Summary:

NtAccessCheck(>) 1 NtOpenDirectoryObject(>) 2 NtUserGetThreadDesktop(>) 10 NtQueryDirectoryFile(>) 46
NtAddAtom(>) 1 NtQueryInstallUILanguage(>) 2 NtUserQueryWindow(>) 10 NtOpenProcessTokenEx(>) 48
NtCallbackReturn(>) 1 NtQueryVirtualMemory(>) 2 NtWriteFile(>) 10 NtOpenThreadTokenEx(>) 48
NtCreateThread(>) 1 NtRegisterThreadTerminatePort(>) 2 NtUserSystemParametersInfo(>) 11 NtUserFindExistingCursorIcon(>) 48
NtEnumerateValueKey(>) 1 NtSetEvent(>) 2 NtDuplicateObject(>) 12 NtUserMessageCall(>) 50
NtGdiCreateBitmap(>) 1 NtTestAlert(>) 2 NtEnumerateKey(>) 12 NtOpenSection(>) 51
NtGdiGetWidthTable(>) 1 NtUserGetProcessWindowStation(>) 2 NtUserGetObjectInformation(>) 12 NtQueryDefaultLocale(>) 51
NtGdiInit(>) 1 NtUserGetSystemMenu(>) 2 NtUserSetWindowPos(>) 12 NtCreateSection(>) 55
NtGdiIntersectClipRect(>) 1 NtGdiHfontCreate(>) 3 NtUserGetAtomName(>) 13 NtDeviceIoControlFile(>) 56
NtGdiQueryFontAssocInfo(>) 1 NtUserInvalidateRect(>) 3 NtUserRemoveProp(>) 13 NtOpenProcessToken(>) 56
NtGdiSelectBitmap(>) 1 NtUserRegisterWindowMessage(>) 3 NtUserSetWindowFNID(>) 13 NtCreateKey(>) 59
NtOpenKeyedEvent(>) 1 NtUserShowWindow(>) 3 NtSetInformationThread(>) 15 NtQueryKey(>) 63
NtQueryEvent(>) 1 NtCreateMutant(>) 4 NtFlushInstructionCache(>) 16 NtUserRegisterClassExWOW(>) 64
NtQueryInformationThread(>) 1 NtGdiCreateCompatibleDC(>) 4 NtNotifyChangeKey(>) 16 NtLockFile(>) 69
NtQueryObject(>) 1 NtUserCallHwndParam(>) 4 NtUserSBGetParms(>) 17 NtReleaseSemaphore(>) 69
NtQueryPerformanceCounter(>) 1 NtUserMoveWindow(>) 4 NtQueryVolumeInformationFile(>) 18 NtUnlockFile(>) 69
NtQuerySystemTime(>) 1 NtGdiGetStockObject(>) 5 NtFsControlFile(>) 20 NtFreeVirtualMemory(>) 70
NtResumeThread(>) 1 NtOpenEvent(>) 5 NtUserSetProp(>) 20 NtReadFile(>) 76
NtSecureConnectPort(>) 1 NtSetInformationObject(>) 5 NtQueryDebugFilterState(>) 22 NtMapViewOfSection(>) 87
NtUserBuildHwndList(>) 1 NtOpenSymbolicLinkObject(>) 6 NtUserSetWindowLong(>) 23 NtWaitForSingleObject(>) 90
NtUserGetGUIThreadInfo(>) 1 NtQuerySymbolicLinkObject(>) 6 NtQuerySection(>) 24 NtQuerySystemInformation(>) 92
NtUserPostMessage(>) 1 NtUserGetClassName(>) 6 NtUserCreateWindowEx(>) 28 NtQueryInformationFile(>) 98
NtUserSetParent(>) 1 NtConnectPort(>) 7 NtUserGetWindowDC(>) 28 NtQueryInformationToken(>) 102
NtAdjustPrivilegesToken(>) 2 NtCreateSemaphore(>) 7 NtOpenThreadToken(>) 30 NtSetInformationProcess(>) 150
NtClearEvent(>) 2 NtUserGetScrollBarInfo(>) 7 NtCreateFile(>) 31 NtQueryInformationProcess(>) 197
NtContinue(>) 2 NtUserSetScrollInfo(>) 7 NtProtectVirtualMemory(>) 31 NtAllocateVirtualMemory(>) 209
NtCreateIoCompletion(>) 2 NtOpenMutant(>) 8 NtRequestWaitReplyPort(>) 32 NtQueryAttributesFile(>) 211
NtGdiCreatePatternBrushInternal(>) 2 NtUserThunkedMenuItemInfo(>) 8 NtUserGetClassInfo(>) 37 NtOpenFile(>) 217
NtGdiCreateSolidBrush(>) 2 NtReleaseMutant(>) 9 NtSetInformationFile(>) 38 NtOpenKey(>) 391
NtGdiDeleteObjectApp(>) 2 NtOpenProcess(>) 10 NtUserCallOneParam(>) 38 NtQueryValueKey(>) 426
NtGdiGetTextCharsetInfo(>) 2 NtQueryDefaultUILanguage(>) 10 NtUnmapViewOfSection(>) 39 NtClose(>) 728
NtGdiGetTextFaceW(>) 2 NtUserCallNoParam(>) 10 NtSetValueKey(>) 44
NtGdiGetTextMetricsW(>) 2 NtUserGetDC(>) 10

Trace:

00001 432 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 432 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00003 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00004 432 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1310720, 1048576, ) == 0x0 00005 432 NtAllocateVirtualMemory (-1, 1310720, 0, 4096, 4096, 4, ... 1310720, 4096, ) == 0x0 00006 432 NtAllocateVirtualMemory (-1, 1314816, 0, 8192, 4096, 4, ... 1314816, 8192, ) == 0x0 00007 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00008 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2359296, 65536, ) == 0x0 00009 432 NtAllocateVirtualMemory (-1, 2359296, 0, 24576, 4096, 4, ... 2359296, 24576, ) == 0x0 00010 432 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00011 432 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00012 432 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00013 432 NtClose (12, ... ) == 0x0 00014 432 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\U:\startupscripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00015 432 NtQueryVolumeInformationFile (12, 1243848, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00016 432 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... ) == STATUS_INVALID_PARAMETER 00017 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 1243832, ... ) }, 1243832, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 432 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e60000), 0x0, 937984, ) == 0x0 00020 432 NtClose (16, ... ) == 0x0 00021 432 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00022 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00023 432 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00024 432 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00025 432 NtClose (16, ... ) == 0x0 00026 432 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00027 432 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00028 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00029 432 NtQueryVirtualMemory (-1, 0x250000, Basic, 28, ... {BaseAddress=0x250000,AllocationBase=0x250000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00030 432 NtAllocateVirtualMemory (-1, 2424832, 0, 4096, 4096, 4, ... 2424832, 4096, ) == 0x0 00031 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 424, 432, 1493, 0} "P\343\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 424, 432, 1493, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 424, 432, 1493, 0} "P\343\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00032 432 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00033 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00034 432 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00035 432 NtClose (16, ... ) == 0x0 00036 432 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00037 432 NtOpenMutant (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\NlsCacheMutant"}, ... 16, ) }, ... 16, ) == 0x0 00038 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 28, ) }, ... 28, ) == 0x0 00039 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x260000), 0x0, 90112, ) == 0x0 00040 432 NtClose (28, ... ) == 0x0 00041 432 NtQueryDefaultLocale (0, 2012046252, ... ) == 0x0 00042 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 28, ) }, ... 28, ) == 0x0 00043 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x280000), 0x0, 212992, ) == 0x0 00044 432 NtClose (28, ... ) == 0x0 00045 432 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 28, ) }, ... 28, ) == 0x0 00046 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2c0000), 0x0, 266240, ) == 0x0 00047 432 NtQuerySection (28, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00048 432 NtClose (28, ... ) == 0x0 00049 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 28, ) }, ... 28, ) == 0x0 00050 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x310000), 0x0, 24576, ) == 0x0 00051 432 NtClose (28, ... ) == 0x0 00052 432 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00053 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00054 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00055 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 424, 432, 1496, 0} "\370\323\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 424, 432, 1496, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 424, 432, 1496, 0} "\370\323\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00056 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WININET.dll"}, ... 28, ) }, ... 28, ) == 0x0 00057 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76200000), 0x0, 618496, ) == 0x0 00058 432 NtClose (28, ... ) == 0x0 00059 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "msvcrt.dll"}, ... 28, ) }, ... 28, ) == 0x0 00060 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 339968, ) == 0x0 00061 432 NtClose (28, ... ) == 0x0 00062 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 28, ) }, ... 28, ) == 0x0 00063 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x772d0000), 0x0, 405504, ) == 0x0 00064 432 NtClose (28, ... ) == 0x0 00065 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00066 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c70000), 0x0, 262144, ) == 0x0 00067 432 NtClose (28, ... ) == 0x0 00068 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "USER32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00069 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77d40000), 0x0, 577536, ) == 0x0 00070 432 NtClose (28, ... ) == 0x0 00071 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00072 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 569344, ) == 0x0 00073 432 NtClose (28, ... ) == 0x0 00074 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00075 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77cc0000), 0x0, 479232, ) == 0x0 00076 432 NtClose (28, ... ) == 0x0 00077 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CRYPT32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00078 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762c0000), 0x0, 565248, ) == 0x0 00079 432 NtClose (28, ... ) == 0x0 00080 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSASN1.dll"}, ... 28, ) }, ... 28, ) == 0x0 00081 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762a0000), 0x0, 61440, ) == 0x0 00082 432 NtClose (28, ... ) == 0x0 00083 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLEAUT32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00084 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77120000), 0x0, 569344, ) == 0x0 00085 432 NtClose (28, ... ) == 0x0 00086 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLE32.DLL"}, ... 28, ) }, ... 28, ) == 0x0 00087 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x771b0000), 0x0, 1155072, ) == 0x0 00088 432 NtClose (28, ... ) == 0x0 00089 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00090 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00091 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00092 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00093 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00094 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00095 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00096 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00097 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00098 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00099 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00100 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00101 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHELL32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00102 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 8339456, ) == 0x0 00103 432 NtClose (28, ... ) == 0x0 00104 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00105 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00106 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00107 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00108 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00109 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00110 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00111 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00112 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00113 432 NtProtectVirtualMemory (-1, (0x40f000), 644, 4, ... (0x40f000), 4096, 2, ) == 0x0 00114 432 NtProtectVirtualMemory (-1, (0x40f000), 4096, 2, ... (0x40f000), 4096, 4, ) == 0x0 00115 432 NtFlushInstructionCache (-1, 4255744, 644, ... ) == 0x0 00116 432 NtOpenProcessToken (-1, 0x8, ... 28, ) == 0x0 00117 432 NtQueryInformationToken (28, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00118 432 NtClose (28, ... ) == 0x0 00119 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00120 432 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00121 432 NtClose (28, ... ) == 0x0 00122 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00123 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 3276800, 65536, ) == 0x0 00124 432 NtAllocateVirtualMemory (-1, 3276800, 0, 4096, 4096, 4, ... 3276800, 4096, ) == 0x0 00125 432 NtAllocateVirtualMemory (-1, 3280896, 0, 8192, 4096, 4, ... 3280896, 8192, ) == 0x0 00126 432 NtAllocateVirtualMemory (-1, 1323008, 0, 4096, 4096, 4, ... 1323008, 4096, ) == 0x0 00127 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 28, ) }, ... 28, ) == 0x0 00128 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x330000), 0x0, 12288, ) == 0x0 00129 432 NtClose (28, ... ) == 0x0 00130 432 NtAllocateVirtualMemory (-1, 3289088, 0, 4096, 4096, 4, ... 3289088, 4096, ) == 0x0 00131 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00132 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1243120, 256, 1242864, 256} (24, {28, 56, new_msg, 0, 1243120, 256, 1242864, 256} "\210\6\31\1\0\0\0\0\1\0\0\0\360\367\22\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 424, 432, 1498, 0} "XQ\26\0\0\0\0\0\0\0\0\0\360\367\22\0\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 424, 432, 1498, 0} (24, {28, 56, new_msg, 0, 1243120, 256, 1242864, 256} "\210\6\31\1\0\0\0\0\1\0\0\0\360\367\22\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 424, 432, 1498, 0} "XQ\26\0\0\0\0\0\0\0\0\0\360\367\22\0\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00133 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00134 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x4f0000), 0x0, 1060864, ) == 0x0 00135 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 32, ) == 0x0 00136 432 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00137 432 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482032, ) == 0x0 00138 432 NtQueryInformationToken (-2147482032, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00139 432 NtQueryInformationToken (-2147482032, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00140 432 NtClose (-2147482032, ... ) == 0x0 00141 432 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 3407872, 4096, ) == 0x0 00142 432 NtFreeVirtualMemory (-1, (0x340000), 4096, 32768, ... (0x340000), 4096, ) == 0x0 00143 432 NtDuplicateObject (-1, 36, -1, 0x0, 0, 2, ... 44, ) == 0x0 00144 432 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00145 432 NtQueryValueKey (-2147482032, (-2147482032, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00146 432 NtClose (-2147482032, ... ) == 0x0 00147 432 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00148 432 NtQueryValueKey (-2147482032, (-2147482032, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00149 432 NtClose (-2147482032, ... ) == 0x0 00150 432 NtQueryDefaultLocale (0, -131036660, ... ) == 0x0 00151 432 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00152 432 NtUserCallNoParam (24, ... ) == 0x0 00153 432 NtGdiCreateCompatibleDC (0, ... 00154 432 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3407872, 4096, ) == 0x0 00153 432 NtGdiCreateCompatibleDC ... ) == 0x1201032a 00155 432 NtGdiGetStockObject (0, ... ) == 0x1900010 00156 432 NtGdiGetStockObject (4, ... ) == 0x1900011 00157 432 NtGdiCreateBitmap (8, 8, 1, 1, 2010393708, ... ) == 0x13050408 00158 432 NtGdiCreateSolidBrush (0, 0, ... 00159 432 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3473408, 4096, ) == 0x0 00158 432 NtGdiCreateSolidBrush ... ) == 0xe10040e 00160 432 NtGdiGetStockObject (13, ... ) == 0x18a0021 00161 432 NtGdiCreateCompatibleDC (0, ... ) == 0x6f010417 00162 432 NtGdiSelectBitmap (1862337559, 319095816, ... ) == 0x185000f 00163 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 00164 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 48, ) }, ... 48, ) == 0x0 00165 432 NtQueryValueKey (48, (48, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (48, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00166 432 NtClose (48, ... ) == 0x0 00167 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00168 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 673, 128, 0, ... ) == 0x810dc017 00169 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00170 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 674, 128, 0, ... ) == 0x810dc01c 00171 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00172 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 675, 128, 0, ... ) == 0x810dc01e 00173 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00174 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 676, 128, 0, ... ) == 0x810d8002 00175 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10013 00176 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 677, 128, 0, ... ) == 0x810dc018 00177 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00178 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 678, 128, 0, ... ) == 0x810dc01a 00179 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00180 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 679, 128, 0, ... ) == 0x810dc01d 00181 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00182 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 681, 128, 0, ... 00183 432 NtAllocateVirtualMemory (-1, 6385664, 0, 4096, 4096, 32, ... 6385664, 4096, ) == 0x0 00182 432 NtUserRegisterClassExWOW ... ) == 0x810dc026 00184 432 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00185 432 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 680, 128, 0, ... ) == 0x810dc019 00186 432 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... ) == 0x810dc020 00187 432 NtUserRegisterClassExWOW (1241676, 1241752, 1241768, 1241740, 0, 130, 0, ... ) == 0x810dc022 00188 432 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... ) == 0x810dc023 00189 432 NtUserRegisterClassExWOW (1241676, 1241752, 1241768, 1241740, 0, 130, 0, ... ) == 0x810dc024 00190 432 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... ) == 0x810dc025 00191 432 NtCallbackReturn (0, 0, 0, ... 00192 432 NtGdiInit (... ) == 0x1 00193 432 NtGdiGetStockObject (18, ... ) == 0x290001c 00194 432 NtGdiGetStockObject (19, ... ) == 0x1b00019 00195 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 48, ) }, ... 48, ) == 0x0 00196 432 NtQueryValueKey (48, (48, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (48, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00197 432 NtQueryValueKey (48, (48, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (48, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00198 432 NtClose (48, ... ) == 0x0 00199 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 48, ) }, ... 48, ) == 0x0 00200 432 NtQueryValueKey (48, (48, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00201 432 NtClose (48, ... ) == 0x0 00202 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 48, ) }, ... 48, ) == 0x0 00203 432 NtSetInformationObject (48, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 00204 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00205 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00206 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\crypt32\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00207 432 NtAllocateVirtualMemory (-1, 1327104, 0, 4096, 4096, 4, ... 1327104, 4096, ) == 0x0 00208 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 52, ) }, ... 52, ) == 0x0 00209 432 NtQueryValueKey (52, (52, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00210 432 NtClose (52, ... ) == 0x0 00211 432 NtAllocateVirtualMemory (-1, 1331200, 0, 4096, 4096, 4, ... 1331200, 4096, ) == 0x0 00212 432 NtAllocateVirtualMemory (-1, 1335296, 0, 4096, 4096, 4, ... 1335296, 4096, ) == 0x0 00213 432 NtAllocateVirtualMemory (-1, 1339392, 0, 4096, 4096, 4, ... 1339392, 4096, ) == 0x0 00214 432 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 52, ) }, ... 52, ) == 0x0 00215 432 NtCreateEvent (0x1f0003, {24, 52, 0x80, 1243532, 0, (0x1f0003, {24, 52, 0x80, 1243532, 0, "Global\crypt32LogoffEvent"}, 0, 0, ... ) }, 0, 0, ... ) == STATUS_ACCESS_DENIED 00216 432 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\crypt32LogoffEvent"}, ... 56, ) }, ... 56, ) == 0x0 00217 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00218 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00219 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 60, ) }, ... 60, ) == 0x0 00220 432 NtQueryValueKey (60, (60, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (60, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00221 432 NtClose (60, ... ) == 0x0 00222 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00223 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00224 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00225 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00226 432 NtAllocateVirtualMemory (-1, 1343488, 0, 4096, 4096, 4, ... 1343488, 4096, ) == 0x0 00227 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 60, ) }, ... 60, ) == 0x0 00228 432 NtQueryValueKey (60, (60, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00229 432 NtQueryValueKey (60, (60, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00230 432 NtQueryValueKey (60, (60, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00231 432 NtClose (60, ... ) == 0x0 00232 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 60, ) }, ... 60, ) == 0x0 00233 432 NtQueryValueKey (60, (60, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00234 432 NtQueryValueKey (60, (60, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00235 432 NtClose (60, ... ) == 0x0 00236 432 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00237 432 NtUserRegisterWindowMessage ( ("{FB8F0821-0164-101B-84ED-08002B2EC713}", ... ) , ... ) == 0xc07b 00238 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00239 432 NtOpenKey (0x9, {24, 48, 0x40, 0, 0, (0x9, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT\UserEra"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00240 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00241 432 NtAllocateVirtualMemory (-1, 1347584, 0, 8192, 4096, 4, ... 1347584, 8192, ) == 0x0 00242 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00243 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 60, ) == 0x0 00244 432 NtQueryInformationToken (60, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00245 432 NtClose (60, ... ) == 0x0 00246 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 60, ) }, ... 60, ) == 0x0 00247 432 NtSetInformationObject (60, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00248 432 NtCreateKey (0xf003f, {24, 60, 0x40, 0, 0, (0xf003f, {24, 60, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History"}, 0, 0x0, 0, ... 64, 2, ) }, 0, 0x0, 0, ... 64, 2, ) == 0x0 00249 432 NtQueryDefaultUILanguage (1241768, ... 00250 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00251 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00252 432 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00253 432 NtClose (-2147482032, ... ) == 0x0 00254 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00255 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00256 432 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482036, ) }, ... -2147482036, ) == 0x0 00257 432 NtQueryValueKey (-2147482036, (-2147482036, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00258 432 NtClose (-2147482036, ... ) == 0x0 00259 432 NtClose (-2147482032, ... ) == 0x0 00249 432 NtQueryDefaultUILanguage ... ) == 0x0 00260 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00261 432 NtQueryInstallUILanguage (2012047340, ... ) == 0x0 00262 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll"}, 1, 96, ... 68, {status=0x0, info=1}, ) }, 1, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00263 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 68, ... 72, ) == 0x0 00264 432 NtMapViewOfSection (72, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x360000), 0x0, 593920, ) == 0x0 00265 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00266 432 NtQueryDefaultUILanguage (2013024600, ... 00267 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00268 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00269 432 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00270 432 NtClose (-2147482032, ... ) == 0x0 00271 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00272 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00273 432 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482036, ) }, ... -2147482036, ) == 0x0 00274 432 NtQueryValueKey (-2147482036, (-2147482036, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00275 432 NtClose (-2147482036, ... ) == 0x0 00276 432 NtClose (-2147482032, ... ) == 0x0 00266 432 NtQueryDefaultUILanguage ... ) == 0x0 00277 432 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00278 432 NtQueryInstallUILanguage (2013024602, ... ) == 0x0 00279 432 NtQueryDefaultLocale (1, 1239804, ... ) == 0x0 00280 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00281 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1240660, 1, 96, 0} (24, {128, 156, new_msg, 0, 1240660, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0P\275=\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0T\365\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1507, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0P\275=\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0T\365\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 424, 432, 1507, 0} (24, {128, 156, new_msg, 0, 1240660, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0P\275=\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0T\365\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1507, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0P\275=\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0T\365\22\0\0\0\0\0" ) ) == 0x0 00282 432 NtClose (68, ... ) == 0x0 00283 432 NtClose (72, ... ) == 0x0 00284 432 NtUnmapViewOfSection (-1, 0x360000, ... ) == 0x0 00285 432 NtUnmapViewOfSection (-1, 0x12f554, ... ) == STATUS_NOT_MAPPED_VIEW 00286 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00287 432 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00288 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00289 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00290 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1238344, ... ) }, 1238344, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00291 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00292 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00293 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00294 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1238936, ... ) }, 1238936, ... ) == 0x0 00295 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 72, {status=0x0, info=1}, ) }, 3, 33, ... 72, {status=0x0, info=1}, ) == 0x0 00296 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00297 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00298 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 68, ... 76, ) == 0x0 00299 432 NtClose (68, ... ) == 0x0 00300 432 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x910000), 0x0, 921600, ) == 0x0 00301 432 NtClose (76, ... ) == 0x0 00302 432 NtUnmapViewOfSection (-1, 0x910000, ... ) == 0x0 00303 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 76, {status=0x0, info=1}, ) }, 5, 96, ... 76, {status=0x0, info=1}, ) == 0x0 00304 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 76, ... 68, ) == 0x0 00305 432 NtQuerySection (68, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00306 432 NtOpenProcessToken (-1, 0x8, ... 80, ) == 0x0 00307 432 NtQueryInformationToken (80, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00308 432 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00309 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 84, ) }, ... 84, ) == 0x0 00310 432 NtQueryValueKey (84, (84, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (84, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00311 432 NtClose (84, ... ) == 0x0 00312 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00313 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 84, ) == 0x0 00314 432 NtQueryInformationToken (84, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00315 432 NtClose (84, ... ) == 0x0 00316 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00317 432 NtClose (80, ... ) == 0x0 00318 432 NtClose (76, ... ) == 0x0 00319 432 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71950000), 0x0, 933888, ) == 0x0 00320 432 NtClose (68, ... ) == 0x0 00321 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00322 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00323 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00324 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00325 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00326 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00327 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00328 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00329 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00330 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00331 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00332 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00333 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00334 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00335 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00336 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00337 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00338 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00339 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00340 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00341 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00342 432 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 1240120, ... ) , 42, 1240120, ... ) == 0x0 00343 432 NtQueryDefaultUILanguage (1238836, ... 00344 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00345 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00346 432 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00347 432 NtClose (-2147482032, ... ) == 0x0 00348 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00349 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00350 432 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482036, ) }, ... -2147482036, ) == 0x0 00351 432 NtQueryValueKey (-2147482036, (-2147482036, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00352 432 NtClose (-2147482036, ... ) == 0x0 00353 432 NtClose (-2147482032, ... ) == 0x0 00343 432 NtQueryDefaultUILanguage ... ) == 0x0 00354 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00355 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1237688, ... ) }, 1237688, ... ) == 0x0 00356 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00357 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 68, ... 76, ) == 0x0 00358 432 NtClose (68, ... ) == 0x0 00359 432 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x360000), 0x0, 4096, ) == 0x0 00360 432 NtClose (76, ... ) == 0x0 00361 432 NtUnmapViewOfSection (-1, 0x360000, ... ) == 0x0 00362 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1237328, ... ) }, 1237328, ... ) == 0x0 00363 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1238028, (0x80100080, {24, 0, 0x40, 0, 1238028, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 76, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 76, {status=0x0, info=1}, ) == 0x0 00364 432 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 76, ... 68, ) == 0x0 00365 432 NtClose (76, ... ) == 0x0 00366 432 NtMapViewOfSection (68, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x360000), {0, 0}, 4096, ) == 0x0 00367 432 NtClose (68, ... ) == 0x0 00368 432 NtUnmapViewOfSection (-1, 0x360000, ... ) == 0x0 00369 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 68, {status=0x0, info=1}, ) }, 1, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00370 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 68, ... 76, ) == 0x0 00371 432 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x360000), 0x0, 4096, ) == 0x0 00372 432 NtQueryInformationFile (68, 1237648, 56, NetworkOpen, ... {status=0x0, info=56}, ) == 0x0 00373 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00374 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1237728, 1, 96, 0} (24, {128, 156, new_msg, 0, 1237728, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1D\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\340\351\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1508, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1D\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\340\351\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 424, 432, 1508, 0} (24, {128, 156, new_msg, 0, 1237728, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1D\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\340\351\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1508, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1D\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\340\351\22\0\0\0\0\0" ) ) == 0x0 00375 432 NtClose (68, ... ) == 0x0 00376 432 NtClose (76, ... ) == 0x0 00377 432 NtUnmapViewOfSection (-1, 0x360000, ... ) == 0x0 00378 432 NtUnmapViewOfSection (-1, 0x12e9e0, ... ) == STATUS_NOT_MAPPED_VIEW 00379 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00380 432 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00381 432 NtUserSystemParametersInfo (104, 0, 1906151468, 0, ... ) == 0x1 00382 432 NtUserGetDC (0, ... ) == 0x1010053 00383 432 NtUserCallOneParam (16842835, 56, ... ) == 0x1 00384 432 NtUserSystemParametersInfo (38, 4, 1906153440, 0, ... ) == 0x1 00385 432 NtUserSystemParametersInfo (66, 12, 1240140, 0, ... ) == 0x1 00386 432 NtOpenProcessToken (-1, 0x8, ... 76, ) == 0x0 00387 432 NtAccessCheck (1343736, 76, 0x1, 1239544, 1239488, 56, 1239572, ... ) == STATUS_NO_IMPERSONATION_TOKEN 00388 432 NtClose (76, ... ) == 0x0 00389 432 NtOpenKey (0x20019, {24, 60, 0x40, 0, 0, (0x20019, {24, 60, 0x40, 0, 0, "Control Panel\Desktop"}, ... 76, ) }, ... 76, ) == 0x0 00390 432 NtQueryValueKey (76, (76, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00391 432 NtClose (76, ... ) == 0x0 00392 432 NtUserSystemParametersInfo (41, 500, 1239640, 0, ... ) == 0x1 00393 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 76, ) }, ... 76, ) == 0x0 00394 432 NtQueryValueKey (76, (76, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00395 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 68, ) }, ... 68, ) == 0x0 00396 432 NtQueryValueKey (68, (68, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00397 432 NtClose (68, ... ) == 0x0 00398 432 NtClose (76, ... ) == 0x0 00399 432 NtUserSystemParametersInfo (102, 0, 1906153328, 0, ... ) == 0x1 00400 432 NtUserSystemParametersInfo (4130, 0, 1240164, 0, ... ) == 0x1 00401 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 76, ) }, ... 76, ) == 0x0 00402 432 NtEnumerateValueKey (76, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 00403 432 NtClose (76, ... ) == 0x0 00404 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00405 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc03b 00406 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc03d 00407 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00408 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc03f 00409 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00410 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc041 00411 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00412 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc043 00413 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc045 00414 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00415 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc047 00416 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00417 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc049 00418 432 NtUserGetClassInfo (1905590272, 1240060, 1240012, 1240088, 0, ... ) == 0xc049 00419 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00420 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc04b 00421 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00422 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc04d 00423 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00424 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc04f 00425 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc051 00426 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00427 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc053 00428 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00429 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc055 00430 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc057 00431 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00432 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc059 00433 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10013 00434 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc05b 00435 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00436 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc05d 00437 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00438 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc05f 00439 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00440 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc017 00441 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00442 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc019 00443 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10013 00444 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... ) == 0x810dc018 00445 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00446 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc01a 00447 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00448 432 NtUserRegisterClassExWOW (1239896, 1239976, 1239960, 1239992, 0, 384, 0, ... 00449 432 NtAllocateVirtualMemory (-1, 6389760, 0, 4096, 4096, 32, ... 6389760, 4096, ) == 0x0 00448 432 NtUserRegisterClassExWOW ... ) == 0x810dc01c 00450 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00451 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc01e 00452 432 NtUserFindExistingCursorIcon (1239444, 1239460, 1240028, ... ) == 0x10011 00453 432 NtUserRegisterClassExWOW (1239956, 1240036, 1240020, 1240052, 0, 384, 0, ... ) == 0x810dc01b 00454 432 NtUserFindExistingCursorIcon (1239440, 1239456, 1240024, ... ) == 0x10011 00455 432 NtUserRegisterClassExWOW (1239952, 1240032, 1240016, 1240048, 0, 384, 0, ... ) == 0x810dc068 00456 432 NtUserFindExistingCursorIcon (1239448, 1239464, 1240032, ... ) == 0x10011 00457 432 NtUserRegisterClassExWOW (1239900, 1239980, 1239964, 1239996, 0, 384, 0, ... ) == 0x810dc06a 00458 432 NtCreateKey (0x2001f, {24, 60, 0x40, 0, 0, (0x2001f, {24, 60, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, 0, 0x0, 0, ... 76, 2, ) }, 0, 0x0, 0, ... 76, 2, ) == 0x0 00459 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SYSTEM\Setup"}, ... 68, ) }, ... 68, ) == 0x0 00460 432 NtQueryValueKey (68, (68, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (68, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00461 432 NtClose (68, ... ) == 0x0 00462 432 NtQueryDefaultUILanguage (1241756, ... 00463 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00464 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00465 432 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00466 432 NtClose (-2147482032, ... ) == 0x0 00467 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00468 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00469 432 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482036, ) }, ... -2147482036, ) == 0x0 00470 432 NtQueryValueKey (-2147482036, (-2147482036, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00471 432 NtClose (-2147482036, ... ) == 0x0 00472 432 NtClose (-2147482032, ... ) == 0x0 00462 432 NtQueryDefaultUILanguage ... ) == 0x0 00473 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00474 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1, 96, ... 68, {status=0x0, info=1}, ) }, 1, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00475 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 68, ... 80, ) == 0x0 00476 432 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x910000), 0x0, 8323072, ) == 0x0 00477 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00478 432 NtQueryDefaultLocale (1, 1239792, ... ) == 0x0 00479 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00480 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1240648, 1, 96, 0} (24, {128, 156, new_msg, 0, 1240648, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0\20\311\310\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0H\365\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1509, 0} " S\26\0\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0\20\311\310\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0H\365\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 424, 432, 1509, 0} (24, {128, 156, new_msg, 0, 1240648, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0\20\311\310\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0H\365\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1509, 0} " S\26\0\33\0\1\0\0\0\0\0\1\361\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1D\0\0\0\377\377\377\377\0\0\0\0\20\311\310\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0H\365\22\0\0\0\0\0" ) ) == 0x0 00481 432 NtClose (68, ... ) == 0x0 00482 432 NtClose (80, ... ) == 0x0 00483 432 NtUnmapViewOfSection (-1, 0x910000, ... ) == 0x0 00484 432 NtUnmapViewOfSection (-1, 0x12f548, ... ) == STATUS_NOT_MAPPED_VIEW 00485 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00486 432 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00487 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00488 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00489 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1238876, ... ) }, 1238876, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00490 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00491 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00492 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00493 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1239468, ... ) }, 1239468, ... ) == 0x0 00494 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 80, {status=0x0, info=1}, ) }, 3, 33, ... 80, {status=0x0, info=1}, ) == 0x0 00495 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00496 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comctl32.dll"}, ... 68, ) }, ... 68, ) == 0x0 00497 432 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77340000), 0x0, 569344, ) == 0x0 00498 432 NtClose (68, ... ) == 0x0 00499 432 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {424, 0}, ... 68, ) == 0x0 00500 432 NtQueryInformationProcess (68, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 00501 432 NtClose (68, ... ) == 0x0 00502 432 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00503 432 NtUserSystemParametersInfo (104, 0, 2000318720, 0, ... ) == 0x1 00504 432 NtUserSystemParametersInfo (38, 4, 2000318708, 0, ... ) == 0x1 00505 432 NtOpenKey (0x20019, {24, 60, 0x40, 0, 0, (0x20019, {24, 60, 0x40, 0, 0, "Control Panel\Desktop"}, ... 68, ) }, ... 68, ) == 0x0 00506 432 NtQueryValueKey (68, (68, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00507 432 NtClose (68, ... ) == 0x0 00508 432 NtUserSystemParametersInfo (41, 500, 1241332, 0, ... ) == 0x1 00509 432 NtUserSystemParametersInfo (102, 0, 2000318732, 0, ... ) == 0x1 00510 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00511 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00512 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc03b 00513 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00514 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc03d 00515 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00516 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00517 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc03f 00518 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00519 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00520 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc041 00521 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00522 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00523 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc043 00524 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00525 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc045 00526 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00527 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00528 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc047 00529 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00530 432 NtUserFindExistingCursorIcon (1241120, 1241136, 1241704, ... ) == 0x10011 00531 432 NtUserRegisterClassExWOW (1241572, 1241652, 1241636, 1241668, 0, 384, 0, ... ) == 0x810dc049 00532 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00533 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00534 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc04b 00535 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00536 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00537 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc04d 00538 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00539 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00540 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc04f 00541 432 NtUserGetClassInfo (1999896576, 1241744, 1241696, 1241772, 0, ... ) == 0x0 00542 432 NtUserRegisterClassExWOW (1241580, 1241660, 1241644, 1241676, 0, 384, 0, ... ) == 0x810dc051 00543 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00544 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00545 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc053 00546 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00547 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00548 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc055 00549 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc057 00550 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00551 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00552 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc059 00553 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00554 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10013 00555 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc05b 00556 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00557 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00558 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc05d 00559 432 NtUserGetClassInfo (1999896576, 1241740, 1241692, 1241768, 0, ... ) == 0x0 00560 432 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 00561 432 NtUserRegisterClassExWOW (1241576, 1241656, 1241640, 1241672, 0, 384, 0, ... ) == 0x810dc05f 00562 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc03b 00563 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc03d 00564 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc03f 00565 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc041 00566 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc043 00567 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc045 00568 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc047 00569 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc049 00570 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc04b 00571 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc04d 00572 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc04f 00573 432 NtUserGetClassInfo (1999896576, 1243496, 1243448, 1243524, 0, ... ) == 0xc051 00574 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc053 00575 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc055 00576 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc059 00577 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc05b 00578 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc05d 00579 432 NtUserGetClassInfo (1999896576, 1243492, 1243444, 1243520, 0, ... ) == 0xc05f 00580 432 NtTestAlert (... ) == 0x0 00581 432 NtContinue (1244464, 1, ... 00582 432 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x40b3e7,}, 4, ... ) == 0x0 00583 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00584 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 3670016, 65536, ) == 0x0 00585 432 NtAllocateVirtualMemory (-1, 3670016, 0, 4096, 4096, 4, ... 3670016, 4096, ) == 0x0 00586 432 NtAllocateVirtualMemory (-1, 3674112, 0, 4096, 4096, 4, ... 3674112, 4096, ) == 0x0 00587 432 NtQueryPerformanceCounter (... {99242531, 0}, {3579545, 0}, ) == 0x0 00588 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1242368, ... ) }, 1242368, ... ) == 0x0 00589 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00590 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 68, ... 84, ) == 0x0 00591 432 NtClose (68, ... ) == 0x0 00592 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x390000), 0x0, 262144, ) == 0x0 00593 432 NtClose (84, ... ) == 0x0 00594 432 NtUnmapViewOfSection (-1, 0x390000, ... ) == 0x0 00595 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00596 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00597 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00598 432 NtAllocateVirtualMemory (-1, 1355776, 0, 4096, 4096, 4, ... 1355776, 4096, ) == 0x0 00599 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\Device\KsecDD"}, 7, 16, ... 84, {status=0x0, info=0}, ) }, 7, 16, ... 84, {status=0x0, info=0}, ) == 0x0 00600 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227\301Z\53\236k\323g\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00601 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00602 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00603 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00604 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00605 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00606 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00607 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00608 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00609 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "\254o\353\232\364\177-l\307?\30\307\204\0\301&_[\215Pz\257\351\234\216\310\364\353&\24\255\356C\27\306.\243h\352<\252\5\3\261\3554i\244\371\217p+\373\316\246Td@\31\4\216\5\352\305T\250\266\346%\267\345\367\202\321\376\277"\317\347\247", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "\254o\353\232\364\177-l\307?\30\307\204\0\301&_[\215Pz\257\351\234\216\310\364\353&\24\255\356C\27\306.\243h\352<\252\5\3\261\3554i\244\371\217p+\373\316\246Td@\31\4\216\5\352\305T\250\266\346%\267\345\367\202\321\376\277"\317\347\247", 80, ... ) \317\347\247", 80, ... ) == 0x0 00610 432 NtClose (-2147482032, ... ) == 0x0 00600 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "sT\34\1779\351\342u\275\14\301\277`\27C\237\363\207\327\2571\237\252\217m/\342\177\330Jlwl\35uo\260j\244\300z7\333m\27\214\336 \354\240p)D\31<;\214\356\237$l}\347\361\365\216\325\327\344\7\30\273W\272r\26\24-\204\214\361\313a\35\145\267d2\224\270\206\214\373\3^0\253~\344<\25Bs\301R\373\300C"\216\273\30\34\3269ie\225N?E\320\354#$\317q,s\375m\226?c\202\316e\34wL\177\341\356\342\222uwFN\361(\214\314\336\335\273OL@\177\374q\327D\244\252[i*\232Mx\354\377S \330P\233\24\255\240\365J\377r\343\272-\304@\341\264\244Eh-\35\376\250IL\335h\341\210\214\220\177\261\306\353\325\262'\311\307\265\200\236%\374\346ZjSH\250;\20233'\31\362\321\250\270m\313%j\254Ie\251tiG\254?\374b\26t", ) \216\273\30\34\3269ie\225N?E\320\354#$\317q,s\375m\226?c\202\316e\34wL\177\341\356\342\222uwFN\361(\214\314\336\335\273OL@\177\374q\327D\244\252[i*\232Mx\354\377S \330P\233\24\255\240\365J\377r\343\272-\304@\341\264\244Eh-\35\376\250IL\335h\341\210\214\220\177\261\306\353\325\262'\311\307\265\200\236%\374\346ZjSH\250;\20233'\31\362\321\250\270m\313%j\254Ie\251tiG\254?\374b\26t", ) == 0x0 00611 432 NtAllocateVirtualMemory (-1, 1359872, 0, 16384, 4096, 4, ... 1359872, 16384, ) == 0x0 00612 432 NtUserRegisterClassExWOW (1244452, 1244532, 1244516, 1244548, 0, 384, 0, ... ) == 0x810dc038 00613 432 NtUserGetAtomName (49208, 1243216, ... ) == 0x15 00614 432 NtUserCreateWindowEx (0, 49208, 49208, (0, 49208, 49208, "OleMainThreadWndName", -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... , -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... 00615 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1240740, ... ) }, 1240740, ... ) == 0x0 00616 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 68, {status=0x0, info=1}, ) }, 5, 96, ... 68, {status=0x0, info=1}, ) == 0x0 00617 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 68, ... 88, ) == 0x0 00618 432 NtClose (68, ... ) == 0x0 00619 432 NtMapViewOfSection (88, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x390000), 0x0, 204800, ) == 0x0 00620 432 NtClose (88, ... ) == 0x0 00621 432 NtUnmapViewOfSection (-1, 0x390000, ... ) == 0x0 00622 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1241056, ... ) }, 1241056, ... ) == 0x0 00623 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 88, {status=0x0, info=1}, ) }, 5, 96, ... 