 0x0 00292 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00293 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 32, ) }, ... 32, ) == 0x0 00294 464 NtQueryValueKey (32, (32, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00295 464 NtClose (32, ... ) == 0x0 00296 464 NtMapViewOfSection (-2147482740, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x580000), 0x0, 1060864, ) == 0x0 00297 464 NtClose (-2147482740, ... ) == 0x0 00298 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 32, ) == 0x0 00299 464 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00300 464 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482740, ) == 0x0 00301 464 NtQueryInformationToken (-2147482740, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00302 464 NtQueryInformationToken (-2147482740, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00303 464 NtClose (-2147482740, ... ) == 0x0 00304 464 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 3407872, 4096, ) == 0x0 00305 464 NtFreeVirtualMemory (-1, (0x340000), 4096, 32768, ... (0x340000), 4096, ) == 0x0 00306 464 NtDuplicateObject (-1, 28, -1, 0x0, 0, 2, ... 40, ) == 0x0 00307 464 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 00308 464 NtQueryValueKey (-2147482740, (-2147482740, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00309 464 NtClose (-2147482740, ... ) == 0x0 00310 464 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 00311 464 NtQueryValueKey (-2147482740, (-2147482740, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00312 464 NtClose (-2147482740, ... ) == 0x0 00313 464 NtQueryDefaultLocale (0, -139609780, ... ) == 0x0 00314 464 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00315 464 NtUserCallNoParam (24, ... ) == 0x0 00316 464 NtGdiCreateCompatibleDC (0, ... 00317 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3407872, 4096, ) == 0x0 00316 464 NtGdiCreateCompatibleDC ... ) == 0xee0105b0 00318 464 NtGdiGetStockObject (0, ... ) == 0x1900010 00319 464 NtGdiGetStockObject (4, ... ) == 0x1900011 00320 464 NtGdiCreateBitmap (8, 8, 1, 1, 2118200212, ... ) == 0x76050581 00321 464 NtGdiCreateSolidBrush (0, 0, ... 00322 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3473408, 4096, ) == 0x0 00321 464 NtGdiCreateSolidBrush ... ) == 0xa51003d2 00323 464 NtGdiGetStockObject (13, ... ) == 0x18a0021 00324 464 NtGdiCreateCompatibleDC (0, ... ) == 0x5201039b 00325 464 NtGdiSelectBitmap (1375798171, 1980040577, ... ) == 0x185000f 00326 464 NtUserGetThreadDesktop (464, 0, ... ) == 0x24 00327 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 44, ) }, ... 44, ) == 0x0 00328 464 NtQueryValueKey (44, (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00329 464 NtClose (44, ... ) == 0x0 00330 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00331 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 673, 128, 0, ... ) == 0x81aec017 00332 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00333 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 674, 128, 0, ... ) == 0x81aec01c 00334 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00335 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 675, 128, 0, ... ) == 0x81aec01e 00336 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00337 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 676, 128, 0, ... ) == 0x81ae8002 00338 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10013 00339 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 677, 128, 0, ... ) == 0x81aec018 00340 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00341 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 678, 128, 0, ... ) == 0x81aec01a 00342 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00343 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 679, 128, 0, ... ) == 0x81aec01d 00344 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00345 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 681, 128, 0, ... ) == 0x81aec026 00346 464 NtUserFindExistingCursorIcon (1240712, 1240728, 1240776, ... ) == 0x10011 00347 464 NtUserRegisterClassExWOW (1240724, 1240792, 1240808, 1240824, 680, 128, 0, ... ) == 0x81aec019 00348 464 NtUserRegisterClassExWOW (1240676, 1240744, 1240760, 1240776, 0, 128, 0, ... ) == 0x81aec020 00349 464 NtUserRegisterClassExWOW (1240932, 1241028, 1241012, 1241000, 0, 130, 0, ... ) == 0x81aec022 00350 464 NtUserRegisterClassExWOW (1240676, 1240744, 1240760, 1240776, 0, 128, 0, ... ) == 0x81aec023 00351 464 NtUserRegisterClassExWOW (1240932, 1241028, 1241012, 1241000, 0, 130, 0, ... ) == 0x81aec024 00352 464 NtUserRegisterClassExWOW (1240676, 1240744, 1240760, 1240776, 0, 128, 0, ... ) == 0x81aec025 00353 464 NtCallbackReturn (0, 0, 0, ... 00354 464 NtGdiInit (... ) == 0x1 00355 464 NtGdiGetStockObject (18, ... ) == 0x290001c 00356 464 NtGdiGetStockObject (19, ... ) == 0x1b00019 00357 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ole32.dll"}, ... 44, ) }, ... 44, ) == 0x0 00358 464 NtMapViewOfSection (44, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x774e0000), 0x0, 1298432, ) == 0x0 00359 464 NtClose (44, ... ) == 0x0 00360 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00361 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00362 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00363 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00364 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00365 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00366 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00367 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00368 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00369 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00370 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00371 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00372 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00373 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00374 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00375 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00376 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00377 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00378 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00379 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00380 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00381 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00382 464 NtAllocateVirtualMemory (-1, 1331200, 0, 4096, 4096, 4, ... 1331200, 4096, ) == 0x0 00383 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\Device\KsecDD"}, 7, 16, ... 44, {status=0x0, info=0}, ) }, 7, 16, ... 44, {status=0x0, info=0}, ) == 0x0 00384 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\321\0\336D\352\237+\205 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00385 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00386 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00387 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00388 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00389 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00390 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00391 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00392 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00393 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "{S\311\346n\357\304\357p}r\PC\35\3020[\3748\227co\227\33l\323\353\236\240\370g\3529R\32\267O\311\271<\304~\320>\301\2\361\251\360\204\253|\247\317\342M\3638\314:\342\351F\214\203\320_L(j[\341\350\354\355\273KOq", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "{S\311\346n\357\304\357p}r\PC\35\3020[\3748\227co\227\33l\323\353\236\240\370g\3529R\32\267O\311\271<\304~\320>\301\2\361\251\360\204\253|\247\317\342M\3638\314:\342\351F\214\203\320_L(j[\341\350\354\355\273KOq", 80, ... ) , 80, ... ) == 0x0 00394 464 NtClose (-2147482740, ... ) == 0x0 00384 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\16A4\357\263\16\215@\313\313\375`*\35\312\267\370\32\24MK*\251 \4`\320y\324\2749\341\240\376{y \14\272\247\264Z~\23\213\261\271\246\253,<\351hp\307|\222A\340\376%G7\273o\342\3761\247\220W\255\351\34A"\13}\301\357D0\252\35\\225\365L\247\341?q\11b\301\34\177\265\242\317j,\250\26W\215\217Z\22\362VN\275\342>\10gI\313\264|\275\32\10\3k\234`\223\263\230\376\7+r\210t\36\311\34\305\26\224\334<\376>\330\2469t\264Wj\276\302b\256C2<\316\221\355#\215\15\367\3251\335\264\315\363\375\35;\224\341A:BGM,\206W\216\256\3\371\316d\222z\220\321\207;\213j'\213\32\207:H.y\277P\253\10T\241\225]z\353\362\320\2541q\357\4\274:\272\332\277\315\226h\304^\316\226H\16\273\365\27\0\36\4\257\32\204\346\5\226\306\307\336", ) \13}\301\357D0\252\35\\225\365L\247\341?q\11b\301\34\177\265\242\317j,\250\26W\215\217Z\22\362VN\275\342>\10gI\313\264|\275\32\10\3k\234`\223\263\230\376\7+r\210t\36\311\34\305\26\224\334<\376>\330\2469t\264Wj\276\302b\256C2<\316\221\355#\215\15\367\3251\335\264\315\363\375\35;\224\341A:BGM,\206W\216\256\3\371\316d\222z\220\321\207;\213j'\213\32\207:H.y\277P\253\10T\241\225]z\353\362\320\2541q\357\4\274:\272\332\277\315\226h\304^\316\226H\16\273\365\27\0\36\4\257\32\204\346\5\226\306\307\336", ) == 0x0 00395 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00396 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00397 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 48, ) }, ... 48, ) == 0x0 00398 464 NtQueryValueKey (48, (48, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (48, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00399 464 NtClose (48, ... ) == 0x0 00400 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Ole"}, ... 48, ) }, ... 48, ) == 0x0 00401 464 NtQueryValueKey (48, (48, "RWLockResourceTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00402 464 NtClose (48, ... ) == 0x0 00403 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00404 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00405 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00406 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00407 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 48, ) }, ... 48, ) == 0x0 00408 464 NtQueryValueKey (48, (48, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00409 464 NtQueryValueKey (48, (48, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00410 464 NtQueryValueKey (48, (48, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00411 464 NtClose (48, ... ) == 0x0 00412 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 48, ) }, ... 48, ) == 0x0 00413 464 NtQueryValueKey (48, (48, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00414 464 NtQueryValueKey (48, (48, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00415 464 NtClose (48, ... ) == 0x0 00416 464 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 48, ) }, ... 48, ) == 0x0 00417 464 NtOpenEvent (0x1f0003, {24, 48, 0x0, 0, 0, (0x1f0003, {24, 48, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00418 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00419 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 52, ) == 0x0 00420 464 NtQueryInformationToken (52, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00421 464 NtClose (52, ... ) == 0x0 00422 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 52, ) }, ... 52, ) == 0x0 00423 464 NtSetInformationObject (52, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00424 464 NtOpenKey (0xf003f, {24, 52, 0x40, 0, 0, (0xf003f, {24, 52, 0x40, 0, 0, "Software\Borland\Locales"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00425 464 NtOpenKey (0xf003f, {24, 52, 0x40, 0, 0, (0xf003f, {24, 52, 0x40, 0, 0, "Software\Borland\Delphi\Locales"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00426 464 NtOpenProcessToken (-1, 0x8, ... 56, ) == 0x0 00427 464 NtQueryInformationToken (56, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00428 464 NtClose (56, ... ) == 0x0 00429 464 NtUserCallOneParam (0, 41, ... ) == 0x4 00430 464 NtAllocateVirtualMemory (-1, 1335296, 0, 4096, 4096, 4, ... 1335296, 4096, ) == 0x0 00431 464 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 1, ... 10027008, 1048576, ) == 0x0 00432 464 NtAllocateVirtualMemory (-1, 1339392, 0, 4096, 4096, 4, ... 1339392, 4096, ) == 0x0 00433 464 NtAllocateVirtualMemory (-1, 10027008, 0, 16384, 4096, 4, ... 10027008, 16384, ) == 0x0 00434 464 NtUserCallNoParam (29, ... 00435 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1242268, ... ) }, 1242268, ... ) == 0x0 00436 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 56, {status=0x0, info=1}, ) }, 5, 96, ... 56, {status=0x0, info=1}, ) == 0x0 00437 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 56, ... 60, ) == 0x0 00438 464 NtClose (56, ... ) == 0x0 00439 464 NtMapViewOfSection (60, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x380000), 0x0, 221184, ) == 0x0 00440 464 NtClose (60, ... ) == 0x0 00441 464 NtUnmapViewOfSection (-1, 0x380000, ... ) == 0x0 00442 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1242576, ... ) }, 1242576, ... ) == 0x0 00443 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 60, {status=0x0, info=1}, ) }, 5, 96, ... 60, {status=0x0, info=1}, ) == 0x0 00444 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 60, ... 56, ) == 0x0 00445 464 NtQuerySection (56, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00446 464 NtClose (60, ... ) == 0x0 00447 464 NtMapViewOfSection (56, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 229376, ) == 0x0 00448 464 NtClose (56, ... ) == 0x0 00449 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00450 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00451 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00452 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00453 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00454 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00455 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00456 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00457 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00458 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00459 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00460 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00461 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00462 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00463 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00464 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00465 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 56, ) == 0x0 00466 464 NtQueryInformationToken (56, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00467 464 NtClose (56, ... ) == 0x0 00468 464 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 56, ) }, ... 56, ) == 0x0 00469 464 NtOpenKey (0x1, {24, 56, 0x40, 0, 0, (0x1, {24, 56, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 60, ) }, ... 60, ) == 0x0 00470 464 NtQueryValueKey (60, (60, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00471 464 NtClose (60, ... ) == 0x0 00472 464 NtClose (56, ... ) == 0x0 00473 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00474 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 56, ) == 0x0 00475 464 NtQueryInformationToken (56, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00476 464 NtClose (56, ... ) == 0x0 00477 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 56, ) }, ... 56, ) == 0x0 00478 464 NtOpenKey (0x1, {24, 56, 0x40, 0, 0, (0x1, {24, 56, 0x40, 0, 0, "Control Panel\Desktop"}, ... 60, ) }, ... 60, ) == 0x0 00479 464 NtQueryValueKey (60, (60, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00480 464 NtClose (60, ... ) == 0x0 00481 464 NtClose (56, ... ) == 0x0 00482 464 NtUserGetProcessWindowStation (... ) == 0x1c 00483 464 NtUserGetObjectInformation (28, 2, 1244364, 64, 1244360, ... ) == 0x1 00484 464 NtUserGetGUIThreadInfo (464, 1244384, ... ) == 0x1 00485 464 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1244228, 64, ... 56, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1244228, 64, ... 56, 0x0, 0x0, 0x0, 64, ) == 0x0 00486 464 NtRequestWaitReplyPort (56, {32, 56, new_msg, 0, 0, 0, 0, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57967, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00487 464 NtRequestWaitReplyPort (56, {32, 56, new_msg, 0, 0, 0, 0, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57968, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57968, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57968, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00488 464 NtUserCallNoParam (29, ... 00489 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1241624, ... ) }, 1241624, ... ) == 0x0 00488 464 NtUserCallNoParam ... ) == 0x0 00490 464 NtUserSystemParametersInfo (41, 0, 1524240760, 0, ... ) == 0x1 00491 464 NtGdiHfontCreate (1243752, 356, 0, 0, 1340336, ... ) == 0x330a04e1 00492 464 NtGdiHfontCreate (1243752, 356, 0, 0, 1340328, ... ) == 0x520a0634 00493 464 NtRequestWaitReplyPort (56, {32, 56, new_msg, 0, 0, 0, 0, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57969, 0} "\0\0\0\0\0\0\0\0<\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57969, 0} (56, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57969, 0} "\0\0\0\0\0\0\0\0<\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00494 464 NtMapViewOfSection (60, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x380000), {0, 0}, 327680, ) == 0x0 00495 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00496 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00497 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00498 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00499 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00500 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00501 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00502 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00503 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00504 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00505 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00506 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00507 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00508 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00509 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00510 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00511 464 NtAllocateVirtualMemory (-1, 3297280, 0, 4096, 4096, 4, ... 