88, {status=0x0, info=1}, ) == 0x0 00624 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 88, ... 68, ) == 0x0 00625 432 NtQuerySection (68, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00626 432 NtClose (88, ... ) == 0x0 00627 432 NtMapViewOfSection (68, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 212992, ) == 0x0 00628 432 NtClose (68, ... ) == 0x0 00629 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00630 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00631 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00632 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 00633 432 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00634 432 NtClose (68, ... ) == 0x0 00635 432 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 68, ) }, ... 68, ) == 0x0 00636 432 NtOpenKey (0x1, {24, 68, 0x40, 0, 0, (0x1, {24, 68, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 88, ) }, ... 88, ) == 0x0 00637 432 NtQueryValueKey (88, (88, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00638 432 NtClose (88, ... ) == 0x0 00639 432 NtClose (68, ... ) == 0x0 00640 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00641 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 00642 432 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00643 432 NtClose (68, ... ) == 0x0 00644 432 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 68, ) }, ... 68, ) == 0x0 00645 432 NtOpenKey (0x1, {24, 68, 0x40, 0, 0, (0x1, {24, 68, 0x40, 0, 0, "Control Panel\Desktop"}, ... 88, ) }, ... 88, ) == 0x0 00646 432 NtQueryValueKey (88, (88, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00647 432 NtClose (88, ... ) == 0x0 00648 432 NtClose (68, ... ) == 0x0 00649 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\UxTheme.dll"}, 1240556, ... ) }, 1240556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00650 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "UxTheme.dll"}, 1240556, ... ) }, 1240556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00651 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\UxTheme.dll"}, 1240556, ... ) }, 1240556, ... ) == 0x0 00652 432 NtUserGetProcessWindowStation (... ) == 0x24 00653 432 NtUserGetObjectInformation (36, 2, 0, 0, 1242852, ... ) == 0x0 00654 432 NtUserGetObjectInformation (36, 2, 1353088, 16, 1242852, ... ) == 0x1 00655 432 NtUserGetGUIThreadInfo (432, 1242808, ... ) == 0x1 00656 432 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1242628, 64, ... 68, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1242628, 64, ... 68, 0x0, 0x0, 0x0, 64, ) == 0x0 00657 432 NtRequestWaitReplyPort (68, {32, 56, new_msg, 0, 0, 0, 0, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1513, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 424, 432, 1513, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1513, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00658 432 NtRequestWaitReplyPort (68, {32, 56, new_msg, 0, 0, 0, 0, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1514, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 424, 432, 1514, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1514, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00659 432 NtUserCallNoParam (29, ... 00660 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1240100, ... ) }, 1240100, ... ) == 0x0 00659 432 NtUserCallNoParam ... ) == 0x0 00661 432 NtUserSystemParametersInfo (41, 0, 1524225160, 0, ... ) == 0x1 00662 432 NtGdiHfontCreate (1242180, 356, 0, 0, 1343808, ... ) == 0x150a0418 00663 432 NtGdiHfontCreate (1242180, 356, 0, 0, 1343800, ... ) == 0x90a040f 00664 432 NtRequestWaitReplyPort (68, {32, 56, new_msg, 0, 0, 0, 0, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1515, 0} "\0\0\0\0\0\0\0\0X\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 424, 432, 1515, 0} (68, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 424, 432, 1515, 0} "\0\0\0\0\0\0\0\0X\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00665 432 NtMapViewOfSection (88, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x390000), {0, 0}, 331776, ) == 0x0 00666 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00667 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00668 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00669 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00670 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00671 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00672 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00673 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00674 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00675 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00676 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00677 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00678 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00679 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00680 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00681 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00682 432 NtUserGetWindowDC (0, ... ) == 0x1010051 00683 432 NtGdiCreatePatternBrushInternal (59048369, 0, 0, ... ) == 0xc100403 00684 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 00685 432 NtUserCallNoParam (29, ... 00686 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1239544, ... ) }, 1239544, ... ) == 0x0 00685 432 NtUserCallNoParam ... ) == 0x0 00687 432 NtUserCallNoParam (29, ... 00688 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1239540, ... ) }, 1239540, ... ) == 0x0 00687 432 NtUserCallNoParam ... ) == 0x0 00689 432 NtUserMessageCall (0x200b2, WM_NCCREATE, 0x0, 0x12f7fc, 0, 670, 0, ... ) == 0x1 00690 432 NtUserMessageCall (0x200b2, WM_NCCALCSIZE, 0x0, 0x12f824, 0, 670, 0, ... ) == 0x0 00691 432 NtUserSetProp (131250, 43288, -1, ... ) == 0x1 00614 432 NtUserCreateWindowEx ... ) == 0x200b2 00692 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#DU\13\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00693 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00694 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00695 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00696 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00697 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00698 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00699 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00700 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00701 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "ky1\214\12\221Z\262\372\37\251\376\367\322\360=v\30i\326\372\321\374\307\200\250\317)\16\232\343\200\21\24#P\251\367\20/Z,g[\31\23\312\257\322\207F(\240B\323\325\354\207\235'\260Lg\254~\347\222\237\0\210\357%|\33\365\206\200\324\361\235", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "ky1\214\12\221Z\262\372\37\251\376\367\322\360=v\30i\326\372\321\374\307\200\250\317)\16\232\343\200\21\24#P\251\367\20/Z,g[\31\23\312\257\322\207F(\240B\323\325\354\207\235'\260Lg\254~\347\222\237\0\210\357%|\33\365\206\200\324\361\235", 80, ... ) , 80, ... ) == 0x0 00702 432 NtClose (-2147482032, ... ) == 0x0 00692 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "u\267\272\303\263\331\14\366\242\320\231\254\274\275\370i\310\333\234Q\333\2\326\31\252u"\356B\315\263D9\337\255kSWOw=\302k\0.\206f\254w\363g\3770\346p\264\34\275\262\344\274;\354\\351\26\272\1N\240s}\252L\347\2069\210\31F\274\333\203\341\1uP\320]c\243d\353\302m\273\300?\216Q\271\236\301V\354u^\353\217\321\224\32\330\25\236\4\214@E\327\340n\327\373\226\3513'\347\244\24\340\316B1\357\320\12\3o\267\224 \361\320\26)\270\360\ \27s\312\371\12\33\363\273'o@%\14\337\3758v~\6\206\14\313}\340\351#M\0\360S\351\234Wu\311\270\237qn\256#De\207\343\35\263\365f\307S\15n\225\307\244\237B52@\226\233.G\302g\345CK\261x\237gS\2308\213:\36gx%\333P.\250\0s\370\341\35[/\207\351\21\217\325\355\261)\234\16", ) \356B\315\263D9\337\255kSWOw=\302k\0.\206f\254w\363g\3770\346p\264\34\275\262\344\274;\354\\351\26\272\1N\240s}\252L\347\2069\210\31F\274\333\203\341\1uP\320]c\243d\353\302m\273\300?\216Q\271\236\301V\354u^\353\217\321\224\32\330\25\236\4\214@E\327\340n\327\373\226\3513'\347\244\24\340\316B1\357\320\12\3o\267\224 \361\320\26)\270\360\ \27s\312\371\12\33\363\273'o@%\14\337\3758v~\6\206\14\313}\340\351#M\0\360S\351\234Wu\311\270\237qn\256#De\207\343\35\263\365f\307S\15n\225\307\244\237B52@\226\233.G\302g\345CK\261x\237gS\2308\213:\36gx%\333P.\250\0s\370\341\35[/\207\351\21\217\325\355\261)\234\16", ) == 0x0 00703 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00704 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00705 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00706 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00707 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00708 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00709 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00710 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00711 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00712 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "\360\315M_P\210\353\306\273\272X\233)\353+l\313p\267!\230\210\376"[S\30\24\313\342\27n\374g\2\350;\344A\240>cpv\376\13\351\324"R\245\276\261t\301/\362\217\307\26\315I\223\227\247E\221\270\265\234\235\213\35\317\341\344\360\200\307", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "\360\315M_P\210\353\306\273\272X\233)\353+l\313p\267!\230\210\376"[S\30\24\313\342\27n\374g\2\350;\344A\240>cpv\376\13\351\324"R\245\276\261t\301/\362\217\307\26\315I\223\227\247E\221\270\265\234\235\213\35\317\341\344\360\200\307", 80, ... ) [S\30\24\313\342\27n\374g\2\350;\344A\240>cpv\376\13\351\324 (-2147482032, "Seed", 0, 3, "\360\315M_P\210\353\306\273\272X\233)\353+l\313p\267!\230\210\376"[S\30\24\313\342\27n\374g\2\350;\344A\240>cpv\376\13\351\324"R\245\276\261t\301/\362\217\307\26\315I\223\227\247E\221\270\265\234\235\213\35\317\341\344\360\200\307", 80, ... ) , 80, ... ) == 0x0 00713 432 NtClose (-2147482032, ... ) == 0x0 00703 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\355\313\316\261\304\241\14\236^\230`]\340\262\344c\11A\256](\203\20\20aMg\231\250%\220\361UR\36J\350\307Q\225F\277;\330\201\236(\215i\4\212\305IK\255\245\7.\235\271\337f\273\305\11Pn\215<\211`\205\27\202qB\253e\222\370\205\2\210\32#\177\25H\\251\274\2U\340\200kx\370ODiY\316\326\312\275\323\276\252tr(\212~C\316\230\14B/D`\223\355\262\367\257\257p\26\12\226\16\11\336'F\222*\323Q\245\222\271\21/y\2708%\202L-\347u\263)#[\314\376\301\31\344$\243\12\267t$\37\201\362i\25v\227\4s\26k\204\305\36`x\313\316\3\277%\231\243\204\21G\6\261Q\372\261\347\7J\25\340\15\246\2158U\214\216\272\377\27@o\370&\256\360\17\201fE\246\304f\265\22\316/3\356\237\21", ) \304\241\14\236^\230`]\340\262\344c\11A\256](\203\20\20aMg\231\250%\220\361UR\36J\350\307Q\225F\277;\330\201\236(\215i\4\212\305IK\255\245\7.\235\271\337f\273\305\11Pn\215<\211`\205\27\202qB\253e\222\370\205\2\210\32#\177\25H\\251\274\2U\340\200kx\370ODiY\316\326\312\275\323\276\252tr(\212~C\316\230\14B/D`\223\355\262\367\257\257p\26\12\226\16\11\336'F\222*\323Q\245\222\271\21/y\2708%\202L-\347u\263)#[\314\376\301\31\344$\243\12\267t$\37\201\362i\25v\227\4s\26k\204\305\36`x\313\316\3\277%\231\243\204\21G\6\261Q\372\261\347\7J\25\340\15\246\2158U\214\216\272\377\27@o\370&\256\360\17\201fE\246\304f\265\22\316/3\356\237\21", ) == 0x0 00714 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\226\3759\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00715 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00716 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00717 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00718 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00719 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00720 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00721 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00722 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00723 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "pz\222\264S\306\22\306\20SL\21CX,\377(\220\6\203\205\11\351\365\320\331\251\3564\302\367\16\304?\266.\265)\217\232\301\314[\252\2331\274\301-\27\376\221g\271^\240\37\231G\377y\336\360\2\266\365\224,\336X\374\1'\276;\366\325V\373z", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "pz\222\264S\306\22\306\20SL\21CX,\377(\220\6\203\205\11\351\365\320\331\251\3564\302\367\16\304?\266.\265)\217\232\301\314[\252\2331\274\301-\27\376\221g\271^\240\37\231G\377y\336\360\2\266\365\224,\336X\374\1'\276;\366\325V\373z", 80, ... ) , 80, ... ) == 0x0 00724 432 NtClose (-2147482032, ... ) == 0x0 00714 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\317d\367\365\326\222\257 \371\336\310p\312\36\257\2513\303\17\0\354t.\242i\3123\372\242\305v?[\4%F\232\103\365\276k@\347\226\371c\226\271>\36Vc]\253"\324P\373\215\334\371;\145\373b\300\34\260U\7\23\375\314\330\311~]R\203\313\323X\225\316(u\27^\3\34\206+U\234\252=\325_|-\244\206p^\350P\221Yx\225\360a\350\346\365/,\366\252\302\345[FVB;\34L\10\236\274\2\245\314O\33\27\275\262\345n\214\1O\357\25\25^\240\375\243=\11x\247H\254\4\233+\256Z\32y\2317\322\3549\354{\330\263\207l\22\221\331\310\3431\273L\300h\356I\334\300\278\246?\330n3\254\367K\27r\313\20\255\214s\316\21G\337\230Fn\366\365$\7\30\253.p\225\242\16`(\376j\260t\252\307\177gV\306Wa\323r\221\322\146\355\251\363\3768V\300\331\337\260", ) \324P\373\215\334\371;\145\373b\300\34\260U\7\23\375\314\330\311~]R\203\313\323X\225\316(u\27^\3\34\206+U\234\252=\325_|-\244\206p^\350P\221Yx\225\360a\350\346\365/,\366\252\302\345[FVB;\34L\10\236\274\2\245\314O\33\27\275\262\345n\214\1O\357\25\25^\240\375\243=\11x\247H\254\4\233+\256Z\32y\2317\322\3549\354{\330\263\207l\22\221\331\310\3431\273L\300h\356I\334\300\278\246?\330n3\254\367K\27r\313\20\255\214s\316\21G\337\230Fn\366\365$\7\30\253.p\225\242\16`(\376j\260t\252\307\177gV\306Wa\323r\221\322\146\355\251\363\3768V\300\331\337\260", ) == 0x0 00725 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00726 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00727 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00728 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00729 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00730 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00731 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00732 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00733 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00734 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "\363L\342\237c&\2260\325x]\352)\350JS\332\30W\224\12\326\35\264\361z\200\365w\265\2423\15\300\27\210K)%\367\363p\317\262*\363S=\4\373\271\347\365#\345\307\316\223C\31\307\30\372\350\333\35-\202\261V`\375\32\22bz\371\7\345\206", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "\363L\342\237c&\2260\325x]\352)\350JS\332\30W\224\12\326\35\264\361z\200\365w\265\2423\15\300\27\210K)%\367\363p\317\262*\363S=\4\373\271\347\365#\345\307\316\223C\31\307\30\372\350\333\35-\202\261V`\375\32\22bz\371\7\345\206", 80, ... ) , 80, ... ) == 0x0 00735 432 NtClose (-2147482032, ... ) == 0x0 00725 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "v\242\250\3\240\376#\320q\201\267\314ZR\22sYb\373|\317\3249\12C\370\342\305\260\222\341, ) , ) == 0x0 00736 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00737 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00738 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00739 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00740 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00741 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00742 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00743 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00744 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00745 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "\257\204,\342\250\275\2009\333\315j\317t?T9\0\374\264\336\341/\352\204\205co7m:\255\22\235\204\327B#\3073\367=\201i[\22\353*@\1"\245k\363\341\377\305q`M7\275\371\311\244\302\261\215Cx~OS<\225u\213\304.\26", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "\257\204,\342\250\275\2009\333\315j\317t?T9\0\374\264\336\341/\352\204\205co7m:\255\22\235\204\327B#\3073\367=\201i[\22\353*@\1"\245k\363\341\377\305q`M7\275\371\311\244\302\261\215Cx~OS<\225u\213\304.\26", 80, ... ) \245k\363\341\377\305q`M7\275\371\311\244\302\261\215Cx~OS<\225u\213\304.\26", 80, ... ) == 0x0 00746 432 NtClose (-2147482032, ... ) == 0x0 00736 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\377\345\324\32\1\32\254\14be\3128\260\217\306\7\7\227p\251\327\3467\257\203V\311i\254\307\271\201:\221r\214\344\5\6\20(!\250\2467h\337!U\17/\217;\360\253O\211K\241?\236|\250\342=0\325<6\235\10kNje\240;H.\320\312\2574D\15\247\326\256\343\256\320e\334vJ\36l\240\350\344\365\236\3#b\202aR\272\325X\266\331\312r\243\321xDX\247\322\214c\109f\277c\3\272t\306M\260\14\277t\365\340\372\376_9_\204^\323jj\334\264\10\220\3\326Q\332\10\212\215\16\373\254\10w\24vn\14\310\374\235\277\201^\314v\205\207\213A\370\3T\226\263\2371E\274Z\231\205c\12\225\316\244\3024R\201\377\20\352r\353\27\261`\233\350\252, ) , ) == 0x0 00747 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00748 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00749 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00750 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00751 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00752 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00753 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00754 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00755 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00756 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "*N\32\26?t\24\237\22`\267\2139!Q)\327\211\230Se\302%l\311^3@,(J.\334v\355\2253n\277\350\206\375\374g\305e\347\263\21\353*\25\240v\253E\223\17\12\2051\346d\227u \207\263\303G\203\302$\300\232c,$\334\10", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "*N\32\26?t\24\237\22`\267\2139!Q)\327\211\230Se\302%l\311^3@,(J.\334v\355\2253n\277\350\206\375\374g\305e\347\263\21\353*\25\240v\253E\223\17\12\2051\346d\227u \207\263\303G\203\302$\300\232c,$\334\10", 80, ... ) , 80, ... ) == 0x0 00757 432 NtClose (-2147482032, ... ) == 0x0 00747 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "X\337jY\253\374>\334Y\272\321\77\335\346\243B\2575\247\211\304\207\376r\372\340\325\31m\222U\4vd\323n1\2\250P\373xm=\225\322\342\243\1w\220\202R"3:\306e\331\331\305s\26\262\274\3038\240\330R\16\17\203w\340dK\330k\300\331\375K\202\305"\302/E\203\203\353 \222!\211\245\300\251w\24\242\2\366\372\35\316^\267\331\314X\221\224=\21\376B\252\322\3547\200w\255Q\235%\325n\227\225\230W'\35\326S\342R\12\214\372\21_\26'd\5\361r\347\3144u\335)\261>\24\333\265~\22QJ\372\200\231\263\270\313\325\242\230\32Eg\375\15\367\374Ii5\363"M\220\204Nj\32\216c\273t\35\213\226\214nb\356[\245\336\202\3740\260\305V\365\213\333\312\267z\211[\277LIv05_\344\275\222\200\263{\1\274\3026n\315\15\356\225Un\213\256ez\25\2405\225\335[", ) 3:\306e\331\331\305s\26\262\274\3038\240\330R\16\17\203w\340dK\330k\300\331\375K\202\305 ... {status=0x0, info=256}, "X\337jY\253\374>\334Y\272\321\77\335\346\243B\2575\247\211\304\207\376r\372\340\325\31m\222U\4vd\323n1\2\250P\373xm=\225\322\342\243\1w\220\202R"3:\306e\331\331\305s\26\262\274\3038\240\330R\16\17\203w\340dK\330k\300\331\375K\202\305"\302/E\203\203\353 \222!\211\245\300\251w\24\242\2\366\372\35\316^\267\331\314X\221\224=\21\376B\252\322\3547\200w\255Q\235%\325n\227\225\230W'\35\326S\342R\12\214\372\21_\26'd\5\361r\347\3144u\335)\261>\24\333\265~\22QJ\372\200\231\263\270\313\325\242\230\32Eg\375\15\367\374Ii5\363"M\220\204Nj\32\216c\273t\35\213\226\214nb\356[\245\336\202\3740\260\305V\365\213\333\312\267z\211[\277LIv05_\344\275\222\200\263{\1\274\3026n\315\15\356\225Un\213\256ez\25\2405\225\335[", ) M\220\204Nj\32\216c\273t\35\213\226\214nb\356[\245\336\202\3740\260\305V\365\213\333\312\267z\211[\277LIv05_\344\275\222\200\263{\1\274\3026n\315\15\356\225Un\213\256ez\25\2405\225\335[", ) == 0x0 00758 432 NtDeviceIoControlFile (84, 0, 0x0, 0x0, 0x390008, (84, 0, 0x0, 0x0, 0x390008, "\256ji\245\233&\227XC'\315>#D\314\229\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\226\3759\211\256\330\235\17\344\33w\16\220\12=\375\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00759 432 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00760 432 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00761 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00762 432 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00763 432 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00764 432 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00765 432 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00766 432 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482032, 2, ) }, 0, 0x0, 0, ... -2147482032, 2, ) == 0x0 00767 432 NtSetValueKey (-2147482032, (-2147482032, "Seed", 0, 3, "Q\335*\254\256\361\370\207\330\273*h\263V\327\227\226YN\37D\330\316\322\254Zp\242\306\364\215k\367\13}\367\260Km\374\240\211\273L\20\365df\361;\264\274\\25\333\17\243\3509\377\26y\27\345\202\217\375;\304q\210\207\243(\275\21\236\7t", 80, ... ) , 0, 3, (-2147482032, "Seed", 0, 3, "Q\335*\254\256\361\370\207\330\273*h\263V\327\227\226YN\37D\330\316\322\254Zp\242\306\364\215k\367\13}\367\260Km\374\240\211\273L\20\365df\361;\264\274\\25\333\17\243\3509\377\26y\27\345\202\217\375;\304q\210\207\243(\275\21\236\7t", 80, ... ) , 80, ... ) == 0x0 00768 432 NtClose (-2147482032, ... ) == 0x0 00758 432 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\212\257\37\6\2724\357\315\366\374k\e\374\354cW\25),\320\347t\210J\275\34ku\306\346\6a\200\363\327\36\3\263\210_\10o"\211\262\23\213\36\21\356\264\275\266\11\367\207\321\230\11X1\260\214\323N|\316\226\241\343\221#^!\27n<\276\263\236\203gaxH\342\305\221\3230\313\360!\205\274N\321d\300^*DMy\224\330\330*\15\261\340\35\364Gi_\266\341G\272\302F\207s\5Si\3535\202\256\3227>\262\205\213gG\354\303\356!\354\301h\1\322\22_\216\214\36\336GMqxkL\202\3\240i\26r\217\315\250\277\321/\17\357\12\213\23;\304\254\21\34\26\264\27\15\267'\230\322\274\324\320\306\311\4$:\336\0"^\0\367\242Q\321\222w\301;J\33\311cGJ\13\17\252O\11\207H\14\235\6\131\365\314\3\334\243\342\21qf\302qZX!r^A\350\233\246\0\4\24\243\11", ) \211\262\23\213\36\21\356\264\275\266\11\367\207\321\230\11X1\260\214\323N|\316\226\241\343\221#^!\27n<\276\263\236\203gaxH\342\305\221\3230\313\360!\205\274N\321d\300^*DMy\224\330\330*\15\261\340\35\364Gi_\266\341G\272\302F\207s\5Si\3535\202\256\3227>\262\205\213gG\354\303\356!\354\301h\1\322\22_\216\214\36\336GMqxkL\202\3\240i\26r\217\315\250\277\321/\17\357\12\213\23;\304\254\21\34\26\264\27\15\267'\230\322\274\324\320\306\311\4$:\336\0 ... {status=0x0, info=256}, "\212\257\37\6\2724\357\315\366\374k\e\374\354cW\25),\320\347t\210J\275\34ku\306\346\6a\200\363\327\36\3\263\210_\10o"\211\262\23\213\36\21\356\264\275\266\11\367\207\321\230\11X1\260\214\323N|\316\226\241\343\221#^!\27n<\276\263\236\203gaxH\342\305\221\3230\313\360!\205\274N\321d\300^*DMy\224\330\330*\15\261\340\35\364Gi_\266\341G\272\302F\207s\5Si\3535\202\256\3227>\262\205\213gG\354\303\356!\354\301h\1\322\22_\216\214\36\336GMqxkL\202\3\240i\26r\217\315\250\277\321/\17\357\12\213\23;\304\254\21\34\26\264\27\15\267'\230\322\274\324\320\306\311\4$:\336\0"^\0\367\242Q\321\222w\301;J\33\311cGJ\13\17\252O\11\207H\14\235\6\131\365\314\3\334\243\342\21qf\302qZX!r^A\350\233\246\0\4\24\243\11", ) , ) == 0x0 00769 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 92, ) == 0x0 00770 432 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 9502720, 1048576, ) == 0x0 00771 432 NtAllocateVirtualMemory (-1, 10543104, 0, 8192, 4096, 4, ... 10543104, 8192, ) == 0x0 00772 432 NtProtectVirtualMemory (-1, (0xa0e000), 4096, 260, ... (0xa0e000), 4096, 4, ) == 0x0 00773 432 NtCreateThread (0x1f03ff, 0x0, -1, 1243940, 1244656, 1, ... 96, {424, 380}, ) == 0x0 00774 432 NtQueryInformationThread (96, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ffdd000,Pid=424,Tid=380,}, 0x0, ) == 0x0 00775 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1998275196, 0, 2147344384, -4} (24, {28, 56, new_msg, 0, 1998275196, 0, 2147344384, -4} "\0\0\0\0\1\0\1\0T\0\0\0\0\0\0\0`\0\0\0\250\1\0\0|\1\0\0" ... {28, 56, reply, 0, 424, 432, 1516, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0`\0\0\0\250\1\0\0|\1\0\0" ) ... {28, 56, reply, 0, 424, 432, 1516, 0} (24, {28, 56, new_msg, 0, 1998275196, 0, 2147344384, -4} "\0\0\0\0\1\0\1\0T\0\0\0\0\0\0\0`\0\0\0\250\1\0\0|\1\0\0" ... {28, 56, reply, 0, 424, 432, 1516, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0`\0\0\0\250\1\0\0|\1\0\0" ) ) == 0x0 00776 432 NtResumeThread (96, ... 1, ) == 0x0 00777 432 NtQueryDefaultLocale (1, 1244108, ... ) == 0x0 00778 380 NtAllocateVirtualMemory (-1, 3293184, 0, 4096, 4096, 4, ... 3293184, 4096, ) == 0x0 00779 380 NtTestAlert (... ) == 0x0 00780 380 NtContinue (10550576, 1, ... 00781 380 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00782 380 NtWaitForSingleObject (92, 0, 0x0, ... 00783 432 NtQueryDefaultLocale (1, 1244088, ... ) == 0x0 00784 432 NtQueryDefaultLocale (1, 1244108, ... ) == 0x0 00785 432 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1374944, 0, (0x1f0003, {24, 52, 0x80, 1374944, 0, "shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}"}, 0, 2147483647, ... 100, ) }, 0, 2147483647, ... 100, ) == STATUS_OBJECT_NAME_EXISTS 00786 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 00787 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 00788 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 104, ) }, ... 104, ) == 0x0 00789 432 NtQueryValueKey (104, (104, "CommonFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0"}, 72, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (104, "CommonFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0"}, 72, ) }, 72, ) == 0x0 00790 432 NtClose (104, ... ) == 0x0 00791 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files"}, 1242688, ... ) }, 1242688, ... ) == 0x0 00792 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\Carlson"}, 1244280, ... ) }, 1244280, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00793 432 NtCreateFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\Carlson"}, 0x0, 128, 3, 2, 16417, 0, 0, ... 104, {status=0x0, info=2}, ) }, 0x0, 128, 3, 2, 16417, 0, 0, ... 104, {status=0x0, info=2}, ) == 0x0 00794 432 NtClose (104, ... ) == 0x0 00795 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\Carlson"}, 1244280, ... ) }, 1244280, ... ) == 0x0 00796 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\Carlson"}, 7, 2113568, ... 104, {status=0x0, info=1}, ) }, 7, 2113568, ... 104, {status=0x0, info=1}, ) == 0x0 00797 432 NtSetInformationFile (104, 1244256, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00798 432 NtClose (104, ... ) == 0x0 00799 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1243196, (0x80100080, {24, 0, 0x40, 0, 1243196, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) == 0x0 00800 432 NtQueryInformationFile (104, 1244132, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 00801 432 NtQueryInformationFile (104, 1244104, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 00802 432 NtQueryInformationFile (104, 1244056, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00803 432 NtAllocateVirtualMemory (-1, 1376256, 0, 8192, 4096, 4, ... 1376256, 8192, ) == 0x0 00804 432 NtQueryInformationFile (104, 1375912, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 00805 432 NtQueryInformationFile (104, 1242600, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00806 432 NtQueryInformationFile (104, 1242444, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 00807 432 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 1242452, (0x40110080, {24, 0, 0x40, 0, 1242452, "\??\C:\Program Files\Common Files\Carlson\carlton"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 00808 432 NtClose (-2147482032, ... ) == 0x0 00807 432 NtCreateFile ... 108, {status=0x0, info=2}, ) == 0x0 00809 432 NtQueryVolumeInformationFile (108, 1241824, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 00810 432 NtQueryInformationFile (108, 1241784, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00811 432 NtQueryVolumeInformationFile (104, 1241824, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 00812 432 NtQueryVolumeInformationFile (104, 1241508, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00813 432 NtSetInformationFile (108, 1241612, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 00814 432 NtCreateSection (0xf001f, 0x0, 0x0, 2, 134217728, 104, ... 112, ) == 0x0 00815 432 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xa10000), {0, 0}, 81920, ) == 0x0 00816 432 NtClose (112, ... ) == 0x0 00817 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0\23\271\212\233W\330\344\310W\330\344\310W\330\344\310D\320\215\310U\330\344\310R\324\353\310X\330\344\310R\324\273\310y\330\344\310\324\320\273\310T\330\344\310\255\373\375\310S\330\344\310\215\373\370\310V\330\344\310D\320\271\310U\330\344\310\324\320\271\310\\330\344\310W\330\345\310\313\330\344\310R\324\204\310X\330\344\310\273\323\272\310V\330\344\310R\324\276\310V\330\344\310RichW\330\344\310\0\0\0\0\0\0\0\0PE\0\0L\1\4\0\345m\341F\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\12\0\334\0\0\0^\0\0\0\0\0\0\347\263\0\0\0\20\0\0\0\360\0\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0`\1\0\0\4\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\360\10\1\0\264\0\0\0\00\1\0`)\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\10\1\0H\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\204\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 00818 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "\0\0\0\0\0\0\0\0\0\0 \0 \0 \0 \0 \0 \0 \0 \0 \0h\0(\0(\0(\0(\0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0H\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\204\0\204\0\204\0\204\0\204\0\204\0\204\0\204\0\204\0\204\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\201\1\201\1\201\1\201\1\201\1\201\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\20\0\20\0\20\0\20\0\20\0\20\0\202\1\202\1\202\1\202\1\202\1\202\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\20\0\20\0\20\0\20\0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0 \0H\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\20\0\24\0\24\0\20\0\20\0\20\0\20\0\20\0\24\0\20\0\20\0\20\0\20\0\20\0\20\0\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\1\20\0\1\1\1\1\1\1\1\1\1\1\1\1\1\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1\2\1", 18432, 0x0, 0, ... {status=0x0, info=18432}, ) , 18432, 0x0, 0, ... {status=0x0, info=18432}, ) == 0x0 00819 432 NtUnmapViewOfSection (-1, 0xa10000, ... ) == 0x0 00820 432 NtSetInformationFile (108, 1244056, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00821 432 NtClose (104, ... ) == 0x0 00822 432 NtClose (108, ... ) == 0x0 00823 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 00824 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 00825 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 108, 2, ) }, 0, 0x0, 0, ... 108, 2, ) == 0x0 00826 432 NtQueryValueKey (108, (108, "Common Start Menu", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0"}, 70, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (108, "Common Start Menu", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0"}, 70, ) }, 70, ) == 0x0 00827 432 NtClose (108, ... ) == 0x0 00828 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu"}, 1242688, ... ) }, 1242688, ... ) == 0x0 00829 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 108, 2, ) }, 0, 0x0, 0, ... 108, 2, ) == 0x0 00830 432 NtSetValueKey (108, (108, "Common Start Menu", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0", 94, ... ) , 0, 1, (108, "Common Start Menu", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0", 94, ... ) , 94, ... ) == 0x0 00831 432 NtClose (108, ... ) == 0x0 00832 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 108, ) }, ... 108, ) == 0x0 00833 432 NtQueryValueKey (108, (108, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (108, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00834 432 NtClose (108, ... ) == 0x0 00835 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CLBCATQ.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00836 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\CLBCATQ.DLL"}, 1241228, ... ) }, 1241228, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00837 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "CLBCATQ.DLL"}, 1241228, ... ) }, 1241228, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00838 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\CLBCATQ.DLL"}, 1241228, ... ) }, 1241228, ... ) == 0x0 00839 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\CLBCATQ.DLL"}, 5, 96, ... 108, {status=0x0, info=1}, ) }, 5, 96, ... 108, {status=0x0, info=1}, ) == 0x0 00840 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 108, ... 104, ) == 0x0 00841 432 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00842 432 NtClose (108, ... ) == 0x0 00843 432 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76fd0000), 0x0, 491520, ) == 0x0 00844 432 NtClose (104, ... ) == 0x0 00845 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMRes.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00846 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\COMRes.dll"}, 1240424, ... ) }, 1240424, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00847 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "COMRes.dll"}, 1240424, ... ) }, 1240424, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00848 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\COMRes.dll"}, 1240424, ... ) }, 1240424, ... ) == 0x0 00849 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\COMRes.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00850 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 108, ) == 0x0 00851 432 NtQuerySection (108, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00852 432 NtClose (104, ... ) == 0x0 00853 432 NtMapViewOfSection (108, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77050000), 0x0, 806912, ) == 0x0 00854 432 NtClose (108, ... ) == 0x0 00855 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "VERSION.dll"}, ... 108, ) }, ... 108, ) == 0x0 00856 432 NtMapViewOfSection (108, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 28672, ) == 0x0 00857 432 NtClose (108, ... ) == 0x0 00858 432 NtOpenKey (0xf003f, {24, 48, 0x40, 0, 0, (0xf003f, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00859 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00860 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\OLE"}, ... 108, ) }, ... 108, ) == 0x0 00861 432 NtQueryValueKey (108, (108, "MinimumFreeMemPercentageToCreateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00862 432 NtQueryValueKey (108, (108, "MinimumFreeMemPercentageToCreateObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00863 432 NtClose (108, ... ) == 0x0 00864 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\Registration"}, 1241256, ... ) }, 1241256, ... ) == 0x0 00865 432 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00866 432 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 00867 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 108, ) }, ... 108, ) == 0x0 00868 432 NtQueryValueKey (108, (108, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (108, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00869 432 NtClose (108, ... ) == 0x0 00870 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Classes"}, ... 108, ) }, ... 108, ) == 0x0 00871 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 104, ) == 0x0 00872 432 NtNotifyChangeKey (108, 104, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00873 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 112, ) }, ... 112, ) == 0x0 00874 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 116, ) == 0x0 00875 432 NtNotifyChangeKey (112, 116, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00876 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 120, ) == 0x0 00877 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER"}, ... 124, ) }, ... 124, ) == 0x0 00878 432 NtSetInformationObject (124, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 00879 432 NtNotifyChangeKey (124, 120, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00880 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Classes"}, ... 128, ) }, ... 128, ) == 0x0 00881 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 132, ) == 0x0 00882 432 NtNotifyChangeKey (128, 132, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00883 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 136, ) == 0x0 00884 432 NtNotifyChangeKey (124, 136, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00885 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 140, ) }, ... 140, ) == 0x0 00886 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 144, ) == 0x0 00887 432 NtNotifyChangeKey (140, 144, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00888 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 148, ) }, ... 148, ) == 0x0 00889 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 152, ) == 0x0 00890 432 NtNotifyChangeKey (148, 152, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00891 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 156, ) }, ... 156, ) == 0x0 00892 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 160, ) == 0x0 00893 432 NtNotifyChangeKey (156, 160, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00894 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Classes"}, ... 164, ) }, ... 164, ) == 0x0 00895 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 168, ) == 0x0 00896 432 NtNotifyChangeKey (164, 168, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00897 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 172, ) }, ... 172, ) == 0x0 00898 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 176, ) == 0x0 00899 432 NtNotifyChangeKey (172, 176, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00900 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 180, ) == 0x0 00901 432 NtNotifyChangeKey (124, 180, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00902 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 184, ) }, ... 184, ) == 0x0 00903 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 188, ) == 0x0 00904 432 NtNotifyChangeKey (184, 188, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00905 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 192, ) }, ... 192, ) == 0x0 00906 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 196, ) == 0x0 00907 432 NtNotifyChangeKey (192, 196, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00908 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 200, ) }, ... 200, ) == 0x0 00909 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 204, ) == 0x0 00910 432 NtNotifyChangeKey (200, 204, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 00911 432 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00912 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 208, ) }, ... 208, ) == 0x0 00913 432 NtQueryValueKey (208, (208, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (208, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 00914 432 NtClose (208, ... ) == 0x0 00915 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00916 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00917 432 NtOpenSection (0x4, {24, 52, 0x0, 0, 0, (0x4, {24, 52, 0x0, 0, 0, "__R_000000000007_SMem__"}, ... 208, ) }, ... 208, ) == 0x0 00918 432 NtMapViewOfSection (208, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x3f0000), {0, 0}, 24576, ) == 0x0 00919 432 NtAllocateVirtualMemory (-1, 3297280, 0, 8192, 4096, 4, ... 3297280, 8192, ) == 0x0 00920 432 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00921 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 212, ) }, ... 212, ) == 0x0 00922 432 NtQueryValueKey (212, (212, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (212, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 00923 432 NtClose (212, ... ) == 0x0 00924 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00925 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00926 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 1, ... 10551296, 65536, ) == 0x0 00927 432 NtAllocateVirtualMemory (-1, 10551296, 0, 4096, 4096, 4, ... 10551296, 4096, ) == 0x0 00928 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00929 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 212, ) == 0x0 00930 432 NtQueryInformationToken (212, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00931 432 NtClose (212, ... ) == 0x0 00932 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes"}, ... 212, ) }, ... 212, ) == 0x0 00933 432 NtSetInformationObject (214, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00934 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 00935 432 NtOpenKey (0x20019, {24, 214, 0x40, 0, 0, (0x20019, {24, 214, 0x40, 0, 0, "CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00936 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... 216, ) }, ... 216, ) == 0x0 00937 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}0"}, 162, ) }, 162, ) == 0x0 00938 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00939 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00940 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00941 432 NtClose (220, ... ) == 0x0 00942 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00943 432 NtOpenKey (0x1, {24, 218, 0x40, 0, 0, (0x1, {24, 218, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00944 432 NtClose (218, ... ) == 0x0 00945 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 00946 432 NtOpenKey (0x20019, {24, 214, 0x40, 0, 0, (0x20019, {24, 214, 0x40, 0, 0, "CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00947 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... 216, ) }, ... 216, ) == 0x0 00948 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}0"}, 162, ) }, 162, ) == 0x0 00949 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00950 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00951 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00952 432 NtClose (220, ... ) == 0x0 00953 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00954 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocServer32"}, ... 220, ) }, ... 220, ) == 0x0 00955 432 NtQueryKey (222, Name, 392, ... {Name= (222, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, 192, ) }, 192, ) == 0x0 00956 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00957 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 224, ) == 0x0 00958 432 NtQueryInformationToken (224, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00959 432 NtClose (224, ... ) == 0x0 00960 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00961 432 NtQueryValueKey (222, (222, "InprocServer32", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00962 432 NtClose (222, ... ) == 0x0 00963 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 00964 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00965 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00966 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00967 432 NtClose (220, ... ) == 0x0 00968 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00969 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00970 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 00971 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00972 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00973 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00974 432 NtClose (220, ... ) == 0x0 00975 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00976 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00977 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 00978 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00979 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00980 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00981 432 NtClose (220, ... ) == 0x0 00982 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00983 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocServer32"}, ... 220, ) }, ... 220, ) == 0x0 00984 432 NtQueryKey (222, Name, 392, ... {Name= (222, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, 192, ) }, 192, ) == 0x0 00985 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00986 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 224, ) == 0x0 00987 432 NtQueryInformationToken (224, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00988 432 NtClose (224, ... ) == 0x0 00989 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00990 432 NtQueryValueKey (222, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (222, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="s\0h\0e\0l\0l\03\02\0.\0d\0l\0l\0\0\0"}, 36, ) }, 36, ) == 0x0 00991 432 NtClose (222, ... ) == 0x0 00992 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 00993 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00994 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 00995 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00996 432 NtClose (220, ... ) == 0x0 00997 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00998 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00999 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 01000 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01001 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 01002 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01003 432 NtClose (220, ... ) == 0x0 01004 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01005 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01006 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 01007 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01008 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 01009 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01010 432 NtClose (220, ... ) == 0x0 01011 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01012 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01013 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}_"}, 162, ) }, 162, ) == 0x0 01014 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01015 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 01016 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01017 432 NtClose (220, ... ) == 0x0 01018 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01019 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01020 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01021 432 NtOpenKey (0x20019, {24, 214, 0x40, 0, 0, (0x20019, {24, 214, 0x40, 0, 0, "CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01022 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... 220, ) }, ... 220, ) == 0x0 01023 432 NtQueryKey (222, Name, 392, ... {Name= (222, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}0"}, 162, ) }, 162, ) == 0x0 01024 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01025 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 224, ) == 0x0 01026 432 NtQueryInformationToken (224, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01027 432 NtClose (224, ... ) == 0x0 01028 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01029 432 NtQueryValueKey (222, (222, "AppID", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01030 432 NtClose (222, ... ) == 0x0 01031 432 NtClose (218, ... ) == 0x0 01032 432 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {424, 0}, ... 216, ) == 0x0 01033 432 NtQueryInformationProcess (216, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 01034 432 NtClose (216, ... ) == 0x0 01035 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01036 432 NtOpenKey (0x20019, {24, 214, 0x40, 0, 0, (0x20019, {24, 214, 0x40, 0, 0, "CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01037 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... 216, ) }, ... 216, ) == 0x0 01038 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}0"}, 162, ) }, 162, ) == 0x0 01039 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01040 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 01041 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01042 432 NtClose (220, ... ) == 0x0 01043 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01044 432 NtOpenKey (0x2000000, {24, 218, 0x40, 0, 0, (0x2000000, {24, 218, 0x40, 0, 0, "InprocServer32"}, ... 220, ) }, ... 220, ) == 0x0 01045 432 NtQueryKey (222, Name, 392, ... {Name= (222, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01046 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01047 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 224, ) == 0x0 01048 432 NtQueryInformationToken (224, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01049 432 NtClose (224, ... ) == 0x0 01050 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01051 432 NtQueryValueKey (222, (222, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0p\0a\0r\0t\0m\0e\0n\0t\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (222, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0p\0a\0r\0t\0m\0e\0n\0t\0\0\0"}, 32, ) }, 32, ) == 0x0 01052 432 NtClose (222, ... ) == 0x0 01053 432 NtClose (218, ... ) == 0x0 01054 432 NtAllocateVirtualMemory (-1, 1384448, 0, 8192, 4096, 4, ... 1384448, 8192, ) == 0x0 01055 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01056 432 NtOpenKey (0x20019, {24, 214, 0x40, 0, 0, (0x20019, {24, 214, 0x40, 0, 0, "CLSID\{00021401-0000-0000-C000-000000000046}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01057 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}"}, ... 216, ) }, ... 216, ) == 0x0 01058 432 NtQueryKey (218, Name, 384, ... {Name= (218, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}0"}, 162, ) }, 162, ) == 0x0 01059 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01060 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 01061 432 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01062 432 NtClose (220, ... ) == 0x0 01063 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01064 432 NtOpenKey (0x1, {24, 218, 0x40, 0, 0, (0x1, {24, 218, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01065 432 NtClose (218, ... ) == 0x0 01066 432 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 01067 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 216, ) == 0x0 01068 432 NtOpenFile (0x10080, {24, 0, 0x40, 0, 0, (0x10080, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\carlton"}, 7, 2113600, ... ) }, 7, 2113600, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01069 432 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1374944, 0, (0x1f0003, {24, 52, 0x80, 1374944, 0, "shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}"}, 0, 2147483647, ... 220, ) }, 0, 2147483647, ... 220, ) == STATUS_OBJECT_NAME_EXISTS 01070 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01071 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01072 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01073 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01074 432 NtQueryValueKey (224, (224, "NoNetHood", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01075 432 NtClose (224, ... ) == 0x0 01076 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01077 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01078 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01079 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01080 432 NtQueryValueKey (224, (224, "NoPropertiesMyComputer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01081 432 NtClose (224, ... ) == 0x0 01082 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01083 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01084 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01085 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01086 432 NtQueryValueKey (224, (224, "NoInternetIcon", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01087 432 NtClose (224, ... ) == 0x0 01088 432 NtOpenKey (0x9, {24, 48, 0x40, 0, 0, (0x9, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01089 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01090 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01091 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01092 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01093 432 NtQueryValueKey (224, (224, "NoCommonGroups", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01094 432 NtClose (224, ... ) == 0x0 01095 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01096 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01097 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01098 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01099 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01100 432 NtQueryValueKey (224, (224, "NoControlPanel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01101 432 NtClose (224, ... ) == 0x0 01102 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01103 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01104 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01105 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 224, ) }, ... 