3297280, 4096, ) == 0x0 00512 464 NtUserGetWindowDC (0, ... ) == 0x1010051 00513 464 NtGdiCreatePatternBrushInternal (59048383, 0, 0, ... ) == 0x72100798 00514 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00515 464 NtUserCallNoParam (29, ... 00516 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1241064, ... ) }, 1241064, ... ) == 0x0 00515 464 NtUserCallNoParam ... ) == 0x0 00517 464 NtUserCallNoParam (29, ... 00518 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1241060, ... ) }, 1241060, ... ) == 0x0 00517 464 NtUserCallNoParam ... ) == 0x0 00434 464 NtUserCallNoParam ... ) == 0x1 00519 464 NtQueryVirtualMemory (-1, 0x373313, Basic, 28, ... {BaseAddress=0x373000,AllocationBase=0x360000,AllocationProtect=0x4,RegionSize=0xa000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00520 464 NtQueryInformationProcess (-1, 34, 4, ... {process info, class 34, size 4}, 0x0, ) == 0x0 00521 464 NtContinue (1244356, 0, ... 00522 464 NtQueryVirtualMemory (-1, 0x372d5c, Basic, 28, ... {BaseAddress=0x372000,AllocationBase=0x360000,AllocationProtect=0x4,RegionSize=0xb000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00523 464 NtQueryInformationProcess (-1, 34, 4, ... {process info, class 34, size 4}, 0x0, ) == 0x0 00524 464 NtContinue (1244032, 0, ... 00525 464 NtQueryVirtualMemory (-1, 0x372dc0, Basic, 28, ... {BaseAddress=0x372000,AllocationBase=0x360000,AllocationProtect=0x4,RegionSize=0xb000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00526 464 NtQueryInformationProcess (-1, 34, 4, ... {process info, class 34, size 4}, 0x0, ) == 0x0 00527 464 NtContinue (1244032, 0, ... 00528 464 NtQueryVirtualMemory (-1, 0x370d71, Basic, 28, ... {BaseAddress=0x370000,AllocationBase=0x360000,AllocationProtect=0x4,RegionSize=0xd000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00529 464 NtQueryInformationProcess (-1, 34, 4, ... {process info, class 34, size 4}, 0x0, ) == 0x0 00530 464 NtQueryVirtualMemory (-1, 0x373132, Basic, 28, ... {BaseAddress=0x373000,AllocationBase=0x360000,AllocationProtect=0x4,RegionSize=0xa000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00531 464 NtQueryInformationProcess (-1, 34, 4, ... {process info, class 34, size 4}, 0x0, ) == 0x0 00532 464 NtQueryVirtualMemory (-1, 0x7c816fe0, Basic, 28, ... {BaseAddress=0x7c816000,AllocationBase=0x7c800000,AllocationProtect=0x80,RegionSize=0x6e000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 00533 464 NtQueryInformationProcess (-1, DebugPort, 4, ... {process info, class 7, size 4}, 0x0, ) == 0x0 00534 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00535 464 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 00536 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00537 464 NtQueryInformationJobObject (0, BasicLimit, 48, ... ) == STATUS_ACCESS_DENIED 00538 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug"}, ... 64, ) }, ... 64, ) == 0x0 00539 464 NtQueryValueKey (64, (64, "Auto", Partial, 526, ... TitleIdx=0, Type=1, Data="0\0\0\0"}, 16, ) , Partial, 526, ... TitleIdx=0, Type=1, Data= (64, "Auto", Partial, 526, ... TitleIdx=0, Type=1, Data="0\0\0\0"}, 16, ) }, 16, ) == 0x0 00540 464 NtQueryValueKey (64, (64, "Debugger", Partial, 526, ... TitleIdx=0, Type=1, Data=""\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0V\0i\0s\0u\0a\0l\0 \0S\0t\0u\0d\0i\0o\0\\0C\0o\0m\0m\0o\0n\0\\0M\0S\0D\0e\0v\09\08\0\\0B\0i\0n\0\\0m\0s\0d\0e\0v\0.\0e\0x\0e\0"\0 \0-\0p\0 \0%\0l\0d\0 \0-\0e\0 \0%\0l\0d\0\0\0"}, 184, ) , Partial, 526, ... TitleIdx=0, Type=1, Data=" (64, "Debugger", Partial, 526, ... TitleIdx=0, Type=1, Data=""\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0V\0i\0s\0u\0a\0l\0 \0S\0t\0u\0d\0i\0o\0\\0C\0o\0m\0m\0o\0n\0\\0M\0S\0D\0e\0v\09\08\0\\0B\0i\0n\0\\0m\0s\0d\0e\0v\0.\0e\0x\0e\0"\0 \0-\0p\0 \0%\0l\0d\0 \0-\0e\0 \0%\0l\0d\0\0\0"}, 184, ) \0 \0-\0p\0 \0%\0l\0d\0 \0-\0e\0 \0%\0l\0d\0\0\0"}, 184, ) == 0x0 00541 464 NtClose (64, ... ) == 0x0 00542 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\faultrep.dll"}, 1239712, ... ) }, 1239712, ... ) == 0x0 00543 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\faultrep.dll"}, 5, 96, ... 64, {status=0x0, info=1}, ) }, 5, 96, ... 64, {status=0x0, info=1}, ) == 0x0 00544 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 64, ... 68, ) == 0x0 00545 464 NtClose (64, ... ) == 0x0 00546 464 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x3d0000), 0x0, 81920, ) == 0x0 00547 464 NtClose (68, ... ) == 0x0 00548 464 NtUnmapViewOfSection (-1, 0x3d0000, ... ) == 0x0 00549 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\faultrep.dll"}, 1240020, ... ) }, 1240020, ... ) == 0x0 00550 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\faultrep.dll"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00551 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 68, ... 64, ) == 0x0 00552 464 NtQuerySection (64, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00553 464 NtClose (68, ... ) == 0x0 00554 464 NtMapViewOfSection (64, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x69450000), 0x0, 90112, ) == 0x0 00555 464 NtClose (64, ... ) == 0x0 00556 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "VERSION.dll"}, ... 64, ) }, ... 64, ) == 0x0 00557 464 NtMapViewOfSection (64, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 32768, ) == 0x0 00558 464 NtClose (64, ... ) == 0x0 00559 464 NtProtectVirtualMemory (-1, (0x77c01000), 304, 4, ... (0x77c01000), 4096, 32, ) == 0x0 00560 464 NtProtectVirtualMemory (-1, (0x77c01000), 4096, 32, ... (0x77c01000), 4096, 4, ) == 0x0 00561 464 NtFlushInstructionCache (-1, 2009075712, 304, ... ) == 0x0 00562 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "USERENV.dll"}, ... 64, ) }, ... 64, ) == 0x0 00563 464 NtMapViewOfSection (64, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x769c0000), 0x0, 733184, ) == 0x0 00564 464 NtClose (64, ... ) == 0x0 00565 464 NtProtectVirtualMemory (-1, (0x769c1000), 1244, 4, ... (0x769c1000), 4096, 32, ) == 0x0 00566 464 NtProtectVirtualMemory (-1, (0x769c1000), 4096, 32, ... (0x769c1000), 4096, 4, ) == 0x0 00567 464 NtFlushInstructionCache (-1, 1989939200, 1244, ... ) == 0x0 00568 464 NtProtectVirtualMemory (-1, (0x769c1000), 1244, 4, ... (0x769c1000), 4096, 32, ) == 0x0 00569 464 NtProtectVirtualMemory (-1, (0x769c1000), 4096, 32, ... (0x769c1000), 4096, 4, ) == 0x0 00570 464 NtFlushInstructionCache (-1, 1989939200, 1244, ... ) == 0x0 00571 464 NtProtectVirtualMemory (-1, (0x769c1000), 1244, 4, ... (0x769c1000), 4096, 32, ) == 0x0 00572 464 NtProtectVirtualMemory (-1, (0x769c1000), 4096, 32, ... (0x769c1000), 4096, 4, ) == 0x0 00573 464 NtFlushInstructionCache (-1, 1989939200, 1244, ... ) == 0x0 00574 464 NtProtectVirtualMemory (-1, (0x769c1000), 1244, 4, ... (0x769c1000), 4096, 32, ) == 0x0 00575 464 NtProtectVirtualMemory (-1, (0x769c1000), 4096, 32, ... (0x769c1000), 4096, 4, ) == 0x0 00576 464 NtFlushInstructionCache (-1, 1989939200, 1244, ... ) == 0x0 00577 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WINSTA.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00578 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WINSTA.dll"}, 1239196, ... ) }, 1239196, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00579 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WINSTA.dll"}, 1239196, ... ) }, 1239196, ... ) == 0x0 00580 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WINSTA.dll"}, 5, 96, ... 64, {status=0x0, info=1}, ) }, 5, 96, ... 64, {status=0x0, info=1}, ) == 0x0 00581 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 64, ... 68, ) == 0x0 00582 464 NtQuerySection (68, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00583 464 NtClose (64, ... ) == 0x0 00584 464 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76360000), 0x0, 65536, ) == 0x0 00585 464 NtClose (68, ... ) == 0x0 00586 464 NtProtectVirtualMemory (-1, (0x76361000), 212, 4, ... (0x76361000), 4096, 32, ) == 0x0 00587 464 NtProtectVirtualMemory (-1, (0x76361000), 4096, 32, ... (0x76361000), 4096, 4, ) == 0x0 00588 464 NtFlushInstructionCache (-1, 1983254528, 212, ... ) == 0x0 00589 464 NtProtectVirtualMemory (-1, (0x76361000), 212, 4, ... (0x76361000), 4096, 32, ) == 0x0 00590 464 NtProtectVirtualMemory (-1, (0x76361000), 4096, 32, ... (0x76361000), 4096, 4, ) == 0x0 00591 464 NtFlushInstructionCache (-1, 1983254528, 212, ... ) == 0x0 00592 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETAPI32.dll"}, ... 68, ) }, ... 68, ) == 0x0 00593 464 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5b860000), 0x0, 344064, ) == 0x0 00594 464 NtClose (68, ... ) == 0x0 00595 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 00596 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 00597 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 00598 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 00599 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 00600 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 00601 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 00602 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 00603 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 00604 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 00605 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 00606 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 00607 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 00608 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 00609 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 00610 464 NtProtectVirtualMemory (-1, (0x76361000), 212, 4, ... (0x76361000), 4096, 32, ) == 0x0 00611 464 NtProtectVirtualMemory (-1, (0x76361000), 4096, 32, ... (0x76361000), 4096, 4, ) == 0x0 00612 464 NtFlushInstructionCache (-1, 1983254528, 212, ... ) == 0x0 00613 464 NtProtectVirtualMemory (-1, (0x76361000), 212, 4, ... (0x76361000), 4096, 32, ) == 0x0 00614 464 NtProtectVirtualMemory (-1, (0x76361000), 4096, 32, ... (0x76361000), 4096, 4, ) == 0x0 00615 464 NtFlushInstructionCache (-1, 1983254528, 212, ... ) == 0x0 00616 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WTSAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00617 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WTSAPI32.dll"}, 1239196, ... ) }, 1239196, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00618 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WTSAPI32.dll"}, 1239196, ... ) }, 1239196, ... ) == 0x0 00619 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WTSAPI32.dll"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00620 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 68, ... 64, ) == 0x0 00621 464 NtQuerySection (64, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00622 464 NtClose (68, ... ) == 0x0 00623 464 NtMapViewOfSection (64, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f50000), 0x0, 32768, ) == 0x0 00624 464 NtClose (64, ... ) == 0x0 00625 464 NtProtectVirtualMemory (-1, (0x76f51000), 332, 4, ... (0x76f51000), 4096, 32, ) == 0x0 00626 464 NtProtectVirtualMemory (-1, (0x76f51000), 4096, 32, ... (0x76f51000), 4096, 4, ) == 0x0 00627 464 NtFlushInstructionCache (-1, 1995771904, 332, ... ) == 0x0 00628 464 NtProtectVirtualMemory (-1, (0x76f51000), 332, 4, ... (0x76f51000), 4096, 32, ) == 0x0 00629 464 NtProtectVirtualMemory (-1, (0x76f51000), 4096, 32, ... (0x76f51000), 4096, 4, ) == 0x0 00630 464 NtFlushInstructionCache (-1, 1995771904, 332, ... ) == 0x0 00631 464 NtProtectVirtualMemory (-1, (0x76f51000), 332, 4, ... (0x76f51000), 4096, 32, ) == 0x0 00632 464 NtProtectVirtualMemory (-1, (0x76f51000), 4096, 32, ... (0x76f51000), 4096, 4, ) == 0x0 00633 464 NtFlushInstructionCache (-1, 1995771904, 332, ... ) == 0x0 00634 464 NtProtectVirtualMemory (-1, (0x76f51000), 332, 4, ... (0x76f51000), 4096, 32, ) == 0x0 00635 464 NtProtectVirtualMemory (-1, (0x76f51000), 4096, 32, ... (0x76f51000), 4096, 4, ) == 0x0 00636 464 NtFlushInstructionCache (-1, 1995771904, 332, ... ) == 0x0 00637 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00638 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SETUPAPI.dll"}, 1239196, ... ) }, 1239196, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00639 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 1239196, ... ) }, 1239196, ... ) == 0x0 00640 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 5, 96, ... 64, {status=0x0, info=1}, ) }, 5, 96, ... 64, {status=0x0, info=1}, ) == 0x0 00641 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 64, ... 68, ) == 0x0 00642 464 NtQuerySection (68, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00643 464 NtClose (64, ... ) == 0x0 00644 464 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77920000), 0x0, 995328, ) == 0x0 00645 464 NtClose (68, ... ) == 0x0 00646 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 00647 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 00648 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 00649 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 00650 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 00651 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 00652 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 00653 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 00654 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 00655 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 00656 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 00657 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 00658 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 00659 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 00660 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 00661 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 68, ) }, ... 68, ) == 0x0 00662 464 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77f60000), 0x0, 483328, ) == 0x0 00663 464 NtClose (68, ... ) == 0x0 00664 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00665 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00666 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00667 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00668 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00669 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00670 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00671 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00672 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00673 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00674 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00675 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00676 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00677 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00678 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00679 464 NtProtectVirtualMemory (-1, (0x69451000), 736, 4, ... (0x69451000), 4096, 32, ) == 0x0 00680 464 NtProtectVirtualMemory (-1, (0x69451000), 4096, 32, ... (0x69451000), 4096, 4, ) == 0x0 00681 464 NtFlushInstructionCache (-1, 1766133760, 736, ... ) == 0x0 00682 464 NtProtectVirtualMemory (-1, (0x69451000), 736, 4, ... (0x69451000), 4096, 32, ) == 0x0 00683 464 NtProtectVirtualMemory (-1, (0x69451000), 4096, 32, ... (0x69451000), 4096, 4, ) == 0x0 00684 464 NtFlushInstructionCache (-1, 1766133760, 736, ... ) == 0x0 00685 464 NtProtectVirtualMemory (-1, (0x69451000), 736, 4, ... (0x69451000), 4096, 32, ) == 0x0 00686 464 NtProtectVirtualMemory (-1, (0x69451000), 4096, 32, ... (0x69451000), 4096, 4, ) == 0x0 00687 464 NtFlushInstructionCache (-1, 1766133760, 736, ... ) == 0x0 00688 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00689 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USERENV.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00690 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 68, ) }, ... 68, ) == 0x0 00691 464 NtQueryValueKey (68, (68, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00692 464 NtClose (68, ... ) == 0x0 00693 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 68, ) }, ... 68, ) == 0x0 00694 464 NtQueryValueKey (68, (68, "ChkAccDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00695 464 NtClose (68, ... ) == 0x0 00696 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "System\CurrentControlSet\Control\ProductOptions"}, ... 68, ) }, ... 68, ) == 0x0 00697 464 NtQueryValueKey (68, (68, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) }, 24, ) == 0x0 00698 464 NtClose (68, ... ) == 0x0 00699 464 NtCreateEvent (0x1f0003, {24, 48, 0x80, 1237788, 0, (0x1f0003, {24, 48, 0x80, 1237788, 0, "Global\userenv: User Profile setup event"}, 0, 1, ... 68, ) }, 0, 1, ... 68, ) == STATUS_OBJECT_NAME_EXISTS 00700 464 NtQueryDefaultUILanguage (2090319928, ... 00701 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00702 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0 00703 464 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00704 464 NtClose (-2147482740, ... ) == 0x0 00705 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 00706 464 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00707 464 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0 00708 464 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00709 464 NtClose (-2147481328, ... ) == 0x0 00710 464 NtClose (-2147482740, ... ) == 0x0 00700 464 NtQueryDefaultUILanguage ... ) == 0x0 00711 464 NtQueryInstallUILanguage (2090319930, ... ) == 0x0 00712 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00713 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00714 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00715 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00716 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00717 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00718 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00719 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00720 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00721 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00722 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00723 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00724 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00725 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00726 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00727 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00728 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00729 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00730 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00731 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00732 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00733 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00734 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00735 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00736 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00737 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00738 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00739 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 64, ) == 0x0 00740 464 NtQueryInformationToken (64, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00741 464 NtClose (64, ... ) == 0x0 00742 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 64, ) }, ... 64, ) == 0x0 00743 464 NtOpenKey (0x20019, {24, 64, 0x40, 0, 0, (0x20019, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 72, ) }, ... 72, ) == 0x0 00744 464 NtQueryValueKey (72, (72, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (72, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) }, 66, ) == 0x0 00745 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00746 464 NtQueryValueKey (72, (72, "Local Settings", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 70, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (72, "Local Settings", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 70, ) }, 70, ) == 0x0 00747 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00748 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00749 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00750 464 NtQueryDefaultLocale (1, 1237540, ... ) == 0x0 00751 464 NtClose (72, ... ) == 0x0 00752 464 NtClose (64, ... ) == 0x0 00753 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 64, ) }, ... 64, ) == 0x0 00754 464 NtQueryValueKey (64, (64, "RsopDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00755 464 NtClose (64, ... ) == 0x0 00756 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 64, ) }, ... 64, ) == 0x0 00757 464 NtQueryValueKey (64, (64, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00758 464 NtQueryValueKey (64, (64, "RsopLogging", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00759 464 NtClose (64, ... ) == 0x0 00760 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\System"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00761 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 64, ) }, ... 64, ) == 0x0 00762 464 NtQueryValueKey (64, (64, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00763 464 NtClose (64, ... ) == 0x0 00764 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\System"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00765 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NETAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00766 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINSTA.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00767 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WTSAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00768 464 NtQueryPerformanceCounter (... {924499975, 10}, {3579545, 0}, ) == 0x0 00769 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00770 464 NtQueryDefaultLocale (1, 1239916, ... ) == 0x0 00771 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 00772 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "System\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00773 464 NtQueryValueKey (64, (64, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (64, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00774 464 NtClose (64, ... ) == 0x0 00775 464 NtUserGetProcessWindowStation (... ) == 0x1c 00776 464 NtUserGetObjectInformation (28, 1, 1239512, 12, 1239524, ... ) == 0x1 00777 464 NtOpenKey (0xf003f, {24, 16, 0x40, 0, 0, (0xf003f, {24, 16, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\MiniNT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00778 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "System\WPA\PnP"}, ... 64, ) }, ... 64, ) == 0x0 00779 464 NtQueryValueKey (64, (64, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (64, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) }, 16, ) == 0x0 00780 464 NtClose (64, ... ) == 0x0 00781 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "SYSTEM\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00782 464 NtQueryValueKey (64, (64, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 00783 464 NtQueryValueKey (64, (64, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 00784 464 NtClose (64, ... ) == 0x0 00785 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "SYSTEM\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00786 464 NtQueryValueKey (64, (64, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 00787 464 NtQueryValueKey (64, (64, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 00788 464 NtClose (64, ... ) == 0x0 00789 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00790 464 NtQueryValueKey (64, (64, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 00791 464 NtQueryValueKey (64, (64, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 00792 464 NtClose (64, ... ) == 0x0 00793 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00794 464 NtQueryValueKey (64, (64, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 00795 464 NtQueryValueKey (64, (64, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 00796 464 NtClose (64, ... ) == 0x0 00797 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00798 464 NtQueryValueKey (64, (64, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 00799 464 NtQueryValueKey (64, (64, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (64, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 00800 464 NtClose (64, ... ) == 0x0 00801 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 64, ) }, ... 64, ) == 0x0 00802 464 NtQueryValueKey (64, (64, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (64, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 00803 464 NtQueryValueKey (64, (64, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (64, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 00804 464 NtClose (64, ... ) == 0x0 00805 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 64, ) }, ... 64, ) == 0x0 00806 464 NtQueryValueKey (64, (64, "DevicePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 00807 464 NtQueryValueKey (64, (64, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) , Partial, 346, ... TitleIdx=0, Type=2, Data= (64, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) }, 346, ) == 0x0 00808 464 NtAllocateVirtualMemory (-1, 1343488, 0, 4096, 4096, 4, ... 1343488, 4096, ) == 0x0 00809 464 NtClose (64, ... ) == 0x0 00810 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 64, ) == 0x0 00811 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 72, ) == 0x0 00812 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 76, ) == 0x0 00813 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 80, ) == 0x0 00814 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 84, ) == 0x0 00815 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 88, ) == 0x0 00816 464 NtOpenKey (0x1, {24, 16, 0x40, 0, 0, (0x1, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 92, ) }, ... 92, ) == 0x0 00817 464 NtQueryValueKey (92, (92, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (92, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00818 464 NtQueryValueKey (92, (92, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (92, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00819 464 NtQueryValueKey (92, (92, "LogPath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00820 464 NtOpenKey (0x1, {24, 92, 0x40, 0, 0, (0x1, {24, 92, 0x40, 0, 0, "AppLogLevels"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00821 464 NtClose (92, ... ) == 0x0 00822 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 1239428, ... ) }, 1239428, ... ) == 0x0 00823 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName"}, ... 92, ) }, ... 92, ) == 0x0 00824 464 NtQueryValueKey (92, (92, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (92, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (92, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 00825 464 NtClose (92, ... ) == 0x0 00826 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 92, ) }, ... 92, ) == 0x0 00827 464 NtQueryValueKey (92, (92, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (92, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Data= (92, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) }, 52, ) == 0x0 00828 464 NtClose (92, ... ) == 0x0 00829 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\System\DNSclient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00830 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 92, ) }, ... 92, ) == 0x0 00831 464 NtQueryValueKey (92, (92, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (92, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Data= (92, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) }, 34, ) == 0x0 00832 464 NtClose (92, ... ) == 0x0 00833 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00834 464 NtOpenKey (0x2000000, {24, 16, 0x40, 0, 0, (0x2000000, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00835 464 NtCreateSemaphore (0x1f0003, {24, 48, 0x80, 1343256, 0, (0x1f0003, {24, 48, 0x80, 1343256, 0, "shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}"}, 0, 2147483647, ... 92, ) }, 0, 2147483647, ... 92, ) == STATUS_OBJECT_NAME_EXISTS 00836 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\faultrep.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00837 464 NtOpenKey (0x20119, {24, 16, 0x40, 0, 0, (0x20119, {24, 16, 0x40, 0, 0, "Software\Policies\Microsoft\PCHealth\ErrorReporting"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00838 464 NtCreateKey (0x20119, {24, 16, 0x40, 0, 0, (0x20119, {24, 16, 0x40, 0, 0, "Software\Microsoft\PCHealth\ErrorReporting"}, 0, 0x0, 0, ... 96, 2, ) }, 0, 0x0, 0, ... 96, 2, ) == 0x0 00839 464 NtOpenKey (0x10000, {24, 96, 0x40, 0, 0, (0x10000, {24, 96, 0x40, 0, 0, "DW"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00840 464 NtQueryValueKey (96, (96, "DoReport", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "DoReport", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00841 464 NtQueryValueKey (96, (96, "ShowUI", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "ShowUI", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00842 464 NtQueryValueKey (96, (96, "AllOrNone", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "AllOrNone", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00843 464 NtQueryValueKey (96, (96, "IncludeMicrosoftApps", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "IncludeMicrosoftApps", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00844 464 NtQueryValueKey (96, (96, "IncludeWindowsApps", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "IncludeWindowsApps", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00845 464 NtQueryValueKey (96, (96, "DoTextLog", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00846 464 NtQueryValueKey (96, (96, "IncludeKernelFaults", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "IncludeKernelFaults", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00847 464 NtQueryValueKey (96, (96, "IncludeShutdownErrs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00848 464 NtQueryValueKey (96, (96, "NumberOfFaultPipes", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00849 464 NtQueryValueKey (96, (96, "NumberOfHangPipes", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00850 464 NtQueryValueKey (96, (96, "MaxUserQueueSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00851 464 NtQueryValueKey (96, (96, "ForceQueueMode", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00852 464 NtCreateKey (0x20119, {24, 96, 0x40, 0, 0, (0x20119, {24, 96, 0x40, 0, 0, "ExclusionList"}, 0, 0x0, 0, ... 100, 2, ) }, 0, 0x0, 0, ... 100, 2, ) == 0x0 00853 464 NtCreateKey (0x20119, {24, 96, 0x40, 0, 0, (0x20119, {24, 96, 0x40, 0, 0, "InclusionList"}, 0, 0x0, 0, ... 104, 2, ) }, 0, 0x0, 0, ... 104, 2, ) == 0x0 00854 464 NtClose (96, ... ) == 0x0 00855 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "System\Setup"}, ... 96, ) }, ... 96, ) == 0x0 00856 464 NtQueryValueKey (96, (96, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (96, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00857 464 NtClose (96, ... ) == 0x0 00858 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00859 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00860 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1236956, ... ) }, 1236956, ... ) == 0x0 00861 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\"}, 3, 16417, ... 96, {status=0x0, info=1}, ) }, 3, 16417, ... 96, {status=0x0, info=1}, ) == 0x0 00862 464 NtQueryDirectoryFile (96, 0, 0, 0, 1236384, 616, BothDirectory, 1, (96, 0, 0, 0, 1236384, 616, BothDirectory, 1, "work", 0, ... {status=0x0, info=104}, ) , 0, ... {status=0x0, info=104}, ) == 0x0 00863 464 NtClose (96, ... ) == 0x0 00864 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 96, {status=0x0, info=1}, ) }, 3, 16417, ... 96, {status=0x0, info=1}, ) == 0x0 00865 464 NtQueryDirectoryFile (96, 0, 0, 0, 1236384, 616, BothDirectory, 1, (96, 0, 0, 0, 1236384, 616, BothDirectory, 1, "packed.exe", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 00866 464 NtClose (96, ... ) == 0x0 00867 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00868 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00869 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00870 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00871 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1235604, ... ) }, 1235604, ... ) == 0x0 00872 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1234376, ... ) }, 1234376, ... ) == 0x0 00873 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00874 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00875 464 NtQueryValueKey (100, (100, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00876 464 NtOpenThreadToken (-2, 0x2000c, 1, ... ) == STATUS_NO_TOKEN 00877 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 00878 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00879 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00880 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 96, ) }, ... 96, ) == 0x0 00881 464 NtQueryValueKey (96, (96, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00882 464 NtClose (96, ... ) == 0x0 00883 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00884 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 96, ) == 0x0 00885 464 NtAllocateVirtualMemory (-1, 1347584, 0, 4096, 4096, 4, ... 1347584, 4096, ) == 0x0 00886 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 108, ) == 0x0 00887 464 NtQuerySystemTime (... {1726689472, 29915843}, ) == 0x0 00888 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 112, ) == 0x0 00889 464 NtOpenKey (0x20019, {24, 16, 0x40, 0, 0, (0x20019, {24, 16, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00890 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 00891 464 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 00892 464 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 00893 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 116, ) == 0x0 00894 464 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 120, ) == 0x0 00895 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\327O\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00896 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00897 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00898 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00899 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00900 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00901 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00902 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00903 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00904 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "6"{\264\337\15\344a\274ln\350@\260}*d\231.\264\352\374\341\256/\347`\252\211\313U\27\267\4\247\245\355\3103\223\243\1\2469;\204)\360\254\366o\21]\13;3F|%tg\10\310\3532\376\232i\313\231\213\15\307\350\262\203\4:g\371", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "6"{\264\337\15\344a\274ln\350@\260}*d\231.\264\352\374\341\256/\347`\252\211\313U\27\267\4\247\245\355\3103\223\243\1\2469;\204)\360\254\366o\21]\13;3F|%tg\10\310\3532\376\232i\313\231\213\15\307\350\262\203\4:g\371", 80, ... ) {\264\337\15\344a\274ln\350@\260}*d\231.\264\352\374\341\256/\347`\252\211\313U\27\267\4\247\245\355\3103\223\243\1\2469;\204)\360\254\366o\21]\13;3F|%tg\10\310\3532\376\232i\313\231\213\15\307\350\262\203\4:g\371", 80, ... ) == 0x0 00905 464 NtClose (-2147482740, ... ) == 0x0 00895 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\222\312h\20Y\226R|<-;\250\352\335\25\242\241=\346o\233\177\276\177/\263HL\301a\227\22\264\310\246_\373\200\276\34?!\12\207w\323\100\371C\352\37\2765\3\314\273\350J\355\274=\365}\214\330ISI \16\361\213(&\362\350\\340\260\265{\276\S\341\2357f8}\251\206\274g\211!`\215\23X\230\6\361\241\371f"\332\351\67\21\334`\13\240\262?\2609\270\34\360\251\337\36d\266\202\21cO\251|kADL\340h\32\234&\226\33Z0\251w%c\322\304FZ\305\343x\361\365\14\370\244\225\301\265\34\265\330\360\220\250\31Y\35\237\261\377Z>:\237\362\210\12\330\276d\300\6\264\10{p\36\352~\205\330r\232nos3p\224%\222\362?o\251\220\345cc~\337\371\273}\230\31\343\321\361e\233\344=\263s%[\3343\345P\335\20\340\302\354HK#E@(\2750\257\274\5", ) \332\351\67\21\334`\13\240\262?