224, ) == 0x0 01106 432 NtQueryValueKey (224, (224, "NoSetFolders", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01107 432 NtClose (224, ... ) == 0x0 01108 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESi"}, 138, ) }, 138, ) == 0x0 01109 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01110 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... 224, ) }, ... 224, ) == 0x0 01111 432 NtQueryKey (226, Name, 392, ... {Name= (226, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01112 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01113 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 228, ) == 0x0 01114 432 NtQueryInformationToken (228, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01115 432 NtClose (228, ... ) == 0x0 01116 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01117 432 NtQueryValueKey (226, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (226, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0S\0H\0E\0L\0L\03\02\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01118 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1236316, ... ) }, 1236316, ... ) == 0x0 01119 432 NtClose (226, ... ) == 0x0 01120 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01121 432 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "_fCanRegisterWithShellService"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01122 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01123 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SETUPAPI.dll"}, 1237464, ... ) }, 1237464, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01124 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "SETUPAPI.dll"}, 1237464, ... ) }, 1237464, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01125 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SETUPAPI.dll"}, 1237464, ... ) }, 1237464, ... ) == 0x0 01126 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SETUPAPI.dll"}, 5, 96, ... 224, {status=0x0, info=1}, ) }, 5, 96, ... 224, {status=0x0, info=1}, ) == 0x0 01127 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 224, ... 228, ) == 0x0 01128 432 NtQuerySection (228, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01129 432 NtClose (224, ... ) == 0x0 01130 432 NtMapViewOfSection (228, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76670000), 0x0, 933888, ) == 0x0 01131 432 NtClose (228, ... ) == 0x0 01132 432 NtQueryDefaultLocale (1, 1237296, ... ) == 0x0 01133 432 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01134 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01135 432 NtQueryValueKey (228, (228, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01136 432 NtClose (228, ... ) == 0x0 01137 432 NtUserGetProcessWindowStation (... ) == 0x24 01138 432 NtUserGetObjectInformation (36, 1, 1236968, 12, 1236980, ... ) == 0x1 01139 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Control\Session Manager\WPA\PnP"}, ... 228, ) }, ... 228, ) == 0x0 01140 432 NtQueryValueKey (228, (228, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\345\252r\363"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\345\252r\363"}, 16, ) }, 16, ) == 0x0 01141 432 NtClose (228, ... ) == 0x0 01142 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "SYSTEM\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01143 432 NtQueryValueKey (228, (228, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 01144 432 NtQueryValueKey (228, (228, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 01145 432 NtClose (228, ... ) == 0x0 01146 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "SYSTEM\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01147 432 NtQueryValueKey (228, (228, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 01148 432 NtQueryValueKey (228, (228, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 01149 432 NtClose (228, ... ) == 0x0 01150 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01151 432 NtQueryValueKey (228, (228, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01152 432 NtQueryValueKey (228, (228, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01153 432 NtClose (228, ... ) == 0x0 01154 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01155 432 NtQueryValueKey (228, (228, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01156 432 NtQueryValueKey (228, (228, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (228, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01157 432 NtClose (228, ... ) == 0x0 01158 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 228, ) }, ... 228, ) == 0x0 01159 432 NtQueryValueKey (228, (228, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (228, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 01160 432 NtQueryValueKey (228, (228, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (228, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 01161 432 NtClose (228, ... ) == 0x0 01162 432 NtAllocateVirtualMemory (-1, 1396736, 0, 4096, 4096, 4, ... 1396736, 4096, ) == 0x0 01163 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 228, ) }, ... 228, ) == 0x0 01164 432 NtQueryValueKey (228, (228, "DevicePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (228, "DevicePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0\0\0"}, 46, ) }, 46, ) == 0x0 01165 432 NtClose (228, ... ) == 0x0 01166 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 228, ) == 0x0 01167 432 NtCreateMutant (0x1f0001, 0x0, 0, ... 224, ) == 0x0 01168 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 232, ) == 0x0 01169 432 NtCreateMutant (0x1f0001, 0x0, 0, ... 236, ) == 0x0 01170 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 240, ) == 0x0 01171 432 NtCreateMutant (0x1f0001, 0x0, 0, ... 244, ) == 0x0 01172 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 248, ) }, ... 248, ) == 0x0 01173 432 NtQueryValueKey (248, (248, "LogLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01174 432 NtQueryValueKey (248, (248, "LogPath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01175 432 NtOpenKey (0x1, {24, 248, 0x40, 0, 0, (0x1, {24, 248, 0x40, 0, 0, "AppLogLevels"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01176 432 NtClose (248, ... ) == 0x0 01177 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 1236888, ... ) }, 1236888, ... ) == 0x0 01178 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName"}, ... 248, ) }, ... 248, ) == 0x0 01179 432 NtQueryValueKey (248, (248, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (248, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (248, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 01180 432 NtClose (248, ... ) == 0x0 01181 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 248, ) }, ... 248, ) == 0x0 01182 432 NtQueryValueKey (248, (248, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (248, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) , Data= (248, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) }, 52, ) == 0x0 01183 432 NtClose (248, ... ) == 0x0 01184 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\System\DNSclient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01185 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 248, ) }, ... 248, ) == 0x0 01186 432 NtQueryValueKey (248, (248, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (248, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Data= (248, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) }, 34, ) == 0x0 01187 432 NtClose (248, ... ) == 0x0 01188 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01189 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01190 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 248, ) }, ... 248, ) == 0x0 01191 432 NtQueryValueKey (248, (248, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01192 432 NtClose (248, ... ) == 0x0 01193 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01194 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 248, ) == 0x0 01195 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 252, ) == 0x0 01196 432 NtQuerySystemTime (... {-129453690, 29889264}, ) == 0x0 01197 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 256, ) == 0x0 01198 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01199 432 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 01200 432 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 01201 432 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 01202 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 260, ) == 0x0 01203 432 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 264, ) == 0x0 01204 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 268, ) }, ... 268, ) == 0x0 01205 432 NtOpenKey (0x20019, {24, 268, 0x40, 0, 0, (0x20019, {24, 268, 0x40, 0, 0, "ActiveComputerName"}, ... 272, ) }, ... 272, ) == 0x0 01206 432 NtQueryValueKey (272, (272, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (272, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (272, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 01207 432 NtClose (272, ... ) == 0x0 01208 432 NtClose (268, ... ) == 0x0 01209 432 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 268, ) == 0x0 01210 432 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 272, ) == 0x0 01211 432 NtDuplicateObject (-1, 268, -1, 0x0, 0, 2, ... 276, ) == 0x0 01212 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01213 432 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 1400832, 4096, ) == 0x0 01214 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 280, ) == 0x0 01215 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01216 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01217 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1237668, (0xc0100080, {24, 0, 0x40, 0, 1237668, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 284, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 284, {status=0x0, info=1}, ) == 0x0 01218 432 NtSetInformationFile (284, 1237724, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 01219 432 NtSetInformationFile (284, 1237716, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 01220 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01221 432 NtWriteFile (284, 261, 0, 0, (284, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 01222 432 NtReadFile (284, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (284, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 01223 432 NtFsControlFile (284, 261, 0x0, 0x0, 0x11c017, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\351\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\351\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 01224 432 NtFsControlFile (284, 261, 0x0, 0x0, 0x11c017, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0j\0\0\0\2\0\0\0R\0\0\0\0\0\37\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305*\0,\0\14\344gv\26\0\0\0\0\0\0\0\25\0\0\0S\0e\0L\0o\0a\0d\0D\0r\0i\0v\0e\0r\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 106, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 106, 1024, ... {status=0x103, info=48}, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0j\0\0\0\2\0\0\0R\0\0\0\0\0\37\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305*\0,\0\14\344gv\26\0\0\0\0\0\0\0\25\0\0\0S\0e\0L\0o\0a\0d\0D\0r\0i\0v\0e\0r\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 106, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 01225 432 NtFsControlFile (284, 261, 0x0, 0x0, 0x11c017, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\12\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=36}, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\244\242\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\12\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 01226 432 NtClose (280, ... ) == 0x0 01227 432 NtClose (284, ... ) == 0x0 01228 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01229 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 284, ) == 0x0 01230 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01231 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01232 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1237668, (0xc0100080, {24, 0, 0x40, 0, 1237668, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 280, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 280, {status=0x0, info=1}, ) == 0x0 01233 432 NtSetInformationFile (280, 1237724, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 01234 432 NtSetInformationFile (280, 1237716, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 01235 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01236 432 NtWriteFile (280, 261, 0, 0, (280, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 01237 432 NtReadFile (280, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (280, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 01238 432 NtFsControlFile (280, 261, 0x0, 0x0, 0x11c017, (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\351\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\351\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336 \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 01239 432 NtFsControlFile (280, 261, 0x0, 0x0, 0x11c017, (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0b\0\0\0\2\0\0\0J\0\0\0\0\0\37\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305"\0$\0l\343gv\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 98, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \0$\0l\343gv\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0 (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0b\0\0\0\2\0\0\0J\0\0\0\0\0\37\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305"\0$\0l\343gv\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 98, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) == 0x103 01240 432 NtFsControlFile (280, 261, 0x0, 0x0, 0x11c017, (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=36}, (280, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\245\242\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 01241 432 NtClose (284, ... ) == 0x0 01242 432 NtClose (280, ... ) == 0x0 01243 432 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 01244 432 NtOpenProcessToken (-1, 0x20, ... 280, ) == 0x0 01245 432 NtAdjustPrivilegesToken (280, 0, 1400576, 0, 0, 0, ... ) == 0x0 01246 432 NtClose (280, ... ) == 0x0 01247 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01248 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 280, ) == 0x0 01249 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01250 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01251 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1237908, (0xc0100080, {24, 0, 0x40, 0, 1237908, "\??\PIPE\ntsvcs"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 284, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 284, {status=0x0, info=1}, ) == 0x0 01252 432 NtSetInformationFile (284, 1237964, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 01253 432 NtSetInformationFile (284, 1237956, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 01254 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01255 432 NtWriteFile (284, 261, 0, 0, (284, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 01256 432 NtReadFile (284, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (284, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\200"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x0 01257 432 NtFsControlFile (284, 261, 0x0, 0x0, 0x11c017, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\27\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0", 48, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\200"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 48, 1024, ... {status=0x103, info=68}, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\27\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0", 48, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\200"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x103 01258 432 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 01259 432 NtOpenProcessToken (-1, 0x20, ... 288, ) == 0x0 01260 432 NtAdjustPrivilegesToken (288, 0, 1401584, 0, 0, 0, ... ) == 0x0 01261 432 NtClose (288, ... ) == 0x0 01262 432 NtFsControlFile (284, 261, 0x0, 0x0, 0x11c017, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\04\0\0\0\2\0\0\0\34\0\0\0\0\0\26\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0S\1\0\0\0\0\0\0", 52, 1024, ... {status=0x103, info=32}, "\5\0\2\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\0\0S\1\0\0\0\0\0\0", ) , 52, 1024, ... {status=0x103, info=32}, (284, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\04\0\0\0\2\0\0\0\34\0\0\0\0\0\26\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0S\1\0\0\0\0\0\0", 52, 1024, ... {status=0x103, info=32}, "\5\0\2\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\0\0S\1\0\0\0\0\0\0", ) , ) == 0x103 01263 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 288, {status=0x0, info=1}, ) }, 3, 96, ... 288, {status=0x0, info=1}, ) == 0x0 01264 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 292, ) }, ... 292, ) == 0x0 01265 432 NtQuerySymbolicLinkObject (292, ... (292, ... "\Device\FloppyPDO0", 38, ) , 38, ) == 0x0 01266 432 NtClose (292, ... ) == 0x0 01267 432 NtQueryVolumeInformationFile (288, 1238368, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01268 432 NtClose (288, ... ) == 0x0 01269 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 288, {status=0x0, info=1}, ) }, 3, 16, ... 288, {status=0x0, info=1}, ) == 0x0 01270 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, "\36\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", ) , ) == 0x0 01271 432 NtClose (288, ... ) == 0x0 01272 432 NtQueryInformationFile (-1, 1238368, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01273 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238320, (0x100080, {24, 0, 0x40, 0, 1238320, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01274 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 32, ... , 54, 32, ... 01275 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01276 432 NtClose (-2147482032, ... ) == 0x0 01274 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01277 432 NtAllocateVirtualMemory (-1, 1404928, 0, 4096, 4096, 4, ... 1404928, 4096, ) == 0x0 01278 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 374, ... , 54, 374, ... 01279 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01280 432 NtClose (-2147482032, ... ) == 0x0 01278 432 NtDeviceIoControlFile ... {status=0x0, info=374}, ... {status=0x0, info=374}, "v\1\0\0\2\0\0\0\372\0\0\0`\0\0\08\0\0\0\244\0\0\0\334\0\0\0\36\0v\0Z\1\0\0\34\0\\08\0\0\0\244\0p\0\334\0\0\0\36\0\0\0\\0?\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0A\0:\0", ) , ) == 0x0 01281 432 NtClose (288, ... ) == 0x0 01282 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01283 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e6-a4ba-11db-9d02-806d6172696f}\"}, ... 292, ) }, ... 292, ) == 0x0 01284 432 NtClose (288, ... ) == 0x0 01285 432 NtQueryValueKey (292, (292, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01286 432 NtQueryValueKey (292, (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0\7\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0\7\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\10\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) , Partial, 712, ... TitleIdx=0, Type=3, Data= (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0\7\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0\7\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\10\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) }, 712, ) == 0x0 01287 432 NtClose (292, ... ) == 0x0 01288 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 292, ) }, ... 292, ) == 0x0 01289 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, (0x2000000, {24, 292, 0x40, 0, 0, "{1a0315e6-a4ba-11db-9d02-806d6172696f}\"}, ... 288, ) }, ... 288, ) == 0x0 01290 432 NtClose (292, ... ) == 0x0 01291 432 NtQueryValueKey (288, (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01292 432 NtClose (288, ... ) == 0x0 01293 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\IDE#CdRomTEAC_CD-224E-N__________________________1.AA____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 288, {status=0x0, info=0}, ) }, 3, 96, ... 288, {status=0x0, info=0}, ) == 0x0 01294 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\IDE#CdRomTEAC_CD-224E-N__________________________1.AA____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 292, ) }, ... 292, ) == 0x0 01295 432 NtQuerySymbolicLinkObject (292, ... (292, ... "\Device\Ide\IdeDeviceP1T0L0-e", 60, ) , 60, ) == 0x0 01296 432 NtClose (292, ... ) == 0x0 01297 432 NtQueryVolumeInformationFile (288, 1238368, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01298 432 NtClose (288, ... ) == 0x0 01299 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\IDE#CdRomTEAC_CD-224E-N__________________________1.AA____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 288, {status=0x0, info=0}, ) }, 3, 16, ... 288, {status=0x0, info=0}, ) == 0x0 01300 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=30}, (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=30}, "\34\0\\0D\0e\0v\0i\0c\0e\0\\0C\0d\0R\0o\0m\00\0", ) , ) == 0x0 01301 432 NtClose (288, ... ) == 0x0 01302 432 NtQueryInformationFile (-1, 1238368, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01303 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238320, (0x100080, {24, 0, 0x40, 0, 1238320, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01304 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\34\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0C\0d\0R\0o\0m\00\0", 52, 32, ... , 52, 32, ... 01305 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\CdRom0"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01306 432 NtClose (-2147482032, ... ) == 0x0 01304 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01307 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\34\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0C\0d\0R\0o\0m\00\0", 52, 490, ... , 52, 490, ... 01308 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\CdRom0"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01309 432 NtClose (-2147482032, ... ) == 0x0 01307 432 NtDeviceIoControlFile ... {status=0x0, info=490}, ... {status=0x0, info=490}, "\352\1\0\0\2\0\0\0n\1\0\0`\0\0\08\0\0\0\32\1\0\0R\1\0\0\34\0v\0\316\1\0\0\34\0\\08\0\0\0\32\1o\0R\1\0\0\34\0\0\0\\0?\0?\0\\0I\0D\0E\0#\0C\0d\0R\0o\0m\0T\0E\0A\0C\0_\0C\0D\0-\02\02\04\0E\0-\0N\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\01\0.\0A\0A\0_\0_\0_\0_\0#\03\00\03\01\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\01\03\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\\0D\0e\0v\0i\0c\0e\0\\0C\0d\0R\0o\0m\00\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0D\0:\0", ) , ) == 0x0 01310 432 NtClose (288, ... ) == 0x0 01311 432 NtAllocateVirtualMemory (-1, 1409024, 0, 4096, 4096, 4, ... 1409024, 4096, ) == 0x0 01312 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01313 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e7-a4ba-11db-9d02-806d6172696f}\"}, ... 292, ) }, ... 292, ) == 0x0 01314 432 NtClose (288, ... ) == 0x0 01315 432 NtQueryValueKey (292, (292, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01316 432 NtQueryValueKey (292, (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0I\0D\0E\0#\0C\0d\0R\0o\0m\0T\0E\0A\0C\0_\0C\0D\0-\02\02\04\0E\0-\0N\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\01\0.\0A\0A\0_\0_\0_\0_\0#\03\00\03\01\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\01\03\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0%\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0%\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0&\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) , Partial, 712, ... TitleIdx=0, Type=3, Data= (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0I\0D\0E\0#\0C\0d\0R\0o\0m\0T\0E\0A\0C\0_\0C\0D\0-\02\02\04\0E\0-\0N\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\0_\01\0.\0A\0A\0_\0_\0_\0_\0#\03\00\03\01\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\00\03\01\03\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0%\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0%\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0&\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) }, 712, ) == 0x0 01317 432 NtClose (292, ... ) == 0x0 01318 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 292, ) }, ... 292, ) == 0x0 01319 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, (0x2000000, {24, 292, 0x40, 0, 0, "{1a0315e7-a4ba-11db-9d02-806d6172696f}\"}, ... 288, ) }, ... 288, ) == 0x0 01320 432 NtClose (292, ... ) == 0x0 01321 432 NtQueryValueKey (288, (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01322 432 NtClose (288, ... ) == 0x0 01323 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&SignatureEF3BEF3BOffset7E00LengthBFB48200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 288, {status=0x0, info=0}, ) }, 3, 96, ... 288, {status=0x0, info=0}, ) == 0x0 01324 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&SignatureEF3BEF3BOffset7E00LengthBFB48200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 292, ) }, ... 292, ) == 0x0 01325 432 NtQuerySymbolicLinkObject (292, ... (292, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01326 432 NtClose (292, ... ) == 0x0 01327 432 NtQueryVolumeInformationFile (288, 1238368, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01328 432 NtClose (288, ... ) == 0x0 01329 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&SignatureEF3BEF3BOffset7E00LengthBFB48200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 288, {status=0x0, info=0}, ) }, 3, 16, ... 288, {status=0x0, info=0}, ) == 0x0 01330 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, (288, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, ".\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", ) , ) == 0x0 01331 432 NtClose (288, ... ) == 0x0 01332 432 NtQueryInformationFile (-1, 1238368, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01333 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238320, (0x100080, {24, 0, 0x40, 0, 1238320, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01334 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 32, ... , 70, 32, ... 01335 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01336 432 NtClose (-2147482032, ... ) == 0x0 01334 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01337 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0008, (288, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 238, ... , 70, 238, ... 01338 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01339 432 NtClose (-2147482032, ... ) == 0x0 01337 432 NtDeviceIoControlFile ... {status=0x0, info=238}, ... {status=0x0, info=238}, "\356\0\0\0\2\0\0\0r\0\0\0`\0\0\08\0\0\0\14\0\0\0D\0\0\0.\0v\0\322\0\0\0\34\0\\08\0\0\0\14\0d\0D\0\0\0.\0k\0;\357;\357\0~\0\0\0\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0C\0:\0", ) , ) == 0x0 01340 432 NtClose (288, ... ) == 0x0 01341 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01342 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 292, ) }, ... 292, ) == 0x0 01343 432 NtClose (288, ... ) == 0x0 01344 432 NtQueryValueKey (292, (292, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01345 432 NtQueryValueKey (292, (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\0E\0F\03\0B\0E\0F\03\0B\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\0B\0F\0B\04\08\02\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0B\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0B\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0C\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) , Partial, 712, ... TitleIdx=0, Type=3, Data= (292, "Data", Partial, 712, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\0E\0F\03\0B\0E\0F\03\0B\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\0B\0F\0B\04\08\02\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\0\0\0\0\0\310\2\0\0B\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0$\1\0\0B\5\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0C\5\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0<\0\0\0T\345\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\220\345\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0"}, 712, ) }, 712, ) == 0x0 01346 432 NtClose (292, ... ) == 0x0 01347 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 292, ) }, ... 292, ) == 0x0 01348 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, (0x2000000, {24, 292, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 288, ) }, ... 288, ) == 0x0 01349 432 NtClose (292, ... ) == 0x0 01350 432 NtQueryValueKey (288, (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (288, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01351 432 NtClose (288, ... ) == 0x0 01352 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01353 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01354 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01355 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e9-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01356 432 NtClose (-2147482032, ... ) == 0x0 01354 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01357 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01358 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e9-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01359 432 NtClose (-2147482032, ... ) == 0x0 01357 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01360 432 NtClose (288, ... ) == 0x0 01361 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01362 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01363 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01364 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e9-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01365 432 NtClose (-2147482032, ... ) == 0x0 01363 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01366 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\09\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01367 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e9-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01368 432 NtClose (-2147482032, ... ) == 0x0 01366 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01369 432 NtClose (288, ... ) == 0x0 01370 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, 0, 0x0, 0, ... 288, 2, ) }, 0, 0x0, 0, ... 288, 2, ) == 0x0 01371 432 NtSetValueKey (288, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01372 432 NtClose (288, ... ) == 0x0 01373 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\C\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01374 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01375 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\C\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01376 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\C\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01377 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\C\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01378 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01379 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\C\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01380 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\C\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01381 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01382 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01383 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01384 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e7-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01385 432 NtClose (-2147482032, ... ) == 0x0 01383 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01386 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01387 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e7-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01388 432 NtClose (-2147482032, ... ) == 0x0 01386 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0D\0:\0\0\0\0\0", ) , ) == 0x0 01389 432 NtClose (288, ... ) == 0x0 01390 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01391 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01392 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01393 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e7-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01394 432 NtClose (-2147482032, ... ) == 0x0 01392 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01395 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\07\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01396 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e7-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=0}, ) }, 0, 64, ... -2147482032, {status=0x0, info=0}, ) == 0x0 01397 432 NtClose (-2147482032, ... ) == 0x0 01395 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0D\0:\0\0\0\0\0", ) , ) == 0x0 01398 432 NtClose (288, ... ) == 0x0 01399 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a0315e7-a4ba-11db-9d02-806d6172696f}\"}, 0, 0x0, 0, ... 288, 2, ) }, 0, 0x0, 0, ... 288, 2, ) == 0x0 01400 432 NtSetValueKey (288, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01401 432 NtClose (288, ... ) == 0x0 01402 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\D\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01403 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01404 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\D\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01405 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\D\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01406 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\D\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01407 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01408 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\D\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01409 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\D\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01410 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01411 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01412 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01413 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e6-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01414 432 NtClose (-2147482032, ... ) == 0x0 01412 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01415 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01416 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e6-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01417 432 NtClose (-2147482032, ... ) == 0x0 01415 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01418 432 NtClose (288, ... ) == 0x0 01419 432 NtQueryInformationFile (-1, 1239572, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01420 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239524, (0x100080, {24, 0, 0x40, 0, 1239524, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01421 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01422 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e6-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01423 432 NtClose (-2147482032, ... ) == 0x0 01421 432 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01424 432 NtDeviceIoControlFile (288, 0, 0x0, 0x0, 0x6d0034, (288, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\01\0a\00\03\01\05\0e\06\0-\0a\04\0b\0a\0-\01\01\0d\0b\0-\09\0d\00\02\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01425 432 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{1a0315e6-a4ba-11db-9d02-806d6172696f}"}, 0, 64, ... -2147482032, {status=0x0, info=1}, ) }, 0, 64, ... -2147482032, {status=0x0, info=1}, ) == 0x0 01426 432 NtClose (-2147482032, ... ) == 0x0 01424 432 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01427 432 NtClose (288, ... ) == 0x0 01428 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a0315e6-a4ba-11db-9d02-806d6172696f}\"}, 0, 0x0, 0, ... 288, 2, ) }, 0, 0x0, 0, ... 288, 2, ) == 0x0 01429 432 NtSetValueKey (288, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (288, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01430 432 NtClose (288, ... ) == 0x0 01431 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\A\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01432 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01433 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\A\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01434 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\A\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01435 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\A\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01436 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01437 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Applications\Explorer.exe\Drives\A\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01438 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\A\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01439 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01440 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01441 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\F:"}, 3, 96, ... 288, {status=0x0, info=1}, ) }, 3, 96, ... 288, {status=0x0, info=1}, ) == 0x0 01442 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\F:"}, ... 292, ) }, ... 292, ) == 0x0 01443 432 NtQuerySymbolicLinkObject (292, ... (292, ... "\Device\WinDfs\F:00000000000091ce", 66, ) , 66, ) == 0x0 01444 432 NtClose (292, ... ) == 0x0 01445 432 NtQueryVolumeInformationFile (288, 1239616, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01446 432 NtClose (288, ... ) == 0x0 01447 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01448 432 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 288, {status=0x0, info=1}, ) }, 3, 96, ... 288, {status=0x0, info=1}, ) == 0x0 01449 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 292, ) }, ... 292, ) == 0x0 01450 432 NtQuerySymbolicLinkObject (292, ... (292, ... "\Device\WinDfs\U:00000000000091ce", 66, ) , 66, ) == 0x0 01451 432 NtClose (292, ... ) == 0x0 01452 432 NtQueryVolumeInformationFile (288, 1239616, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01453 432 NtClose (288, ... ) == 0x0 01454 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01455 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01456 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 292, ) }, ... 292, ) == 0x0 01457 432 NtClose (288, ... ) == 0x0 01458 432 NtQueryValueKey (292, (292, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (292, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01459 432 NtClose (292, ... ) == 0x0 01460 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01461 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01462 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 292, ) }, ... 292, ) == 0x0 01463 432 NtQueryKey (294, Name, 392, ... {Name= (294, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 01464 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01465 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 01466 432 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01467 432 NtClose (288, ... ) == 0x0 01468 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01469 432 NtEnumerateKey (294, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name= (294, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 01470 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01471 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01472 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 288, ) }, ... 288, ) == 0x0 01473 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 01474 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01475 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 296, ) == 0x0 01476 432 NtQueryInformationToken (296, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01477 432 NtClose (296, ... ) == 0x0 01478 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01479 432 NtQueryValueKey (290, (290, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (290, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 01480 432 NtClose (290, ... ) == 0x0 01481 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01482 432 NtEnumerateKey (294, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 01483 432 NtClose (294, ... ) == 0x0 01484 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 292, {status=0x0, info=1}, ) }, 3, 16417, ... 292, {status=0x0, info=1}, ) == 0x0 01485 432 NtQueryDirectoryFile (292, 0, 0, 0, 1237808, 616, BothDirectory, 1, (292, 0, 0, 0, 1237808, 616, BothDirectory, 1, "Program Files", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 01486 432 NtClose (292, ... ) == 0x0 01487 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01488 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01489 432 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 01490 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1233180, ... ) }, 1233180, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01491 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01492 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01493 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01494 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01495 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1233152, ... ) }, 1233152, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01496 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01497 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01498 432 NtAllocateVirtualMemory (-1, 1413120, 0, 4096, 4096, 4, ... 1413120, 4096, ) == 0x0 01499 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01500 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01501 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1233516, ... ) }, 1233516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01502 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01503 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01504 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01505 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01506 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1233516, ... ) }, 1233516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01507 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01508 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01509 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01510 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01511 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1233516, ... ) }, 1233516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01512 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01513 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01514 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01515 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01516 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Directory"}, ... 292, ) }, ... 292, ) == 0x0 01517 432 NtQueryKey (294, Name, 384, ... {Name= (294, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01518 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01519 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 01520 432 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01521 432 NtClose (288, ... ) == 0x0 01522 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01523 432 NtOpenKey (0x1, {24, 294, 0x40, 0, 0, (0x1, {24, 294, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01524 432 NtQueryKey (294, Name, 384, ... {Name= (294, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01525 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01526 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 01527 432 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01528 432 NtClose (288, ... ) == 0x0 01529 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01530 432 NtOpenKey (0x2000000, {24, 294, 0x40, 0, 0, ""}, ... 288, ) == 0x0 01531 432 NtClose (294, ... ) == 0x0 01532 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01533 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01534 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01535 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 292, ) }, ... 292, ) == 0x0 01536 432 NtQueryValueKey (292, (292, "DontShowSuperHidden", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01537 432 NtClose (292, ... ) == 0x0 01538 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01539 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 292, ) }, ... 292, ) == 0x0 01540 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, ""}, ... 296, ) == 0x0 01541 432 NtQueryValueKey (296, (296, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (296, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 01542 432 NtQueryValueKey (296, (296, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (296, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 01543 432 NtClose (296, ... ) == 0x0 01544 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01545 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01546 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01547 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01548 432 NtQueryValueKey (296, (296, "ForceActiveDesktopOn", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01549 432 NtClose (296, ... ) == 0x0 01550 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01551 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01552 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01553 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01554 432 NtQueryValueKey (296, (296, "NoActiveDesktop", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01555 432 NtClose (296, ... ) == 0x0 01556 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01557 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01558 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01559 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01560 432 NtQueryValueKey (296, (296, "NoWebView", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01561 432 NtClose (296, ... ) == 0x0 01562 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01563 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01564 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01565 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01566 432 NtQueryValueKey (296, (296, "ClassicShell", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01567 432 NtClose (296, ... ) == 0x0 01568 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01569 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01570 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01571 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01572 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01573 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01574 432 NtQueryValueKey (296, (296, "SeparateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01575 432 NtClose (296, ... ) == 0x0 01576 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01577 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01578 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01579 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01580 432 NtQueryValueKey (296, (296, "NoNetCrawling", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01581 432 NtClose (296, ... ) == 0x0 01582 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01583 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01584 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01585 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 296, ) }, ... 296, ) == 0x0 01586 432 NtQueryValueKey (296, (296, "NoSimpleStartMenu", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01587 432 NtClose (296, ... ) == 0x0 01588 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01589 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01590 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01591 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, (0x2000000, {24, 292, 0x40, 0, 0, "Advanced"}, ... 296, ) }, ... 296, ) == 0x0 01592 432 NtQueryValueKey (296, (296, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\2\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\2\0\0\0"}, 16, ) }, 16, ) == 0x0 01593 432 NtQueryValueKey (296, (296, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01594 432 NtQueryValueKey (296, (296, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01595 432 NtQueryValueKey (296, (296, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01596 432 NtQueryValueKey (296, (296, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01597 432 NtQueryValueKey (296, (296, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01598 432 NtQueryValueKey (296, (296, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01599 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 01600 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 01601 432 NtQueryValueKey (296, (296, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01602 432 NtQueryValueKey (296, (296, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01603 432 NtQueryValueKey (296, (296, "ShowSuperHidden", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01604 432 NtQueryValueKey (296, (296, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (296, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01605 432 NtQueryValueKey (296, (296, "NoNetCrawling", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01606 432 NtClose (296, ... ) == 0x0 01607 432 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1374944, 0, (0x1f0003, {24, 52, 0x80, 1374944, 0, "shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57}"}, 0, 2147483647, ... 296, ) }, 0, 2147483647, ... 296, ) == STATUS_OBJECT_NAME_EXISTS 01608 432 NtReleaseSemaphore (296, 1, ... 0, ) == 0x0 01609 432 NtWaitForSingleObject (296, 0, {0, 0}, ... ) == 0x0 01610 432 NtQueryKey (290, Name, 384, ... {Name= (290, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01611 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01612 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 300, ) == 0x0 01613 432 NtQueryInformationToken (300, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01614 432 NtClose (300, ... ) == 0x0 01615 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01616 432 NtOpenKey (0x1, {24, 290, 0x40, 0, 0, (0x1, {24, 290, 0x40, 0, 0, "ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01617 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01618 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01619 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 300, ) == 0x0 01620 432 NtQueryInformationToken (300, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01621 432 NtClose (300, ... ) == 0x0 01622 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01623 432 NtQueryValueKey (290, (290, "DocObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01624 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01625 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01626 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 300, ) == 0x0 01627 432 NtQueryInformationToken (300, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01628 432 NtClose (300, ... ) == 0x0 01629 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01630 432 NtQueryValueKey (290, (290, "BrowseInPlace", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01631 432 NtQueryKey (290, Name, 384, ... {Name= (290, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01632 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01633 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 300, ) == 0x0 01634 432 NtQueryInformationToken (300, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01635 432 NtClose (300, ... ) == 0x0 01636 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01637 432 NtOpenKey (0x1, {24, 290, 0x40, 0, 0, (0x1, {24, 290, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01638 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01639 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Folder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01640 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Folder"}, ... 300, ) }, ... 