\2609\270\34\360\251\337\36d\266\202\21cO\251|kADL\340h\32\234&\226\33Z0\251w%c\322\304FZ\305\343x\361\365\14\370\244\225\301\265\34\265\330\360\220\250\31Y\35\237\261\377Z>:\237\362\210\12\330\276d\300\6\264\10{p\36\352~\205\330r\232nos3p\224%\222\362?o\251\220\345cc~\337\371\273}\230\31\343\321\361e\233\344=\263s%[\3343\345P\335\20\340\302\354HK#E@(\2750\257\274\5", ) == 0x0 00906 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00907 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00908 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00909 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00910 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00911 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00912 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00913 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00914 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00915 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "\261\0\261\7\254jV\240\2729\32\240}\15\255\372\266\7gz\217\20\347\240\324\21\2530?\332\302u\327\346\312\373\252\210\235\206\203\275\30l\320\227>_\316!\212\343x;\231\6O\342\314\225\327:Q;~<\244\256\267\224\22\322\245\161\31\313\236", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "\261\0\261\7\254jV\240\2729\32\240}\15\255\372\266\7gz\217\20\347\240\324\21\2530?\332\302u\327\346\312\373\252\210\235\206\203\275\30l\320\227>_\316!\212\343x;\231\6O\342\314\225\327:Q;~<\244\256\267\224\22\322\245\161\31\313\236", 80, ... ) , 80, ... ) == 0x0 00916 464 NtClose (-2147482740, ... ) == 0x0 00906 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "X\267\201\375\30\245\331\16+k\226\2234\334\236\34\312\344\224\26?Xf\201\246\210\271\330ru"\232J\310!\31R\322\356\243\360.>\266\233\372\307\270\37\2322A\3226\254\250u9\327\253\341\361\266\2718\227*\27m\367\345'\4\244|\12\263-L".0{\356`\356\344\24QD\357\330O\13\212t\34\331\255?v\244\226\317\0\277\243\35h\325`\3073.\16Y_\271\307\16c\2735\2067)?u[\256#\245b\27\336\211\243\263\204D\12'\326\241I \267s\234\261\347\244\265&\227\337Jq/Q", ) \232J\310!\31R\322\356\243\360.>\266\233\372\307\270\37\2322A\3226\254\250u9\327\253\341\361\266\2718\227*\27m\367\345'\4\244|\12\263-L275\312\271.\375\1\333\232\334m\317*\206\12\21\240\356\211\\323\277\252\24\326\325\207\220\9\237\245Rb&XqZ\333\200\241\315\262{\350\342\300\323\345\316\210\356\270\320W'zX\34\332\224gQ0\121`I\206\327\340\0\11\3216\202\355\313\323\373\330\227d\247\15_\243\264$\306 ... {status=0x0, info=256}, "X\267\201\375\30\245\331\16+k\226\2234\334\236\34\312\344\224\26?Xf\201\246\210\271\330ru"\232J\310!\31R\322\356\243\360.>\266\233\372\307\270\37\2322A\3226\254\250u9\327\253\341\361\266\2718\227*\27m\367\345'\4\244|\12\263-L".0{\356`\356\344\24QD\357\330O\13\212t\34\331\255?v\244\226\317\0\277\243\35h\325`\3073.\16Y_\271\307\16c\2735\2067)?u[\256#\245b\27\336\211\243\263\204D\12'\326\241I \267s\234\261\347\244\265&\227\337Jq/Q", ) , ) == 0x0 00917 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\257*\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00918 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00919 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00920 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00921 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00922 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00923 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00924 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00925 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00926 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "_\367\25\236\362K\24k\272$U\217\353\271\312L\254]h\277\331\360\23\213I\353\371\215\347\343q\353\337\300o,Rq\7\277Z}\366\227\30\322R\37z\354\302\227{CV\367\247\272rq\335$}\346\32\272\270 >\257Rr@d^\306b\236\236q", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "_\367\25\236\362K\24k\272$U\217\353\271\312L\254]h\277\331\360\23\213I\353\371\215\347\343q\353\337\300o,Rq\7\277Z}\366\227\30\322R\37z\354\302\227{CV\367\247\272rq\335$}\346\32\272\270 >\257Rr@d^\306b\236\236q", 80, ... ) , 80, ... ) == 0x0 00927 464 NtClose (-2147482740, ... ) == 0x0 00917 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "g\3066\254\215\362\302\17\314p\177\213\301\265Q\24\34\246\322\1\230\311\320\323\200\207\236r\306\363\234d\242(\5PWr\231\373\304t\35_\4\242H\37\321\246\272? \340\352\276\322\267h\34\242\3461-\32\205Q\235l\6o\2309\246R\231=\303\315\32\62\22\256\317\233oL\265\320MNR\177kT\233\264\210x\11\376\25o\202198\274o\2t\14\4]\264R@6\311\2077\262\253\266l\267\211\236\255\372P\245\17\344\25\231\226d\200K\376\21\350H0\2345_\272\330\25\1\275\355\2056\304C:\22\35\324\220\371>\244\275\354i\317x\334}6\265\233\261\310\274\37\22\220;\14\346\16\331Yz\26\347\256\25\25\34\230.\264\33\307\331\5\253s\236-\360\246\33h\300\225\217\300\346\377\271"|\31\313\265\254\363\16#(=l8\336\314 %\365\250\335\252\221S\322\350\36\4\303\301\253\3448]\353hy~", ) |\31\313\265\254\363\16#(=l8\336\314 %\365\250\335\252\221S\322\350\36\4\303\301\253\3448]\353hy~", ) == 0x0 00928 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00929 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00930 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00931 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00932 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00933 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00934 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00935 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00936 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00937 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "\310 \234\336R\3515#\274 \352\376\300g\33\2761U\306M5\5\350~N\267&\254\33\252\343\227\13\177\232\373sdj\215p\262\214\275\352\7\306\22\3369\345\206gO\320\353\326\311\322\32\343\262\375\245f\231Q\204\227k\354\333\365\354\332\222\177fy|", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "\310 \234\336R\3515#\274 \352\376\300g\33\2761U\306M5\5\350~N\267&\254\33\252\343\227\13\177\232\373sdj\215p\262\214\275\352\7\306\22\3369\345\206gO\320\353\326\311\322\32\343\262\375\245f\231Q\204\227k\354\333\365\354\332\222\177fy|", 80, ... ) , 80, ... ) == 0x0 00938 464 NtClose (-2147482740, ... ) == 0x0 00928 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\233=\3171\334\256j\350\262\244\232k\1\202\254\320\327uw\343u\372\317\257\327N\15\216\221;\211=\206\345\1\33$\331\302\330~\317\303\27\224\350+\245\263\363\313\15x\5S\314n\3768R\342\300<0\253\2359\260\330@CF\365\7\241nq\254\305\263\7\247\332\335)\276T+\253\374\367C60U\6o\312jD\331>~\321\323+\260'C\215so=\312\275+\302\224\265`\347G\221\300\216\30\367\236\356\332,\216HQLaN\251j\5\25v;\301\22KW\240\335\33h\300`=\325\373RV\355\236\30\350\352\26<1!\2\237\232@\267\336|~\7t,\327\360z4^\337\335\1t\34\345`d\246\345\13\375J\352\342\3157yV!\146\322\334\305\326L\215\255\244\2407A\202\271\303+Z\310\12&r\311\272v5n\5\270\32\223\335\31fgR\235\320L(\241L~X=\246\375A]e\277\370Y", ) , ) == 0x0 00939 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00940 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00941 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00942 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00943 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00944 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00945 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00946 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00947 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00948 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "\36\246\\273\232\345x\333!h\307\234\377\200\320&\353\233\17\6\253\25\332\362R\3156\234\177\315\\311\212\370B\276\10b>7\205\272Ud\2702Q!\306j\230|\305\341\212\334\323\301@YtS-U\24\251&\223\353\314*\345`h\3221/S~*", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "\36\246\\273\232\345x\333!h\307\234\377\200\320&\353\233\17\6\253\25\332\362R\3156\234\177\315\\311\212\370B\276\10b>7\205\272Ud\2702Q!\306j\230|\305\341\212\334\323\301@YtS-U\24\251&\223\353\314*\345`h\3221/S~*", 80, ... ) , 80, ... ) == 0x0 00949 464 NtClose (-2147482740, ... ) == 0x0 00939 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, ">:;\205\224\324\2=\232\11i\4S\373\234\324N\13{R\342\222\335R\351\357\322{\23\17\244\326\2\265\364\225\245=c2f\326\351\2?\210\312\355~\332Ub\210O\23\344\4\336\306\313R\30\153wx\364\226\216\345\11\371\305\252\334\273\326\371,\34\305\202W\267\220\234|\262E\26\24\301cH\377\331\377\231\24`\205\243w\372=\7\334\27\305\265h@ki\357\220\255!\20\13\375\3257\211\223\233\272\347\177\217Pa\377\353\266\\246\311\33\178o\255\302\0\201\361\360\335\323|\274\3039\108\177\21y\327@~/\375\373\"\263\224y\213\6\27\221\350\\275\177'\212HaF\304\226O\351\235}\302\313\275<\355\205<\336\344n\354bX\306\225Wm\355,a\263V\360D\207\4\177\225~\257^:n\371~\26\371y\20\331Y\210\211s\375\233<=\346\33zV\363]\30\203%\330\204\303\365c\375", ) \263\224y\213\6\27\221\350\\275\177'\212HaF\304\226O\351\235}\302\313\275<\355\205<\336\344n\354bX\306\225Wm\355,a\263V\360D\207\4\177\225~\257^:n\371~\26\371y\20\331Y\210\211s\375\233<=\346\33zV\363]\30\203%\330\204\303\365c\375", ) == 0x0 00950 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00951 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00952 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00953 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00954 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00955 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00956 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00957 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00958 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00959 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "o4\3\316\353\4}\314t\214\373/\241\335x\332\367\243\11\320\203W\312\261N\37\267\357\301\266(\340\232\267\342\244\245\15\33\0\240F\1I\360\254\322\33M\302\276b3\200\16'\301\366\203\37\343\372|\325\271#J\345\15\345\224\243\33eq\17\334\235\265\37", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "o4\3\316\353\4}\314t\214\373/\241\335x\332\367\243\11\320\203W\312\261N\37\267\357\301\266(\340\232\267\342\244\245\15\33\0\240F\1I\360\254\322\33M\302\276b3\200\16'\301\366\203\37\343\372|\325\271#J\345\15\345\224\243\33eq\17\334\235\265\37", 80, ... ) , 80, ... ) == 0x0 00960 464 NtClose (-2147482740, ... ) == 0x0 00950 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\327\242U\30\274+o\324\266\332=\321\23+\230\374\3369\277\346S~N\326t@\247\377b\22d\342p\24\251\35Z0%ny\212ig{\373\34s\317\234R\372l'\26\31`5i\226\232\377\25\14\274\255rX\313c\225c\354/\367\322\201\200w\14\336\202\204\254@]R\237n\243Gm\2755\257\261m\355\270\366\23\323\211\7\233\34\337-f!_P\22, ) , ) == 0x0 00961 464 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\31U\235\236{.\307\3162\357PJo\227\310}\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\257*\263\366\34,T\260\30\202\342\274\334\350\342w\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00962 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00963 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00964 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00965 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00966 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00967 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00968 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00969 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482740, 2, ) }, 0, 0x0, 0, ... -2147482740, 2, ) == 0x0 00970 464 NtSetValueKey (-2147482740, (-2147482740, "Seed", 0, 3, "\351\2767\201\7\350\315PA\230,\11\177\336D@\333\215\177\303\340\\344+\340\312\310$\240N\322\243\302C\233\210\2760M\233^\260\261\225\353bF\213\251\2700\362\21\302\245o\331\245\7\362\275\331\275\240\7=\350\320\275\14\37\372\215\211o\35\245\13\23\17", 80, ... ) , 0, 3, (-2147482740, "Seed", 0, 3, "\351\2767\201\7\350\315PA\230,\11\177\336D@\333\215\177\303\340\\344+\340\312\310$\240N\322\243\302C\233\210\2760M\233^\260\261\225\353bF\213\251\2700\362\21\302\245o\331\245\7\362\275\331\275\240\7=\350\320\275\14\37\372\215\211o\35\245\13\23\17", 80, ... ) , 80, ... ) == 0x0 00971 464 NtClose (-2147482740, ... ) == 0x0 00961 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\346\202\275\332R\274z'\2476j\215\13\363\335\340\330\236\245Up\326j\253\346\242\320f\177\244\337_\37\310m\231\34`\36*\31\255,^\375(7|\247\17\325\333T\230\201l\1777\203\312\310\372\0\276\232\14\325\25\305\35\202?\300\2462\20\16,\372Z\25\244\216VL\11y\10\177.u\345\37\365 8\322\233\321l2gez\12\267\371Cb\264\361\\270\245\314\355\5\25\227\35\354\251\240\257\330\35\235\352\334\235\305\246c\34\32O$\347D\372w\225\371\311\334\256\277P\267Af\267j\230\376\367D\203\215\22\270xc\240>\225\12\200\205\241\226~\226\355$\361\314\251wh\356\207\322;\11\304FsjM\322\205a\373<:\357\302\3\357i\227\313\6EmR\345zs\17\4\25\27Uq\312\256]\300'@,\217\2442\234\257\353\242\334@\271\373\222z\220}\207Xd\310c\371\326\261`\335^o4\22\313\246\342\256", ) , ) == 0x0 00972 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 124, ) == 0x0 00973 464 NtConnectPort ( ("\RPC Control\IcaApi", {12, 2, 1, 0}, 0x0, 0x0, 1234748, 188, ... 128, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 0}, 0x0, 0x0, 1234748, 188, ... 128, 0x0, 0x0, 0x0, 188, ) == 0x0 00974 464 NtRequestWaitReplyPort (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} "\0\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\08\232\24\0\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\215u\274\237\148\346k\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\374\31ZZx\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1036, 464, 57973, 0} "\7\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\215u\274\237\148\346k\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\374\31ZZx\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ... {200, 224, reply, 0, 1036, 464, 57973, 0} (128, {200, 224, new_msg, 0, 1350664, 12, 2, 1310721} "\0\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\08\232\24\0\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\215u\274\237\148\346k\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\374\31ZZx\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1036, 464, 57973, 0} "\7\0\0\0\274\0\0\0x\1\24\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0x\1\24\0\0\0\0\0\0\0\24\0\2\0\0\0\215u\274\237\148\346k\270\233\24\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\220\233\24\0\374\31ZZx\1\24\0\260\233\24\0h\1\24\0\0\0\0\0\0\0\0\0\260\233\24\0P\0\0\0\270\233\24\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\274\325\22\0\372\31\221|P\335\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 00975 464 NtRequestWaitReplyPort (128, {32, 56, new_msg, 0, 0, 0, 0, 0} (128, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 1036, 464, 57974, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ... {124, 148, reply, 0, 1036, 464, 57974, 0} (128, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 1036, 464, 57974, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ) == 0x0 00976 464 NtAllocateVirtualMemory (-1, 1351680, 0, 4096, 4096, 4, ... 1351680, 4096, ) == 0x0 00977 464 NtRequestWaitReplyPort (128, {44, 68, new_msg, 56, 1036, 464, 57974, 0} (128, {44, 68, new_msg, 56, 1036, 464, 57974, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 1036, 464, 57975, 0} "\2\376\255\201\4\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 1036, 464, 57975, 0} (128, {44, 68, new_msg, 56, 1036, 464, 57974, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 1036, 464, 57975, 0} "\2\376\255\201\4\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\14\5\0\0\320\371\15\0" ) ) == 0x0 00978 464 NtRequestWaitReplyPort (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 1036, 464, 57976, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 1036, 464, 57976, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 1036, 464, 57976, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 00979 464 NtRequestWaitReplyPort (128, {44, 68, new_msg, 56, 1036, 464, 57975, 0} (128, {44, 68, new_msg, 56, 1036, 464, 57975, 0} "\1\376\0\0B\2\5\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200\377\377\377\377\324\376\255\201\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 1036, 464, 57977, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 1036, 464, 57977, 0} (128, {44, 68, new_msg, 56, 1036, 464, 57975, 0} "\1\376\0\0B\2\5\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200\377\377\377\377\324\376\255\201\1\0\0\0\210\236\24\0\10\5\0\0" ... {40, 64, reply, 0, 1036, 464, 57977, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ) == 0x0 00980 464 NtRequestWaitReplyPort (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 1036, 464, 57978, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 1036, 464, 57978, 0} (128, {64, 88, new_msg, 56, 1351024, 1235324, 1351296, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 1036, 464, 57978, 0} "\10\0\0\0@\0\1\10\2\0\0t\330\22\0\210\236\24\0\220\335\22\0\30\356\220|p\5\221|\1\0\0\0\210\236\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 00981 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 132, ) }, ... 132, ) == 0x0 00982 464 NtOpenKey (0x20019, {24, 132, 0x40, 0, 0, (0x20019, {24, 132, 0x40, 0, 0, "ActiveComputerName"}, ... 136, ) }, ... 136, ) == 0x0 00983 464 NtQueryValueKey (136, (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (136, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 00984 464 NtClose (136, ... ) == 0x0 00985 464 NtClose (132, ... ) == 0x0 00986 464 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 132, ) == 0x0 00987 464 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 136, ) == 0x0 00988 464 NtDuplicateObject (-1, 132, -1, 0x0, 0, 2, ... 140, ) == 0x0 00989 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 00990 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 144, ) == 0x0 00991 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 00992 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 00993 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234784, (0xc0100080, {24, 0, 0x40, 0, 1234784, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 148, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 148, {status=0x0, info=1}, ) == 0x0 00994 464 NtSetInformationFile (148, 1234840, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 00995 464 NtSetInformationFile (148, 1234828, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 00996 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 00997 464 NtWriteFile (148, 117, 0, 0, (148, 117, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 00998 464 NtReadFile (148, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (148, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 00999 464 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 01000 464 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , ) == 0x103 01001 464 NtFsControlFile (148, 117, 0x0, 0x0, 0x11c017, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (148, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 01002 464 NtClose (144, ... ) == 0x0 01003 464 NtClose (148, ... ) == 0x0 01004 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01005 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 148, ) == 0x0 01006 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01007 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01008 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234756, (0xc0100080, {24, 0, 0x40, 0, 1234756, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 144, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 144, {status=0x0, info=1}, ) == 0x0 01009 464 NtSetInformationFile (144, 1234812, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 01010 464 NtSetInformationFile (144, 1234800, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 01011 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01012 464 NtWriteFile (144, 117, 0, 0, (144, 117, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 01013 464 NtReadFile (144, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (144, 117, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 01014 464 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\14\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\14\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 01015 464 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\334\340\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , ) == 0x103 01016 464 NtFsControlFile (144, 117, 0x0, 0x0, 0x11c017, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (144, 117, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\250\251\24\0\1\0\0\0\264\251\24\0 \0\0\0\1\0\0\0\16\0\20\0\300\251\24\0\320\251\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\20\252\24\0\1\0\0\0\1\0\0\0 \252\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 01017 464 NtClose (148, ... ) == 0x0 01018 464 NtClose (144, ... ) == 0x0 01019 464 NtOpenProcessToken (-1, 0x20008, ... 144, ) == 0x0 01020 464 NtQueryInformationToken (144, User, 0, ... ) == STATUS_BUFFER_TOO_SMALL 01021 464 NtQueryInformationToken (144, User, 36, ... {token info, class 1, size 36}, 36, ) == 0x0 01022 464 NtOpenDirectoryObject (0x2, {24, 0, 0x40, 0, 0, (0x2, {24, 0, 0x40, 0, 0, "\Windows\WindowStations"}, ... 148, ) }, ... 148, ) == 0x0 01023 464 NtUserOpenWindowStation ({24, 148, 0x40, 0, 0, ({24, 148, 0x40, 0, 0, "winsta0"}, 0x37f, ... ) }, 0x37f, ... ) == 0x98 01024 464 NtClose (148, ... ) == 0x0 01025 464 NtUserCloseWindowStation (152, ... 01026 464 NtClose (152, ... ) == 0x0 01025 464 NtUserCloseWindowStation ... ) == 0x1 01027 464 NtClose (144, ... ) == 0x0 01028 464 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 144, ) == 0x0 01029 464 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 152, ) == 0x0 01030 464 NtCreateMutant (0x1f0001, {24, 0, 0x2, 0, 0, 0x0}, 0, ... 148, ) == 0x0 01031 464 NtDuplicateObject (-1, -1, -1, 0x1f0fff, 2, 0, ... 156, ) == 0x0 01032 464 NtCreateSection (0xf0007, {24, 0, 0x2, 0, 0, 0x0}, {7248, 0}, 4, 134217728, 0, ... 160, ) == 0x0 01033 464 NtMapViewOfSection (160, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3d0000), {0, 0}, 8192, ) == 0x0 01034 464 NtQueryDefaultUILanguage (1235448, ... 01035 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01036 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0 01037 464 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01038 464 NtClose (-2147482740, ... ) == 0x0 01039 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 01040 464 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01041 464 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0 01042 464 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01043 464 NtClose (-2147481328, ... ) == 0x0 01044 464 NtClose (-2147482740, ... ) == 0x0 01034 464 NtQueryDefaultUILanguage ... ) == 0x0 01045 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01046 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01047 464 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 01048 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233692, ... ) }, 1233692, ... ) == 0x0 01049 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232464, ... ) }, 1232464, ... ) == 0x0 01050 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01051 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01052 464 NtCreateFile (0x10100080, {24, 0, 0x40, 0, 1234800, (0x10100080, {24, 0, 0x40, 0, 1234800, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\ca1_appcompat.txt"}, 0x0, 128, 0, 2, 96, 0, 0, ... }, 0x0, 128, 0, 2, 96, 0, 0, ... 01053 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0 01054 464 NtClose (-2147482740, ... ) == 0x0 01055 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 01056 464 NtClose (-2147482740, ... ) == 0x0 01057 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 01058 464 NtClose (-2147482740, ... ) == 0x0 01052 464 NtCreateFile ... 164, {status=0x0, info=2}, ) == 0x0 01059 464 NtClose (164, ... ) == 0x0 01060 464 NtCreateSection (0xf001f, 0x0, {4194304, 0}, 4, 67108864, 0, ... 164, ) == 0x0 01061 464 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 4194304, 2, 0, 4, ... (0xa90000), 0x0, 4194304, ) == 0x0 01062 464 NtAllocateVirtualMemory (-1, 11075584, 0, 1, 4096, 4, ... 11075584, 4096, ) == 0x0 01063 464 NtAllocateVirtualMemory (-1, 11079680, 0, 1968, 4096, 4, ... 11079680, 4096, ) == 0x0 01064 464 NtCreateSection (0xf0007, 0x0, {22396, 0}, 4, 134217728, 0, ... 168, ) == 0x0 01065 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01066 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01067 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01068 464 NtClose (164, ... ) == 0x0 01069 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01070 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01071 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01072 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01073 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01074 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01075 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01076 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01077 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01078 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01079 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01080 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01081 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01082 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01083 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01084 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01085 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01086 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01087 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01088 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01089 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01090 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01091 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01092 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01093 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01094 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01095 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01096 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01097 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01098 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01099 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01100 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01101 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01102 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01103 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01104 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01105 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01106 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01107 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01108 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01109 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01110 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01111 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01112 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01113 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01114 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01115 464 NtClose (168, ... ) == 0x0 01116 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01117 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\u:"}, 3, 96, ... 168, {status=0x0, info=1}, ) }, 3, 96, ... 168, {status=0x0, info=1}, ) == 0x0 01118 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\u:"}, ... 164, ) }, ... 164, ) == 0x0 01119 464 NtQuerySymbolicLinkObject (164, ... (164, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 01120 464 NtClose (164, ... ) == 0x0 01121 464 NtQueryVolumeInformationFile (168, 1234016, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01122 464 NtClose (168, ... ) == 0x0 01123 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1232812, ... ) }, 1232812, ... ) == 0x0 01124 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 168, {status=0x0, info=1}, ) }, 5, 96, ... 168, {status=0x0, info=1}, ) == 0x0 01125 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 168, ... 164, ) == 0x0 01126 464 NtClose (168, ... ) == 0x0 01127 464 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x3e0000), 0x0, 126976, ) == 0x0 01128 464 NtClose (164, ... ) == 0x0 01129 464 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 01130 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1233120, ... ) }, 1233120, ... ) == 0x0 01131 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 164, {status=0x0, info=1}, ) }, 5, 96, ... 164, {status=0x0, info=1}, ) == 0x0 01132 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 164, ... 168, ) == 0x0 01133 464 NtQuerySection (168, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01134 464 NtClose (164, ... ) == 0x0 01135 464 NtMapViewOfSection (168, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 01136 464 NtClose (168, ... ) == 0x0 01137 464 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 01138 464 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 01139 464 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 01140 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01141 464 NtAllocateVirtualMemory (-1, 1355776, 0, 12288, 4096, 4, ... 1355776, 12288, ) == 0x0 01142 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1234508, ... ) }, 1234508, ... ) == 0x0 01143 464 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234516, (0x40100080, {24, 0, 0x40, 0, 1234516, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\ca1_appcompat.txt"}, 0x0, 128, 0, 5, 96, 0, 0, ... }, 0x0, 128, 0, 5, 96, 0, 0, ... 01144 464 NtClose (-2147482740, ... ) == 0x0 01145 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0 01146 464 NtClose (-2147482740, ... ) == 0x0 01147 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 01148 464 NtClose (-2147482740, ... ) == 0x0 01149 464 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, (-2147482740, 0, 0, 0, -519819264, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 01150 464 NtClose (-2147482740, ... ) == 0x0 01143 464 NtCreateFile ... 168, {status=0x0, info=3}, ) == 0x0 01151 464 NtAllocateVirtualMemory (-1, 1368064, 0, 12288, 4096, 4, ... 1368064, 12288, ) == 0x0 01152 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 164, {status=0x0, info=1}, ) }, 3, 16417, ... 164, {status=0x0, info=1}, ) == 0x0 01153 464 NtQueryDirectoryFile (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, "packed.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 01154 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "\377\376", 2, 0x0, 0, ... {status=0x0, info=2}, ) , 2, 0x0, 0, ... {status=0x0, info=2}, ) == 0x0 01155 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \01\0.\00\0 (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \0U\0T\0F\0-\01\06\0 (168, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) , 106, 0x0, 0, ... {status=0x0, info=106}, ) == 0x0 01156 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) , 122, 0x0, 0, ... {status=0x0, info=122}, ) == 0x0 01157 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233600, ... ) }, 1233600, ... ) == 0x0 01158 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work"}, 3, 16417, ... 172, {status=0x0, info=1}, ) }, 3, 16417, ... 172, {status=0x0, info=1}, ) == 0x0 01159 464 NtQueryDirectoryFile (172, 0, 0, 0, 1233212, 592, Directory, 1, (172, 0, 0, 0, 1233212, 592, Directory, 1, "packed.exe", 0, ... {status=0x0, info=84}, ) , 0, ... {status=0x0, info=84}, ) == 0x0 01160 464 NtClose (172, ... ) == 0x0 01161 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01162 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01163 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232132, ... ) }, 1232132, ... ) == 0x0 01164 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1230904, ... ) }, 1230904, ... ) == 0x0 01165 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01166 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01167 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) == 0x0 01168 464 NtQueryInformationFile (172, 1233688, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01169 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 172, ... 176, ) == 0x0 01170 464 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 167936, ) == 0x0 01171 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01172 464 NtClose (176, ... ) == 0x0 01173 464 NtClose (172, ... ) == 0x0 01174 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\06\06\09\01\02\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\01\03\08\07\07\0E\01\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \0W\0I\0N\03\02\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\02\09\04\0A\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \00\0x\00\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... \01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\06\06\09\01\02\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\01\03\08\07\07\0E\01\06\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\02\09\04\0A\06\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\01\00\0/\00\02\0/\02\00\00\06\0 \00\08\0:\05\06\0:\00\09\0"\0 \0/\0>\0\15\0\12\0", 418, 0x0, 0, ... , 418, 0x0, 0, ... 01175 464 NtContinue (-139612716, 0, ... 01174 464 NtWriteFile ... {status=0x0, info=418}, ) == 0x0 01176 464 NtQueryDirectoryFile (164, 0, 0, 0, 1371248, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES 01177 464 NtClose (164, ... ) == 0x0 01178 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0", 16, 0x0, 0, ... {status=0x0, info=16}, ) , 16, 0x0, 0, ... {status=0x0, info=16}, ) == 0x0 01179 464 NtClose (168, ... ) == 0x0 01180 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1234508, ... ) }, 1234508, ... ) == 0x0 01181 464 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234516, (0x40100080, {24, 0, 0x40, 0, 1234516, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\ca1_appcompat.txt"}, 0x0, 128, 0, 3, 96, 0, 0, ... 168, {status=0x0, info=1}, ) }, 0x0, 128, 0, 3, 96, 0, 0, ... 168, {status=0x0, info=1}, ) == 0x0 01182 464 NtQueryInformationFile (168, 1234540, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01183 464 NtSetInformationFile (168, 1234572, 8, Position, ... {status=0x0, info=0}, ) == 0x0 01184 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 164, {status=0x0, info=1}, ) }, 3, 16417, ... 164, {status=0x0, info=1}, ) == 0x0 01185 464 NtQueryDirectoryFile (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, (164, 0, 0, 0, 1233220, 616, BothDirectory, 1, "kernel32.dll", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 01186 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (168, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) , 126, 0x0, 0, ... {status=0x0, info=126}, ) == 0x0 01187 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1233572, ... ) }, 1233572, ... ) == 0x0 01188 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 3, 16417, ... 172, {status=0x0, info=1}, ) }, 3, 16417, ... 172, {status=0x0, info=1}, ) == 0x0 01189 464 NtQueryDirectoryFile (172, 0, 0, 0, 1233212, 592, Directory, 1, (172, 0, 0, 0, 1233212, 592, Directory, 1, "kernel32.dll", 0, ... {status=0x0, info=88}, ) , 0, ... {status=0x0, info=88}, ) == 0x0 01190 464 NtClose (172, ... ) == 0x0 01191 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01192 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01193 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232132, ... ) }, 1232132, ... ) == 0x0 01194 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230904, ... ) }, 1230904, ... ) == 0x0 01195 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01196 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01197 464 NtQueryDefaultLocale (1, 1233092, ... ) == 0x0 01198 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01199 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01200 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232124, ... ) }, 1232124, ... ) == 0x0 01201 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230896, ... ) }, 1230896, ... ) == 0x0 01202 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01203 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01204 464 NtQueryDefaultLocale (1, 1233084, ... ) == 0x0 01205 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 172, {status=0x0, info=1}, ) == 0x0 01206 464 NtQueryInformationFile (172, 1233688, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01207 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 172, ... 176, ) == 0x0 01208 464 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 987136, ) == 0x0 01209 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01210 464 NtClose (176, ... ) == 0x0 01211 464 NtClose (172, ... ) == 0x0 01212 464 NtQueryDefaultUILanguage (1233044, ... 