300, ) == 0x0 01641 432 NtQueryKey (302, Name, 384, ... {Name= (302, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Foldert"}, 86, ) }, 86, ) == 0x0 01642 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01643 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 01644 432 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01645 432 NtClose (304, ... ) == 0x0 01646 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Folder\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01647 432 NtOpenKey (0x1, {24, 302, 0x40, 0, 0, (0x1, {24, 302, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01648 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01649 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01650 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 01651 432 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01652 432 NtClose (304, ... ) == 0x0 01653 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01654 432 NtQueryValueKey (290, (290, "IsShortcut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01655 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01656 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01657 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 01658 432 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01659 432 NtClose (304, ... ) == 0x0 01660 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01661 432 NtQueryValueKey (290, (290, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (290, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01662 432 NtQueryKey (290, Name, 392, ... {Name= (290, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 01663 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01664 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 01665 432 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01666 432 NtClose (304, ... ) == 0x0 01667 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01668 432 NtQueryValueKey (290, (290, "NeverShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01669 432 NtClose (290, ... ) == 0x0 01670 432 NtClose (302, ... ) == 0x0 01671 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01672 432 NtQueryDirectoryFile (300, 0, 0, 0, 1237696, 616, BothDirectory, 1, (300, 0, 0, 0, 1237696, 616, BothDirectory, 1, "Common Files", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 01673 432 NtClose (300, ... ) == 0x0 01674 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01675 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01676 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1234612, ... ) }, 1234612, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01677 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01678 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01679 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01680 432 NtQueryDirectoryFile (300, 0, 0, 0, 1237612, 616, BothDirectory, 1, (300, 0, 0, 0, 1237612, 616, BothDirectory, 1, "Carlson", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01681 432 NtClose (300, ... ) == 0x0 01682 432 NtAllocateVirtualMemory (-1, 1417216, 0, 4096, 4096, 4, ... 1417216, 4096, ) == 0x0 01683 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\Common Files\Carlson\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01684 432 NtQueryDirectoryFile (300, 0, 0, 0, 1237544, 616, BothDirectory, 1, (300, 0, 0, 0, 1237544, 616, BothDirectory, 1, "carlton", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01685 432 NtClose (300, ... ) == 0x0 01686 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01687 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01688 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01689 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01690 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01691 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01692 432 NtQueryValueKey (300, (300, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (300, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) }, 66, ) == 0x0 01693 432 NtClose (300, ... ) == 0x0 01694 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents"}, 1238552, ... ) }, 1238552, ... ) == 0x0 01695 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01696 432 NtSetValueKey (300, (300, "Personal", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 96, ... ) , 0, 1, (300, "Personal", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 96, ... ) , 96, ... ) == 0x0 01697 432 NtClose (300, ... ) == 0x0 01698 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1236964, ... ) }, 1236964, ... ) == 0x0 01699 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 300, {status=0x0, info=1}, ) }, 5, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01700 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 300, ... 288, ) == 0x0 01701 432 NtClose (300, ... ) == 0x0 01702 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa20000), 0x0, 262144, ) == 0x0 01703 432 NtClose (288, ... ) == 0x0 01704 432 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01705 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01706 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01707 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01708 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 300, ) }, ... 300, ) == 0x0 01709 432 NtClose (288, ... ) == 0x0 01710 432 NtQueryValueKey (300, (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01711 432 NtClose (300, ... ) == 0x0 01712 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01713 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236868, 616, BothDirectory, 1, (300, 0, 0, 0, 1236868, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 01714 432 NtClose (300, ... ) == 0x0 01715 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01716 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236772, 616, BothDirectory, 1, (300, 0, 0, 0, 1236772, 616, BothDirectory, 1, "SRI-user", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01717 432 NtClose (300, ... ) == 0x0 01718 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01719 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236692, 616, BothDirectory, 1, (300, 0, 0, 0, 1236692, 616, BothDirectory, 1, "My Documents", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 01720 432 NtClose (300, ... ) == 0x0 01721 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01722 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01723 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1232064, ... ) }, 1232064, ... ) == 0x0 01724 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01725 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01726 432 NtAllocateVirtualMemory (-1, 1421312, 0, 4096, 4096, 4, ... 1421312, 4096, ) == 0x0 01727 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01728 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01729 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01730 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01731 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01732 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01733 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01734 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01735 432 NtClose (300, ... ) == 0x0 01736 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01737 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01738 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01739 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01740 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01741 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01742 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01743 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01744 432 NtClose (300, ... ) == 0x0 01745 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01746 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01747 432 NtClose (300, ... ) == 0x0 01748 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01749 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01750 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1232064, ... ) }, 1232064, ... ) == 0x0 01751 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01752 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01753 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01754 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01755 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01756 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01757 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01758 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01759 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01760 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01761 432 NtClose (300, ... ) == 0x0 01762 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01763 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01764 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01765 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01766 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01767 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01768 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01769 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01770 432 NtClose (300, ... ) == 0x0 01771 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01772 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01773 432 NtClose (300, ... ) == 0x0 01774 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01775 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01776 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234120, ... ) }, 1234120, ... ) == 0x0 01777 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01778 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01779 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01780 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01781 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01782 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01783 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01784 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01785 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01786 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01787 432 NtClose (300, ... ) == 0x0 01788 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01789 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01790 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1232400, ... ) }, 1232400, ... ) == 0x0 01791 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01792 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01793 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01794 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01795 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01796 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01797 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01798 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01799 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01800 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01801 432 NtClose (300, ... ) == 0x0 01802 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01803 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01804 432 NtClose (300, ... ) == 0x0 01805 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01806 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01807 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1232400, ... ) }, 1232400, ... ) == 0x0 01808 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01809 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01810 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01811 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01812 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01813 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01814 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01815 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01816 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01817 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01818 432 NtClose (300, ... ) == 0x0 01819 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01820 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01821 432 NtClose (300, ... ) == 0x0 01822 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01823 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01824 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1232400, ... ) }, 1232400, ... ) == 0x0 01825 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01826 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01827 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01828 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01829 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01830 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 10616832, 1052672, ) == 0x0 01831 432 NtAllocateVirtualMemory (-1, 10616832, 0, 83, 4096, 4, ... 10616832, 4096, ) == 0x0 01832 432 NtReadFile (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (300, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 01833 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01834 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01835 432 NtClose (300, ... ) == 0x0 01836 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01837 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01838 432 NtClose (300, ... ) == 0x0 01839 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01840 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01841 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01842 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01843 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01844 432 NtQueryValueKey (300, (300, "Common Documents", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (300, "Common Documents", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 01845 432 NtClose (300, ... ) == 0x0 01846 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents"}, 1238552, ... ) }, 1238552, ... ) == 0x0 01847 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01848 432 NtSetValueKey (300, (300, "Common Documents", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 92, ... ) , 0, 1, (300, "Common Documents", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 92, ... ) , 92, ... ) == 0x0 01849 432 NtClose (300, ... ) == 0x0 01850 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1236964, ... ) }, 1236964, ... ) == 0x0 01851 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 300, {status=0x0, info=1}, ) }, 5, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01852 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 300, ... 288, ) == 0x0 01853 432 NtClose (300, ... ) == 0x0 01854 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa20000), 0x0, 262144, ) == 0x0 01855 432 NtClose (288, ... ) == 0x0 01856 432 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01857 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01858 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01859 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01860 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 300, ) }, ... 300, ) == 0x0 01861 432 NtClose (288, ... ) == 0x0 01862 432 NtQueryValueKey (300, (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01863 432 NtClose (300, ... ) == 0x0 01864 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01865 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236872, 616, BothDirectory, 1, (300, 0, 0, 0, 1236872, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 01866 432 NtClose (300, ... ) == 0x0 01867 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01868 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236780, 616, BothDirectory, 1, (300, 0, 0, 0, 1236780, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01869 432 NtClose (300, ... ) == 0x0 01870 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01871 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236708, 616, BothDirectory, 1, (300, 0, 0, 0, 1236708, 616, BothDirectory, 1, "Documents", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01872 432 NtClose (300, ... ) == 0x0 01873 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01874 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01875 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1232080, ... ) }, 1232080, ... ) == 0x0 01876 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01877 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01878 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01879 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01880 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01881 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 10616832, 1052672, ) == 0x0 01882 432 NtAllocateVirtualMemory (-1, 10616832, 0, 142, 4096, 4, ... 10616832, 4096, ) == 0x0 01883 432 NtReadFile (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 01884 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01885 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01886 432 NtClose (300, ... ) == 0x0 01887 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01888 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01889 432 NtClose (300, ... ) == 0x0 01890 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01891 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01892 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1232052, ... ) }, 1232052, ... ) == 0x0 01893 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01894 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01895 432 NtAllocateVirtualMemory (-1, 1425408, 0, 4096, 4096, 4, ... 1425408, 4096, ) == 0x0 01896 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01897 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01898 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01899 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 10616832, 1052672, ) == 0x0 01900 432 NtAllocateVirtualMemory (-1, 10616832, 0, 142, 4096, 4, ... 10616832, 4096, ) == 0x0 01901 432 NtReadFile (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 01902 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01903 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01904 432 NtClose (300, ... ) == 0x0 01905 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01906 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01907 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1232416, ... ) }, 1232416, ... ) == 0x0 01908 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01909 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01910 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01911 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01912 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01913 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 10616832, 1052672, ) == 0x0 01914 432 NtAllocateVirtualMemory (-1, 10616832, 0, 142, 4096, 4, ... 10616832, 4096, ) == 0x0 01915 432 NtReadFile (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 01916 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01917 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01918 432 NtClose (300, ... ) == 0x0 01919 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01920 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01921 432 NtClose (300, ... ) == 0x0 01922 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01923 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01924 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1232416, ... ) }, 1232416, ... ) == 0x0 01925 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01926 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01927 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01928 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01929 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01930 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 10616832, 1052672, ) == 0x0 01931 432 NtAllocateVirtualMemory (-1, 10616832, 0, 142, 4096, 4, ... 10616832, 4096, ) == 0x0 01932 432 NtReadFile (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 01933 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01934 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01935 432 NtClose (300, ... ) == 0x0 01936 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01937 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01938 432 NtClose (300, ... ) == 0x0 01939 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01940 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01941 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1232416, ... ) }, 1232416, ... ) == 0x0 01942 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01943 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01944 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 300, {status=0x0, info=1}, ) }, 7, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01945 432 NtLockFile (300, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 01946 432 NtQueryInformationFile (300, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01947 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 10616832, 1052672, ) == 0x0 01948 432 NtAllocateVirtualMemory (-1, 10616832, 0, 142, 4096, 4, ... 10616832, 4096, ) == 0x0 01949 432 NtReadFile (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (300, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 01950 432 NtFreeVirtualMemory (-1, (0xa20000), 1052672, 32768, ... (0xa20000), 1052672, ) == 0x0 01951 432 NtUnlockFile (300, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 01952 432 NtClose (300, ... ) == 0x0 01953 432 NtOpenProcessToken (-1, 0x8, ... 300, ) == 0x0 01954 432 NtQueryInformationToken (300, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01955 432 NtClose (300, ... ) == 0x0 01956 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01957 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01958 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01959 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01960 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01961 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01962 432 NtQueryValueKey (300, (300, "Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (300, "Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 56, ) }, 56, ) == 0x0 01963 432 NtClose (300, ... ) == 0x0 01964 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Desktop"}, 1238552, ... ) }, 1238552, ... ) == 0x0 01965 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01966 432 NtSetValueKey (300, (300, "Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 86, ... ) , 0, 1, (300, "Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 86, ... ) , 86, ... ) == 0x0 01967 432 NtClose (300, ... ) == 0x0 01968 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1236964, ... ) }, 1236964, ... ) == 0x0 01969 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 300, {status=0x0, info=1}, ) }, 5, 96, ... 300, {status=0x0, info=1}, ) == 0x0 01970 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 300, ... 288, ) == 0x0 01971 432 NtClose (300, ... ) == 0x0 01972 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa20000), 0x0, 262144, ) == 0x0 01973 432 NtClose (288, ... ) == 0x0 01974 432 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01975 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01976 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01977 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 01978 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 300, ) }, ... 300, ) == 0x0 01979 432 NtClose (288, ... ) == 0x0 01980 432 NtQueryValueKey (300, (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01981 432 NtClose (300, ... ) == 0x0 01982 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01983 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236880, 616, BothDirectory, 1, (300, 0, 0, 0, 1236880, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 01984 432 NtClose (300, ... ) == 0x0 01985 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01986 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236792, 616, BothDirectory, 1, (300, 0, 0, 0, 1236792, 616, BothDirectory, 1, "SRI-user", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01987 432 NtClose (300, ... ) == 0x0 01988 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 01989 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236724, 616, BothDirectory, 1, (300, 0, 0, 0, 1236724, 616, BothDirectory, 1, "Desktop", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01990 432 NtClose (300, ... ) == 0x0 01991 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01992 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01993 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 01994 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 01995 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 01996 432 NtQueryValueKey (300, (300, "Common Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (300, "Common Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 64, ) }, 64, ) == 0x0 01997 432 NtClose (300, ... ) == 0x0 01998 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Desktop"}, 1238552, ... ) }, 1238552, ... ) == 0x0 01999 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 300, 2, ) }, 0, 0x0, 0, ... 300, 2, ) == 0x0 02000 432 NtSetValueKey (300, (300, "Common Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 88, ... ) , 0, 1, (300, "Common Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 88, ... ) , 88, ... ) == 0x0 02001 432 NtClose (300, ... ) == 0x0 02002 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1236964, ... ) }, 1236964, ... ) == 0x0 02003 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 300, {status=0x0, info=1}, ) }, 5, 96, ... 300, {status=0x0, info=1}, ) == 0x0 02004 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 300, ... 288, ) == 0x0 02005 432 NtClose (300, ... ) == 0x0 02006 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa20000), 0x0, 262144, ) == 0x0 02007 432 NtClose (288, ... ) == 0x0 02008 432 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 02009 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02010 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02011 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 288, ) }, ... 288, ) == 0x0 02012 432 NtOpenKey (0x2000000, {24, 288, 0x40, 0, 0, (0x2000000, {24, 288, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 300, ) }, ... 300, ) == 0x0 02013 432 NtClose (288, ... ) == 0x0 02014 432 NtQueryValueKey (300, (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (300, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02015 432 NtClose (300, ... ) == 0x0 02016 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 02017 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236876, 616, BothDirectory, 1, (300, 0, 0, 0, 1236876, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02018 432 NtClose (300, ... ) == 0x0 02019 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 02020 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236788, 616, BothDirectory, 1, (300, 0, 0, 0, 1236788, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02021 432 NtClose (300, ... ) == 0x0 02022 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 300, {status=0x0, info=1}, ) }, 3, 16417, ... 300, {status=0x0, info=1}, ) == 0x0 02023 432 NtQueryDirectoryFile (300, 0, 0, 0, 1236720, 616, BothDirectory, 1, (300, 0, 0, 0, 1236720, 616, BothDirectory, 1, "Desktop", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02024 432 NtClose (300, ... ) == 0x0 02025 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02026 432 NtOpenKey (0x2000000, {24, 292, 0x40, 0, 0, (0x2000000, {24, 292, 0x40, 0, 0, "FileExts"}, ... 300, ) }, ... 300, ) == 0x0 02027 432 NtOpenKey (0x2000000, {24, 300, 0x40, 0, 0, (0x2000000, {24, 300, 0x40, 0, 0, "."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02028 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02029 432 NtOpenKey (0x2000000, {24, 300, 0x40, 0, 0, (0x2000000, {24, 300, 0x40, 0, 0, "."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02030 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02031 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02032 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02033 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 02034 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 02035 432 NtReleaseSemaphore (296, 1, ... 0, ) == 0x0 02036 432 NtWaitForSingleObject (296, 0, {0, 0}, ... ) == 0x0 02037 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02038 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "SystemFileAssociations\."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02039 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\SystemFileAssociations\."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02040 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESs"}, 138, ) }, 138, ) == 0x0 02041 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02042 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\."}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02043 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "LINKINFO.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02044 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\LINKINFO.dll"}, 1238172, ... ) }, 1238172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02045 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "LINKINFO.dll"}, 1238172, ... ) }, 1238172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02046 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\LINKINFO.dll"}, 1238172, ... ) }, 1238172, ... ) == 0x0 02047 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\LINKINFO.dll"}, 5, 96, ... 288, {status=0x0, info=1}, ) }, 5, 96, ... 288, {status=0x0, info=1}, ) == 0x0 02048 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 288, ... 304, ) == 0x0 02049 432 NtQuerySection (304, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02050 432 NtClose (288, ... ) == 0x0 02051 432 NtMapViewOfSection (304, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76980000), 0x0, 28672, ) == 0x0 02052 432 NtClose (304, ... ) == 0x0 02053 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02054 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02055 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02056 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 10616832, 65536, ) == 0x0 02057 432 NtAllocateVirtualMemory (-1, 10616832, 0, 4096, 4096, 4, ... 10616832, 4096, ) == 0x0 02058 432 NtAllocateVirtualMemory (-1, 10620928, 0, 8192, 4096, 4, ... 10620928, 8192, ) == 0x0 02059 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESs"}, 138, ) }, 138, ) == 0x0 02060 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Network\SharingHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02061 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Network\SharingHandler"}, ... 304, ) }, ... 304, ) == 0x0 02062 432 NtQueryKey (306, Name, 392, ... {Name= (306, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Network\SharingHandlert"}, 118, ) }, 118, ) == 0x0 02063 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02064 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 02065 432 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02066 432 NtClose (288, ... ) == 0x0 02067 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Network\SharingHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02068 432 NtQueryValueKey (306, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (306, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="n\0t\0s\0h\0r\0u\0i\0.\0d\0l\0l\0\0\0"}, 36, ) }, 36, ) == 0x0 02069 432 NtClose (306, ... ) == 0x0 02070 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ntshrui.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02071 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ntshrui.dll"}, 1235868, ... ) }, 1235868, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02072 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ntshrui.dll"}, 1235868, ... ) }, 1235868, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02073 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntshrui.dll"}, 1235868, ... ) }, 1235868, ... ) == 0x0 02074 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntshrui.dll"}, 5, 96, ... 304, {status=0x0, info=1}, ) }, 5, 96, ... 304, {status=0x0, info=1}, ) == 0x0 02075 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 304, ... 288, ) == 0x0 02076 432 NtQuerySection (288, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02077 432 NtClose (304, ... ) == 0x0 02078 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76990000), 0x0, 147456, ) == 0x0 02079 432 NtClose (288, ... ) == 0x0 02080 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ATL.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02081 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ATL.DLL"}, 1235064, ... ) }, 1235064, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02082 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ATL.DLL"}, 1235064, ... ) }, 1235064, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02083 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ATL.DLL"}, 1235064, ... ) }, 1235064, ... ) == 0x0 02084 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ATL.DLL"}, 5, 96, ... 288, {status=0x0, info=1}, ) }, 5, 96, ... 288, {status=0x0, info=1}, ) == 0x0 02085 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 288, ... 304, ) == 0x0 02086 432 NtQuerySection (304, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02087 432 NtClose (288, ... ) == 0x0 02088 432 NtMapViewOfSection (304, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76b20000), 0x0, 86016, ) == 0x0 02089 432 NtClose (304, ... ) == 0x0 02090 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02091 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\NETAPI32.dll"}, 1235064, ... ) }, 1235064, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02092 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "NETAPI32.dll"}, 1235064, ... ) }, 1235064, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02093 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETAPI32.dll"}, 1235064, ... ) }, 1235064, ... ) == 0x0 02094 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETAPI32.dll"}, 5, 96, ... 304, {status=0x0, info=1}, ) }, 5, 96, ... 304, {status=0x0, info=1}, ) == 0x0 02095 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 304, ... 288, ) == 0x0 02096 432 NtQuerySection (288, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02097 432 NtClose (304, ... ) == 0x0 02098 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71c20000), 0x0, 323584, ) == 0x0 02099 432 NtClose (288, ... ) == 0x0 02100 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "USERENV.dll"}, ... 288, ) }, ... 288, ) == 0x0 02101 432 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75a70000), 0x0, 667648, ) == 0x0 02102 432 NtClose (288, ... ) == 0x0 02103 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02104 432 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10682368, 262144, ) == 0x0 02105 432 NtAllocateVirtualMemory (-1, 10682368, 0, 4096, 4096, 4, ... 10682368, 4096, ) == 0x0 02106 432 NtAllocateVirtualMemory (-1, 10686464, 0, 8192, 4096, 4, ... 10686464, 8192, ) == 0x0 02107 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02108 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02109 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 288, ) }, ... 288, ) == 0x0 02110 432 NtQueryValueKey (288, (288, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02111 432 NtClose (288, ... ) == 0x0 02112 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 288, ) }, ... 288, ) == 0x0 02113 432 NtQueryValueKey (288, (288, "ChkAccDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02114 432 NtClose (288, ... ) == 0x0 02115 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Control\ProductOptions"}, ... 288, ) }, ... 288, ) == 0x0 02116 432 NtQueryValueKey (288, (288, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (288, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) }, 24, ) == 0x0 02117 432 NtClose (288, ... ) == 0x0 02118 432 NtCreateEvent (0x1f0003, {24, 52, 0x80, 1235492, 0, (0x1f0003, {24, 52, 0x80, 1235492, 0, "Global\userenv: User Profile setup event"}, 0, 1, ... 288, ) }, 0, 1, ... 288, ) == STATUS_OBJECT_NAME_EXISTS 02119 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02120 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02121 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02122 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02123 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02124 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02125 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02126 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02127 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02128 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02129 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02130 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02131 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02132 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02133 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02134 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02135 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02136 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02137 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02138 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02139 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02140 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02141 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02142 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02143 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02144 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02145 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02146 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 02147 432 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02148 432 NtClose (304, ... ) == 0x0 02149 432 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 304, ) }, ... 304, ) == 0x0 02150 432 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 308, ) }, ... 308, ) == 0x0 02151 432 NtQueryValueKey (308, (308, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (308, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) }, 66, ) == 0x0 02152 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02153 432 NtQueryValueKey (308, (308, "Local Settings", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 70, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (308, "Local Settings", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 70, ) }, 70, ) == 0x0 02154 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02155 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02156 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02157 432 NtQueryDefaultLocale (1, 1233328, ... ) == 0x0 02158 432 NtClose (308, ... ) == 0x0 02159 432 NtClose (304, ... ) == 0x0 02160 432 NtAllocateVirtualMemory (-1, 3305472, 0, 4096, 4096, 4, ... 3305472, 4096, ) == 0x0 02161 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 304, ) }, ... 304, ) == 0x0 02162 432 NtQueryValueKey (304, (304, "RsopDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02163 432 NtClose (304, ... ) == 0x0 02164 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 304, ) }, ... 304, ) == 0x0 02165 432 NtQueryValueKey (304, (304, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02166 432 NtQueryValueKey (304, (304, "RsopLogging", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02167 432 NtClose (304, ... ) == 0x0 02168 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\System"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02169 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\winlogon"}, ... 304, ) }, ... 304, ) == 0x0 02170 432 NtQueryValueKey (304, (304, "UserEnvDebugLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02171 432 NtClose (304, ... ) == 0x0 02172 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\System"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02173 432 NtQueryDefaultUILanguage (1234240, ... 02174 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02175 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 02176 432 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02177 432 NtClose (-2147482032, ... ) == 0x0 02178 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 02179 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02180 432 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 02181 432 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02182 432 NtClose (-2147482044, ... ) == 0x0 02183 432 NtClose (-2147482032, ... ) == 0x0 02173 432 NtQueryDefaultUILanguage ... ) == 0x0 02184 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02185 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntshrui.dll"}, 1, 96, ... 304, {status=0x0, info=1}, ) }, 1, 96, ... 304, {status=0x0, info=1}, ) == 0x0 02186 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 304, ... 308, ) == 0x0 02187 432 NtMapViewOfSection (308, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0xa70000), 0x0, 139264, ) == 0x0 02188 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntshrui.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02189 432 NtQueryDefaultLocale (1, 1232276, ... ) == 0x0 02190 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntshrui.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02191 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1233132, 1, 96, 0} (24, {128, 156, new_msg, 0, 1233132, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\324\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\10\1\0\0\377\377\377\377\0\0\0\0p\250\247\0\0\0\0\0y\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\354\327\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1517, 0} " S\26\0\33\0\1\0\0\0\0\0\1\324\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\10\1\0\0\377\377\377\377\0\0\0\0p\250\247\0\0\0\0\0y\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\354\327\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 424, 432, 1517, 0} (24, {128, 156, new_msg, 0, 1233132, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\324\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\10\1\0\0\377\377\377\377\0\0\0\0p\250\247\0\0\0\0\0y\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\354\327\22\0\0\0\0\0" ... {128, 156, reply, 0, 424, 432, 1517, 0} " S\26\0\33\0\1\0\0\0\0\0\1\324\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\10\1\0\0\377\377\377\377\0\0\0\0p\250\247\0\0\0\0\0y\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\354\327\22\0\0\0\0\0" ) ) == 0x0 02192 432 NtClose (304, ... ) == 0x0 02193 432 NtClose (308, ... ) == 0x0 02194 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 02195 432 NtUnmapViewOfSection (-1, 0x12d7ec, ... ) == STATUS_NOT_MAPPED_VIEW 02196 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02197 432 NtAllocateVirtualMemory (-1, 1429504, 0, 4096, 4096, 4, ... 1429504, 4096, ) == 0x0 02198 432 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02199 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02200 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02201 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1231360, ... ) }, 1231360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02202 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02203 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02204 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02205 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1231952, ... ) }, 1231952, ... ) == 0x0 02206 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 308, {status=0x0, info=1}, ) }, 3, 33, ... 308, {status=0x0, info=1}, ) == 0x0 02207 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02208 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02209 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 304, {status=0x0, info=1}, ) }, 3, 16417, ... 304, {status=0x0, info=1}, ) == 0x0 02210 432 NtQueryInformationFile (304, 1237372, 528, Name, ... {status=0x0, info=6}, ) == 0x0 02211 432 NtQueryVolumeInformationFile (304, 1401624, 544, Volume, ... {status=0x0, info=18}, ) == 0x0 02212 432 NtClose (304, ... ) == 0x0 02213 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02214 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02215 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 304, ) == 0x0 02216 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02217 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02218 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1235728, (0xc0100080, {24, 0, 0x40, 0, 1235728, "\??\PIPE\srvsvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 312, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 312, {status=0x0, info=1}, ) == 0x0 02219 432 NtSetInformationFile (312, 1235784, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02220 432 NtSetInformationFile (312, 1235776, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02221 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02222 432 NtWriteFile (312, 261, 0, 0, (312, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\310O2Kp\26\323\1\22xZG\277n\341\210\3\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02223 432 NtReadFile (312, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (312, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\355#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02224 432 NtFsControlFile (312, 261, 0x0, 0x0, 0x11c017, (312, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0\17\0\0\0\0\0\366\1\0\0\366\1\0\0|\341\22\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\355#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 56, 1024, ... {status=0x103, info=68}, (312, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0\17\0\0\0\0\0\366\1\0\0\366\1\0\0|\341\22\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\355#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02225 432 NtClose (304, ... ) == 0x0 02226 432 NtClose (312, ... ) == 0x0 02227 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Control\ProductOptions"}, ... 312, ) }, ... 312, ) == 0x0 02228 432 NtQueryValueKey (312, (312, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (312, "ProductType", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0N\0T\0\0\0"}, 24, ) }, 24, ) == 0x0 02229 432 NtClose (312, ... ) == 0x0 02230 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02231 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 312, ) == 0x0 02232 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02233 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02234 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1235748, (0xc0100080, {24, 0, 0x40, 0, 1235748, "\??\PIPE\srvsvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 304, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 304, {status=0x0, info=1}, ) == 0x0 02235 432 NtSetInformationFile (304, 1235804, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02236 432 NtSetInformationFile (304, 1235796, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02237 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02238 432 NtWriteFile (304, 261, 0, 0, (304, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\310O2Kp\26\323\1\22xZG\277n\341\210\3\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02239 432 NtReadFile (304, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (304, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\356#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02240 432 NtFsControlFile (304, 261, 0x0, 0x0, 0x11c017, (304, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\1\0\0\0,\0\0\0\0\0\20\0\24&\231v\1\0\0\0\0\0\0\0\1\0\0\0\0\0ZG\3\0\0\0\0\0\0\0\3\0\0\0C\0$\0\0\0\10\0\365\1\0\0", 68, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\356#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 68, 1024, ... {status=0x103, info=68}, (304, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\1\0\0\0,\0\0\0\0\0\20\0\24&\231v\1\0\0\0\0\0\0\0\1\0\0\0\0\0ZG\3\0\0\0\0\0\0\0\3\0\0\0C\0$\0\0\0\10\0\365\1\0\0", 68, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\356#\0\0\15\0\PIPE\srvsvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02241 432 NtClose (312, ... ) == 0x0 02242 432 NtClose (304, ... ) == 0x0 02243 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 304, ) }, ... 304, ) == 0x0 02244 432 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "ActiveComputerName"}, ... 312, ) }, ... 312, ) == 0x0 02245 432 NtQueryValueKey (312, (312, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (312, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (312, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 02246 432 NtClose (312, ... ) == 0x0 02247 432 NtClose (304, ... ) == 0x0 02248 432 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1239548, (0x100080, {24, 0, 0x40, 0, 1239548, "\??\C:\Program Files\Common Files\Carlson\carlton"}, 0x0, 128, 7, 1, 16416, 0, 0, ... 304, {status=0x0, info=1}, ) }, 0x0, 128, 7, 1, 16416, 0, 0, ... 304, {status=0x0, info=1}, ) == 0x0 02249 432 NtQueryVolumeInformationFile (304, 1239432, 24, Volume, ... {status=0x0, info=18}, ) == 0x0 02250 432 NtQueryInformationFile (304, 1239456, 104, All, ... ) == STATUS_BUFFER_OVERFLOW 02251 432 NtFsControlFile (304, 0, 0x0, 0x0, 0x900c0, 0x0, 0, 64, ... ) == STATUS_INVALID_DEVICE_REQUEST 02252 432 NtClose (304, ... ) == 0x0 02253 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02254 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02255 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\carlton"}, 1241516, ... ) }, 1241516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02256 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02257 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02258 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\carlton"}, 1242032, ... ) }, 1242032, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02259 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1242016, (0xc0100080, {24, 0, 0x40, 0, 1242016, "\??\C:\Documents and Settings\All Users\Start Menu\carlton"}, 0x0, 0, 3, 5, 96, 0, 0, ... }, 0x0, 0, 3, 5, 96, 0, 0, ... 02260 432 NtClose (-2147482032, ... ) == 0x0 02259 432 NtCreateFile ... 304, {status=0x0, info=2}, ) == 0x0 02261 432 NtUserMessageCall (0x10076, WM_USER+0x19, 0x0, 0x0, 0, 688, 0, ... ) == 0x1006c 02262 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02263 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES"}, 138, ) }, 138, ) == 0x0 02264 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02265 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 312, ) }, ... 312, ) == 0x0 02266 432 NtQueryKey (314, Name, 392, ... {Name= (314, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 02267 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02268 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 316, ) == 0x0 02269 432 NtQueryInformationToken (316, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02270 432 NtClose (316, ... ) == 0x0 02271 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02272 432 NtEnumerateKey (314, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name= (314, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 02273 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02274 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02275 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 316, ) }, ... 316, ) == 0x0 02276 432 NtQueryKey (318, Name, 392, ... {Name= (318, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 02277 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02278 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 320, ) == 0x0 02279 432 NtQueryInformationToken (320, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02280 432 NtClose (320, ... ) == 0x0 02281 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02282 432 NtQueryValueKey (318, (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 02283 432 NtClose (318, ... ) == 0x0 02284 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02285 432 NtEnumerateKey (314, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 02286 432 NtClose (314, ... ) == 0x0 02287 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 02288 432 NtUserQueryWindow (65644, 1, ... ) == 0x7b8 02289 432 NtCreateSection (0xf0007, 0x0, {396, 0}, 4, 134217728, 0, ... 312, ) == 0x0 02290 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 02291 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 316, ) == 0x0 02292 432 NtDuplicateObject (-1, 312, 316, 0xf001f, 0, 2, ... 780, ) == 0x0 02293 432 NtClose (316, ... ) == 0x0 02294 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 02295 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 02296 432 NtClose (312, ... ) == 0x0 02297 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 312, ) == 0x0 02298 432 NtDuplicateObject (312, 780, -1, 0xf001f, 0, 2, ... 316, ) == 0x0 02299 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 02300 432 NtClose (312, ... ) == 0x0 02301 432 NtMapViewOfSection (316, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 02302 432 NtClose (316, ... ) == 0x0 02303 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 02304 432 NtUserMessageCall (0x1006c, WM_USER+0x3, 0x30c, 0x77c, 0, 695, 0, ... ) == 0x1 02305 432 NtAllocateVirtualMemory (-1, 1433600, 0, 8192, 4096, 4, ... 