01213 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01214 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0 01215 464 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01216 464 NtClose (-2147482740, ... ) == 0x0 01217 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 01218 464 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01219 464 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0 01220 464 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01221 464 NtClose (-2147481328, ... ) == 0x0 01222 464 NtClose (-2147482740, ... ) == 0x0 01212 464 NtQueryDefaultUILanguage ... ) == 0x0 01223 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \09\08\04\05\07\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \00\0x\0F\00\0B\03\03\01\0F\06\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0 (168, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) == 0x0 01224 464 NtQueryDirectoryFile (164, 0, 0, 0, 1362544, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES 01225 464 NtClose (164, ... ) == 0x0 01226 464 NtWriteFile (168, 0, 0, 0, (168, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0<\0/\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 42, 0x0, 0, ... {status=0x0, info=42}, ) , 42, 0x0, 0, ... {status=0x0, info=42}, ) == 0x0 01227 464 NtClose (168, ... ) == 0x0 01228 464 NtUnmapViewOfSection (-1, 0x77b40000, ... ) == 0x0 01229 464 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 01230 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1231780, ... ) }, 1231780, ... ) == 0x0 01231 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1232516, ... ) }, 1232516, ... ) == 0x0 01232 464 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 168, {status=0x0, info=1}, ) }, 5, 96, ... 168, {status=0x0, info=1}, ) == 0x0 01233 464 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 168, ... 164, ) == 0x0 01234 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01235 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 172, ) }, ... 172, ) == 0x0 01236 464 NtQueryValueKey (172, (172, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01237 464 NtClose (172, ... ) == 0x0 01238 464 NtQueryVolumeInformationFile (168, 1231792, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01239 464 NtOpenMutant (0x120001, {24, 48, 0x0, 0, 0, (0x120001, {24, 48, 0x0, 0, 0, "ShimCacheMutex"}, ... 172, ) }, ... 172, ) == 0x0 01240 464 NtWaitForSingleObject (172, 0, {-1000000, -1}, ... ) == 0x0 01241 464 NtOpenSection (0x2, {24, 48, 0x0, 0, 0, (0x2, {24, 48, 0x0, 0, 0, "ShimSharedMemory"}, ... 176, ) }, ... 176, ) == 0x0 01242 464 NtMapViewOfSection (176, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 57344, ) == 0x0 01243 464 NtReleaseMutant (172, ... 0x0, ) == 0x0 01244 464 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0 01245 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1229724, ... ) }, 1229724, ... ) == 0x0 01246 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 180, {status=0x0, info=1}, ) }, 5, 96, ... 180, {status=0x0, info=1}, ) == 0x0 01247 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 180, ... 184, ) == 0x0 01248 464 NtClose (180, ... ) == 0x0 01249 464 NtMapViewOfSection (184, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa90000), 0x0, 126976, ) == 0x0 01250 464 NtClose (184, ... ) == 0x0 01251 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01252 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1230032, ... ) }, 1230032, ... ) == 0x0 01253 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 184, {status=0x0, info=1}, ) }, 5, 96, ... 184, {status=0x0, info=1}, ) == 0x0 01254 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 184, ... 180, ) == 0x0 01255 464 NtQuerySection (180, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01256 464 NtClose (184, ... ) == 0x0 01257 464 NtMapViewOfSection (180, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 01258 464 NtClose (180, ... ) == 0x0 01259 464 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 01260 464 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 01261 464 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 01262 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01263 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 180, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 180, {status=0x0, info=1}, ) == 0x0 01264 464 NtQueryInformationFile (180, 1230048, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01265 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 180, ... 184, ) == 0x0 01266 464 NtMapViewOfSection (184, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa90000), 0x0, 1191936, ) == 0x0 01267 464 NtQueryInformationFile (180, 1230148, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01268 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01269 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01270 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01271 464 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01272 464 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 188, ) }, ... 188, ) == 0x0 01273 464 NtQueryValueKey (188, (188, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (188, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01274 464 NtClose (188, ... ) == 0x0 01275 464 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01276 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01277 464 NtQueryDirectoryFile (188, 0, 0, 0, 1227744, 616, BothDirectory, 1, (188, 0, 0, 0, 1227744, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01278 464 NtClose (188, ... ) == 0x0 01279 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01280 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01281 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228120, ... ) }, 1228120, ... ) == 0x0 01282 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01283 464 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01284 464 NtClose (188, ... ) == 0x0 01285 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01286 464 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01287 464 NtClose (188, ... ) == 0x0 01288 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01289 464 NtQueryDirectoryFile (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, (188, 0, 0, 0, 1227548, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01290 464 NtClose (188, ... ) == 0x0 01291 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01292 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01293 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01294 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01295 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01296 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0 01297 464 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01298 464 NtClose (188, ... ) == 0x0 01299 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01300 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01301 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228952, ... ) }, 1228952, ... ) == 0x0 01302 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01303 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01304 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227820, ... ) }, 1227820, ... ) == 0x0 01305 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 188, {status=0x0, info=1}, ) }, 5, 96, ... 188, {status=0x0, info=1}, ) == 0x0 01306 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 188, ... 192, ) == 0x0 01307 464 NtClose (188, ... ) == 0x0 01308 464 NtMapViewOfSection (192, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xbc0000), 0x0, 180224, ) == 0x0 01309 464 NtClose (192, ... ) == 0x0 01310 464 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 01311 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227416, ... ) }, 1227416, ... ) == 0x0 01312 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228160, (0x80100080, {24, 0, 0x40, 0, 1228160, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) == 0x0 01313 464 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 192, ... 188, ) == 0x0 01314 464 NtClose (192, ... ) == 0x0 01315 464 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xbc0000), {0, 0}, 180224, ) == 0x0 01316 464 NtClose (188, ... ) == 0x0 01317 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01318 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01319 464 NtQueryDefaultLocale (1, 1228780, ... ) == 0x0 01320 464 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 01321 464 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 01322 464 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 01323 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01324 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01325 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227812, ... ) }, 1227812, ... ) == 0x0 01326 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 188, {status=0x0, info=1}, ) }, 5, 96, ... 188, {status=0x0, info=1}, ) == 0x0 01327 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 188, ... 192, ) == 0x0 01328 464 NtClose (188, ... ) == 0x0 01329 464 NtMapViewOfSection (192, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xbc0000), 0x0, 180224, ) == 0x0 01330 464 NtClose (192, ... ) == 0x0 01331 464 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 01332 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227408, ... ) }, 1227408, ... ) == 0x0 01333 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228152, (0x80100080, {24, 0, 0x40, 0, 1228152, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 192, {status=0x0, info=1}, ) == 0x0 01334 464 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 192, ... 188, ) == 0x0 01335 464 NtClose (192, ... ) == 0x0 01336 464 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xbc0000), {0, 0}, 180224, ) == 0x0 01337 464 NtClose (188, ... ) == 0x0 01338 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01339 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01340 464 NtQueryDefaultLocale (1, 1228772, ... ) == 0x0 01341 464 NtQueryVirtualMemory (-1, 0xbc0000, Basic, 28, ... {BaseAddress=0xbc0000,AllocationBase=0xbc0000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 01342 464 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 01343 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01344 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01345 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0 01346 464 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01347 464 NtClose (188, ... ) == 0x0 01348 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01349 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01350 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01351 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1229372, ... ) }, 1229372, ... ) == 0x0 01352 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01353 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01354 464 NtClose (188, ... ) == 0x0 01355 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01356 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01357 464 NtClose (188, ... ) == 0x0 01358 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01359 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, (188, 0, 0, 0, 1228800, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01360 464 NtClose (188, ... ) == 0x0 01361 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01362 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01363 464 NtWaitForSingleObject (172, 0, {-1000000, -1}, ... ) == 0x0 01364 464 NtReleaseMutant (172, ... 0x0, ) == 0x0 01365 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01366 464 NtClose (184, ... ) == 0x0 01367 464 NtClose (180, ... ) == 0x0 01368 464 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 01369 464 NtOpenProcessToken (-1, 0xa, ... 180, ) == 0x0 01370 464 NtQueryInformationToken (180, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 01371 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01372 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0 01373 464 NtQueryValueKey (184, (184, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (184, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01374 464 NtQueryValueKey (184, (184, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (184, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01375 464 NtClose (184, ... ) == 0x0 01376 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01377 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0 01378 464 NtQueryValueKey (184, (184, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01379 464 NtClose (184, ... ) == 0x0 01380 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01381 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01382 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01383 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01384 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01385 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01386 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01387 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01388 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01389 464 NtQueryDefaultLocale (1, 1231220, ... ) == 0x0 01390 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 184, ) }, ... 184, ) == 0x0 01391 464 NtEnumerateKey (184, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (184, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 01392 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 188, ) }, ... 188, ) == 0x0 01393 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 01394 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01395 464 NtClose (188, ... ) == 0x0 01396 464 NtEnumerateKey (184, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 01397 464 NtClose (184, ... ) == 0x0 01398 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 184, ) }, ... 184, ) == 0x0 01399 464 NtEnumerateKey (184, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0 01400 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 188, ) }, ... 188, ) == 0x0 01401 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0 01402 464 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 01403 464 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01404 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01405 464 NtClose (188, ... ) == 0x0 01406 464 NtEnumerateKey (184, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0 01407 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 188, ) }, ... 188, ) == 0x0 01408 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0 01409 464 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 01410 464 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01411 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01412 464 NtClose (188, ... ) == 0x0 01413 464 NtEnumerateKey (184, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0 01414 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 188, ) }, ... 188, ) == 0x0 01415 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0 01416 464 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 01417 464 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01418 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01419 464 NtClose (188, ... ) == 0x0 01420 464 NtEnumerateKey (184, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0 01421 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 188, ) }, ... 188, ) == 0x0 01422 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0 01423 464 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 01424 464 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01425 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01426 464 NtClose (188, ... ) == 0x0 01427 464 NtEnumerateKey (184, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (184, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0 01428 464 NtOpenKey (0x20019, {24, 184, 0x40, 0, 0, (0x20019, {24, 184, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 188, ) }, ... 