1433600, 8192, ) == 0x0 02306 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02307 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02308 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02309 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02310 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02311 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02312 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02313 432 NtQueryValueKey (316, (316, "Start Menu", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0"}, 62, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (316, "Start Menu", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0"}, 62, ) }, 62, ) == 0x0 02314 432 NtClose (316, ... ) == 0x0 02315 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02316 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02317 432 NtSetValueKey (316, (316, "Start Menu", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0", 92, ... ) , 0, 1, (316, "Start Menu", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\0\0", 92, ... ) , 92, ... ) == 0x0 02318 432 NtClose (316, ... ) == 0x0 02319 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02320 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02321 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02322 432 NtClose (316, ... ) == 0x0 02323 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02324 432 NtClose (312, ... ) == 0x0 02325 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02326 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02327 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02328 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02329 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02330 432 NtClose (312, ... ) == 0x0 02331 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02332 432 NtClose (316, ... ) == 0x0 02333 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02334 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239520, 616, BothDirectory, 1, (316, 0, 0, 0, 1239520, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02335 432 NtClose (316, ... ) == 0x0 02336 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02337 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239428, 616, BothDirectory, 1, (316, 0, 0, 0, 1239428, 616, BothDirectory, 1, "SRI-user", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02338 432 NtClose (316, ... ) == 0x0 02339 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02340 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239352, 616, BothDirectory, 1, (316, 0, 0, 0, 1239352, 616, BothDirectory, 1, "Start Menu", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02341 432 NtClose (316, ... ) == 0x0 02342 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02343 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02344 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 1234724, ... ) }, 1234724, ... ) == 0x0 02345 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02346 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02347 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02348 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02349 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02350 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02351 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02352 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12", ) , ) == 0x0 02353 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02354 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02355 432 NtClose (316, ... ) == 0x0 02356 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02357 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02358 432 NtClose (316, ... ) == 0x0 02359 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02360 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02361 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 1234696, ... ) }, 1234696, ... ) == 0x0 02362 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02363 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02364 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02365 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02366 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02367 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02368 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02369 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12", ) , ) == 0x0 02370 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02371 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02372 432 NtClose (316, ... ) == 0x0 02373 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02374 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02375 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 1235060, ... ) }, 1235060, ... ) == 0x0 02376 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02377 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02378 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02379 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02380 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02381 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02382 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02383 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12", ) , ) == 0x0 02384 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02385 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02386 432 NtClose (316, ... ) == 0x0 02387 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02388 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02389 432 NtClose (316, ... ) == 0x0 02390 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02391 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02392 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 1235060, ... ) }, 1235060, ... ) == 0x0 02393 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02394 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02395 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02396 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02397 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02398 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02399 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02400 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12", ) , ) == 0x0 02401 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02402 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02403 432 NtClose (316, ... ) == 0x0 02404 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02405 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02406 432 NtClose (316, ... ) == 0x0 02407 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02408 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02409 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 1235060, ... ) }, 1235060, ... ) == 0x0 02410 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02411 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02412 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02413 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02414 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02415 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02416 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02417 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12", ) , ) == 0x0 02418 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02419 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02420 432 NtClose (316, ... ) == 0x0 02421 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02422 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02423 432 NtClose (316, ... ) == 0x0 02424 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02425 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02426 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02427 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02428 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02429 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02430 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02431 432 NtClose (316, ... ) == 0x0 02432 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02433 432 NtClose (312, ... ) == 0x0 02434 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02435 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02436 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02437 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02438 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02439 432 NtClose (312, ... ) == 0x0 02440 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02441 432 NtClose (316, ... ) == 0x0 02442 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02443 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239520, 616, BothDirectory, 1, (316, 0, 0, 0, 1239520, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02444 432 NtClose (316, ... ) == 0x0 02445 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02446 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239424, 616, BothDirectory, 1, (316, 0, 0, 0, 1239424, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02447 432 NtClose (316, ... ) == 0x0 02448 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02449 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239348, 616, BothDirectory, 1, (316, 0, 0, 0, 1239348, 616, BothDirectory, 1, "Start Menu", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02450 432 NtClose (316, ... ) == 0x0 02451 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02452 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02453 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 1234720, ... ) }, 1234720, ... ) == 0x0 02454 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02455 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02456 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02457 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02458 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02459 432 NtAllocateVirtualMemory (-1, 0, 0, 1048794, 8192, 4, ... 11206656, 1052672, ) == 0x0 02460 432 NtAllocateVirtualMemory (-1, 11206656, 0, 218, 4096, 4, ... 11206656, 4096, ) == 0x0 02461 432 NtReadFile (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12[LocalizedFileNames]\15\12Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075\15\12Activate Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000\15\12", ) , ) == 0x0 02462 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02463 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02464 432 NtClose (316, ... ) == 0x0 02465 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02466 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02467 432 NtClose (316, ... ) == 0x0 02468 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02469 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02470 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 1234692, ... ) }, 1234692, ... ) == 0x0 02471 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02472 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02473 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02474 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02475 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02476 432 NtAllocateVirtualMemory (-1, 0, 0, 1048794, 8192, 4, ... 11206656, 1052672, ) == 0x0 02477 432 NtAllocateVirtualMemory (-1, 11206656, 0, 218, 4096, 4, ... 11206656, 4096, ) == 0x0 02478 432 NtReadFile (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12[LocalizedFileNames]\15\12Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075\15\12Activate Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000\15\12", ) , ) == 0x0 02479 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02480 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02481 432 NtClose (316, ... ) == 0x0 02482 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02483 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02484 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 1235056, ... ) }, 1235056, ... ) == 0x0 02485 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02486 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02487 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02488 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02489 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02490 432 NtAllocateVirtualMemory (-1, 0, 0, 1048794, 8192, 4, ... 11206656, 1052672, ) == 0x0 02491 432 NtAllocateVirtualMemory (-1, 11206656, 0, 218, 4096, 4, ... 11206656, 4096, ) == 0x0 02492 432 NtReadFile (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12[LocalizedFileNames]\15\12Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075\15\12Activate Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000\15\12", ) , ) == 0x0 02493 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02494 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02495 432 NtClose (316, ... ) == 0x0 02496 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02497 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02498 432 NtClose (316, ... ) == 0x0 02499 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02500 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02501 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 1235056, ... ) }, 1235056, ... ) == 0x0 02502 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02503 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02504 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02505 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02506 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02507 432 NtAllocateVirtualMemory (-1, 0, 0, 1048794, 8192, 4, ... 11206656, 1052672, ) == 0x0 02508 432 NtAllocateVirtualMemory (-1, 11206656, 0, 218, 4096, 4, ... 11206656, 4096, ) == 0x0 02509 432 NtReadFile (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12[LocalizedFileNames]\15\12Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075\15\12Activate Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000\15\12", ) , ) == 0x0 02510 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02511 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02512 432 NtClose (316, ... ) == 0x0 02513 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02514 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02515 432 NtClose (316, ... ) == 0x0 02516 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02517 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02518 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 1235056, ... ) }, 1235056, ... ) == 0x0 02519 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02520 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02521 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Start Menu\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02522 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02523 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02524 432 NtAllocateVirtualMemory (-1, 0, 0, 1048794, 8192, 4, ... 11206656, 1052672, ) == 0x0 02525 432 NtAllocateVirtualMemory (-1, 11206656, 0, 218, 4096, 4, ... 11206656, 4096, ) == 0x0 02526 432 NtReadFile (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, (316, 0, 0, 0, 214, 0x0, 2012046884, ... {status=0x0, info=214}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21786\15\12[LocalizedFileNames]\15\12Windows Catalog.lnk=@%SystemRoot%\system32\shell32.dll,-22075\15\12Activate Windows.lnk=@%SystemRoot%\system32\oobe\msoobe.exe,-2000\15\12", ) , ) == 0x0 02527 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02528 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02529 432 NtClose (316, ... ) == 0x0 02530 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02531 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02532 432 NtClose (316, ... ) == 0x0 02533 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02534 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02535 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02536 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02537 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02538 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02539 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02540 432 NtQueryValueKey (316, (316, "Common AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 82, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (316, "Common AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 82, ) }, 82, ) == 0x0 02541 432 NtClose (316, ... ) == 0x0 02542 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02543 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02544 432 NtSetValueKey (316, (316, "Common AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 106, ... ) , 0, 1, (316, "Common AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 106, ... ) , 106, ... ) == 0x0 02545 432 NtClose (316, ... ) == 0x0 02546 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02547 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02548 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02549 432 NtClose (316, ... ) == 0x0 02550 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02551 432 NtClose (312, ... ) == 0x0 02552 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02553 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02554 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02555 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02556 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02557 432 NtClose (312, ... ) == 0x0 02558 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02559 432 NtClose (316, ... ) == 0x0 02560 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02561 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239508, 616, BothDirectory, 1, (316, 0, 0, 0, 1239508, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02562 432 NtClose (316, ... ) == 0x0 02563 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02564 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239400, 616, BothDirectory, 1, (316, 0, 0, 0, 1239400, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02565 432 NtClose (316, ... ) == 0x0 02566 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02567 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239312, 616, BothDirectory, 1, (316, 0, 0, 0, 1239312, 616, BothDirectory, 1, "Application Data", 0, ... {status=0x0, info=126}, ) , 0, ... {status=0x0, info=126}, ) == 0x0 02568 432 NtClose (316, ... ) == 0x0 02569 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02570 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02571 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 1234684, ... ) }, 1234684, ... ) == 0x0 02572 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02573 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02574 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02575 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02576 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02577 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02578 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02579 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02580 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02581 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02582 432 NtClose (316, ... ) == 0x0 02583 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02584 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02585 432 NtClose (316, ... ) == 0x0 02586 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02587 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02588 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 1234656, ... ) }, 1234656, ... ) == 0x0 02589 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02590 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02591 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02592 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02593 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02594 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02595 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02596 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02597 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02598 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02599 432 NtClose (316, ... ) == 0x0 02600 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02601 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02602 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 1235020, ... ) }, 1235020, ... ) == 0x0 02603 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02604 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02605 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02606 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02607 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02608 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02609 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02610 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02611 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02612 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02613 432 NtClose (316, ... ) == 0x0 02614 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02615 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02616 432 NtClose (316, ... ) == 0x0 02617 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02618 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02619 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 1235020, ... ) }, 1235020, ... ) == 0x0 02620 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02621 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02622 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02623 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02624 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02625 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02626 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02627 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02628 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02629 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02630 432 NtClose (316, ... ) == 0x0 02631 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02632 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02633 432 NtClose (316, ... ) == 0x0 02634 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02635 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02636 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 1235020, ... ) }, 1235020, ... ) == 0x0 02637 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02638 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02639 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02640 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02641 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02642 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02643 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02644 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02645 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02646 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02647 432 NtClose (316, ... ) == 0x0 02648 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02649 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02650 432 NtClose (316, ... ) == 0x0 02651 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02652 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02653 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02654 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02655 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02656 432 NtQueryValueKey (316, (316, "AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 74, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (316, "AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 74, ) }, 74, ) == 0x0 02657 432 NtClose (316, ... ) == 0x0 02658 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02659 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02660 432 NtSetValueKey (316, (316, "AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 104, ... ) , 0, 1, (316, "AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 104, ... ) , 104, ... ) == 0x0 02661 432 NtClose (316, ... ) == 0x0 02662 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02663 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02664 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02665 432 NtClose (316, ... ) == 0x0 02666 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02667 432 NtClose (312, ... ) == 0x0 02668 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02669 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02670 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02671 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02672 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02673 432 NtClose (312, ... ) == 0x0 02674 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02675 432 NtClose (316, ... ) == 0x0 02676 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02677 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239508, 616, BothDirectory, 1, (316, 0, 0, 0, 1239508, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02678 432 NtClose (316, ... ) == 0x0 02679 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02680 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239404, 616, BothDirectory, 1, (316, 0, 0, 0, 1239404, 616, BothDirectory, 1, "SRI-user", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02681 432 NtClose (316, ... ) == 0x0 02682 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02683 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239316, 616, BothDirectory, 1, (316, 0, 0, 0, 1239316, 616, BothDirectory, 1, "Application Data", 0, ... {status=0x0, info=126}, ) , 0, ... {status=0x0, info=126}, ) == 0x0 02684 432 NtClose (316, ... ) == 0x0 02685 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02686 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02687 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 1234688, ... ) }, 1234688, ... ) == 0x0 02688 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02689 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02690 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02691 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02692 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02693 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02694 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02695 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02696 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02697 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02698 432 NtClose (316, ... ) == 0x0 02699 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02700 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02701 432 NtClose (316, ... ) == 0x0 02702 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02703 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02704 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 1234660, ... ) }, 1234660, ... ) == 0x0 02705 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02706 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02707 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02708 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02709 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02710 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02711 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02712 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02713 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02714 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02715 432 NtClose (316, ... ) == 0x0 02716 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02717 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02718 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 1235024, ... ) }, 1235024, ... ) == 0x0 02719 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02720 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02721 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02722 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02723 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02724 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02725 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02726 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02727 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02728 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02729 432 NtClose (316, ... ) == 0x0 02730 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02731 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02732 432 NtClose (316, ... ) == 0x0 02733 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02734 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02735 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 1235024, ... ) }, 1235024, ... ) == 0x0 02736 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02737 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02738 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02739 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02740 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02741 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02742 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02743 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02744 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02745 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02746 432 NtClose (316, ... ) == 0x0 02747 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02748 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02749 432 NtClose (316, ... ) == 0x0 02750 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02751 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02752 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 1235024, ... ) }, 1235024, ... ) == 0x0 02753 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02754 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02755 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Application Data\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02756 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02757 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02758 432 NtAllocateVirtualMemory (-1, 0, 0, 1048642, 8192, 4, ... 11206656, 1052672, ) == 0x0 02759 432 NtAllocateVirtualMemory (-1, 11206656, 0, 66, 4096, 4, ... 11206656, 4096, ) == 0x0 02760 432 NtReadFile (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, (316, 0, 0, 0, 62, 0x0, 2012046884, ... {status=0x0, info=62}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21765\15\12", ) , ) == 0x0 02761 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02762 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02763 432 NtClose (316, ... ) == 0x0 02764 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02765 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02766 432 NtClose (316, ... ) == 0x0 02767 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02768 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02769 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02770 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02771 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02772 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02773 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02774 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02775 432 NtClose (316, ... ) == 0x0 02776 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02777 432 NtClose (312, ... ) == 0x0 02778 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02779 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02780 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02781 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02782 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02783 432 NtClose (312, ... ) == 0x0 02784 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02785 432 NtClose (316, ... ) == 0x0 02786 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02787 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239572, 616, BothDirectory, 1, (316, 0, 0, 0, 1239572, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02788 432 NtClose (316, ... ) == 0x0 02789 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02790 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239500, 616, BothDirectory, 1, (316, 0, 0, 0, 1239500, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02791 432 NtClose (316, ... ) == 0x0 02792 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02793 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02794 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02795 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02796 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02797 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02798 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02799 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02800 432 NtClose (316, ... ) == 0x0 02801 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02802 432 NtClose (312, ... ) == 0x0 02803 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02804 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02805 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02806 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02807 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02808 432 NtClose (312, ... ) == 0x0 02809 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02810 432 NtClose (316, ... ) == 0x0 02811 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02812 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239572, 616, BothDirectory, 1, (316, 0, 0, 0, 1239572, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02813 432 NtClose (316, ... ) == 0x0 02814 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02815 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239500, 616, BothDirectory, 1, (316, 0, 0, 0, 1239500, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02816 432 NtClose (316, ... ) == 0x0 02817 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02818 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02819 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02820 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02821 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02822 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02823 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02824 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02825 432 NtClose (316, ... ) == 0x0 02826 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02827 432 NtClose (312, ... ) == 0x0 02828 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02829 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02830 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02831 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02832 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02833 432 NtClose (312, ... ) == 0x0 02834 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02835 432 NtClose (316, ... ) == 0x0 02836 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02837 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239592, 616, BothDirectory, 1, (316, 0, 0, 0, 1239592, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02838 432 NtClose (316, ... ) == 0x0 02839 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02840 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02841 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 02842 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 02843 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02844 432 NtQueryValueKey (316, (316, "My Pictures", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0"}, 90, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (316, "My Pictures", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0"}, 90, ) }, 90, ) == 0x0 02845 432 NtClose (316, ... ) == 0x0 02846 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures"}, 1241200, ... ) }, 1241200, ... ) == 0x0 02847 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 02848 432 NtSetValueKey (316, (316, "My Pictures", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0", 120, ... ) , 0, 1, (316, "My Pictures", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0", 120, ... ) , 120, ... ) == 0x0 02849 432 NtClose (316, ... ) == 0x0 02850 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 02851 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02852 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02853 432 NtClose (316, ... ) == 0x0 02854 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 02855 432 NtClose (312, ... ) == 0x0 02856 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 02857 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02858 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02859 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 02860 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 02861 432 NtClose (312, ... ) == 0x0 02862 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02863 432 NtClose (316, ... ) == 0x0 02864 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02865 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239492, 616, BothDirectory, 1, (316, 0, 0, 0, 1239492, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02866 432 NtClose (316, ... ) == 0x0 02867 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02868 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239372, 616, BothDirectory, 1, (316, 0, 0, 0, 1239372, 616, BothDirectory, 1, "SRI-user", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02869 432 NtClose (316, ... ) == 0x0 02870 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02871 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239268, 616, BothDirectory, 1, (316, 0, 0, 0, 1239268, 616, BothDirectory, 1, "My Documents", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 02872 432 NtClose (316, ... ) == 0x0 02873 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02874 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02875 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234640, ... ) }, 1234640, ... ) == 0x0 02876 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02877 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02878 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02879 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02880 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02881 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02882 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02883 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02884 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02885 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02886 432 NtClose (316, ... ) == 0x0 02887 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02888 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02889 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02890 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02891 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02892 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02893 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02894 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02895 432 NtClose (316, ... ) == 0x0 02896 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02897 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02898 432 NtClose (316, ... ) == 0x0 02899 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02900 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02901 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234640, ... ) }, 1234640, ... ) == 0x0 02902 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02903 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02904 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02905 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02906 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02907 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02908 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02909 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02910 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02911 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02912 432 NtClose (316, ... ) == 0x0 02913 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02914 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02915 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02916 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02917 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02918 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02919 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02920 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02921 432 NtClose (316, ... ) == 0x0 02922 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02923 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02924 432 NtClose (316, ... ) == 0x0 02925 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02926 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02927 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1236696, ... ) }, 1236696, ... ) == 0x0 02928 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02929 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02930 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02931 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02932 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02933 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02934 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02935 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02936 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02937 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02938 432 NtClose (316, ... ) == 0x0 02939 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02940 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02941 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234976, ... ) }, 1234976, ... ) == 0x0 02942 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02943 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02944 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02945 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02946 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02947 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02948 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02949 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02950 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02951 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02952 432 NtClose (316, ... ) == 0x0 02953 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02954 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02955 432 NtClose (316, ... ) == 0x0 02956 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02957 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02958 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234976, ... ) }, 1234976, ... ) == 0x0 02959 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02960 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02961 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02962 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02963 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02964 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02965 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02966 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02967 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02968 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02969 432 NtClose (316, ... ) == 0x0 02970 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02971 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02972 432 NtClose (316, ... ) == 0x0 02973 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02974 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02975 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 1234976, ... ) }, 1234976, ... ) == 0x0 02976 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02977 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02978 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02979 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 02980 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02981 432 NtAllocateVirtualMemory (-1, 0, 0, 1048659, 8192, 4, ... 11206656, 1052672, ) == 0x0 02982 432 NtAllocateVirtualMemory (-1, 11206656, 0, 83, 4096, 4, ... 11206656, 4096, ) == 0x0 02983 432 NtReadFile (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, (316, 0, 0, 0, 79, 0x0, 2012046884, ... {status=0x0, info=79}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02984 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 02985 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 02986 432 NtClose (316, ... ) == 0x0 02987 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02988 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02989 432 NtClose (316, ... ) == 0x0 02990 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 02991 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239192, 616, BothDirectory, 1, (316, 0, 0, 0, 1239192, 616, BothDirectory, 1, "My Pictures", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02992 432 NtClose (316, ... ) == 0x0 02993 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02994 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02995 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1234564, ... ) }, 1234564, ... ) == 0x0 02996 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02997 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02998 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02999 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03000 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03001 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03002 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03003 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03004 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03005 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03006 432 NtClose (316, ... ) == 0x0 03007 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03008 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03009 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03010 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03011 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03012 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03013 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03014 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03015 432 NtClose (316, ... ) == 0x0 03016 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03017 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03018 432 NtClose (316, ... ) == 0x0 03019 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03020 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03021 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1234564, ... ) }, 1234564, ... ) == 0x0 03022 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03023 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03024 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03025 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03026 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03027 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03028 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03029 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03030 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03031 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03032 432 NtClose (316, ... ) == 0x0 03033 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03034 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03035 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03036 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03037 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03038 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03039 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03040 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03041 432 NtClose (316, ... ) == 0x0 03042 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03043 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03044 432 NtClose (316, ... ) == 0x0 03045 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03046 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03047 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1236620, ... ) }, 1236620, ... ) == 0x0 03048 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03049 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03050 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03051 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03052 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03053 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03054 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03055 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03056 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03057 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03058 432 NtClose (316, ... ) == 0x0 03059 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03060 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03061 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1234900, ... ) }, 1234900, ... ) == 0x0 03062 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03063 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03064 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03065 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03066 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03067 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03068 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03069 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03070 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03071 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03072 432 NtClose (316, ... ) == 0x0 03073 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03074 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03075 432 NtClose (316, ... ) == 0x0 03076 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03077 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03078 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1234900, ... ) }, 1234900, ... ) == 0x0 03079 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03080 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03081 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03082 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03083 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03084 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03085 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03086 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03087 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03088 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03089 432 NtClose (316, ... ) == 0x0 03090 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03091 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03092 432 NtClose (316, ... ) == 0x0 03093 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03094 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03095 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 1234900, ... ) }, 1234900, ... ) == 0x0 03096 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03097 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03098 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\My Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03099 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03100 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03101 432 NtAllocateVirtualMemory (-1, 0, 0, 1048766, 8192, 4, ... 11206656, 1052672, ) == 0x0 03102 432 NtAllocateVirtualMemory (-1, 11206656, 0, 190, 4096, 4, ... 11206656, 4096, ) == 0x0 03103 432 NtReadFile (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, (316, 0, 0, 0, 186, 0x0, 2012046884, ... {status=0x0, info=186}, "[DeleteOnCopy]\15\12Owner=SRI-user\15\12Personalized=39\15\12PersonalizedName=My Pictures\15\12[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\System32\mydocs.dll\15\12IconIndex=-101\15\12", ) , ) == 0x0 03104 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03105 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03106 432 NtClose (316, ... ) == 0x0 03107 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03108 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03109 432 NtClose (316, ... ) == 0x0 03110 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03111 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03112 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03113 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03114 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03115 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03116 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03117 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03118 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 316, ) }, ... 316, ) == 0x0 03119 432 NtQueryValueKey (316, (316, "ProgramFilesDir (x86)", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03120 432 NtClose (316, ... ) == 0x0 03121 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03122 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03123 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03124 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03125 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 316, ) }, ... 316, ) == 0x0 03126 432 NtQueryValueKey (316, (316, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (316, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 03127 432 NtClose (316, ... ) == 0x0 03128 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files"}, 1241200, ... ) }, 1241200, ... ) == 0x0 03129 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 03130 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03131 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 03132 432 NtClose (316, ... ) == 0x0 03133 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 03134 432 NtClose (312, ... ) == 0x0 03135 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 03136 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03137 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03138 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 03139 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 03140 432 NtClose (312, ... ) == 0x0 03141 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03142 432 NtClose (316, ... ) == 0x0 03143 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 03144 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239580, 616, BothDirectory, 1, (316, 0, 0, 0, 1239580, 616, BothDirectory, 1, "Program Files", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 03145 432 NtClose (316, ... ) == 0x0 03146 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03147 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03148 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1234952, ... ) }, 1234952, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03149 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03150 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03151 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03152 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03153 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1234924, ... ) }, 1234924, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03154 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03155 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03156 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03157 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03158 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1235288, ... ) }, 1235288, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03159 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03160 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03161 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03162 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03163 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1235288, ... ) }, 1235288, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03164 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03165 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03166 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03167 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03168 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\desktop.ini"}, 1235288, ... ) }, 1235288, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03169 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03170 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03171 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03172 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03173 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03174 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03175 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 03176 432 NtQueryValueKey (316, (316, "CommonPictures", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03177 432 NtClose (316, ... ) == 0x0 03178 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 316, ) }, ... 316, ) == 0x0 03179 432 NtQueryValueKey (316, (316, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (316, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) }, 86, ) == 0x0 03180 432 NtClose (316, ... ) == 0x0 03181 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 316, ) }, ... 316, ) == 0x0 03182 432 NtQueryValueKey (316, (316, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (316, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) }, 32, ) == 0x0 03183 432 NtClose (316, ... ) == 0x0 03184 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures"}, 1241200, ... ) }, 1241200, ... ) == 0x0 03185 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 316, 2, ) }, 0, 0x0, 0, ... 316, 2, ) == 0x0 03186 432 NtSetValueKey (316, (316, "CommonPictures", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0", 116, ... ) , 0, 1, (316, "CommonPictures", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0P\0i\0c\0t\0u\0r\0e\0s\0\0\0", 116, ... ) , 116, ... ) == 0x0 03187 432 NtClose (316, ... ) == 0x0 03188 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 03189 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03190 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 03191 432 NtClose (316, ... ) == 0x0 03192 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 03193 432 NtClose (312, ... ) == 0x0 03194 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 03195 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03196 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03197 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 312, ) }, ... 312, ) == 0x0 03198 432 NtOpenKey (0x2000000, {24, 312, 0x40, 0, 0, (0x2000000, {24, 312, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 316, ) }, ... 316, ) == 0x0 03199 432 NtClose (312, ... ) == 0x0 03200 432 NtQueryValueKey (316, (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (316, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03201 432 NtClose (316, ... ) == 0x0 03202 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 03203 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239496, 616, BothDirectory, 1, (316, 0, 0, 0, 1239496, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 03204 432 NtClose (316, ... ) == 0x0 03205 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 03206 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239380, 616, BothDirectory, 1, (316, 0, 0, 0, 1239380, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 03207 432 NtClose (316, ... ) == 0x0 03208 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 03209 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239284, 616, BothDirectory, 1, (316, 0, 0, 0, 1239284, 616, BothDirectory, 1, "Documents", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 03210 432 NtClose (316, ... ) == 0x0 03211 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03212 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03213 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234656, ... ) }, 1234656, ... ) == 0x0 03214 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03215 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03216 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03217 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03218 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03219 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03220 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03221 432 NtReadFile (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03222 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03223 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03224 432 NtClose (316, ... ) == 0x0 03225 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03226 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03227 432 NtClose (316, ... ) == 0x0 03228 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03229 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03230 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234628, ... ) }, 1234628, ... ) == 0x0 03231 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03232 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03233 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03234 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03235 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03236 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03237 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03238 432 NtReadFile (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03239 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03240 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03241 432 NtClose (316, ... ) == 0x0 03242 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03243 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03244 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234992, ... ) }, 1234992, ... ) == 0x0 03245 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03246 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03247 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03248 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03249 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03250 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03251 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03252 432 NtReadFile (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03253 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03254 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03255 432 NtClose (316, ... ) == 0x0 03256 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03257 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03258 432 NtClose (316, ... ) == 0x0 03259 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03260 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03261 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234992, ... ) }, 1234992, ... ) == 0x0 03262 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03263 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03264 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03265 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03266 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03267 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03268 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03269 432 NtReadFile (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03270 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03271 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03272 432 NtClose (316, ... ) == 0x0 03273 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03274 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03275 432 NtClose (316, ... ) == 0x0 03276 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03277 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03278 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234992, ... ) }, 1234992, ... ) == 0x0 03279 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03280 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03281 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03282 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03283 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03284 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03285 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03286 432 NtReadFile (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (316, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03287 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03288 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03289 432 NtClose (316, ... ) == 0x0 03290 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03291 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03292 432 NtClose (316, ... ) == 0x0 03293 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\"}, 3, 16417, ... 316, {status=0x0, info=1}, ) }, 3, 16417, ... 316, {status=0x0, info=1}, ) == 0x0 03294 432 NtQueryDirectoryFile (316, 0, 0, 0, 1239208, 616, BothDirectory, 1, (316, 0, 0, 0, 1239208, 616, BothDirectory, 1, "My Pictures", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 03295 432 NtClose (316, ... ) == 0x0 03296 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03297 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03298 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 1234580, ... ) }, 1234580, ... ) == 0x0 03299 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03300 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03301 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03302 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03303 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03304 432 NtAllocateVirtualMemory (-1, 0, 0, 1048730, 8192, 4, ... 11206656, 1052672, ) == 0x0 03305 432 NtAllocateVirtualMemory (-1, 11206656, 0, 154, 4096, 4, ... 11206656, 4096, ) == 0x0 03306 432 NtReadFile (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\system32\mydocs.dll\15\12IconIndex=-101\15\12LocalizedResourceName=@shell32.dll,-28997\15\12", ) , ) == 0x0 03307 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03308 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03309 432 NtClose (316, ... ) == 0x0 03310 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03311 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03312 432 NtClose (316, ... ) == 0x0 03313 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03314 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03315 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 1234552, ... ) }, 1234552, ... ) == 0x0 03316 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03317 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03318 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03319 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03320 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03321 432 NtAllocateVirtualMemory (-1, 0, 0, 1048730, 8192, 4, ... 11206656, 1052672, ) == 0x0 03322 432 NtAllocateVirtualMemory (-1, 11206656, 0, 154, 4096, 4, ... 11206656, 4096, ) == 0x0 03323 432 NtReadFile (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\system32\mydocs.dll\15\12IconIndex=-101\15\12LocalizedResourceName=@shell32.dll,-28997\15\12", ) , ) == 0x0 03324 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03325 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03326 432 NtClose (316, ... ) == 0x0 03327 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03328 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03329 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 1234916, ... ) }, 1234916, ... ) == 0x0 03330 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03331 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03332 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03333 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03334 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03335 432 NtAllocateVirtualMemory (-1, 0, 0, 1048730, 8192, 4, ... 11206656, 1052672, ) == 0x0 03336 432 NtAllocateVirtualMemory (-1, 11206656, 0, 154, 4096, 4, ... 11206656, 4096, ) == 0x0 03337 432 NtReadFile (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\system32\mydocs.dll\15\12IconIndex=-101\15\12LocalizedResourceName=@shell32.dll,-28997\15\12", ) , ) == 0x0 03338 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03339 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03340 432 NtClose (316, ... ) == 0x0 03341 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03342 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03343 432 NtClose (316, ... ) == 0x0 03344 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03345 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03346 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 1234916, ... ) }, 1234916, ... ) == 0x0 03347 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03348 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03349 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03350 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03351 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03352 432 NtAllocateVirtualMemory (-1, 0, 0, 1048730, 8192, 4, ... 11206656, 1052672, ) == 0x0 03353 432 NtAllocateVirtualMemory (-1, 11206656, 0, 154, 4096, 4, ... 11206656, 4096, ) == 0x0 03354 432 NtReadFile (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\system32\mydocs.dll\15\12IconIndex=-101\15\12LocalizedResourceName=@shell32.dll,-28997\15\12", ) , ) == 0x0 03355 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03356 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03357 432 NtClose (316, ... ) == 0x0 03358 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03359 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03360 432 NtClose (316, ... ) == 0x0 03361 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03362 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03363 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 1234916, ... ) }, 1234916, ... ) == 0x0 03364 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03365 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03366 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini"}, 7, 96, ... 316, {status=0x0, info=1}, ) }, 7, 96, ... 316, {status=0x0, info=1}, ) == 0x0 03367 432 NtLockFile (316, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03368 432 NtQueryInformationFile (316, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03369 432 NtAllocateVirtualMemory (-1, 0, 0, 1048730, 8192, 4, ... 11206656, 1052672, ) == 0x0 03370 432 NtAllocateVirtualMemory (-1, 11206656, 0, 154, 4096, 4, ... 11206656, 4096, ) == 0x0 03371 432 NtReadFile (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, (316, 0, 0, 0, 150, 0x0, 2012046884, ... {status=0x0, info=150}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12688\15\12IconFile=%SystemRoot%\system32\mydocs.dll\15\12IconIndex=-101\15\12LocalizedResourceName=@shell32.dll,-28997\15\12", ) , ) == 0x0 03372 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03373 432 NtUnlockFile (316, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03374 432 NtClose (316, ... ) == 0x0 03375 432 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 03376 432 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03377 432 NtClose (316, ... ) == 0x0 03378 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03379 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03380 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03381 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03382 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03383 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03384 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03385 432 NtAllocateVirtualMemory (-1, 1441792, 0, 4096, 4096, 4, ... 1441792, 4096, ) == 0x0 03386 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES"}, 138, ) }, 138, ) == 0x0 03387 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03388 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\InProcServer32"}, ... 316, ) }, ... 316, ) == 0x0 03389 432 NtQueryKey (318, Name, 392, ... {Name= (318, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\InProcServer32"}, 192, ) }, 192, ) == 0x0 03390 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03391 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 312, ) == 0x0 03392 432 NtQueryInformationToken (312, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03393 432 NtClose (312, ... ) == 0x0 03394 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03395 432 NtQueryValueKey (318, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (318, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0S\0H\0E\0L\0L\03\02\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 03396 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1237152, ... ) }, 1237152, ... ) == 0x0 03397 432 NtClose (318, ... ) == 0x0 03398 432 NtReleaseSemaphore (220, 1, ... 0, ) == 0x0 03399 432 NtWaitForSingleObject (220, 0, {0, 0}, ... ) == 0x0 03400 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03401 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 316, ) }, ... 316, ) == 0x0 03402 432 NtQueryValueKey (316, (316, "NoSharedDocuments", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03403 432 NtClose (316, ... ) == 0x0 03404 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03405 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 316, ) == 0x0 03406 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03407 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03408 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1238980, (0xc0100080, {24, 0, 0x40, 0, 1238980, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 312, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 312, {status=0x0, info=1}, ) == 0x0 03409 432 NtSetInformationFile (312, 1239036, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 03410 432 NtSetInformationFile (312, 1239028, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 03411 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03412 432 NtWriteFile (312, 261, 0, 0, (312, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 03413 432 NtReadFile (312, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (312, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\357#\0\0\15\0\PIPE\wkssvc\0\200\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 03414 432 NtFsControlFile (312, 261, 0x0, 0x0, 0x11c017, (312, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\357#\0\0\15\0\PIPE\wkssvc\0\200\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 32, 1024, ... {status=0x103, info=68}, (312, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\357#\0\0\15\0\PIPE\wkssvc\0\200\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 03415 432 NtClose (316, ... ) == 0x0 03416 432 NtClose (312, ... ) == 0x0 03417 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03418 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03419 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03420 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03421 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 312, 2, ) }, 0, 0x0, 0, ... 312, 2, ) == 0x0 03422 432 NtQueryValueKey (312, (312, "CommonMusic", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03423 432 NtClose (312, ... ) == 0x0 03424 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 312, ) }, ... 312, ) == 0x0 03425 432 NtQueryValueKey (312, (312, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (312, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) }, 86, ) == 0x0 03426 432 NtClose (312, ... ) == 0x0 03427 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 312, ) }, ... 312, ) == 0x0 03428 432 NtQueryValueKey (312, (312, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (312, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) }, 32, ) == 0x0 03429 432 NtClose (312, ... ) == 0x0 03430 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music"}, 1241200, ... ) }, 1241200, ... ) == 0x0 03431 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 312, 2, ) }, 0, 0x0, 0, ... 312, 2, ) == 0x0 03432 432 NtSetValueKey (312, (312, "CommonMusic", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0M\0u\0s\0i\0c\0\0\0", 110, ... ) , 0, 1, (312, "CommonMusic", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\\0M\0y\0 \0M\0u\0s\0i\0c\0\0\0", 110, ... ) , 110, ... ) == 0x0 03433 432 NtClose (312, ... ) == 0x0 03434 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1239612, ... ) }, 1239612, ... ) == 0x0 03435 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 312, {status=0x0, info=1}, ) }, 5, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03436 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 312, ... 316, ) == 0x0 03437 432 NtClose (312, ... ) == 0x0 03438 432 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xab0000), 0x0, 262144, ) == 0x0 03439 432 NtClose (316, ... ) == 0x0 03440 432 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 03441 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03442 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03443 432 NtOpenKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 316, ) }, ... 316, ) == 0x0 03444 432 NtOpenKey (0x2000000, {24, 316, 0x40, 0, 0, (0x2000000, {24, 316, 0x40, 0, 0, "{1a0315e9-a4ba-11db-9d02-806d6172696f}\"}, ... 312, ) }, ... 312, ) == 0x0 03445 432 NtClose (316, ... ) == 0x0 03446 432 NtQueryValueKey (312, (312, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (312, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03447 432 NtClose (312, ... ) == 0x0 03448 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 312, {status=0x0, info=1}, ) }, 3, 16417, ... 312, {status=0x0, info=1}, ) == 0x0 03449 432 NtQueryDirectoryFile (312, 0, 0, 0, 1239504, 616, BothDirectory, 1, (312, 0, 0, 0, 1239504, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 03450 432 NtClose (312, ... ) == 0x0 03451 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 312, {status=0x0, info=1}, ) }, 3, 16417, ... 312, {status=0x0, info=1}, ) == 0x0 03452 432 NtQueryDirectoryFile (312, 0, 0, 0, 1239392, 616, BothDirectory, 1, (312, 0, 0, 0, 1239392, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 03453 432 NtClose (312, ... ) == 0x0 03454 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 312, {status=0x0, info=1}, ) }, 3, 16417, ... 312, {status=0x0, info=1}, ) == 0x0 03455 432 NtQueryDirectoryFile (312, 0, 0, 0, 1239300, 616, BothDirectory, 1, (312, 0, 0, 0, 1239300, 616, BothDirectory, 1, "Documents", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 03456 432 NtClose (312, ... ) == 0x0 03457 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03458 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03459 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234672, ... ) }, 1234672, ... ) == 0x0 03460 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03461 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03462 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03463 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03464 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03465 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03466 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03467 432 NtReadFile (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03468 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03469 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03470 432 NtClose (312, ... ) == 0x0 03471 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03472 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03473 432 NtClose (312, ... ) == 0x0 03474 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03475 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03476 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1234644, ... ) }, 1234644, ... ) == 0x0 03477 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03478 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03479 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03480 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03481 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03482 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03483 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03484 432 NtReadFile (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03485 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03486 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03487 432 NtClose (312, ... ) == 0x0 03488 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03489 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03490 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1235008, ... ) }, 1235008, ... ) == 0x0 03491 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03492 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03493 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03494 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03495 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03496 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03497 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03498 432 NtReadFile (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03499 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03500 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03501 432 NtClose (312, ... ) == 0x0 03502 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03503 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03504 432 NtClose (312, ... ) == 0x0 03505 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03506 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03507 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1235008, ... ) }, 1235008, ... ) == 0x0 03508 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03509 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03510 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03511 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03512 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03513 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03514 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03515 432 NtReadFile (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03516 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03517 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03518 432 NtClose (312, ... ) == 0x0 03519 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03520 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03521 432 NtClose (312, ... ) == 0x0 03522 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03523 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03524 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1235008, ... ) }, 1235008, ... ) == 0x0 03525 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03526 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03527 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03528 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03529 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03530 432 NtAllocateVirtualMemory (-1, 0, 0, 1048718, 8192, 4, ... 11206656, 1052672, ) == 0x0 03531 432 NtAllocateVirtualMemory (-1, 11206656, 0, 142, 4096, 4, ... 11206656, 4096, ) == 0x0 03532 432 NtReadFile (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, (312, 0, 0, 0, 138, 0x0, 2012046884, ... {status=0x0, info=138}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on SRI-S3S1K11CZE9\15\12", ) , ) == 0x0 03533 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03534 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03535 432 NtClose (312, ... ) == 0x0 03536 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03537 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03538 432 NtClose (312, ... ) == 0x0 03539 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\"}, 3, 16417, ... 312, {status=0x0, info=1}, ) }, 3, 16417, ... 312, {status=0x0, info=1}, ) == 0x0 03540 432 NtQueryDirectoryFile (312, 0, 0, 0, 1239228, 616, BothDirectory, 1, (312, 0, 0, 0, 1239228, 616, BothDirectory, 1, "My Music", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03541 432 NtClose (312, ... ) == 0x0 03542 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03543 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03544 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 1234600, ... ) }, 1234600, ... ) == 0x0 03545 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03546 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03547 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03548 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03549 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03550 432 NtAllocateVirtualMemory (-1, 0, 0, 1048731, 8192, 4, ... 11206656, 1052672, ) == 0x0 03551 432 NtAllocateVirtualMemory (-1, 11206656, 0, 155, 4096, 4, ... 11206656, 4096, ) == 0x0 03552 432 NtReadFile (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12689\15\12IconFile=%SystemRoot%\system32\SHELL32.dll\15\12IconIndex=-237\15\12LocalizedResourceName=@shell32.dll,-28995\15\12", ) , ) == 0x0 03553 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03554 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03555 432 NtClose (312, ... ) == 0x0 03556 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03557 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03558 432 NtClose (312, ... ) == 0x0 03559 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03560 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03561 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 1234572, ... ) }, 1234572, ... ) == 0x0 03562 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03563 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03564 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03565 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03566 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03567 432 NtAllocateVirtualMemory (-1, 0, 0, 1048731, 8192, 4, ... 11206656, 1052672, ) == 0x0 03568 432 NtAllocateVirtualMemory (-1, 11206656, 0, 155, 4096, 4, ... 11206656, 4096, ) == 0x0 03569 432 NtReadFile (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12689\15\12IconFile=%SystemRoot%\system32\SHELL32.dll\15\12IconIndex=-237\15\12LocalizedResourceName=@shell32.dll,-28995\15\12", ) , ) == 0x0 03570 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03571 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03572 432 NtClose (312, ... ) == 0x0 03573 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03574 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03575 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 1234936, ... ) }, 1234936, ... ) == 0x0 03576 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03577 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03578 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03579 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03580 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03581 432 NtAllocateVirtualMemory (-1, 0, 0, 1048731, 8192, 4, ... 11206656, 1052672, ) == 0x0 03582 432 NtAllocateVirtualMemory (-1, 11206656, 0, 155, 4096, 4, ... 11206656, 4096, ) == 0x0 03583 432 NtReadFile (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12689\15\12IconFile=%SystemRoot%\system32\SHELL32.dll\15\12IconIndex=-237\15\12LocalizedResourceName=@shell32.dll,-28995\15\12", ) , ) == 0x0 03584 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03585 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03586 432 NtClose (312, ... ) == 0x0 03587 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03588 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03589 432 NtClose (312, ... ) == 0x0 03590 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03591 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03592 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 1234936, ... ) }, 1234936, ... ) == 0x0 03593 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03594 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03595 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03596 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03597 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03598 432 NtAllocateVirtualMemory (-1, 0, 0, 1048731, 8192, 4, ... 11206656, 1052672, ) == 0x0 03599 432 NtAllocateVirtualMemory (-1, 11206656, 0, 155, 4096, 4, ... 11206656, 4096, ) == 0x0 03600 432 NtReadFile (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12689\15\12IconFile=%SystemRoot%\system32\SHELL32.dll\15\12IconIndex=-237\15\12LocalizedResourceName=@shell32.dll,-28995\15\12", ) , ) == 0x0 03601 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03602 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03603 432 NtClose (312, ... ) == 0x0 03604 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03605 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03606 432 NtClose (312, ... ) == 0x0 03607 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03608 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03609 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 1234936, ... ) }, 1234936, ... ) == 0x0 03610 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03611 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03612 432 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Music\desktop.ini"}, 7, 96, ... 312, {status=0x0, info=1}, ) }, 7, 96, ... 312, {status=0x0, info=1}, ) == 0x0 03613 432 NtLockFile (312, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=-2142329745}, ) == 0x0 03614 432 NtQueryInformationFile (312, 1420864, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03615 432 NtAllocateVirtualMemory (-1, 0, 0, 1048731, 8192, 4, ... 11206656, 1052672, ) == 0x0 03616 432 NtAllocateVirtualMemory (-1, 11206656, 0, 155, 4096, 4, ... 11206656, 4096, ) == 0x0 03617 432 NtReadFile (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, (312, 0, 0, 0, 151, 0x0, 2012046884, ... {status=0x0, info=151}, "[.ShellClassInfo]\15\12InfoTip=@Shell32.dll,-12689\15\12IconFile=%SystemRoot%\system32\SHELL32.dll\15\12IconIndex=-237\15\12LocalizedResourceName=@shell32.dll,-28995\15\12", ) , ) == 0x0 03618 432 NtFreeVirtualMemory (-1, (0xab0000), 1052672, 32768, ... (0xab0000), 1052672, ) == 0x0 03619 432 NtUnlockFile (312, {0, 0}, {-1, -1}, 432, ... ) == STATUS_RANGE_NOT_LOCKED 03620 432 NtClose (312, ... ) == 0x0 03621 432 NtOpenProcessToken (-1, 0x8, ... 312, ) == 0x0 03622 432 NtQueryInformationToken (312, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 03623 432 NtClose (312, ... ) == 0x0 03624 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03625 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03626 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03627 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03628 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03629 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03630 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03631 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03632 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03633 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 03634 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 03635 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 312, 2, ) }, 0, 0x0, 0, ... 312, 2, ) == 0x0 03636 432 NtQueryValueKey (312, (312, "CommonVideo", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03637 432 NtClose (312, ... ) == 0x0 03638 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 312, ) }, ... 312, ) == 0x0 03639 432 NtQueryValueKey (312, (312, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (312, "ProfilesDirectory", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0D\0r\0i\0v\0e\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\0\0"}, 86, ) }, 86, ) == 0x0 03640 432 NtClose (312, ... ) == 0x0 03641 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\ProfileList"}, ... 312, ) }, ... 312, ) == 0x0 03642 432 NtQueryValueKey (312, (312, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (312, "AllUsersProfile", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0"}, 32, ) }, 32, ) == 0x0 03643 432 NtClose (312, ... ) == 0x0 03644 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\My Videos"}, 1241200, ... ) }, 1241200, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03645 432 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 312, 2, ) }, 0, 0x0, 0, ... 312, 2, ) == 0x0 03646 432 NtSetValueKey (312, (312, "CommonVideo", 0, 1, "\0\0", 2, ... ) , 0, 1, (312, "CommonVideo", 0, 1, "\0\0", 2, ... ) , 2, ... ) == 0x0 03647 432 NtClose (312, ... ) == 0x0 03648 432 NtWriteFile (304, 0, 0, 0, (304, 0, 0, 0, "L\0\0\0\1\24\2\0\0\0\0\0\300\0\0\0\0\0\0F\217\0\0\0 \0\0\0\200GE\370\360\22\310\1\0\330\255\324\346\22\310\1\0k\306A\361\22\310\1\08\1\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\09\1\24\0\37P\340O\320 \352:i\20\242\330\10\0+00\235\31\0/C:\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0J\01\0\0\0\0\006\31\211\21\0PROGRA~1\0\02\0\3\0\4\0\357\27606\342\0w6\08\24\0\0\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0\30\0H\01\0\0\0\0\006\342\0\20\0COMMON~1\0\00\0\3\0\4\0\357\27606\342\0/6\08\24\0\0\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0\30\0<\01\0\0\0\0\0T7\222A\22\0CARLSON\0&\0\3\0\4\0\357\276T7\222AT7\08\24\0\0\0C\0a\0r\0l\0s\0o\0n\0\0\0\26\0<\02\0\08\1\0T7\323A \0carlton\0&\0\3\0\4\0\357\276T7\222AT7\08\24\0\0\0c\0a\0r\0l\0t\0o\0n\0\0\0\26\0\0\0\\0\0\0\34\0\0\0\1\0\0\0\34\0\0\0-\0\0\0\0\0\0\0[\0\0\0\21\0\0\0\3\0\0\0\350\35\361<\20\0\0\0\0C:\Program Files\Common Files\Carlson\carlton\0\0\17\0I\0n\0t\0e\0r\0n\0e\0t", 639, 0x0, 0, ... {status=0x0, info=639}, ) , 639, 0x0, 0, ... {status=0x0, info=639}, ) == 0x0 03649 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES"}, 138, ) }, 138, ) == 0x0 03650 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03651 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 312, ) }, ... 312, ) == 0x0 03652 432 NtQueryKey (314, Name, 392, ... {Name= (314, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 03653 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03654 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 316, ) == 0x0 03655 432 NtQueryInformationToken (316, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03656 432 NtClose (316, ... ) == 0x0 03657 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03658 432 NtEnumerateKey (314, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name= (314, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 03659 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03660 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03661 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 316, ) }, ... 316, ) == 0x0 03662 432 NtQueryKey (318, Name, 392, ... {Name= (318, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 03663 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03664 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 320, ) == 0x0 03665 432 NtQueryInformationToken (320, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03666 432 NtClose (320, ... ) == 0x0 03667 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03668 432 NtQueryValueKey (318, (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 03669 432 NtClose (318, ... ) == 0x0 03670 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03671 432 NtEnumerateKey (314, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 03672 432 NtClose (314, ... ) == 0x0 03673 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 03674 432 NtUserQueryWindow (65644, 1, ... ) == 0x7b8 03675 432 NtCreateSection (0xf0007, 0x0, {396, 0}, 4, 134217728, 0, ... 312, ) == 0x0 03676 432 NtMapViewOfSection (312, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03677 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 316, ) == 0x0 03678 432 NtDuplicateObject (-1, 312, 316, 0xf001f, 0, 2, ... 780, ) == 0x0 03679 432 NtClose (316, ... ) == 0x0 03680 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03681 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03682 432 NtClose (312, ... ) == 0x0 03683 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 312, ) == 0x0 03684 432 NtDuplicateObject (312, 780, -1, 0xf001f, 0, 2, ... 316, ) == 0x0 03685 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03686 432 NtClose (312, ... ) == 0x0 03687 432 NtMapViewOfSection (316, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03688 432 NtClose (316, ... ) == 0x0 03689 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03690 432 NtUserMessageCall (0x1006c, WM_USER+0x3, 0x30c, 0x77c, 0, 695, 0, ... ) == 0x1 03691 432 NtClose (304, ... ) == 0x0 03692 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03693 432 NtOpenKey (0x2000000, {24, 214, 0x40, 0, 0, (0x2000000, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03694 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 304, ) }, ... 304, ) == 0x0 03695 432 NtQueryKey (306, Name, 392, ... {Name= (306, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 03696 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03697 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 316, ) == 0x0 03698 432 NtQueryInformationToken (316, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03699 432 NtClose (316, ... ) == 0x0 03700 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03701 432 NtEnumerateKey (306, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name= (306, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 03702 432 NtQueryKey (214, Name, 384, ... {Name= (214, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03703 432 NtOpenKey (0x1, {24, 214, 0x40, 0, 0, (0x1, {24, 214, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03704 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 316, ) }, ... 316, ) == 0x0 03705 432 NtQueryKey (318, Name, 392, ... {Name= (318, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 03706 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03707 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 312, ) == 0x0 03708 432 NtQueryInformationToken (312, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03709 432 NtClose (312, ... ) == 0x0 03710 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03711 432 NtQueryValueKey (318, (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (318, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 03712 432 NtClose (318, ... ) == 0x0 03713 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03714 432 NtEnumerateKey (306, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 03715 432 NtClose (306, ... ) == 0x0 03716 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 03717 432 NtUserQueryWindow (65644, 1, ... ) == 0x7b8 03718 432 NtCreateSection (0xf0007, 0x0, {396, 0}, 4, 134217728, 0, ... 304, ) == 0x0 03719 432 NtMapViewOfSection (304, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03720 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 316, ) == 0x0 03721 432 NtDuplicateObject (-1, 304, 316, 0xf001f, 0, 2, ... 780, ) == 0x0 03722 432 NtClose (316, ... ) == 0x0 03723 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03724 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03725 432 NtClose (304, ... ) == 0x0 03726 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 304, ) == 0x0 03727 432 NtDuplicateObject (304, 780, -1, 0xf001f, 0, 2, ... 316, ) == 0x0 03728 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03729 432 NtClose (304, ... ) == 0x0 03730 432 NtMapViewOfSection (316, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03731 432 NtClose (316, ... ) == 0x0 03732 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03733 432 NtUserMessageCall (0x1006c, WM_USER+0x3, 0x30c, 0x77c, 0, 695, 0, ... ) == 0x1 03734 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 03735 432 NtUserQueryWindow (65644, 1, ... ) == 0x7b8 03736 432 NtCreateSection (0xf0007, 0x0, {56, 0}, 4, 134217728, 0, ... 316, ) == 0x0 03737 432 NtMapViewOfSection (316, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03738 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 304, ) == 0x0 03739 432 NtDuplicateObject (-1, 316, 304, 0xf001f, 0, 2, ... 780, ) == 0x0 03740 432 NtClose (304, ... ) == 0x0 03741 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03742 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03743 432 NtClose (316, ... ) == 0x0 03744 432 NtOpenProcess (0x40, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 316, ) == 0x0 03745 432 NtDuplicateObject (316, 780, -1, 0xf001f, 0, 2, ... 304, ) == 0x0 03746 432 NtClose (-1, ... ) == STATUS_INVALID_HANDLE 03747 432 NtClose (316, ... ) == 0x0 03748 432 NtMapViewOfSection (304, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 4096, ) == 0x0 03749 432 NtClose (304, ... ) == 0x0 03750 432 NtUnmapViewOfSection (-1, 0xa70000, ... ) == 0x0 03751 432 NtUserMessageCall (0x1006c, WM_USER+0x3, 0x30c, 0x77c, 0, 695, 0, ... ) == 0x1 03752 432 NtClose (216, ... ) == 0x0 03753 432 NtQueryDefaultLocale (1, 1244036, ... ) == 0x0 03754 432 NtQueryDefaultLocale (1, 1244016, ... ) == 0x0 03755 432 NtCreateKey (0xf003f, {24, 60, 0x40, 0, 0, (0xf003f, {24, 60, 0x40, 0, 0, "Software\Carlson\Connection\carlton"}, 0, 0x0, 0, ... ) }, 0, 0x0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03756 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software"}, 0, 0x0, 0, ... 216, 2, ) }, 0, 0x0, 0, ... 216, 2, ) == 0x0 03757 432 NtCreateKey (0x2000000, {24, 216, 0x40, 0, 0, (0x2000000, {24, 216, 0x40, 0, 0, "Carlson"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 03758 432 NtSetInformationFile (-2147482700, -131038172, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03759 432 NtSetInformationFile (-2147482700, -131038208, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03760 432 NtSetInformationFile (-2147482700, -131038644, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03761 432 NtSetInformationFile (-2147482700, -131038460, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03762 432 NtSetInformationFile (-2147482700, -131038268, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03757 432 NtCreateKey ... 304, 1, ) == 0x0 03763 432 NtClose (216, ... ) == 0x0 03764 432 NtCreateKey (0x2000000, {24, 304, 0x40, 0, 0, (0x2000000, {24, 304, 0x40, 0, 0, "Connection"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 03765 432 NtSetInformationFile (-2147482700, -131038540, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03764 432 NtCreateKey ... 216, 1, ) == 0x0 03766 432 NtClose (304, ... ) == 0x0 03767 432 NtCreateKey (0xf003f, {24, 216, 0x40, 0, 0, (0xf003f, {24, 216, 0x40, 0, 0, "carlton"}, 0, 0x0, 0, ... 304, 1, ) }, 0, 0x0, 0, ... 304, 1, ) == 0x0 03768 432 NtClose (216, ... ) == 0x0 03769 432 NtSetValueKey (304, (304, "uninstExe", 0, 1, "C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\\0C\0a\0r\0l\0s\0o\0n\0\\0c\0a\0r\0l\0t\0o\0n\0\0\0", 92, ... ) , 0, 1, (304, "uninstExe", 0, 1, "C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\\0C\0a\0r\0l\0s\0o\0n\0\\0c\0a\0r\0l\0t\0o\0n\0\0\0", 92, ... ) , 92, ... ) == 0x0 03770 432 NtSetValueKey (304, (304, "uninstShortcut", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\\0c\0a\0r\0l\0t\0o\0n\0\0\0", 110, ... , 0, 1, (304, "uninstShortcut", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0S\0t\0a\0r\0t\0 \0M\0e\0n\0u\0\\0c\0a\0r\0l\0t\0o\0n\0\0\0", 110, ... , 110, ... 03771 432 NtSetInformationFile (-2147482700, -131037836, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03770 432 NtSetValueKey ... ) == 0x0 03772 432 NtClose (304, ... ) == 0x0 03773 432 NtCreateKey (0xf003f, {24, 48, 0x40, 0, 0, (0xf003f, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Carlson"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 03774 432 NtSetInformationFile (-2147482808, -131038172, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03775 432 NtSetInformationFile (-2147482808, -131038644, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03776 432 NtSetInformationFile (-2147482808, -131038268, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 03773 432 NtCreateKey ... 304, 1, ) == 0x0 03777 432 NtSetValueKey (304, (304, "DisplayName", 0, 1, "C\0a\0r\0l\0s\0o\0n\0 \0D\0i\0a\0l\0e\0r\0\0\0", 30, ... ) , 0, 1, (304, "DisplayName", 0, 1, "C\0a\0r\0l\0s\0o\0n\0 \0D\0i\0a\0l\0e\0r\0\0\0", 30, ... ) , 30, ... ) == 0x0 03778 432 NtSetValueKey (304, (304, "UninstallString", 0, 1, "C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\\0C\0a\0r\0l\0s\0o\0n\0\\0c\0a\0r\0l\0t\0o\0n\0 \0-\0u\0\0\0", 98, ... ) , 0, 1, (304, "UninstallString", 0, 1, "C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\\0C\0a\0r\0l\0s\0o\0n\0\\0c\0a\0r\0l\0t\0o\0n\0 \0-\0u\0\0\0", 98, ... ) , 98, ... ) == 0x0 03779 432 NtClose (304, ... ) == 0x0 03780 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 03781 432 NtUserQueryWindow (65644, 1, ... ) == 0x7b8 03782 432 NtQueryDefaultLocale (1, 1244484, ... ) == 0x0 03783 432 NtGdiCreateCompatibleDC (0, ... ) == 0x801040b 03784 432 NtGdiGetTextCharsetInfo (134284299, 0, 0, ... ) == 0x0 03785 432 NtGdiHfontCreate (1243812, 356, 0, 0, 1343792, ... ) == 0x90a040c 03786 432 NtGdiGetTextMetricsW (134284299, 1244120, 68, ... 03787 432 NtQueryInformationFile (304, -131037824, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03788 432 NtQueryInformationFile (304, -131037904, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 03789 432 NtQueryVolumeInformationFile (304, -131038440, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 03790 432 NtClose (304, ... ) == 0x0 03786 432 NtGdiGetTextMetricsW ... ) == 0x1 03791 432 NtGdiGetTextFaceW (134284299, 32, 1244256, 1, ... ) == 0xe 03792 432 NtGdiGetWidthTable (134284299, 52, 1444624, 308, 1445240, 1420824, 1420840, ... ) == 0x1 03793 432 NtGdiDeleteObjectApp (134284299, ... ) == 0x1 03794 432 NtUserGetAtomName (32770, 1243256, ... ) == 0x6 03795 432 NtUserCreateWindowEx (-2147417343, 32770, 32770, "", -2134238524, 350, 257, 324, 255, 65556, 0, 4194304, 0, 1073742848, 0, ... 