188, ) == 0x0 01429 464 NtQueryValueKey (188, (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (188, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0 01430 464 NtQueryValueKey (188, (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 01431 464 NtQueryValueKey (188, (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (188, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01432 464 NtQueryValueKey (188, (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (188, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01433 464 NtClose (188, ... ) == 0x0 01434 464 NtEnumerateKey (184, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 01435 464 NtClose (184, ... ) == 0x0 01436 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01437 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01438 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01439 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01440 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01441 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01442 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01443 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01444 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01445 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01446 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01447 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01448 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01449 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01450 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01451 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01452 464 NtClose (184, ... ) == 0x0 01453 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01454 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01455 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01456 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01457 464 NtClose (184, ... ) == 0x0 01458 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01459 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01460 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01461 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01462 464 NtClose (184, ... ) == 0x0 01463 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01464 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01465 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01466 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01467 464 NtClose (184, ... ) == 0x0 01468 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01469 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01470 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01471 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01472 464 NtClose (184, ... ) == 0x0 01473 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01474 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01475 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01476 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01477 464 NtClose (184, ... ) == 0x0 01478 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01479 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01480 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01481 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01482 464 NtClose (184, ... ) == 0x0 01483 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01484 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01485 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01486 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01487 464 NtClose (184, ... ) == 0x0 01488 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01489 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01490 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01491 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01492 464 NtClose (184, ... ) == 0x0 01493 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01494 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01495 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01496 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01497 464 NtClose (184, ... ) == 0x0 01498 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01499 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01500 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01501 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01502 464 NtClose (184, ... ) == 0x0 01503 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01504 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01505 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01506 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01507 464 NtClose (184, ... ) == 0x0 01508 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01509 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01510 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01511 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01512 464 NtClose (184, ... ) == 0x0 01513 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01514 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01515 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01516 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01517 464 NtClose (184, ... ) == 0x0 01518 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01519 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01520 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01521 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01522 464 NtClose (184, ... ) == 0x0 01523 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01524 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0 01525 464 NtQueryValueKey (184, (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (184, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 01526 464 NtClose (184, ... ) == 0x0 01527 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01528 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 184, ) == 0x0 01529 464 NtQueryInformationToken (184, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01530 464 NtClose (184, ... ) == 0x0 01531 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01532 464 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01533 464 NtOpenProcessToken (-1, 0xa, ... 184, ) == 0x0 01534 464 NtDuplicateToken (184, 0xc, {24, 0, 0x0, 0, 1231652, 0x0}, 0, 2, ... 188, ) == 0x0 01535 464 NtClose (184, ... ) == 0x0 01536 464 NtAccessCheck (1379984, 188, 0x1, 1231728, 1231780, 56, 1231760, ... (0x1), ) == 0x0 01537 464 NtClose (188, ... ) == 0x0 01538 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 188, ) }, ... 188, ) == 0x0 01539 464 NtQueryValueKey (188, (188, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (188, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01540 464 NtClose (188, ... ) == 0x0 01541 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 188, ) }, ... 188, ) == 0x0 01542 464 NtQuerySymbolicLinkObject (188, ... (188, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01543 464 NtClose (188, ... ) == 0x0 01544 464 NtQueryVolumeInformationFile (168, 1229484, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01545 464 NtQueryInformationFile (168, 1229600, 528, Name, ... {status=0x0, info=58}, ) == 0x0 01546 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01547 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01548 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228772, ... ) }, 1228772, ... ) == 0x0 01549 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01550 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01551 464 NtClose (188, ... ) == 0x0 01552 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01553 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01554 464 NtClose (188, ... ) == 0x0 01555 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 188, {status=0x0, info=1}, ) }, 3, 16417, ... 188, {status=0x0, info=1}, ) == 0x0 01556 464 NtQueryDirectoryFile (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, (188, 0, 0, 0, 1228200, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01557 464 NtClose (188, ... ) == 0x0 01558 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01559 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01560 464 NtQueryInformationFile (168, 1231640, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01561 464 NtCreateSection (0xf0005, 0x0, {180224, 0}, 2, 134217728, 168, ... 188, ) == 0x0 01562 464 NtMapViewOfSection (188, -1, (0x0), 0, 0, {0, 0}, 180224, 1, 0, 2, ... (0xa90000), {0, 0}, 180224, ) == 0x0 01563 464 NtClose (188, ... ) == 0x0 01564 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01565 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 188, ) == 0x0 01566 464 NtQueryInformationToken (188, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01567 464 NtClose (188, ... ) == 0x0 01568 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 188, ) }, ... 188, ) == 0x0 01569 464 NtOpenKey (0x20019, {24, 188, 0x40, 0, 0, (0x20019, {24, 188, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 184, ) }, ... 184, ) == 0x0 01570 464 NtClose (188, ... ) == 0x0 01571 464 NtQueryValueKey (184, (184, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01572 464 NtQueryValueKey (184, (184, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (184, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0 01573 464 NtClose (184, ... ) == 0x0 01574 464 NtUnmapViewOfSection (-1, 0xa90000, ... ) == 0x0 01575 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 4128768, 4096, ) == 0x0 01576 464 NtAllocateVirtualMemory (-1, 4128768, 0, 4096, 4096, 4, ... 4128768, 4096, ) == 0x0 01577 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 184, ) }, ... 184, ) == 0x0 01578 464 NtQueryValueKey (184, (184, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01579 464 NtClose (184, ... ) == 0x0 01580 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01581 464 NtQueryInformationToken (180, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 01582 464 NtQueryInformationToken (180, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 01583 464 NtClose (180, ... ) == 0x0 01584 464 NtQuerySection (164, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01585 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01586 464 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 01587 464 NtCreateProcessEx (1233564, 2035711, 0, -1, 4, 164, 0, 0, 0, ... ) == 0x0 01588 464 NtSetInformationProcess (180, PriorityClass, {process info, class 18, size 2}, 512, ... ) == 0x0 01589 464 NtSetInformationProcess (180, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01590 464 NtQueryInformationProcess (180, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdc000,AffinityMask=0x1,BasePriority=8,Pid=1292,ParentPid=1036,}, 0x0, ) == 0x0 01591 464 NtReadVirtualMemory (180, 0x7ffdc008, 4, ... (180, 0x7ffdc008, 4, ... "\0\0\00", 0x0, ) , 0x0, ) == 0x0 01592 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01593 464 NtReadVirtualMemory (180, 0x30000000, 4096, ... (180, 0x30000000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0$\206\244\23`\347\312@`\347\312@`\347\312@9\304\331@b\347\312@`\347\313@d\347\312@\210\370\301@a\347\312@\343\373\304@j\347\312@\210\370\300@I\347\312@6\370\331@h\347\312@\272\304\326@i\347\312@\220\370\301@p\347\312@`\347\312@H\346\312@Rich`\347\312@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0N\23\216?\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\24\0\220\2\0\0\240\0\0\0\0\0\0\232t\0\0\0\20\0\0\0\320\3\0\0\0\00\0\20\0\0\0\20\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0@\3\0\0\20\0\0\237*\3\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\327\211\2\0z\1\0\0\00\3\0\244\12\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Z\236\2\08\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0`\2\0\0\370\0\0\0\0\20\0\0\270\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\222\216\2\0", 4096, ) , 4096, ) == 0x0 01594 464 NtReadVirtualMemory (180, 0x30033000, 256, ... (180, 0x30033000, 256, ... "\0\0\0\0J\23\216?\0\0\0\0\0\0\3\0\5\0\0\0(\0\0\200\13\0\0\0@\0\0\200\20\0\0\0X\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0e\0\0\0p\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\210\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\240\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\270\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\310\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\330\0\0\0\3600\3\0\26\3\0\0\0\0\0\0\0\0\0\0\104\3\0\254\1\0\0\0\0\0\0\0\0\0\0\2645\3\0\360\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\0\310\200\0\0\0\0\14\0\0\0\0\0f\1", 256, ) , 256, ) == 0x0 01595 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01596 464 NtQueryInformationProcess (180, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdc000,AffinityMask=0x1,BasePriority=8,Pid=1292,ParentPid=1036,}, 0x0, ) == 0x0 01597 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 1232516, ... ) }, 1232516, ... ) == 0x0 01598 464 NtAllocateVirtualMemory (-1, 0, 0, 2428, 4096, 4, ... 11075584, 4096, ) == 0x0 01599 464 NtAllocateVirtualMemory (180, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0 01600 464 NtWriteVirtualMemory (180, 0x10000, (180, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0 01601 464 NtAllocateVirtualMemory (180, 0, 0, 2428, 4096, 4, ... 131072, 4096, ) == 0x0 01602 464 NtWriteVirtualMemory (180, 0x20000, (180, 0x20000, "\0\20\0\0|\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\0\0\0\0\13\0\0\0&\0\10\2\220\2\0\0\16\0\0\0\364\3\366\3\230\4\0\0:\0<\0\220\10\0\0N\0P\0\314\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\0<\0\34\11\0\0\36\0 \0X\11\0\0\0\0\2\0x\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2428, ... 0x0, ) , 2428, ... 0x0, ) == 0x0 01603 464 NtWriteVirtualMemory (180, 0x7ffdc010, (180, 0x7ffdc010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01604 464 NtAllocateVirtualMemory (180, 0, 0, 388, 4096, 4, ... 196608, 4096, ) == 0x0 01605 464 NtWriteVirtualMemory (180, 0x30000, (180, 0x30000, "S\0h\0i\0m\0E\0n\0g\0.\0d\0l\0l\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\1\0\0\253\355\15\254\210\255\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 388, ... 0x0, ) , 388, ... 0x0, ) == 0x0 01606 464 NtWriteVirtualMemory (180, 0x7ffdc1e8, (180, 0x7ffdc1e8, "\0\0\3\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01607 464 NtFreeVirtualMemory (-1, (0xa90000), 0, 32768, ... (0xa90000), 4096, ) == 0x0 01608 464 NtAllocateVirtualMemory (180, 0, 0, 1048576, 8192, 4, ... 262144, 1048576, ) == 0x0 01609 464 NtAllocateVirtualMemory (180, 1302528, 0, 8192, 4096, 4, ... 1302528, 8192, ) == 0x0 01610 464 NtProtectVirtualMemory (180, (0x13e000), 4096, 260, ... (0x13e000), 4096, 4, ) == 0x0 01611 464 NtCreateThread (0x1f03ff, 0x0, 180, 1233572, 1233236, 1, ... 184, {1292, 1956}, ) == 0x0 01612 464 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 0, 2147344384, 2008285840, 0} (24, {168, 196, new_msg, 0, 0, 2147344384, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\267\0\0\0\270\0\0\0\14\5\0\0\244\7\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 1036, 464, 57979, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\264\0\0\0\270\0\0\0\14\5\0\0\244\7\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ... {168, 196, reply, 0, 1036, 464, 57979, 0} (24, {168, 196, new_msg, 0, 0, 2147344384, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\267\0\0\0\270\0\0\0\14\5\0\0\244\7\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 1036, 464, 57979, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\264\0\0\0\270\0\0\0\14\5\0\0\244\7\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\214\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ) == 0x0 01613 464 NtResumeThread (184, ... 1, ) == 0x0 01614 464 NtClose (168, ... ) == 0x0 01615 464 NtClose (164, ... ) == 0x0 01616 464 NtClose (184, ... ) == 0x0 01617 464 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0 01618 464 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x102 01619 464 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0 01620 464 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x102 01621 464 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0 01622 464 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x102 01623 464 NtWaitForMultipleObjects (2, (152, 180, ), 1, 0, {1294967296, -1}, ... ) == 0x0 01624 464 NtWaitForSingleObject (144, 0, {0, 0}, ... ) == 0x0 01625 464 NtClose (180, ... ) == 0x0 01626 464 NtUnmapViewOfSection (-1, 0x3d0000, ... ) == 0x0 01627 464 NtClose (160, ... ) == 0x0 01628 464 NtClose (144, ... ) == 0x0 01629 464 NtClose (152, ... ) == 0x0 01630 464 NtClose (148, ... ) == 0x0 01631 464 NtClose (156, ... ) == 0x0 01632 464 NtClose (100, ... ) == 0x0 01633 464 NtClose (104, ... ) == 0x0 01634 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x7,}, 4, ... ) == 0x0 01635 464 NtWaitForMultipleObjects (2, (64, 72, ), 1, 0, 0x0, ... ) == 0x1 01636 464 NtClose (72, ... ) == 0x0 01637 464 NtSetEvent (64, ... 0x0, ) == 0x0 01638 464 NtClose (64, ... ) == 0x0 01639 464 NtWaitForMultipleObjects (2, (76, 80, ), 1, 0, 0x0, ... ) == 0x1 01640 464 NtClose (80, ... ) == 0x0 01641 464 NtSetEvent (76, ... 0x0, ) == 0x0 01642 464 NtClose (76, ... ) == 0x0 01643 464 NtWaitForMultipleObjects (2, (84, 88, ), 1, 0, 0x0, ... ) == 0x1 01644 464 NtClose (88, ... ) == 0x0 01645 464 NtSetEvent (84, ... 0x0, ) == 0x0 01646 464 NtClose (84, ... ) == 0x0 01647 464 NtRequestWaitReplyPort (128, {88, 112, new_msg, 0, 1036, 464, 57977, 0} (128, {88, 112, new_msg, 0, 1036, 464, 57977, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 1036, 464, 58105, 0} "\2\31\221|\1\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\1\365\11\0\1\0\0\0d\365\11\0\0\0\0\0\0\0\0\0\1\0\0\0\10\376\257\0\0\0\0\0\334\377\257\0\30\356\220|p\5\221|\377\377\377\377m\5\221|\344f\347w" ) ... {124, 148, reply, 0, 1036, 464, 58105, 0} (128, {88, 112, new_msg, 0, 1036, 464, 57977, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 1036, 464, 58105, 0} "\2\31\221|\1\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\1\365\11\0\1\0\0\0d\365\11\0\0\0\0\0\0\0\0\0\1\0\0\0\10\376\257\0\0\0\0\0\334\377\257\0\30\356\220|p\5\221|\377\377\377\377m\5\221|\344f\347w" ) ) == 0x0 01648 464 NtClose (124, ... ) == 0x0 01649 464 NtClose (128, ... ) == 0x0 01650 464 NtClose (68, ... ) == 0x0 01651 464 NtUnmapViewOfSection (-1, 0x69450000, ... ) == 0x0 01652 464 NtUnmapViewOfSection (-1, 0x77920000, ... ) == 0x0 01653 464 NtUnmapViewOfSection (-1, 0x76f50000, ... ) == 0x0 01654 464 NtUnmapViewOfSection (-1, 0x76360000, ... ) == 0x0 01655 464 NtUnmapViewOfSection (-1, 0x5b860000, ... ) == 0x0 01656 464 NtUnmapViewOfSection (-1, 0x769c0000, ... ) == 0x0 01657 464 NtContinue (1242900, 0, ... 