03796 432 NtUserSetWindowFNID (65734, 676, ... ) == 0x1 03797 432 NtUserCallHwndParam (65734, 1375396, 78, ... ) == 0x14fca4 03798 432 NtUserMessageCall (0x100c6, WM_NCCREATE, 0x0, 0x12f81c, 0, 670, 1, ... ) == 0x1 03799 432 NtUserMessageCall (0x100c6, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03800 432 NtUserGetClassName (65734, 0, 1242400, ... ) == 0x6 03801 432 NtUserRemoveProp (65734, 43282, ... ) == 0x0 03802 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 1241960, 2000809832, 1242496, 2012750850} (24, {24, 52, new_msg, 0, 1241960, 2000809832, 1242496, 2012750850} "\0\0\0\0\5\4\3\0\365\26\365w\315\27\365w\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1518, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\315\27\365w\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1518, 0} (24, {24, 52, new_msg, 0, 1241960, 2000809832, 1242496, 2012750850} "\0\0\0\0\5\4\3\0\365\26\365w\315\27\365w\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1518, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\315\27\365w\260\1\0\0\0\0\0\0" ) ) == 0x0 03803 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 03804 432 NtUserGetObjectInformation (40, 2, 1242076, 520, 0, ... ) == 0x1 03805 432 NtGdiDeleteObjectApp (202376195, ... ) == 0x1 03806 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03807 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03808 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03809 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03810 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03811 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03812 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03813 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03814 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03815 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03816 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03817 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03818 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03819 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03820 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03821 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03822 432 NtUserGetWindowDC (0, ... ) == 0x1010051 03823 432 NtGdiCreatePatternBrushInternal (59048369, 0, 0, ... ) == 0xd100403 03824 432 NtUserCallOneParam (16842833, 56, ... ) == 0x1 03825 432 NtUserSetProp (65734, 43288, 3306336, ... ) == 0x1 03795 432 NtUserCreateWindowEx ... ) == 0x100c6 03826 432 NtUserGetSystemMenu (65734, 0, ... 03827 432 NtQueryDefaultLocale (1, 1244156, ... ) == 0x0 03828 432 NtUserCallNoParam (0, ... ) == 0x2006b 03829 432 NtUserCallNoParam (0, ... 03830 432 NtAllocateVirtualMemory (-1, 6393856, 0, 4096, 4096, 32, ... 6393856, 4096, ) == 0x0 03829 432 NtUserCallNoParam ... ) == 0x2006d 03831 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03832 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03833 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03834 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03835 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03836 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 0, ... ) == 0x1 03837 432 NtUserThunkedMenuItemInfo (131181, -1, 1, 1, 1244196, 1244244, ... ) == 0x1 03838 432 NtUserThunkedMenuItemInfo (131179, -1, 1, 1, 1244292, 1244340, ... ) == 0x1 03826 432 NtUserGetSystemMenu ... ) == 0x2006d 03839 432 NtFlushInstructionCache (-1, 1413064, 13, ... ) == 0x0 03840 432 NtUserGetAtomName (49175, 1243256, ... ) == 0x6 03841 432 NtUserCreateWindowEx (-2147483644, 49175, 49175, (-2147483644, 49175, 49175, "&Connect", 1476460545, 233, 185, 75, 23, 65734, 1, 4194304, 0, 1073742848, 0, ... , 1476460545, 233, 185, 75, 23, 65734, 1, 4194304, 0, 1073742848, 0, ... 03842 432 NtUserSetWindowFNID (65736, 673, ... ) == 0x1 03843 432 NtUserSetWindowLong (65736, 0, 1424644, 0, ... ) == 0x0 03844 432 NtUserMessageCall (0x100c8, WM_NCCREATE, 0x0, 0x12f80c, 0, 670, 1, ... ) == 0x1 03845 432 NtUserMessageCall (0x100c8, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03846 432 NtUserSetProp (65736, 43288, -1, ... ) == 0x1 03841 432 NtUserCreateWindowEx ... ) == 0x100c8 03847 432 NtUserGetAtomName (49180, 1243256, ... ) == 0x8 03848 432 NtUserCreateWindowEx (-2147483132, 49180, 49180, "", 1478557955, 74, 93, 234, 125, 65734, 201, 4194304, 0, 1073742848, 0, ... 03849 432 NtUserSetWindowFNID (65738, 674, ... ) == 0x1 03850 432 NtUserSetWindowLong (65738, 0, 1445684, 0, ... ) == 0x0 03851 432 NtUserCallHwndParam (65738, 3330, 81, ... ) == 0xbc649719 03852 432 NtUserCallHwndParam (65738, 3760, 76, ... ) == 0xbc64971a 03853 432 NtUserCallHwndParam (65738, 2307, 76, ... ) == 0xbc649715 03854 432 NtUserMessageCall (0x100ca, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03855 432 NtUserSetProp (65738, 43288, -1, ... ) == 0x1 03856 432 NtUserGetDC (65738, ... ) == 0x1010050 03857 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 03858 432 NtUserCreateWindowEx (128, 49182, 49182, 0x0, 1554022467, 0, 24, 234, 101, 65738, 1000, 4194304, 0, 1024, 0, ... 03859 432 NtUserSetWindowFNID (65740, 678, ... ) == 0x1 03860 432 NtUserSetWindowLong (65740, 0, 1408528, 0, ... ) == 0x0 03861 432 NtUserMessageCall (0x100cc, WM_NCCREATE, 0x0, 0x12f03c, 0, 670, 0, ... ) == 0x1 03862 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x0, 0x12f064, 0, 670, 0, ... ) == 0x0 03863 432 NtUserGetClassName (65738, 0, 1240120, ... ) == 0x8 03864 432 NtUserGetClassName (65740, 0, 1240388, ... ) == 0x9 03865 432 NtUserRemoveProp (65740, 43282, ... ) == 0x0 03866 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 2012550797, 1998325665, 1310720, 0} (24, {24, 52, new_msg, 0, 2012550797, 1998325665, 1310720, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1519, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1519, 0} (24, {24, 52, new_msg, 0, 2012550797, 1998325665, 1310720, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1519, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\260\1\0\0\0\0\0\0" ) ) == 0x0 03867 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 03868 432 NtUserGetObjectInformation (40, 2, 1240060, 520, 0, ... ) == 0x1 03869 432 NtUserSetProp (65740, 43288, 3307488, ... ) == 0x1 03870 432 NtUserGetDC (65740, ... ) == 0x1010052 03871 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03872 432 NtUserPostMessage (65740, 5, 0, 0, ... ) == 0x1 03873 432 NtUserSetWindowPos (65740, 0, 0, 0, 234, 98, 22, ... 03874 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12ee40, 0, 670, 0, ... ) == 0x0 03875 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12ee14, 0, 670, 0, ... ) == 0x0 03876 432 NtUserSetScrollInfo (65740, 1, 1239416, 0, ... 03877 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12e87c, 0, 670, 0, ... ) == 0x0 03878 432 NtUserSetScrollInfo (65740, 1, 1237984, 0, ... ) == 0x0 03879 432 NtUserSBGetParms (65740, 1, 6396036, 1237848, ... ) == 0x1 03880 432 NtUserSetProp (65740, 43285, 3308640, ... ) == 0x1 03881 432 NtUserRemoveProp (65740, 43282, ... ) == 0x0 03882 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 1236992, 0, 24, 1237196} (24, {24, 52, new_msg, 0, 1236992, 0, 24, 1237196} "\0\0\0\0\5\4\3\0\1\5\0\0\0\0\0\5\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1520, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\5\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1520, 0} (24, {24, 52, new_msg, 0, 1236992, 0, 24, 1237196} "\0\0\0\0\5\4\3\0\1\5\0\0\0\0\0\5\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1520, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\5\260\1\0\0\0\0\0\0" ) ) == 0x0 03883 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 03884 432 NtUserGetObjectInformation (40, 2, 1237068, 520, 0, ... ) == 0x1 03885 432 NtUserSBGetParms (65740, 1, 6396036, 1237740, ... ) == 0x1 03886 432 NtUserSetWindowLong (65740, -16, 1283489859, 0, ... ) == 0x4c808043 03887 432 NtUserSBGetParms (65740, 0, 6396020, 1237740, ... ) == 0x1 03888 432 NtUserGetScrollBarInfo (65740, -6, 1237604, ... ) == 0x1 03889 432 NtUserGetWindowDC (65740, ... ) == 0x1010052 03890 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03891 432 NtUserSetWindowLong (65740, -16, 1283489859, 0, ... ) == 0x4c808043 03892 432 NtUserRemoveProp (65740, 43285, ... ) == 0x327c60 03876 432 NtUserSetScrollInfo ... ) == 0x0 03893 432 NtUserSBGetParms (65740, 1, 6396036, 1239280, ... ) == 0x1 03894 432 NtUserSetProp (65740, 43285, 3308640, ... ) == 0x1 03895 432 NtUserRemoveProp (65740, 43282, ... ) == 0x0 03896 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 0, 0, 1238356, 6553708} (24, {24, 52, new_msg, 0, 0, 0, 1238356, 6553708} "\0\0\0\0\5\4\3\0 \267\325w\377\377\377\377\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1521, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\377\377\377\377\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1521, 0} (24, {24, 52, new_msg, 0, 0, 0, 1238356, 6553708} "\0\0\0\0\5\4\3\0 \267\325w\377\377\377\377\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1521, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\377\377\377\377\260\1\0\0\0\0\0\0" ) ) == 0x0 03897 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 03898 432 NtUserGetObjectInformation (40, 2, 1238500, 520, 0, ... ) == 0x1 03899 432 NtUserSBGetParms (65740, 1, 6396036, 1239172, ... ) == 0x1 03900 432 NtUserSetWindowLong (65740, -16, 1283489859, 0, ... ) == 0x4c808043 03901 432 NtUserSBGetParms (65740, 0, 6396020, 1239172, ... ) == 0x1 03902 432 NtUserGetScrollBarInfo (65740, -6, 1239036, ... ) == 0x1 03903 432 NtUserGetWindowDC (65740, ... ) == 0x1010052 03904 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03905 432 NtUserSetWindowLong (65740, -16, 1283489859, 0, ... ) == 0x4c808043 03906 432 NtUserRemoveProp (65740, 43285, ... ) == 0x327c60 03907 432 NtUserGetWindowDC (65740, ... ) == 0x1010052 03908 432 NtUserSetProp (65740, 43285, 3308640, ... ) == 0x1 03909 432 NtUserRemoveProp (65740, 43282, ... ) == 0x0 03910 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 3308472, 3307524, 3307488, 60} (24, {24, 52, new_msg, 0, 3308472, 3307524, 3307488, 60} "\0\0\0\0\5\4\3\0\227\2\0\0\367\1\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1522, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\367\1\0\0\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1522, 0} (24, {24, 52, new_msg, 0, 3308472, 3307524, 3307488, 60} "\0\0\0\0\5\4\3\0\227\2\0\0\367\1\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1522, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\367\1\0\0\260\1\0\0\0\0\0\0" ) ) == 0x0 03911 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 03912 432 NtUserGetObjectInformation (40, 2, 1238336, 520, 0, ... ) == 0x1 03913 432 NtUserSBGetParms (65740, 1, 6396036, 1239008, ... ) == 0x1 03914 432 NtUserSetWindowLong (65740, -16, 1283489859, 0, ... ) == 0x4c808043 03915 432 NtUserSBGetParms (65740, 0, 6396020, 1239008, ... ) == 0x1 03916 432 NtUserGetScrollBarInfo (65740, -6, 1238872, ... ) == 0x1 03917 432 NtUserGetWindowDC (65740, ... ) == 0x1010054 03918 432 NtUserCallOneParam (16842836, 56, ... ) == 0x1 03919 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03873 432 NtUserSetWindowPos ... ) == 0x1 03858 432 NtUserCreateWindowEx ... ) == 0x100cc 03920 432 NtUserShowWindow (65740, 0, ... ) == 0x10 03921 432 NtUserSetParent (65740, 0, ... ) == 0x100ca 03922 432 NtUserShowWindow (65740, 0, ... ) == 0x0 03923 432 NtUserInvalidateRect (65738, 1445692, 1, ... ) == 0x1 03924 432 NtUserSetWindowPos (65738, 0, 0, 0, 234, 24, 22, ... 03925 432 NtUserMessageCall (0x100ca, WM_WINDOWPOSCHANGING, 0x0, 0x12f5a8, 0, 670, 1, ... ) == 0x0 03926 432 NtUserMessageCall (0x100ca, WM_NCCALCSIZE, 0x1, 0x12f57c, 0, 670, 1, ... ) == 0x0 03924 432 NtUserSetWindowPos ... ) == 0x1 03927 432 NtUserMoveWindow (65740, 0, 24, 234, 101, 0, ... 03928 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12f5cc, 0, 670, 0, ... ) == 0x0 03929 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12f5a0, 0, 670, 0, ... ) == 0x0 03930 432 NtUserSetWindowPos (65740, 0, 0, 0, 234, 98, 22, ... 03931 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12f134, 0, 670, 0, ... ) == 0x0 03932 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12f108, 0, 670, 0, ... ) == 0x0 03930 432 NtUserSetWindowPos ... ) == 0x1 03927 432 NtUserMoveWindow ... ) == 0x1 03848 432 NtUserCreateWindowEx ... ) == 0x100ca 03933 432 NtUserGetDC (65740, ... ) == 0x1010054 03934 432 NtUserSetWindowPos (65740, 0, 0, 0, 234, 93, 22, ... 03935 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12f9b8, 0, 670, 0, ... ) == 0x0 03936 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12f98c, 0, 670, 0, ... ) == 0x0 03937 432 NtUserSetScrollInfo (65740, 1, 1242352, 0, ... ) == 0x0 03938 432 NtUserSBGetParms (65740, 1, 6396036, 1242216, ... ) == 0x1 03939 432 NtUserGetScrollBarInfo (65740, -5, 1242080, ... ) == 0x1 03940 432 NtUserGetWindowDC (65740, ... ) == 0x1010052 03941 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03934 432 NtUserSetWindowPos ... ) == 0x1 03942 432 NtUserCallOneParam (16842836, 56, ... ) == 0x1 03943 432 NtUserGetDC (65738, ... ) == 0x1010050 03944 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 03945 432 NtUserShowWindow (65740, 0, ... ) == 0x0 03946 432 NtUserInvalidateRect (65738, 1445692, 1, ... ) == 0x1 03947 432 NtUserSetWindowPos (65738, 0, 0, 0, 234, 21, 22, ... 03948 432 NtUserMessageCall (0x100ca, WM_WINDOWPOSCHANGING, 0x0, 0x12fb28, 0, 670, 1, ... ) == 0x0 03949 432 NtUserMessageCall (0x100ca, WM_NCCALCSIZE, 0x1, 0x12fafc, 0, 670, 1, ... ) == 0x0 03947 432 NtUserSetWindowPos ... ) == 0x1 03950 432 NtUserMoveWindow (65740, 0, 21, 234, 101, 0, ... 03951 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12fb4c, 0, 670, 0, ... ) == 0x0 03952 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12fb20, 0, 670, 0, ... ) == 0x0 03953 432 NtUserSetWindowPos (65740, 0, 0, 0, 234, 93, 22, ... 03954 432 NtUserMessageCall (0x100cc, WM_WINDOWPOSCHANGING, 0x0, 0x12f6b4, 0, 670, 0, ... ) == 0x0 03955 432 NtUserMessageCall (0x100cc, WM_NCCALCSIZE, 0x1, 0x12f688, 0, 670, 0, ... ) == 0x0 03953 432 NtUserSetWindowPos ... ) == 0x1 03950 432 NtUserMoveWindow ... ) == 0x1 03956 432 NtUserGetAtomName (49177, 1243256, ... ) == 0x6 03957 432 NtUserCreateWindowEx (-2147483644, 49177, 49177, (-2147483644, 49177, 49177, "Modem", 1342308352, 8, 98, 60, 15, 65734, 202, 4194304, 0, 1073742848, 0, ... , 1342308352, 8, 98, 60, 15, 65734, 202, 4194304, 0, 1073742848, 0, ... 03958 432 NtUserSetWindowFNID (65742, 680, ... ) == 0x1 03959 432 NtUserSetWindowLong (65742, 0, 1415560, 0, ... ) == 0x0 03960 432 NtUserMessageCall (0x100ce, WM_NCCREATE, 0x0, 0x12f814, 0, 670, 1, ... ) == 0x1 03961 432 NtUserMessageCall (0x100ce, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03962 432 NtUserSetProp (65742, 43288, -1, ... ) == 0x1 03957 432 NtUserCreateWindowEx ... ) == 0x100ce 03963 432 NtUserGetAtomName (49177, 1243256, ... ) == 0x6 03964 432 NtUserCreateWindowEx (-2147483644, 49177, 49177, (-2147483644, 49177, 49177, "Dial prefix", 1342308352, 8, 125, 45, 15, 65734, -1, 4194304, 0, 1073742848, 0, ... , 1342308352, 8, 125, 45, 15, 65734, -1, 4194304, 0, 1073742848, 0, ... 03965 432 NtUserSetWindowFNID (65744, 680, ... ) == 0x1 03966 432 NtUserSetWindowLong (65744, 0, 1415536, 0, ... ) == 0x0 03967 432 NtUserMessageCall (0x100d0, WM_NCCREATE, 0x0, 0x12f808, 0, 670, 1, ... ) == 0x1 03968 432 NtUserMessageCall (0x100d0, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03969 432 NtUserSetProp (65744, 43288, -1, ... ) == 0x1 03964 432 NtUserCreateWindowEx ... ) == 0x100d0 03970 432 NtUserGetAtomName (49176, 1243256, ... ) == 0x4 03971 432 NtUserCreateWindowEx (-2147483132, 49176, 49176, "", 1476468736, 74, 120, 18, 20, 65734, 206, 4194304, 0, 1073742848, 0, ... 03972 432 NtUserSetWindowFNID (65746, 677, ... ) == 0x1 03973 432 NtUserSetWindowLong (65746, 0, 1432040, 0, ... ) == 0x0 03974 432 NtAllocateVirtualMemory (-1, 0, 0, 524280, 8192, 4, ... 11206656, 524288, ) == 0x0 03975 432 NtAllocateVirtualMemory (-1, 11206656, 0, 4096, 4096, 4, ... 11206656, 4096, ) == 0x0 03976 432 NtUserMessageCall (0x100d2, WM_NCCREATE, 0x0, 0x12f81c, 0, 670, 1, ... ) == 0x1 03977 432 NtUserMessageCall (0x100d2, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03978 432 NtUserGetClassName (65734, 0, 1242136, ... ) == 0x6 03979 432 NtUserSetProp (65746, 43288, -1, ... ) == 0x1 03980 432 NtUserGetDC (65746, ... ) == 0x1010050 03981 432 NtGdiIntersectClipRect (16842832, 0, 0, 0, 0, ... ) == 0x3 03982 432 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 03983 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 03984 432 NtUserGetDC (65746, ... ) == 0x1010050 03985 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 03986 432 NtUserInvalidateRect (65746, 0, 1, ... ) == 0x1 03971 432 NtUserCreateWindowEx ... ) == 0x100d2 03987 432 NtUserGetDC (65746, ... ) == 0x1010052 03988 432 NtGdiGetTextFaceW (16842834, 32, 1243928, 0, ... ) == 0xe 03989 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 03990 432 NtUserGetAtomName (49175, 1243256, ... ) == 0x6 03991 432 NtUserCreateWindowEx (-2147483644, 49175, 49175, (-2147483644, 49175, 49175, "Read me first", 1342177287, 8, 10, 300, 70, 65734, -1, 4194304, 0, 1073742848, 0, ... , 1342177287, 8, 10, 300, 70, 65734, -1, 4194304, 0, 1073742848, 0, ... 03992 432 NtUserSetWindowFNID (65748, 673, ... ) == 0x1 03993 432 NtUserSetWindowLong (65748, 0, 1424624, 0, ... ) == 0x0 03994 432 NtUserMessageCall (0x100d4, WM_NCCREATE, 0x0, 0x12f804, 0, 670, 1, ... ) == 0x1 03995 432 NtUserMessageCall (0x100d4, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 03996 432 NtUserSetProp (65748, 43288, -1, ... ) == 0x1 03991 432 NtUserCreateWindowEx ... ) == 0x100d4 03997 432 NtUserGetAtomName (49177, 1243256, ... ) == 0x6 03998 432 NtUserCreateWindowEx (-2147483644, 49177, 49177, "", 1342308352, 18, 26, 281, 42, 65734, 205, 4194304, 0, 1073742848, 0, ... 03999 432 NtUserSetWindowFNID (65750, 680, ... ) == 0x1 04000 432 NtUserSetWindowLong (65750, 0, 1415512, 0, ... ) == 0x0 04001 432 NtUserMessageCall (0x100d6, WM_NCCREATE, 0x0, 0x12f81c, 0, 670, 1, ... ) == 0x1 04002 432 NtUserMessageCall (0x100d6, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 04003 432 NtUserSetProp (65750, 43288, -1, ... ) == 0x1 03998 432 NtUserCreateWindowEx ... ) == 0x100d6 04004 432 NtUserGetAtomName (49178, 1243256, ... ) == 0x7 04005 432 NtUserCreateWindowEx (-2147483132, 49178, 49178, "", 1344340224, 74, 151, 234, 20, 65734, 204, 4194304, 0, 1073742848, 0, ... 04006 432 NtUserSetWindowFNID (65752, 678, ... ) == 0x1 04007 432 NtUserSetWindowLong (65752, 0, 1408352, 0, ... ) == 0x0 04008 432 NtUserMessageCall (0x100d8, WM_NCCREATE, 0x0, 0x12f81c, 0, 670, 1, ... ) == 0x1 04009 432 NtUserMessageCall (0x100d8, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 04010 432 NtUserGetClassName (65734, 0, 1242136, ... ) == 0x6 04011 432 NtUserGetClassName (65752, 0, 1242404, ... ) == 0x7 04012 432 NtUserRemoveProp (65752, 43282, ... ) == 0x0 04013 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 20, 1443304, 1311152, 0} (24, {24, 52, new_msg, 0, 20, 1443304, 1311152, 0} "\0\0\0\0\5\4\3\0\6\0\0\0`\363\22#\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1523, 0} "\0\0\0\0\5\4\3\0\0\0\0\0`\363\22#\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1523, 0} (24, {24, 52, new_msg, 0, 20, 1443304, 1311152, 0} "\0\0\0\0\5\4\3\0\6\0\0\0`\363\22#\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1523, 0} "\0\0\0\0\5\4\3\0\0\0\0\0`\363\22#\260\1\0\0\0\0\0\0" ) ) == 0x0 04014 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 04015 432 NtUserGetObjectInformation (40, 2, 1242076, 520, 0, ... ) == 0x1 04016 432 NtAllocateVirtualMemory (-1, 3309568, 0, 4096, 4096, 4, ... 3309568, 4096, ) == 0x0 04017 432 NtUserSetProp (65752, 43288, 3309040, ... ) == 0x1 04018 432 NtUserGetDC (65752, ... ) == 0x1010050 04019 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 04020 432 NtUserSetScrollInfo (65752, 1, 1242616, 0, ... 04021 432 NtUserMessageCall (0x100d8, WM_NCCALCSIZE, 0x1, 0x12f4fc, 0, 670, 1, ... ) == 0x0 04022 432 NtUserSetScrollInfo (65752, 1, 1241184, 0, ... ) == 0x0 04023 432 NtUserSBGetParms (65752, 1, 6397428, 1241048, ... ) == 0x1 04024 432 NtUserSetProp (65752, 43285, 3310192, ... ) == 0x1 04025 432 NtUserRemoveProp (65752, 43282, ... ) == 0x0 04026 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 0, 0, 0, 2010406685} (24, {24, 52, new_msg, 0, 0, 0, 0, 2010406685} "\0\0\0\0\5\4\3\0\347\377\377\377\1\0\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1524, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1524, 0} (24, {24, 52, new_msg, 0, 0, 0, 0, 2010406685} "\0\0\0\0\5\4\3\0\347\377\377\377\1\0\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1524, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\260\1\0\0\0\0\0\0" ) ) == 0x0 04027 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 04028 432 NtUserGetObjectInformation (40, 2, 1240268, 520, 0, ... ) == 0x1 04029 432 NtUserSBGetParms (65752, 1, 6397428, 1240940, ... ) == 0x1 04030 432 NtUserSetWindowLong (65752, -16, 1073807616, 0, ... ) == 0x40010100 04031 432 NtUserSBGetParms (65752, 0, 6397412, 1240940, ... ) == 0x1 04032 432 NtUserGetScrollBarInfo (65752, -6, 1240804, ... ) == 0x1 04033 432 NtUserGetWindowDC (65752, ... ) == 0x1010050 04034 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 04035 432 NtUserSetWindowLong (65752, -16, 1073807616, 0, ... ) == 0x40010100 04036 432 NtUserRemoveProp (65752, 43285, ... ) == 0x328270 04020 432 NtUserSetScrollInfo ... ) == 0x0 04037 432 NtUserSBGetParms (65752, 1, 6397428, 1242480, ... ) == 0x1 04038 432 NtUserSetProp (65752, 43285, 3310192, ... ) == 0x1 04039 432 NtUserRemoveProp (65752, 43282, ... ) == 0x0 04040 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 0, 0, 1241556, 1241656} (24, {24, 52, new_msg, 0, 0, 0, 1241556, 1241656} "\0\0\0\0\5\4\3\0 \267\325w\377\377\377\377\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1525, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\377\377\377\377\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1525, 0} (24, {24, 52, new_msg, 0, 0, 0, 1241556, 1241656} "\0\0\0\0\5\4\3\0 \267\325w\377\377\377\377\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1525, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\377\377\377\377\260\1\0\0\0\0\0\0" ) ) == 0x0 04041 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 04042 432 NtUserGetObjectInformation (40, 2, 1241700, 520, 0, ... ) == 0x1 04043 432 NtUserSBGetParms (65752, 1, 6397428, 1242372, ... ) == 0x1 04044 432 NtUserSetWindowLong (65752, -16, 1073807616, 0, ... ) == 0x40010100 04045 432 NtUserSBGetParms (65752, 0, 6397412, 1242372, ... ) == 0x1 04046 432 NtUserGetScrollBarInfo (65752, -6, 1242236, ... ) == 0x1 04047 432 NtUserGetWindowDC (65752, ... ) == 0x1010050 04048 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 04049 432 NtUserSetWindowLong (65752, -16, 1073807616, 0, ... ) == 0x40010100 04050 432 NtUserRemoveProp (65752, 43285, ... ) == 0x328270 04051 432 NtUserGetWindowDC (65752, ... ) == 0x1010050 04052 432 NtUserSetProp (65752, 43285, 3310192, ... ) == 0x1 04053 432 NtUserRemoveProp (65752, 43282, ... ) == 0x0 04054 432 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 3310024, 3309076, 3309040, 60} (24, {24, 52, new_msg, 0, 3310024, 3309076, 3309040, 60} "\0\0\0\0\5\4\3\0\227\2\0\0\313\1\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1526, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\313\1\0\0\260\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 424, 432, 1526, 0} (24, {24, 52, new_msg, 0, 3310024, 3309076, 3309040, 60} "\0\0\0\0\5\4\3\0\227\2\0\0\313\1\0\0\260\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 424, 432, 1526, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\313\1\0\0\260\1\0\0\0\0\0\0" ) ) == 0x0 04055 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x28 04056 432 NtUserGetObjectInformation (40, 2, 1241536, 520, 0, ... ) == 0x1 04057 432 NtUserSBGetParms (65752, 1, 6397428, 1242208, ... ) == 0x1 04058 432 NtUserSetWindowLong (65752, -16, 1073807616, 0, ... ) == 0x40010100 04059 432 NtUserSBGetParms (65752, 0, 6397412, 1242208, ... ) == 0x1 04060 432 NtUserGetScrollBarInfo (65752, -6, 1242072, ... ) == 0x1 04061 432 NtUserGetWindowDC (65752, ... ) == 0x1010052 04062 432 NtUserCallOneParam (16842834, 56, ... ) == 0x1 04063 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 04005 432 NtUserCreateWindowEx ... ) == 0x100d8 04064 432 NtUserGetDC (65752, ... ) == 0x1010054 04065 432 NtUserCallOneParam (16842836, 56, ... ) == 0x1 04066 432 NtUserGetAtomName (49177, 1243256, ... ) == 0x6 04067 432 NtUserCreateWindowEx (-2147483644, 49177, 49177, (-2147483644, 49177, 49177, "Status", 1342308352, 8, 154, 60, 16, 65734, -1, 4194304, 0, 1073742848, 0, ... , 1342308352, 8, 154, 60, 16, 65734, -1, 4194304, 0, 1073742848, 0, ... 04068 432 NtUserSetWindowFNID (65754, 680, ... ) == 0x1 04069 432 NtUserSetWindowLong (65754, 0, 1415488, 0, ... ) == 0x0 04070 432 NtUserMessageCall (0x100da, WM_NCCREATE, 0x0, 0x12f810, 0, 670, 1, ... ) == 0x1 04071 432 NtUserMessageCall (0x100da, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 04072 432 NtUserSetProp (65754, 43288, -1, ... ) == 0x1 04067 432 NtUserCreateWindowEx ... ) == 0x100da 04073 432 NtUserGetAtomName (49175, 1243256, ... ) == 0x6 04074 432 NtUserCreateWindowEx (-2147483644, 49175, 49175, (-2147483644, 49175, 49175, "&Help", 1342242816, 188, 185, 38, 24, 65734, 209, 4194304, 0, 1073742848, 0, ... , 1342242816, 188, 185, 38, 24, 65734, 209, 4194304, 0, 1073742848, 0, ... 04075 432 NtUserSetWindowFNID (65756, 673, ... ) == 0x1 04076 432 NtUserSetWindowLong (65756, 0, 1424604, 0, ... ) == 0x0 04077 432 NtUserMessageCall (0x100dc, WM_NCCREATE, 0x0, 0x12f814, 0, 670, 1, ... ) == 0x1 04078 432 NtUserMessageCall (0x100dc, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 04079 432 NtUserSetProp (65756, 43288, -1, ... ) == 0x1 04074 432 NtUserCreateWindowEx ... ) == 0x100dc 04080 432 NtUserGetAtomName (49177, 1243256, ... ) == 0x6 04081 432 NtUserCreateWindowEx (-2147483644, 49177, 49177, (-2147483644, 49177, 49177, "(optional prefix to access an outside line)", 1342308352, 101, 124, 195, 13, 65734, -1, 4194304, 0, 1073742848, 0, ... , 1342308352, 101, 124, 195, 13, 65734, -1, 4194304, 0, 1073742848, 0, ... 04082 432 NtAllocateVirtualMemory (-1, 6397952, 0, 4096, 4096, 32, ... 6397952, 4096, ) == 0x0 04083 432 NtUserSetWindowFNID (65758, 680, ... ) == 0x1 04084 432 NtUserSetWindowLong (65758, 0, 1415464, 0, ... ) == 0x0 04085 432 NtUserMessageCall (0x100de, WM_NCCREATE, 0x0, 0x12f7c8, 0, 670, 1, ... ) == 0x1 04086 432 NtUserMessageCall (0x100de, WM_NCCALCSIZE, 0x0, 0x12f84c, 0, 670, 1, ... ) == 0x0 04087 432 NtUserSetProp (65758, 43288, -1, ... ) == 0x1 04081 432 NtUserCreateWindowEx ... ) == 0x100de 04088 432 NtUserSetWindowLong (65734, -21, 74565, 1, ... ) == 0x0 04089 432 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x100aa, 0x100a8, 0x60036, 0x20064, 0x100a0, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x10098, 0x1008c, 0x1007c, 0x10026, 0x100c6, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b0, 0x100ae, 0x2005c, 0x100cc, 0x100ac, 0x100a6, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 36, ) == 0x0 04090 432 NtQueryDefaultLocale (1, 1243480, ... ) == 0x0 04091 432 NtQueryDefaultLocale (1, 1242636, ... ) == 0x0 04092 432 NtQueryDefaultLocale (1, 1242616, ... ) == 0x0 04093 432 NtCreateKey (0xf003f, {24, 60, 0x40, 0, 0, (0xf003f, {24, 60, 0x40, 0, 0, "Software\Carlson\Connection\carlton"}, 0, 0x0, 0, ... 304, 2, ) }, 0, 0x0, 0, ... 304, 2, ) == 0x0 04094 432 NtQueryValueKey (304, (304, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04095 432 NtClose (304, ... ) == 0x0 04096 432 NtOpenKey (0x20019, {24, 60, 0x40, 0, 0, (0x20019, {24, 60, 0x40, 0, 0, "RemoteAccess"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04097 432 NtQueryDefaultLocale (1, 1241788, ... ) == 0x0 04098 432 NtQueryDefaultLocale (1, 1241768, ... ) == 0x0 04099 432 NtCreateKey (0xf003f, {24, 60, 0x40, 0, 0, (0xf003f, {24, 60, 0x40, 0, 0, "Software\Carlson\Connection\carlton"}, 0, 0x0, 0, ... 304, 2, ) }, 0, 0x0, 0, ... 304, 2, ) == 0x0 04100 432 NtSetValueKey (304, (304, "Default", 0, 1, "\2\0\0\0", 4, ... ) , 0, 1, (304, "Default", 0, 1, "\2\0\0\0", 4, ... ) , 4, ... ) == 0x0 04101 432 NtSetValueKey (304, (304, "InternetProfile", 0, 1, "P\0\364\0\22\0\0\0", 8, ... , 0, 1, (304, "InternetProfile", 0, 1, "P\0\364\0\22\0\0\0", 8, ... , 8, ... 04102 432 NtSetInformationFile (-2147482700, -131037836, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04101 432 NtSetValueKey ... ) == 0x0 04103 432 NtClose (304, ... ) == 0x0 04104 432 NtQueryDefaultLocale (1, 1242892, ... ) == 0x0 04105 432 NtQueryDefaultLocale (1, 1242872, ... ) == 0x0 04106 432 NtOpenKey (0x20019, {24, 60, 0x40, 0, 0, (0x20019, {24, 60, 0x40, 0, 0, "Software\Carlson\Connection\carlton"}, ... 304, ) }, ... 304, ) == 0x0 04107 432 NtQueryValueKey (304, (304, "cc", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04108 432 NtClose (304, ... ) == 0x0 04109 432 NtQueryValueKey (76, (76, "FromCacheTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04110 432 NtQueryValueKey (76, (76, "SecureProtocols", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04111 432 NtQueryValueKey (76, (76, "CertificateRevocation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04112 432 NtQueryValueKey (76, (76, "DisableKeepAlive", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04113 432 NtQueryValueKey (76, (76, "DisablePassport", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04114 432 NtQueryValueKey (76, (76, "CacheMode", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04115 432 NtQueryValueKey (76, (76, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04116 432 NtQueryValueKey (76, (76, "ProxyHttp1.1", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04117 432 NtQueryValueKey (76, (76, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04118 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04119 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\Secur32.dll"}, 1238572, ... ) }, 1238572, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04120 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "Secur32.dll"}, 1238572, ... ) }, 1238572, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04121 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Secur32.dll"}, 1238572, ... ) }, 1238572, ... ) == 0x0 04122 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Secur32.dll"}, 5, 96, ... 304, {status=0x0, info=1}, ) }, 5, 96, ... 304, {status=0x0, info=1}, ) == 0x0 04123 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 304, ... 216, ) == 0x0 04124 432 NtQuerySection (216, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04125 432 NtClose (304, ... ) == 0x0 04126 432 NtMapViewOfSection (216, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f90000), 0x0, 65536, ) == 0x0 04127 432 NtClose (216, ... ) == 0x0 04128 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 216, ) == 0x0 04129 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 304, ) == 0x0 04130 432 NtOpenEvent (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\SECURITY\LSA_AUTHENTICATION_INITIALIZED"}, ... 316, ) }, ... 316, ) == 0x0 04131 432 NtQueryEvent (316, Basic, 8, ... {EventType=0,SignalState=1,}, 0x0, ) == 0x0 04132 432 NtClose (316, ... ) == 0x0 04133 432 NtConnectPort ( ("\LsaAuthenticationPort", {12, 2, 1, 0}, 0x0, 0x0, 1240056, 140, ... 316, 0x0, 0x0, 256, 140, ) , {12, 2, 1, 0}, 0x0, 0x0, 1240056, 140, ... 316, 0x0, 0x0, 256, 140, ) == 0x0 04134 432 NtRequestWaitReplyPort (316, {28, 52, new_msg, 0, 0, 0, 0, 0} (316, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\13\30\10\2\220\215\25\0" ... {176, 200, reply, 0, 424, 432, 1528, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\20\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0R\0I\0-\0u\0s\0e\0r\0" ) ... {176, 200, reply, 0, 424, 432, 1528, 0} (316, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\13\30\10\2\220\215\25\0" ... {176, 200, reply, 0, 424, 432, 1528, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\20\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0R\0I\0-\0u\0s\0e\0r\0" ) ) == 0x0 04135 432 NtQueryValueKey (76, (76, "SyncMode5", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04136 432 NtOpenKey (0xf, {24, 48, 0x40, 0, 0, (0xf, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache"}, ... 312, ) }, ... 312, ) == 0x0 04137 432 NtQueryValueKey (312, (312, "FixupKey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04138 432 NtClose (312, ... ) == 0x0 04139 432 NtOpenKey (0xf, {24, 48, 0x40, 0, 0, (0xf, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 312, ) }, ... 312, ) == 0x0 04140 432 NtQueryValueKey (312, (312, "SessionStartTimeDefaultDeltaSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04141 432 NtClose (312, ... ) == 0x0 04142 432 NtOpenKey (0xf, {24, 48, 0x40, 0, 0, (0xf, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 312, ) }, ... 312, ) == 0x0 04143 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\Setup"}, ... 320, ) }, ... 320, ) == 0x0 04144 432 NtQueryValueKey (320, (320, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (320, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04145 432 NtClose (320, ... ) == 0x0 04146 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 320, ) }, ... 320, ) == 0x0 04147 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 324, ) }, ... 324, ) == 0x0 04148 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 328, ) }, ... 328, ) == 0x0 04149 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 332, ) }, ... 332, ) == 0x0 04150 432 NtQueryValueKey (332, (332, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 04151 432 NtQueryValueKey (332, (332, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 04152 432 NtClose (332, ... ) == 0x0 04153 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 332, ) }, ... 332, ) == 0x0 04154 432 NtQueryValueKey (332, (332, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 04155 432 NtQueryValueKey (332, (332, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 04156 432 NtQueryValueKey (332, (332, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 04157 432 NtQueryValueKey (332, (332, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 04158 432 NtQueryValueKey (332, (332, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 04159 432 NtQueryValueKey (332, (332, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 04160 432 NtClose (332, ... ) == 0x0 04161 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "Content"}, ... 332, ) }, ... 332, ) == 0x0 04162 432 NtQueryValueKey (332, (332, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (332, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04163 432 NtClose (332, ... ) == 0x0 04164 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "Content"}, ... 332, ) }, ... 332, ) == 0x0 04165 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04166 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 04167 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 04168 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04169 432 NtQueryValueKey (336, (336, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (336, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 04170 432 NtClose (336, ... ) == 0x0 04171 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1237284, ... ) }, 1237284, ... ) == 0x0 04172 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04173 432 NtSetValueKey (336, (336, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 150, ... ) , 0, 1, (336, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 150, ... ) , 150, ... ) == 0x0 04174 432 NtClose (336, ... ) == 0x0 04175 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1238616, ... ) }, 1238616, ... ) == 0x0 04176 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1238348, ... ) }, 1238348, ... ) == 0x0 04177 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 7, 2113568, ... 336, {status=0x0, info=1}, ) }, 7, 2113568, ... 336, {status=0x0, info=1}, ) == 0x0 04178 432 NtSetInformationFile (336, 1238324, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04179 432 NtClose (336, ... ) == 0x0 04180 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\desktop.ini"}, 1238348, ... ) }, 1238348, ... ) == 0x0 04181 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04182 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04183 432 NtQueryValueKey (332, (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\251~\1\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\251~\1\0"}, 16, ) }, 16, ) == 0x0 04184 432 NtOpenKey (0xf, {24, 48, 0x40, 0, 0, (0xf, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache"}, ... 336, ) }, ... 336, ) == 0x0 04185 432 NtOpenKey (0xf, {24, 336, 0x40, 0, 0, (0xf, {24, 336, 0x40, 0, 0, "Paths"}, ... 340, ) }, ... 340, ) == 0x0 04186 432 NtOpenKey (0xf, {24, 340, 0x40, 0, 0, (0xf, {24, 340, 0x40, 0, 0, "Path1"}, ... 344, ) }, ... 344, ) == 0x0 04187 432 NtOpenKey (0xf, {24, 340, 0x40, 0, 0, (0xf, {24, 340, 0x40, 0, 0, "Path2"}, ... 348, ) }, ... 348, ) == 0x0 04188 432 NtOpenKey (0xf, {24, 340, 0x40, 0, 0, (0xf, {24, 340, 0x40, 0, 0, "Path3"}, ... 352, ) }, ... 352, ) == 0x0 04189 432 NtOpenKey (0xf, {24, 340, 0x40, 0, 0, (0xf, {24, 340, 0x40, 0, 0, "Path4"}, ... 356, ) }, ... 356, ) == 0x0 04190 432 NtOpenKey (0xf, {24, 336, 0x40, 0, 0, (0xf, {24, 336, 0x40, 0, 0, "Special Paths"}, ... 360, ) }, ... 360, ) == 0x0 04191 432 NtSetValueKey (340, (340, "Directory", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\0\0", 174, ... ) , 0, 1, (340, "Directory", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\0\0", 174, ... ) , 174, ... ) == 0x0 04192 432 NtSetValueKey (340, (340, "Paths", 0, 4, "\4\0\0\0", 4, ... ) , 0, 4, (340, "Paths", 0, 4, "\4\0\0\0", 4, ... ) , 4, ... ) == 0x0 04193 432 NtSetValueKey (344, (344, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\01\0\0\0", 188, ... ) , 0, 1, (344, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\01\0\0\0", 188, ... ) , 188, ... ) == 0x0 04194 432 NtSetValueKey (348, (348, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\02\0\0\0", 188, ... ) , 0, 1, (348, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\02\0\0\0", 188, ... ) , 188, ... ) == 0x0 04195 432 NtSetValueKey (352, (352, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\03\0\0\0", 188, ... ) , 0, 1, (352, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\03\0\0\0", 188, ... ) , 188, ... ) == 0x0 04196 432 NtSetValueKey (356, (356, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\04\0\0\0", 188, ... ) , 0, 1, (356, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\04\0\0\0", 188, ... ) , 188, ... ) == 0x0 04197 432 NtSetValueKey (344, (344, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (344, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 04198 432 NtSetValueKey (348, (348, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (348, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 04199 432 NtSetValueKey (352, (352, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (352, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 04200 432 NtSetValueKey (356, (356, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (356, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 04201 432 NtClose (356, ... ) == 0x0 04202 432 NtClose (352, ... ) == 0x0 04203 432 NtClose (348, ... ) == 0x0 04204 432 NtClose (344, ... ) == 0x0 04205 432 NtClose (340, ... ) == 0x0 04206 432 NtClose (360, ... ) == 0x0 04207 432 NtClose (336, ... ) == 0x0 04208 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "Cookies"}, ... 336, ) }, ... 336, ) == 0x0 04209 432 NtQueryValueKey (336, (336, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (336, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04210 432 NtClose (336, ... ) == 0x0 04211 432 NtClose (332, ... ) == 0x0 04212 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "Cookies"}, ... 332, ) }, ... 332, ) == 0x0 04213 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04214 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 04215 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 04216 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04217 432 NtQueryValueKey (336, (336, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (336, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 04218 432 NtClose (336, ... ) == 0x0 04219 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies"}, 1237284, ... ) }, 1237284, ... ) == 0x0 04220 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04221 432 NtSetValueKey (336, (336, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 86, ... ) , 0, 1, (336, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 86, ... ) , 86, ... ) == 0x0 04222 432 NtClose (336, ... ) == 0x0 04223 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies"}, 1238616, ... ) }, 1238616, ... ) == 0x0 04224 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 04225 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 04226 432 NtQueryValueKey (332, (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04227 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "History"}, ... 336, ) }, ... 336, ) == 0x0 04228 432 NtQueryValueKey (336, (336, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (336, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04229 432 NtClose (336, ... ) == 0x0 04230 432 NtClose (332, ... ) == 0x0 04231 432 NtOpenKey (0xf, {24, 324, 0x40, 0, 0, (0xf, {24, 324, 0x40, 0, 0, "History"}, ... 332, ) }, ... 332, ) == 0x0 04232 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04233 432 NtReleaseSemaphore (100, 1, ... 0, ) == 0x0 04234 432 NtWaitForSingleObject (100, 0, {0, 0}, ... ) == 0x0 04235 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04236 432 NtQueryValueKey (336, (336, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (336, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 04237 432 NtClose (336, ... ) == 0x0 04238 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1237284, ... ) }, 1237284, ... ) == 0x0 04239 432 NtCreateKey (0x2000000, {24, 60, 0x40, 0, 0, (0x2000000, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 336, 2, ) }, 0, 0x0, 0, ... 336, 2, ) == 0x0 04240 432 NtSetValueKey (336, (336, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 116, ... ) , 0, 1, (336, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 116, ... ) , 116, ... ) == 0x0 04241 432 NtClose (336, ... ) == 0x0 04242 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1238616, ... ) }, 1238616, ... ) == 0x0 04243 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1238348, ... ) }, 1238348, ... ) == 0x0 04244 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 7, 2113568, ... 336, {status=0x0, info=1}, ) }, 7, 2113568, ... 336, {status=0x0, info=1}, ) == 0x0 04245 432 NtSetInformationFile (336, 1238324, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04246 432 NtClose (336, ... ) == 0x0 04247 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\desktop.ini"}, 1238348, ... ) }, 1238348, ... ) == 0x0 04248 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 04249 432 NtQueryValueKey (332, (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (332, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 04250 432 NtQueryValueKey (332, (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (332, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04251 432 NtClose (332, ... ) == 0x0 04252 432 NtClose (328, ... ) == 0x0 04253 432 NtClose (320, ... ) == 0x0 04254 432 NtClose (324, ... ) == 0x0 04255 432 NtClose (312, ... ) == 0x0 04256 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "_!MSFTHISTORY!_"}, ... 312, ) }, ... 312, ) == 0x0 04257 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "c:!documents and settings!sri-user!local settings!temporary internet files!content.ie5!"}, ... 324, ) }, ... 324, ) == 0x0 04258 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04259 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 3, 8388641, ... 320, {status=0x0, info=1}, ) }, 3, 8388641, ... 320, {status=0x0, info=1}, ) == 0x0 04260 432 NtQueryVolumeInformationFile (320, 1239868, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04261 432 NtClose (320, ... ) == 0x0 04262 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 320, {status=0x0, info=1}, ) }, 3, 8388641, ... 320, {status=0x0, info=1}, ) == 0x0 04263 432 NtQueryVolumeInformationFile (320, 1239892, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04264 432 NtClose (320, ... ) == 0x0 04265 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 1240220, ... ) }, 1240220, ... ) == 0x0 04266 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 320, {status=0x0, info=1}, ) }, 7, 2113568, ... 320, {status=0x0, info=1}, ) == 0x0 04267 432 NtSetInformationFile (320, 1240196, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04268 432 NtClose (320, ... ) == 0x0 04269 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240212, (0xc0100080, {24, 0, 0x40, 1374944, 1240212, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 320, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 320, {status=0x0, info=1}, ) == 0x0 04270 432 NtSetInformationFile (320, 1240264, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04271 432 NtQueryInformationFile (320, 1240264, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04272 432 NtClose (320, ... ) == 0x0 04273 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240196, (0xc0100080, {24, 0, 0x40, 1374944, 1240196, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 320, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 320, {status=0x0, info=1}, ) == 0x0 04274 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768"}, ... 328, ) }, ... 328, ) == 0x0 04275 432 NtMapViewOfSection (328, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa70000), {0, 0}, 32768, ) == 0x0 04276 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04277 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "c:!documents and settings!sri-user!cookies!"}, ... 332, ) }, ... 332, ) == 0x0 04278 432 NtWaitForSingleObject (332, 0, 0x0, ... ) == 0x0 04279 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 3, 8388641, ... 336, {status=0x0, info=1}, ) }, 3, 8388641, ... 336, {status=0x0, info=1}, ) == 0x0 04280 432 NtQueryVolumeInformationFile (336, 1239868, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04281 432 NtClose (336, ... ) == 0x0 04282 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 336, {status=0x0, info=1}, ) }, 3, 8388641, ... 336, {status=0x0, info=1}, ) == 0x0 04283 432 NtQueryVolumeInformationFile (336, 1239892, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04284 432 NtClose (336, ... ) == 0x0 04285 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 1240220, ... ) }, 1240220, ... ) == 0x0 04286 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 7, 2113568, ... 336, {status=0x0, info=1}, ) }, 7, 2113568, ... 336, {status=0x0, info=1}, ) == 0x0 04287 432 NtSetInformationFile (336, 1240196, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04288 432 NtClose (336, ... ) == 0x0 04289 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240212, (0xc0100080, {24, 0, 0x40, 1374944, 1240212, "\??\C:\Documents and Settings\SRI-user\Cookies\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 336, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 336, {status=0x0, info=1}, ) == 0x0 04290 432 NtSetInformationFile (336, 1240264, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04291 432 NtQueryInformationFile (336, 1240264, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04292 432 NtClose (336, ... ) == 0x0 04293 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240196, (0xc0100080, {24, 0, 0x40, 1374944, 1240196, "\??\C:\Documents and Settings\SRI-user\Cookies\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 336, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 336, {status=0x0, info=1}, ) == 0x0 04294 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Cookies_index.dat_16384"}, ... 360, ) }, ... 360, ) == 0x0 04295 432 NtMapViewOfSection (360, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa80000), {0, 0}, 16384, ) == 0x0 04296 432 NtReleaseMutant (332, ... 0x0, ) == 0x0 04297 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "c:!documents and settings!sri-user!local settings!history!history.ie5!"}, ... 340, ) }, ... 340, ) == 0x0 04298 432 NtWaitForSingleObject (340, 0, 0x0, ... ) == 0x0 04299 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 3, 8388641, ... 344, {status=0x0, info=1}, ) }, 3, 8388641, ... 344, {status=0x0, info=1}, ) == 0x0 04300 432 NtQueryVolumeInformationFile (344, 1239868, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04301 432 NtClose (344, ... ) == 0x0 04302 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 344, {status=0x0, info=1}, ) }, 3, 8388641, ... 344, {status=0x0, info=1}, ) == 0x0 04303 432 NtQueryVolumeInformationFile (344, 1239892, 24, Size, ... {status=0x0, info=24}, ) == 0x0 04304 432 NtClose (344, ... ) == 0x0 04305 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 1240220, ... ) }, 1240220, ... ) == 0x0 04306 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 7, 2113568, ... 344, {status=0x0, info=1}, ) }, 7, 2113568, ... 344, {status=0x0, info=1}, ) == 0x0 04307 432 NtSetInformationFile (344, 1240196, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04308 432 NtClose (344, ... ) == 0x0 04309 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240212, (0xc0100080, {24, 0, 0x40, 1374944, 1240212, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 344, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 344, {status=0x0, info=1}, ) == 0x0 04310 432 NtSetInformationFile (344, 1240264, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04311 432 NtQueryInformationFile (344, 1240264, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04312 432 NtClose (344, ... ) == 0x0 04313 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 1374944, 1240196, (0xc0100080, {24, 0, 0x40, 1374944, 1240196, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 344, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 344, {status=0x0, info=1}, ) == 0x0 04314 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Local Settings_History_History.IE5_index.dat_32768"}, ... 348, ) }, ... 348, ) == 0x0 04315 432 NtMapViewOfSection (348, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa90000), {0, 0}, 32768, ) == 0x0 04316 432 NtReleaseMutant (340, ... 0x0, ) == 0x0 04317 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 1240276, ... ) }, 1240276, ... ) == 0x0 04318 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 352, {status=0x0, info=1}, ) }, 7, 2113568, ... 352, {status=0x0, info=1}, ) == 0x0 04319 432 NtSetInformationFile (352, 1240252, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04320 432 NtClose (352, ... ) == 0x0 04321 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini"}, 1240276, ... ) }, 1240276, ... ) == 0x0 04322 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 1240276, ... ) }, 1240276, ... ) == 0x0 04323 432 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 7, 2113568, ... 352, {status=0x0, info=1}, ) }, 7, 2113568, ... 352, {status=0x0, info=1}, ) == 0x0 04324 432 NtSetInformationFile (352, 1240252, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04325 432 NtClose (352, ... ) == 0x0 04326 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\desktop.ini"}, 1240276, ... ) }, 1240276, ... ) == 0x0 04327 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04328 432 NtQueryInformationFile (320, 1238660, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04329 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04330 432 NtOpenKey (0xf, {24, 60, 0x40, 0, 0, (0xf, {24, 60, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 352, ) }, ... 352, ) == 0x0 04331 432 NtOpenKey (0xf, {24, 352, 0x40, 0, 0, (0xf, {24, 352, 0x40, 0, 0, "Extensible Cache"}, ... 356, ) }, ... 356, ) == 0x0 04332 432 NtClose (352, ... ) == 0x0 04333 432 NtWaitForSingleObject (312, 0, {-600000000, -1}, ... ) == 0x0 04334 432 NtEnumerateKey (356, 0, Basic, 288, ... {LastWrite={0x89210de2,0x1c79d95}, TitleIdx=0, Name= (356, 0, Basic, 288, ... {LastWrite={0x89210de2,0x1c79d95}, TitleIdx=0, Name="MSHist012007051420070521"}, 64, ) }, 64, ) == 0x0 04335 432 NtOpenKey (0xf, {24, 356, 0x40, 0, 0, (0xf, {24, 356, 0x40, 0, 0, "MSHist012007051420070521"}, ... 352, ) }, ... 352, ) == 0x0 04336 432 NtQueryValueKey (352, (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04337 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04338 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04339 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04340 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04341 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04342 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04343 432 NtQueryValueKey (352, (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04344 432 NtQueryValueKey (352, (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 04345 432 NtClose (352, ... ) == 0x0 04346 432 NtEnumerateKey (356, 1, Basic, 288, ... {LastWrite={0xfe4bb184,0x1c7a3a9}, TitleIdx=0, Name= (356, 1, Basic, 288, ... {LastWrite={0xfe4bb184,0x1c7a3a9}, TitleIdx=0, Name="MSHist012007052120070528"}, 64, ) }, 64, ) == 0x0 04347 432 NtOpenKey (0xf, {24, 356, 0x40, 0, 0, (0xf, {24, 356, 0x40, 0, 0, "MSHist012007052120070528"}, ... 352, ) }, ... 