01658 464 NtTerminateProcess (0, -1073741682, ... ) == 0x0 01659 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x8,}, 4, ... ) == 0x0 01660 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0 01661 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 01662 464 NtClose (92, ... ) == 0x0 01663 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 01664 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 01665 464 NtUnmapViewOfSection (-1, 0x380000, ... ) == 0x0 01666 464 NtClose (60, ... ) == 0x0 01667 464 NtGdiDeleteObjectApp (1913653144, ... ) == 0x1 01668 464 NtUserGetProcessWindowStation (... ) == 0x1c 01669 464 NtUserBuildNameList (28, 522, 1379448, 1244228, ... ) == 0x0 01670 464 NtUserGetProcessWindowStation (... ) == 0x1c 01671 464 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x3c 01672 464 NtUserBuildHwndList (60, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0xa0102, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 53, ) == 0x0 01673 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 01674 464 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 01675 464 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 01676 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 01677 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 01678 464 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 01679 464 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 01680 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 01681 464 NtUserBuildHwndList (0, 262394, 1, 0, 64, ... (0x80064, 0x60068, 0x6006c, 0x50094, 0x50096, 0x60066, 0x7006a, 0x90058, 0x6006e, 0x5008a, 0x50088, 0x500a0, 0x1, ), 13, ) == 0x0 01682 464 NtUserValidateHandleSecure (524388, ... ) == 0x1 01683 464 NtUserQueryWindow (524388, 0, ... ) == 0x6b8 01684 464 NtUserQueryWindow (524388, 1, ... ) == 0x6d4 01685 464 NtUserValidateHandleSecure (393320, ... ) == 0x1 01686 464 NtUserQueryWindow (393320, 0, ... ) == 0x6b8 01687 464 NtUserQueryWindow (393320, 1, ... ) == 0x6d4 01688 464 NtUserValidateHandleSecure (393324, ... ) == 0x1 01689 464 NtUserQueryWindow (393324, 0, ... ) == 0x6b8 01690 464 NtUserQueryWindow (393324, 1, ... ) == 0x6d4 01691 464 NtUserValidateHandleSecure (327828, ... ) == 0x1 01692 464 NtUserQueryWindow (327828, 0, ... ) == 0x6b8 01693 464 NtUserQueryWindow (327828, 1, ... ) == 0x6d4 01694 464 NtUserValidateHandleSecure (327830, ... ) == 0x1 01695 464 NtUserQueryWindow (327830, 0, ... ) == 0x6b8 01696 464 NtUserQueryWindow (327830, 1, ... ) == 0x6d4 01697 464 NtUserValidateHandleSecure (393318, ... ) == 0x1 01698 464 NtUserQueryWindow (393318, 0, ... ) == 0x6b8 01699 464 NtUserQueryWindow (393318, 1, ... ) == 0x6d4 01700 464 NtUserValidateHandleSecure (458858, ... ) == 0x1 01701 464 NtUserQueryWindow (458858, 0, ... ) == 0x6b8 01702 464 NtUserQueryWindow (458858, 1, ... ) == 0x6d4 01703 464 NtUserValidateHandleSecure (589912, ... ) == 0x1 01704 464 NtUserQueryWindow (589912, 0, ... ) == 0x6b8 01705 464 NtUserQueryWindow (589912, 1, ... ) == 0x6d4 01706 464 NtUserValidateHandleSecure (393326, ... ) == 0x1 01707 464 NtUserQueryWindow (393326, 0, ... ) == 0x6b8 01708 464 NtUserQueryWindow (393326, 1, ... ) == 0x6d4 01709 464 NtUserValidateHandleSecure (327818, ... ) == 0x1 01710 464 NtUserQueryWindow (327818, 0, ... ) == 0x6b8 01711 464 NtUserQueryWindow (327818, 1, ... ) == 0x6d4 01712 464 NtUserValidateHandleSecure (327816, ... ) == 0x1 01713 464 NtUserQueryWindow (327816, 0, ... ) == 0x6b8 01714 464 NtUserQueryWindow (327816, 1, ... ) == 0x6d4 01715 464 NtUserValidateHandleSecure (327840, ... ) == 0x1 01716 464 NtUserQueryWindow (327840, 0, ... ) == 0x6b8 01717 464 NtUserQueryWindow (327840, 1, ... ) == 0x6d4 01718 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 01719 464 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 01720 464 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 01721 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 01722 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 01723 464 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 01724 464 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 01725 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 01726 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 01727 464 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 01728 464 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 01729 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 01730 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 01731 464 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 01732 464 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 01733 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 01734 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 01735 464 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 01736 464 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 01737 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 01738 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 01739 464 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 01740 464 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 01741 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 01742 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 01743 464 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 01744 464 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 01745 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 01746 464 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0 01747 464 NtUserValidateHandleSecure (196670, ... ) == 0x1 01748 464 NtUserQueryWindow (196670, 0, ... ) == 0x6b8 01749 464 NtUserQueryWindow (196670, 1, ... ) == 0x6d4 01750 464 NtUserValidateHandleSecure (196668, ... ) == 0x1 01751 464 NtUserQueryWindow (196668, 0, ... ) == 0x6b8 01752 464 NtUserQueryWindow (196668, 1, ... ) == 0x6d4 01753 464 NtUserValidateHandleSecure (196672, ... ) == 0x1 01754 464 NtUserQueryWindow (196672, 0, ... ) == 0x6b8 01755 464 NtUserQueryWindow (196672, 1, ... ) == 0x6d4 01756 464 NtUserValidateHandleSecure (196674, ... ) == 0x1 01757 464 NtUserQueryWindow (196674, 0, ... ) == 0x6b8 01758 464 NtUserQueryWindow (196674, 1, ... ) == 0x6d4 01759 464 NtUserValidateHandleSecure (196676, ... ) == 0x1 01760 464 NtUserQueryWindow (196676, 0, ... ) == 0x6b8 01761 464 NtUserQueryWindow (196676, 1, ... ) == 0x6d4 01762 464 NtUserValidateHandleSecure (196678, ... ) == 0x1 01763 464 NtUserQueryWindow (196678, 0, ... ) == 0x6b8 01764 464 NtUserQueryWindow (196678, 1, ... ) == 0x6d4 01765 464 NtUserValidateHandleSecure (65654, ... ) == 0x1 01766 464 NtUserQueryWindow (65654, 0, ... ) == 0x6b8 01767 464 NtUserQueryWindow (65654, 1, ... ) == 0x6d4 01768 464 NtUserValidateHandleSecure (65666, ... ) == 0x1 01769 464 NtUserQueryWindow (65666, 0, ... ) == 0x6b8 01770 464 NtUserQueryWindow (65666, 1, ... ) == 0x6d4 01771 464 NtUserValidateHandleSecure (65658, ... ) == 0x1 01772 464 NtUserQueryWindow (65658, 0, ... ) == 0x6b8 01773 464 NtUserQueryWindow (65658, 1, ... ) == 0x6d4 01774 464 NtUserValidateHandleSecure (65662, ... ) == 0x1 01775 464 NtUserQueryWindow (65662, 0, ... ) == 0x6b8 01776 464 NtUserQueryWindow (65662, 1, ... ) == 0x6d4 01777 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 01778 464 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 01779 464 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 01780 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 01781 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 01782 464 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 01783 464 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 01784 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 01785 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 01786 464 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 01787 464 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 01788 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 01789 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 01790 464 NtUserQueryWindow (65744, 0, ... ) == 0x19c 01791 464 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 01792 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 01793 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 01794 464 NtUserQueryWindow (131248, 0, ... ) == 0xa0 01795 464 NtUserQueryWindow (131248, 1, ... ) == 0xe4 01796 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 01797 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 01798 464 NtUserQueryWindow (65740, 0, ... ) == 0x19c 01799 464 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 01800 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 01801 464 NtUserValidateHandleSecure (655618, ... ) == 0x1 01802 464 NtUserQueryWindow (655618, 0, ... ) == 0x50c 01803 464 NtUserQueryWindow (655618, 1, ... ) == 0x7a4 01804 464 NtUserValidateHandleSecure (655618, ... ) == 0x1 01805 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 01806 464 NtUserQueryWindow (459012, 0, ... ) == 0x49c 01807 464 NtUserQueryWindow (459012, 1, ... ) == 0x180 01808 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 01809 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 01810 464 NtUserQueryWindow (459008, 0, ... ) == 0x5e8 01811 464 NtUserQueryWindow (459008, 1, ... ) == 0x1dc 01812 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 01813 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 01814 464 NtUserQueryWindow (131352, 0, ... ) == 0x6ac 01815 464 NtUserQueryWindow (131352, 1, ... ) == 0x7f4 01816 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 01817 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 01818 464 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 01819 464 NtUserQueryWindow (196940, 1, ... ) == 0x474 01820 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 01821 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 01822 464 NtUserQueryWindow (65820, 0, ... ) == 0x22c 01823 464 NtUserQueryWindow (65820, 1, ... ) == 0x220 01824 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 01825 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 01826 464 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 01827 464 NtUserQueryWindow (65766, 1, ... ) == 0x13c 01828 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 01829 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 01830 464 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 01831 464 NtUserQueryWindow (65750, 1, ... ) == 0x13c 01832 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 01833 464 NtUserBuildHwndList (0, 65750, 1, 0, 64, ... (0x100da, 0x100dc, 0x100de, 0x100e0, 0x1, ), 5, ) == 0x0 01834 464 NtUserValidateHandleSecure (65754, ... ) == 0x1 01835 464 NtUserQueryWindow (65754, 0, ... ) == 0x6b8 01836 464 NtUserQueryWindow (65754, 1, ... ) == 0x13c 01837 464 NtUserValidateHandleSecure (65756, ... ) == 0x1 01838 464 NtUserQueryWindow (65756, 0, ... ) == 0x6b8 01839 464 NtUserQueryWindow (65756, 1, ... ) == 0x13c 01840 464 NtUserValidateHandleSecure (65758, ... ) == 0x1 01841 464 NtUserQueryWindow (65758, 0, ... ) == 0x6b8 01842 464 NtUserQueryWindow (65758, 1, ... ) == 0x13c 01843 464 NtUserValidateHandleSecure (65760, ... ) == 0x1 01844 464 NtUserQueryWindow (65760, 0, ... ) == 0x6b8 01845 464 NtUserQueryWindow (65760, 1, ... ) == 0x13c 01846 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 01847 464 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 01848 464 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 01849 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 01850 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 01851 464 NtUserQueryWindow (65738, 0, ... ) == 0x19c 01852 464 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 01853 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 01854 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 01855 464 NtUserQueryWindow (65736, 0, ... ) == 0xa0 01856 464 NtUserQueryWindow (65736, 1, ... ) == 0xe4 01857 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 01858 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 01859 464 NtUserQueryWindow (65722, 0, ... ) == 0x104 01860 464 NtUserQueryWindow (65722, 1, ... ) == 0x108 01861 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 01862 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 01863 464 NtUserQueryWindow (65710, 0, ... ) == 0x104 01864 464 NtUserQueryWindow (65710, 1, ... ) == 0x108 01865 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 01866 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 01867 464 NtUserQueryWindow (65708, 0, ... ) == 0x120 01868 464 NtUserQueryWindow (65708, 1, ... ) == 0x124 01869 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 01870 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 01871 464 NtUserQueryWindow (196774, 0, ... ) == 0xc4 01872 464 NtUserQueryWindow (196774, 1, ... ) == 0xc8 01873 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 01874 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 01875 464 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 01876 464 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 01877 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 01878 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 01879 464 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 01880 464 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 01881 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 01882 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 01883 464 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 01884 464 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 01885 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 01886 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 01887 464 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 01888 464 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 01889 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 01890 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 01891 464 NtUserQueryWindow (65726, 0, ... ) == 0x19c 01892 464 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 01893 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 01894 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 01895 464 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 01896 464 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 01897 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 01898 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 01899 464 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 01900 464 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 01901 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 01902 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 01903 464 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 01904 464 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 01905 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 01906 464 NtUserBuildHwndList (0, 65670, 1, 0, 64, ... (0x1008c, 0x1008e, 0x1, ), 3, ) == 0x0 01907 464 NtUserValidateHandleSecure (65676, ... ) == 0x1 01908 464 NtUserQueryWindow (65676, 0, ... ) == 0x6b8 01909 464 NtUserQueryWindow (65676, 1, ... ) == 0x6bc 01910 464 NtUserValidateHandleSecure (65678, ... ) == 0x1 01911 464 NtUserQueryWindow (65678, 0, ... ) == 0x6b8 01912 464 NtUserQueryWindow (65678, 1, ... ) == 0x6bc 01913 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 01914 464 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 01915 464 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 01916 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 01917 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 01918 464 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 01919 464 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 01920 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 01921 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 01922 464 NtUserQueryWindow (65852, 0, ... ) == 0x22c 01923 464 NtUserQueryWindow (65852, 1, ... ) == 0x220 01924 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 01925 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 01926 464 NtUserQueryWindow (65824, 0, ... ) == 0x22c 01927 464 NtUserQueryWindow (65824, 1, ... ) == 0x220 01928 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 01929 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 01930 464 NtUserQueryWindow (65730, 0, ... ) == 0xa0 01931 464 NtUserQueryWindow (65730, 1, ... ) == 0xe4 01932 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 01933 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 01934 464 NtUserQueryWindow (65724, 0, ... ) == 0xa0 01935 464 NtUserQueryWindow (65724, 1, ... ) == 0xe4 01936 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 01937 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 01938 464 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 01939 464 NtUserQueryWindow (131406, 1, ... ) == 0x474 01940 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 01941 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 01942 464 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 01943 464 NtUserQueryWindow (65752, 1, ... ) == 0x13c 01944 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 01945 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 01946 464 NtUserQueryWindow (65718, 0, ... ) == 0x104 01947 464 NtUserQueryWindow (65718, 1, ... ) == 0x108 01948 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 01949 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 01950 464 NtUserQueryWindow (65720, 0, ... ) == 0x120 01951 464 NtUserQueryWindow (65720, 1, ... ) == 0x124 01952 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 01953 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 01954 464 NtUserQueryWindow (65716, 0, ... ) == 0xc4 01955 464 NtUserQueryWindow (65716, 1, ... ) == 0xc8 01956 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 01957 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 01958 464 NtUserQueryWindow (65728, 0, ... ) == 0x19c 01959 464 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 01960 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 01961 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 01962 464 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 01963 464 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 01964 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 01965 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 01966 464 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 01967 464 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 01968 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 01969 464 NtUserCloseDesktop (60, ... ) == 0x1 01970 464 NtUserGetProcessWindowStation (... ) == 0x1c 01971 464 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 01972 464 NtUserGetProcessWindowStation (... ) == 0x1c 01973 464 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Winlogon"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 01974 464 NtGdiDeleteObjectApp (856294625, ... ) == 0x1 01975 464 NtGdiDeleteObjectApp (1376388660, ... ) == 0x1 01976 464 NtClose (56, ... ) == 0x0 01977 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 01978 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 56, ) }, ... 56, ) == 0x0 01979 464 NtQueryValueKey (56, (56, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01980 464 NtClose (56, ... ) == 0x0 01981 464 NtClose (44, ... ) == 0x0 01982 464 NtFreeVirtualMemory (-1, (0x3f0000), 4096, 32768, ... (0x3f0000), 4096, ) == 0x0 01983 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01984 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01985 464 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 01986 464 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} "\0\0\0\0\3\0\1\0\214\371\21\0\320\220\347w\216\0\0\300" ... {20, 48, reply, 0, 1036, 464, 58108, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\320\220\347w\216\0\0\300" ) ... {20, 48, reply, 0, 1036, 464, 58108, 0} (24, {20, 48, new_msg, 0, 1177968, 2011678370, 1178092, 1177980} "\0\0\0\0\3\0\1\0\214\371\21\0\320\220\347w\216\0\0\300" ... {20, 48, reply, 0, 1036, 464, 58108, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\320\220\347w\216\0\0\300" ) ) == 0x0 01987 464 NtTerminateProcess (-1, -1073741682, ...