352, ) == 0x0 04348 432 NtQueryValueKey (352, (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04349 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04350 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04351 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04352 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04353 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04354 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04355 432 NtQueryValueKey (352, (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04356 432 NtQueryValueKey (352, (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 04357 432 NtClose (352, ... ) == 0x0 04358 432 NtEnumerateKey (356, 2, Basic, 288, ... {LastWrite={0xfe4e13de,0x1c7a3a9}, TitleIdx=0, Name= (356, 2, Basic, 288, ... {LastWrite={0xfe4e13de,0x1c7a3a9}, TitleIdx=0, Name="MSHist012007053120070601"}, 64, ) }, 64, ) == 0x0 04359 432 NtOpenKey (0xf, {24, 356, 0x40, 0, 0, (0xf, {24, 356, 0x40, 0, 0, "MSHist012007053120070601"}, ... 352, ) }, ... 352, ) == 0x0 04360 432 NtQueryValueKey (352, (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04361 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04362 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04363 432 NtQueryValueKey (352, (352, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04364 432 NtQueryValueKey (352, (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (352, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 04365 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04366 432 NtQueryValueKey (352, (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (352, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04367 432 NtQueryValueKey (352, (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04368 432 NtQueryValueKey (352, (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 04369 432 NtClose (352, ... ) == 0x0 04370 432 NtEnumerateKey (356, 3, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 04371 432 NtReleaseMutant (312, ... 0x0, ) == 0x0 04372 432 NtClose (356, ... ) == 0x0 04373 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04374 432 NtQueryInformationFile (320, 1240588, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04375 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04376 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04377 432 NtQueryInformationFile (320, 1240660, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04378 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04379 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04380 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04381 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04382 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04383 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04384 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 356, ) }, ... 356, ) == 0x0 04385 432 NtQueryValueKey (356, (356, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04386 432 NtClose (356, ... ) == 0x0 04387 432 NtQueryValueKey (76, (76, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04388 432 NtQueryValueKey (76, (76, "DisableReadRange", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04389 432 NtQueryValueKey (76, (76, "SocketSendBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04390 432 NtQueryValueKey (76, (76, "SocketReceiveBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04391 432 NtQueryValueKey (76, (76, "KeepAliveTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04392 432 NtQueryValueKey (76, (76, "MaxHttpRedirects", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04393 432 NtQueryValueKey (76, (76, "MaxConnectionsPerServer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04394 432 NtQueryValueKey (76, (76, "MaxConnectionsPer1_0Server", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04395 432 NtQueryValueKey (76, (76, "ServerInfoTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04396 432 NtQueryValueKey (76, (76, "ReceiveTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04397 432 NtQueryValueKey (76, (76, "DisableNTLMPreAuth", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04398 432 NtQueryValueKey (76, (76, "ScavengeCacheLowerBound", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04399 432 NtOpenKey (0x1, {24, 60, 0x40, 0, 0, (0x1, {24, 60, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 356, ) }, ... 356, ) == 0x0 04400 432 NtQueryValueKey (356, (356, "ScavengeCacheFileLifeTime", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04401 432 NtClose (356, ... ) == 0x0 04402 432 NtQueryValueKey (76, (76, "HttpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04403 432 NtQueryValueKey (76, (76, "FtpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04404 432 NtQueryValueKey (76, (76, "GopherDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04405 432 NtQueryValueKey (76, (76, "DisableCachingOfSSLPages", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04406 432 NtQueryValueKey (76, (76, "PerUserCookies", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04407 432 NtQueryValueKey (76, (76, "LeashLegacyCookies", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04408 432 NtQueryValueKey (76, (76, "DisableNT4RasCheck", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04409 432 NtQueryValueKey (76, (76, "DialupUseLanSettings", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04410 432 NtQueryValueKey (76, (76, "SendExtraCRLF", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04411 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 356, ) }, ... 356, ) == 0x0 04412 432 NtQueryValueKey (356, (356, "DontUseDNSLoadBalancing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04413 432 NtClose (356, ... ) == 0x0 04414 432 NtQueryValueKey (76, (76, "DontUseDNSLoadBalancing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04415 432 NtQueryValueKey (76, (76, "NonBlockingClient32", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04416 432 NtQueryValueKey (76, (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 04417 432 NtQueryValueKey (76, (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 04418 432 NtQueryValueKey (76, (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 04419 432 NtQueryValueKey (76, (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (76, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 04420 432 NtQueryValueKey (76, (76, "HeaderExclusionListForCache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04421 432 NtQueryValueKey (76, (76, "DnsCacheEnabled", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04422 432 NtQueryValueKey (76, (76, "DnsCacheEntries", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04423 432 NtQueryValueKey (76, (76, "DnsCacheTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04424 432 NtQueryValueKey (76, (76, "WarnOnPost", Partial, 144, ... TitleIdx=0, Type=3, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (76, "WarnOnPost", Partial, 144, ... TitleIdx=0, Type=3, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04425 432 NtQueryValueKey (76, (76, "WarnAlwaysOnPost", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04426 432 NtQueryValueKey (76, (76, "WarnOnZoneCrossing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04427 432 NtQueryValueKey (76, (76, "WarnOnBadCertSending", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04428 432 NtQueryValueKey (76, (76, "WarnOnBadCertRecving", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04429 432 NtQueryValueKey (76, (76, "WarnOnPostRedirect", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04430 432 NtQueryValueKey (76, (76, "AlwaysDrainOnRedirect", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04431 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "WininetStartupMutex"}, ... 356, ) }, ... 356, ) == 0x0 04432 432 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 352, ) == 0x0 04433 432 NtQueryValueKey (76, (76, "GlobalUserOffline", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04434 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04435 432 NtQueryInformationFile (320, 1240636, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04436 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04437 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "WininetConnectionMutex"}, ... 364, ) }, ... 364, ) == 0x0 04438 432 NtCreateMutant (0x1f0001, 0x0, 0, ... 368, ) == 0x0 04439 432 NtOpenMutant (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "WininetProxyRegistryMutex"}, ... 372, ) }, ... 372, ) == 0x0 04440 432 NtQueryValueKey (76, (76, "EnableAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "EnableAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04441 432 NtQueryValueKey (76, (76, "NoNetAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "NoNetAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04442 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 376, ) }, ... 376, ) == 0x0 04443 432 NtQueryValueKey (376, (376, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (376, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) }, 34, ) == 0x0 04444 432 NtQueryValueKey (376, (376, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (376, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) }, 34, ) == 0x0 04445 432 NtClose (376, ... ) == 0x0 04446 432 NtAllocateVirtualMemory (-1, 1445888, 0, 4096, 4096, 4, ... 1445888, 4096, ) == 0x0 04447 432 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 376, ) == 0x0 04448 432 NtWaitForSingleObject (376, 0, 0x0, ... ) == 0x0 04449 432 NtClearEvent (376, ... ) == 0x0 04450 432 NtSetEvent (376, ... 0x0, ) == 0x0 04451 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "wsock32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04452 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\wsock32.dll"}, 1238524, ... ) }, 1238524, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04453 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "wsock32.dll"}, 1238524, ... ) }, 1238524, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04454 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wsock32.dll"}, 1238524, ... ) }, 1238524, ... ) == 0x0 04455 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wsock32.dll"}, 5, 96, ... 380, {status=0x0, info=1}, ) }, 5, 96, ... 380, {status=0x0, info=1}, ) == 0x0 04456 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 380, ... 384, ) == 0x0 04457 432 NtQuerySection (384, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04458 432 NtClose (380, ... ) == 0x0 04459 432 NtMapViewOfSection (384, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ad0000), 0x0, 32768, ) == 0x0 04460 432 NtClose (384, ... ) == 0x0 04461 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04462 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.dll"}, 1237720, ... ) }, 1237720, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04463 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2_32.dll"}, 1237720, ... ) }, 1237720, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04464 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 1237720, ... ) }, 1237720, ... ) == 0x0 04465 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 5, 96, ... 384, {status=0x0, info=1}, ) }, 5, 96, ... 384, {status=0x0, info=1}, ) == 0x0 04466 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 384, ... 380, ) == 0x0 04467 432 NtQuerySection (380, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04468 432 NtClose (384, ... ) == 0x0 04469 432 NtMapViewOfSection (380, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 86016, ) == 0x0 04470 432 NtClose (380, ... ) == 0x0 04471 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04472 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 1236916, ... ) }, 1236916, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04473 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2HELP.dll"}, 1236916, ... ) }, 1236916, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04474 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 1236916, ... ) }, 1236916, ... ) == 0x0 04475 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 5, 96, ... 380, {status=0x0, info=1}, ) }, 5, 96, ... 380, {status=0x0, info=1}, ) == 0x0 04476 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 380, ... 384, ) == 0x0 04477 432 NtQuerySection (384, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04478 432 NtClose (380, ... ) == 0x0 04479 432 NtMapViewOfSection (384, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 04480 432 NtClose (384, ... ) == 0x0 04481 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 04482 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 04483 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\WinSock2\Parameters"}, ... 384, ) }, ... 384, ) == 0x0 04484 432 NtQueryValueKey (384, (384, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (384, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 04485 432 NtQueryValueKey (384, (384, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (384, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 04486 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 380, ) == 0x0 04487 432 NtOpenKey (0x2000000, {24, 384, 0x40, 0, 0, (0x2000000, {24, 384, 0x40, 0, 0, "Protocol_Catalog9"}, ... 388, ) }, ... 388, ) == 0x0 04488 432 NtQueryValueKey (388, (388, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (388, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) }, 16, ) == 0x0 04489 432 NtNotifyChangeKey (388, 380, 0, 0, 2011390432, 1, 0, 0, 0, 1, ... ) == 0x103 04490 432 NtQueryValueKey (388, (388, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (388, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) }, 16, ) == 0x0 04491 432 NtOpenKey (0x2000000, {24, 388, 0x40, 0, 0, (0x2000000, {24, 388, 0x40, 0, 0, "00000019"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04492 432 NtQueryValueKey (388, (388, "Next_Catalog_Entry_ID", Partial, 144, ... TitleIdx=0, Type=4, Data="\376\3\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (388, "Next_Catalog_Entry_ID", Partial, 144, ... TitleIdx=0, Type=4, Data="\376\3\0\0"}, 16, ) }, 16, ) == 0x0 04493 432 NtQueryValueKey (388, (388, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (388, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 04494 432 NtOpenKey (0x2000000, {24, 388, 0x40, 0, 0, (0x2000000, {24, 388, 0x40, 0, 0, "Catalog_Entries"}, ... 392, ) }, ... 392, ) == 0x0 04495 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000001"}, ... 396, ) }, ... 396, ) == 0x0 04496 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04497 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04498 432 NtAllocateVirtualMemory (-1, 1449984, 0, 4096, 4096, 4, ... 1449984, 4096, ) == 0x0 04499 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\227\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\227\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\227\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\224\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0\225\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\226\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\227\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04500 432 NtClose (396, ... ) == 0x0 04501 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000002"}, ... 396, ) }, ... 396, ) == 0x0 04502 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04503 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04504 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\234\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\234\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\234\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\231\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0\232\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\233\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\234\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04505 432 NtClose (396, ... ) == 0x0 04506 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000003"}, ... 396, ) }, ... 396, ) == 0x0 04507 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04508 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04509 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\241\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\241\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\241\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\236\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0\237\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\240\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\241\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04510 432 NtClose (396, ... ) == 0x0 04511 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000004"}, ... 396, ) }, ... 396, ) == 0x0 04512 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04513 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04514 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\246\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\246\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\246\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\243\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0\244\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\245\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\246\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04515 432 NtClose (396, ... ) == 0x0 04516 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000005"}, ... 396, ) }, ... 396, ) == 0x0 04517 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04518 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04519 432 NtAllocateVirtualMemory (-1, 1454080, 0, 4096, 4096, 4, ... 1454080, 4096, ) == 0x0 04520 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\254\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\254\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\254\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\251\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0\252\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\253\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\254\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04521 432 NtClose (396, ... ) == 0x0 04522 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000006"}, ... 396, ) }, ... 396, ) == 0x0 04523 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04524 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04525 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\261\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\261\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\261\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\256\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0\257\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\260\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\261\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04526 432 NtClose (396, ... ) == 0x0 04527 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000007"}, ... 396, ) }, ... 396, ) == 0x0 04528 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04529 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04530 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\266\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\266\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\266\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\263\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\264\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\265\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\266\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04531 432 NtClose (396, ... ) == 0x0 04532 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000008"}, ... 396, ) }, ... 396, ) == 0x0 04533 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04534 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04535 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\273\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\273\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\273\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\270\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\271\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\272\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\273\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04536 432 NtClose (396, ... ) == 0x0 04537 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000009"}, ... 396, ) }, ... 396, ) == 0x0 04538 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04539 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04540 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\300\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\300\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\300\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\275\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\276\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\277\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\300\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04541 432 NtClose (396, ... ) == 0x0 04542 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000010"}, ... 396, ) }, ... 396, ) == 0x0 04543 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04544 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04545 432 NtAllocateVirtualMemory (-1, 1458176, 0, 4096, 4096, 4, ... 1458176, 4096, ) == 0x0 04546 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\306\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\306\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\306\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0 (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\303\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\210\1\0\0\314\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0X\347\25\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\304\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\214\1\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\25\0\2\0\0\0\220\0\0\0\305\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\306\21\0\0\250\1\0\0\260\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\214\1\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 04547 432 NtClose (396, ... ) == 0x0 04548 432 NtOpenKey (0x20019, {24, 392, 0x40, 0, 0, (0x20019, {24, 392, 0x40, 0, 0, "000000000011"}, ... 396, ) }, ... 396, ) == 0x0 04549 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04550 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04551 432 NtQueryValueKey (396, (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\363\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\310\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\310\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\311\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\210\1\0\0\311\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\312\21\0\0\250\1\0\0\260\1\0\0\305\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0|\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\312\21\0\0\250\1\0\0\260\1\0\0\305\0\0\0\1\0\1\0\2\1\0\0\0\0\0\0\313\21\0\0\250\1\0\0\260\1\0\0\25\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\3\0\37\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\313\21\0\0\250\1\0\0\260\1\0\0\25\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\210\1\0\0\314\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0T\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0\200\1\0\0\350\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0&\0\230\234\25\0\0\0\0\0N\0a\0m\0e\0S\0p\0a\0c\0e\0_\0C\0a\0t\0a\0l\0o\0g\05\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (396, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\363\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\310\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\214\1\0\0\310\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\311\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\210\1\0\0\311\21\0\0\250\1\0\0\260\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\312\21\0\0\250\1\0\0\260\1\0\0\305\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0|\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\312\21\0\0\250\1\0\0\260\1\0\0\305\0\0\0\1\0\1\0\2\1\0\0\0\0\0\0\313\21\0\0\250\1\0\0\260\1\0\0\25\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\3\0\37\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\313\21\0\0\250\1\0\0\260\1\0\0\25\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\210\1\0\0\314\21\0\0\250\1\0\0\260\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0T\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0\200\1\0\0\350\354\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0&\0\230\234\25\0\0\0\0\0N\0a\0m\0e\0S\0p\0a\0c\0e\0_\0C\0a\0t\0a\0l\0o\0g\05\0"}, 900, ) }, 900, ) == 0x0 04552 432 NtClose (396, ... ) == 0x0 04553 432 NtClose (392, ... ) == 0x0 04554 432 NtWaitForSingleObject (380, 0, {0, 0}, ... ) == 0x102 04555 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 392, ) == 0x0 04556 432 NtOpenKey (0x2000000, {24, 384, 0x40, 0, 0, (0x2000000, {24, 384, 0x40, 0, 0, "NameSpace_Catalog5"}, ... 396, ) }, ... 396, ) == 0x0 04557 432 NtQueryValueKey (396, (396, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (396, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 04558 432 NtNotifyChangeKey (396, 392, 0, 0, 2011390432, 1, 0, 0, 0, 1, ... ) == 0x103 04559 432 NtQueryValueKey (396, (396, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (396, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 04560 432 NtOpenKey (0x2000000, {24, 396, 0x40, 0, 0, (0x2000000, {24, 396, 0x40, 0, 0, "00000004"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04561 432 NtQueryValueKey (396, (396, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (396, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) }, 16, ) == 0x0 04562 432 NtOpenKey (0x2000000, {24, 396, 0x40, 0, 0, (0x2000000, {24, 396, 0x40, 0, 0, "Catalog_Entries"}, ... 400, ) }, ... 400, ) == 0x0 04563 432 NtOpenKey (0x20019, {24, 400, 0x40, 0, 0, (0x20019, {24, 400, 0x40, 0, 0, "000000000001"}, ... 404, ) }, ... 404, ) == 0x0 04564 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 04565 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 04566 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 04567 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 04568 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 04569 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 04570 432 NtQueryValueKey (404, (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="@\235\5"\236~\317\21\256Z\0\252\0\247\21+"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="@\235\5"\236~\317\21\256Z\0\252\0\247\21+"}, 28, ) \236~\317\21\256Z\0\252\0\247\21+"}, 28, ) == 0x0 04571 432 NtQueryValueKey (404, (404, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04572 432 NtQueryValueKey (404, (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\14\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\14\0\0\0"}, 16, ) }, 16, ) == 0x0 04573 432 NtQueryValueKey (404, (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04574 432 NtQueryValueKey (404, (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04575 432 NtQueryValueKey (404, (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04576 432 NtClose (404, ... ) == 0x0 04577 432 NtOpenKey (0x20019, {24, 400, 0x40, 0, 0, (0x20019, {24, 400, 0x40, 0, 0, "000000000002"}, ... 404, ) }, ... 404, ) == 0x0 04578 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 04579 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 04580 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 04581 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 04582 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 04583 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 04584 432 NtQueryValueKey (404, (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="\3567&;\200\345\317\21\245U\0\300O\330\324\254"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="\3567&;\200\345\317\21\245U\0\300O\330\324\254"}, 28, ) }, 28, ) == 0x0 04585 432 NtQueryValueKey (404, (404, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04586 432 NtQueryValueKey (404, (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 04587 432 NtQueryValueKey (404, (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04588 432 NtQueryValueKey (404, (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04589 432 NtQueryValueKey (404, (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04590 432 NtClose (404, ... ) == 0x0 04591 432 NtOpenKey (0x20019, {24, 400, 0x40, 0, 0, (0x20019, {24, 400, 0x40, 0, 0, "000000000003"}, ... 404, ) }, ... 404, ) == 0x0 04592 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 04593 432 NtQueryValueKey (404, (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 04594 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 04595 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 04596 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 04597 432 NtQueryValueKey (404, (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (404, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 04598 432 NtQueryValueKey (404, (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data=":$Bf\250;\246J\272\245.\13\327\37\335\203"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (404, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data=":$Bf\250;\246J\272\245.\13\327\37\335\203"}, 28, ) }, 28, ) == 0x0 04599 432 NtQueryValueKey (404, (404, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04600 432 NtQueryValueKey (404, (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\17\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\17\0\0\0"}, 16, ) }, 16, ) == 0x0 04601 432 NtQueryValueKey (404, (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04602 432 NtQueryValueKey (404, (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04603 432 NtQueryValueKey (404, (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04604 432 NtClose (404, ... ) == 0x0 04605 432 NtClose (400, ... ) == 0x0 04606 432 NtWaitForSingleObject (392, 0, {0, 0}, ... ) == 0x102 04607 432 NtClose (384, ... ) == 0x0 04608 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 04609 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 04610 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Winsock2\Parameters"}, ... 384, ) }, ... 384, ) == 0x0 04611 432 NtQueryValueKey (384, (384, "Ws2_32NumHandleBuckets", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04612 432 NtClose (384, ... ) == 0x0 04613 432 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 384, ) == 0x0 04614 432 NtClearEvent (352, ... ) == 0x0 04615 432 NtSetEvent (352, ... 0x0, ) == 0x0 04616 432 NtWaitForSingleObject (324, 0, 0x0, ... ) == 0x0 04617 432 NtQueryInformationFile (320, 1240216, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04618 432 NtReleaseMutant (324, ... 0x0, ) == 0x0 04619 432 NtAllocateVirtualMemory (-1, 1462272, 0, 4096, 4096, 4, ... 1462272, 4096, ) == 0x0 04620 432 NtWaitForSingleObject (392, 0, {0, 0}, ... ) == 0x102 04621 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 1237336, ... ) }, 1237336, ... ) == 0x0 04622 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 5, 96, ... 400, {status=0x0, info=1}, ) }, 5, 96, ... 400, {status=0x0, info=1}, ) == 0x0 04623 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 400, ... 404, ) == 0x0 04624 432 NtClose (400, ... ) == 0x0 04625 432 NtMapViewOfSection (404, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xb30000), 0x0, 229376, ) == 0x0 04626 432 NtClose (404, ... ) == 0x0 04627 432 NtUnmapViewOfSection (-1, 0xb30000, ... ) == 0x0 04628 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 1237652, ... ) }, 1237652, ... ) == 0x0 04629 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 5, 96, ... 404, {status=0x0, info=1}, ) }, 5, 96, ... 404, {status=0x0, info=1}, ) == 0x0 04630 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 404, ... 400, ) == 0x0 04631 432 NtQuerySection (400, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04632 432 NtClose (404, ... ) == 0x0 04633 432 NtMapViewOfSection (400, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71a50000), 0x0, 241664, ) == 0x0 04634 432 NtClose (400, ... ) == 0x0 04635 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 04636 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 04637 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 400, ) == 0x0 04638 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "DNSAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04639 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\DNSAPI.dll"}, 1237452, ... ) }, 1237452, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04640 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "DNSAPI.dll"}, 1237452, ... ) }, 1237452, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04641 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DNSAPI.dll"}, 1237452, ... ) }, 1237452, ... ) == 0x0 04642 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DNSAPI.dll"}, 5, 96, ... 404, {status=0x0, info=1}, ) }, 5, 96, ... 404, {status=0x0, info=1}, ) == 0x0 04643 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 404, ... 408, ) == 0x0 04644 432 NtQuerySection (408, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04645 432 NtClose (404, ... ) == 0x0 04646 432 NtMapViewOfSection (408, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f20000), 0x0, 151552, ) == 0x0 04647 432 NtClose (408, ... ) == 0x0 04648 432 NtCreateKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) }, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) , 0, ... 408, 2, ) == 0x0 04649 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 404, ) }, ... 404, ) == 0x0 04650 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04651 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DNS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04652 432 NtQueryValueKey (404, (404, "QueryAdapterName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04653 432 NtQueryValueKey (408, (408, "DisableAdapterDomainName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04654 432 NtQueryValueKey (404, (404, "UseDomainNameDevolution", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04655 432 NtQueryValueKey (408, (408, "UseDomainNameDevolution", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (408, "UseDomainNameDevolution", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04656 432 NtQueryValueKey (404, (404, "PrioritizeRecordData", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04657 432 NtQueryValueKey (408, (408, "PrioritizeRecordData", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04658 432 NtQueryValueKey (404, (404, "AllowUnqualifiedQuery", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04659 432 NtQueryValueKey (408, (408, "AllowUnqualifiedQuery", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04660 432 NtQueryValueKey (404, (404, "AppendToMultiLabelName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04661 432 NtQueryValueKey (404, (404, "ScreenBadTlds", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04662 432 NtQueryValueKey (404, (404, "ScreenUnreachableServers", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04663 432 NtQueryValueKey (404, (404, "FilterClusterIp", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04664 432 NtQueryValueKey (404, (404, "WaitForNameErrorOnAll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04665 432 NtQueryValueKey (404, (404, "UseEdns", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04666 432 NtQueryValueKey (404, (404, "RegistrationEnabled", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04667 432 NtQueryValueKey (408, (408, "DisableDynamicUpdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04668 432 NtQueryValueKey (404, (404, "RegisterPrimaryName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04669 432 NtQueryValueKey (404, (404, "RegisterAdapterName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04670 432 NtQueryValueKey (408, (408, "EnableAdapterDomainNameRegistration", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04671 432 NtQueryValueKey (404, (404, "RegisterReverseLookup", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04672 432 NtQueryValueKey (408, (408, "DisableReverseAddressRegistrations", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04673 432 NtQueryValueKey (404, (404, "RegisterWanAdapters", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04674 432 NtQueryValueKey (408, (408, "DisableWanDynamicUpdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04675 432 NtQueryValueKey (404, (404, "RegistrationOverwritesInConflict", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04676 432 NtQueryValueKey (408, (408, "DisableReplaceAddressesInConflicts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04677 432 NtQueryValueKey (404, (404, "RegistrationTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04678 432 NtQueryValueKey (408, (408, "DefaultRegistrationTTL", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04679 432 NtQueryValueKey (404, (404, "RegistrationRefreshInterval", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04680 432 NtQueryValueKey (408, (408, "DefaultRegistrationRefreshInterval", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04681 432 NtQueryValueKey (404, (404, "RegistrationMaxAddressCount", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04682 432 NtQueryValueKey (408, (408, "MaxNumberOfAddressesToRegister", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04683 432 NtQueryValueKey (404, (404, "UpdateSecurityLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04684 432 NtQueryValueKey (408, (408, "UpdateSecurityLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04685 432 NtQueryValueKey (404, (404, "UpdateZoneExcludeFile", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04686 432 NtQueryValueKey (404, (404, "UpdateTopLevelDomainZones", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04687 432 NtQueryValueKey (404, (404, "DnsTest", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04688 432 NtQueryValueKey (404, (404, "MaxCacheSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04689 432 NtQueryValueKey (404, (404, "MaxCacheTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04690 432 NtQueryValueKey (404, (404, "MaxNegativeCacheTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04691 432 NtQueryValueKey (404, (404, "AdapterTimeoutLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04692 432 NtQueryValueKey (404, (404, "ServerPriorityTimeLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04693 432 NtQueryValueKey (404, (404, "MaxCachedSockets", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04694 432 NtQueryValueKey (404, (404, "UseMulticast", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04695 432 NtQueryValueKey (404, (404, "MulticastOnNameError", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04696 432 NtQueryValueKey (404, (404, "UseDotLocalDomain", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04697 432 NtQueryValueKey (404, (404, "ListenOnMulticast", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04698 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\Setup"}, ... 412, ) }, ... 412, ) == 0x0 04699 432 NtQueryValueKey (412, (412, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (412, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04700 432 NtClose (412, ... ) == 0x0 04701 432 NtClose (408, ... ) == 0x0 04702 432 NtClose (404, ... ) == 0x0 04703 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 404, ) }, ... 404, ) == 0x0 04704 432 NtQueryValueKey (404, (404, "DnsQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04705 432 NtQueryValueKey (404, (404, "DnsQuickQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04706 432 NtQueryValueKey (404, (404, "DnsMulticastQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04707 432 NtClose (404, ... ) == 0x0 04708 432 NtAllocateVirtualMemory (-1, 1466368, 0, 4096, 4096, 4, ... 1466368, 4096, ) == 0x0 04709 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 404, ) == 0x0 04710 432 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 1}, 0x0, 0x0, 1237928, 112, ... 408, 0x0, 0x0, 0x0, 112, ) , {12, 2, 1, 1}, 0x0, 0x0, 1237928, 112, ... 408, 0x0, 0x0, 0x0, 112, ) == 0x0 04711 432 NtRequestWaitReplyPort (408, {128, 152, new_msg, 0, 123260, 1310720, 1237692, 2012750850} (408, {128, 152, new_msg, 0, 123260, 1310720, 1237692, 2012750850} "\0\351\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\260G\25\0x^\26\0\0\0\0\0p^\26\0\230^\26\0\300^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1530, 0} "\7\351\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\260G\25\0x^\26\0\0\0\0\0p^\26\0\230^\26\0\300^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ... {128, 152, reply, 0, 424, 432, 1530, 0} (408, {128, 152, new_msg, 0, 123260, 1310720, 1237692, 2012750850} "\0\351\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\260G\25\0x^\26\0\0\0\0\0p^\26\0\230^\26\0\300^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1530, 0} "\7\351\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\260G\25\0x^\26\0\0\0\0\0p^\26\0\230^\26\0\300^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ) == 0x0 04712 432 NtRequestWaitReplyPort (408, {64, 88, new_msg, 0, 32, 1, 8, 1310720} (408, {64, 88, new_msg, 0, 32, 1, 8, 1310720} "\1\0\0\0A\2\10\0\230\320\377k\22\241\206\2303F\303\370~4Z\377\377\377\377\4]\210\212\0\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0d\0o\0c\0k\0P\0r\0i\0v\0" ... {52, 76, reply, 0, 424, 432, 1531, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\200W\12\0\1\0\0\0\1\0\0\0\300\250|\201\377\377\377\0" ) ... {52, 76, reply, 0, 424, 432, 1531, 0} (408, {64, 88, new_msg, 0, 32, 1, 8, 1310720} "\1\0\0\0A\2\10\0\230\320\377k\22\241\206\2303F\303\370~4Z\377\377\377\377\4]\210\212\0\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0d\0o\0c\0k\0P\0r\0i\0v\0" ... {52, 76, reply, 0, 424, 432, 1531, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\200W\12\0\1\0\0\0\1\0\0\0\300\250|\201\377\377\377\0" ) ) == 0x0 04713 432 NtClose (404, ... ) == 0x0 04714 432 NtClose (408, ... ) == 0x0 04715 432 NtCreateKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) }, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) , 0, ... 408, 2, ) == 0x0 04716 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 404, ) }, ... 404, ) == 0x0 04717 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04718 432 NtQueryValueKey (408, (408, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04719 432 NtQueryValueKey (408, (408, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04720 432 NtClose (408, ... ) == 0x0 04721 432 NtClose (404, ... ) == 0x0 04722 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 404, ) == 0x0 04723 432 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 1}, 0x0, 0x0, 1237792, 112, ... 408, 0x0, 0x0, 0x0, 112, ) , {12, 2, 1, 1}, 0x0, 0x0, 1237792, 112, ... 408, 0x0, 0x0, 0x0, 112, ) == 0x0 04724 432 NtRequestWaitReplyPort (408, {128, 152, new_msg, 0, 123124, 1310720, 1237556, 2012750850} (408, {128, 152, new_msg, 0, 123124, 1310720, 1237556, 2012750850} "\0\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\260G\25\0\240^\26\0\0\0\0\0\10\0\0\0?\360\367w\221\337\314w\0\0\0\0\0\0\22\0 \344\22\0x\1\24\0H_\26\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1534, 0} "\7\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\260G\25\0\240^\26\0\0\0\0\0\10\0\0\0?\360\367w\221\337\314w\0\0\0\0\0\0\22\0 \344\22\0x\1\24\0H_\26\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ... {128, 152, reply, 0, 424, 432, 1534, 0} (408, {128, 152, new_msg, 0, 123124, 1310720, 1237556, 2012750850} "\0\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\260G\25\0\240^\26\0\0\0\0\0\10\0\0\0?\360\367w\221\337\314w\0\0\0\0\0\0\22\0 \344\22\0x\1\24\0H_\26\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1534, 0} "\7\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\260G\25\0\240^\26\0\0\0\0\0\10\0\0\0?\360\367w\221\337\314w\0\0\0\0\0\0\22\0 \344\22\0x\1\24\0H_\26\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ) == 0x0 04725 432 NtRequestWaitReplyPort (408, {44, 68, new_msg, 0, 424, 432, 1531, 0} (408, {44, 68, new_msg, 0, 424, 432, 1531, 0} "\1\0\0\0A\2\4\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\377\377\377\377\200\2\307w\0\0\0\0\0\0\0\0\1\0\0\0" ... {40, 64, reply, 0, 424, 432, 1535, 0} "\2\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\324\1\0\0\240,\11\0" ) ... {40, 64, reply, 0, 424, 432, 1535, 0} (408, {44, 68, new_msg, 0, 424, 432, 1531, 0} "\1\0\0\0A\2\4\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\377\377\377\377\200\2\307w\0\0\0\0\0\0\0\0\1\0\0\0" ... {40, 64, reply, 0, 424, 432, 1535, 0} "\2\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\324\1\0\0\240,\11\0" ) ) == 0x0 04726 432 NtRequestWaitReplyPort (408, {64, 88, new_msg, 56, 0, 1, 0, 0} (408, {64, 88, new_msg, 56, 0, 1, 0, 0} "\10\344\22\0@\0\314wHG\25\0\350\344\22\0P\345\22\0\0\267\362vP\345\22\0HG\25\0\1\0\0\0h\4\25\0\324\1\0\0\324\1\0\0\240,\11\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {64, 88, reply, 56, 424, 432, 1536, 0} "\10\344\22\0@\0\314wHG\25\0\350\344\22\0P\345\22\0\0\267\362vP\345\22\0HG\25\0\1\0\0\0h\4\25\0\324\1\0\0\324\1\0\0\240,\11\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {64, 88, reply, 56, 424, 432, 1536, 0} (408, {64, 88, new_msg, 56, 0, 1, 0, 0} "\10\344\22\0@\0\314wHG\25\0\350\344\22\0P\345\22\0\0\267\362vP\345\22\0HG\25\0\1\0\0\0h\4\25\0\324\1\0\0\324\1\0\0\240,\11\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {64, 88, reply, 56, 424, 432, 1536, 0} "\10\344\22\0@\0\314wHG\25\0\350\344\22\0P\345\22\0\0\267\362vP\345\22\0HG\25\0\1\0\0\0h\4\25\0\324\1\0\0\324\1\0\0\240,\11\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 04727 432 NtClose (404, ... ) == 0x0 04728 432 NtClose (408, ... ) == 0x0 04729 432 NtCreateKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) }, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) , 0, ... 408, 2, ) == 0x0 04730 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 404, ) }, ... 404, ) == 0x0 04731 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04732 432 NtQueryValueKey (408, (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04733 432 NtQueryValueKey (408, (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04734 432 NtClose (408, ... ) == 0x0 04735 432 NtClose (404, ... ) == 0x0 04736 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 404, ) }, ... 404, ) == 0x0 04737 432 NtQueryValueKey (404, (404, "DnsNbtLookupOrder", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04738 432 NtClose (404, ... ) == 0x0 04739 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 1237336, ... ) }, 1237336, ... ) == 0x0 04740 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... 404, {status=0x0, info=1}, ) }, 5, 96, ... 404, {status=0x0, info=1}, ) == 0x0 04741 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 404, ... 408, ) == 0x0 04742 432 NtClose (404, ... ) == 0x0 04743 432 NtMapViewOfSection (408, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xb30000), 0x0, 16384, ) == 0x0 04744 432 NtClose (408, ... ) == 0x0 04745 432 NtUnmapViewOfSection (-1, 0xb30000, ... ) == 0x0 04746 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 1237652, ... ) }, 1237652, ... ) == 0x0 04747 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... 408, {status=0x0, info=1}, ) }, 5, 96, ... 408, {status=0x0, info=1}, ) == 0x0 04748 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 408, ... 404, ) == 0x0 04749 432 NtQuerySection (404, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04750 432 NtClose (408, ... ) == 0x0 04751 432 NtMapViewOfSection (404, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76fb0000), 0x0, 28672, ) == 0x0 04752 432 NtClose (404, ... ) == 0x0 04753 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WLDAP32.dll"}, ... 404, ) }, ... 404, ) == 0x0 04754 432 NtMapViewOfSection (404, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f60000), 0x0, 180224, ) == 0x0 04755 432 NtClose (404, ... ) == 0x0 04756 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 404, ) == 0x0 04757 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\LDAP"}, ... 408, ) }, ... 408, ) == 0x0 04758 432 NtQueryValueKey (408, (408, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (408, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04759 432 NtClose (408, ... ) == 0x0 04760 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 1237336, ... ) }, 1237336, ... ) == 0x0 04761 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 04762 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 11730944, 65536, ) == 0x0 04763 432 NtAllocateVirtualMemory (-1, 11730944, 0, 4096, 4096, 4, ... 11730944, 4096, ) == 0x0 04764 432 NtAllocateVirtualMemory (-1, 11735040, 0, 8192, 4096, 4, ... 11735040, 8192, ) == 0x0 04765 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 408, ) == 0x0 04766 432 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 1}, 0x0, 0x0, 1237624, 112, ... 412, 0x0, 0x0, 0x0, 112, ) , {12, 2, 1, 1}, 0x0, 0x0, 1237624, 112, ... 412, 0x0, 0x0, 0x0, 112, ) == 0x0 04767 432 NtRequestWaitReplyPort (412, {128, 152, new_msg, 0, 122956, 1310720, 1237388, 2012750850} (412, {128, 152, new_msg, 0, 122956, 1310720, 1237388, 2012750850} "\0\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\260G\25\0(c\26\0\0\0\0\0 c\26\0Hc\26\0pc\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1539, 0} "\7\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\260G\25\0(c\26\0\0\0\0\0 c\26\0Hc\26\0pc\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ... {128, 152, reply, 0, 424, 432, 1539, 0} (412, {128, 152, new_msg, 0, 122956, 1310720, 1237388, 2012750850} "\0\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\260G\25\0(c\26\0\0\0\0\0 c\26\0Hc\26\0pc\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1539, 0} "\7\350\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\260G\25\0(c\26\0\0\0\0\0 c\26\0Hc\26\0pc\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\24\0\0\0\0\0\5\0\0\0\5\0\0\0" ) ) == 0x0 04768 432 NtRequestWaitReplyPort (412, {64, 88, new_msg, 0, 424, 432, 1535, 0} (412, {64, 88, new_msg, 0, 424, 432, 1535, 0} "\1\0\0\0A\2\10\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\377\377\377\377\200\2\307w\0\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\377\377\377\0c\0k\0P\0r\0i\0v\0" ... {52, 76, reply, 0, 424, 432, 1540, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\200]\12\0\1\0\0\0\1\0\0\0\300\250|\201\377\377\377\0" ) ... {52, 76, reply, 0, 424, 432, 1540, 0} (412, {64, 88, new_msg, 0, 424, 432, 1535, 0} "\1\0\0\0A\2\10\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\377\377\377\377\200\2\307w\0\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\377\377\377\0c\0k\0P\0r\0i\0v\0" ... {52, 76, reply, 0, 424, 432, 1540, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\200]\12\0\1\0\0\0\1\0\0\0\300\250|\201\377\377\377\0" ) ) == 0x0 04769 432 NtClose (408, ... ) == 0x0 04770 432 NtClose (412, ... ) == 0x0 04771 432 NtCreateKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 412, 2, ) }, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 412, 2, ) , 0, ... 412, 2, ) == 0x0 04772 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 408, ) }, ... 408, ) == 0x0 04773 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04774 432 NtQueryValueKey (412, (412, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (412, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04775 432 NtQueryValueKey (412, (412, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (412, "Hostname", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04776 432 NtClose (412, ... ) == 0x0 04777 432 NtClose (408, ... ) == 0x0 04778 432 NtCreateKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) }, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 408, 2, ) , 0, ... 408, 2, ) == 0x0 04779 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 412, ) }, ... 412, ) == 0x0 04780 432 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04781 432 NtQueryValueKey (408, (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04782 432 NtQueryValueKey (408, (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (408, "Domain", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04783 432 NtClose (408, ... ) == 0x0 04784 432 NtClose (412, ... ) == 0x0 04785 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\VxD\MSTCP"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04786 432 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Control\ComputerName\ComputerName"}, ... 412, ) }, ... 412, ) == 0x0 04787 432 NtQueryValueKey (412, (412, "ComputerName", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (412, "ComputerName", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04788 432 NtQueryValueKey (412, (412, "ComputerName", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (412, "ComputerName", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 28, ) }, 28, ) == 0x0 04789 432 NtClose (412, ... ) == 0x0 04790 432 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 412, ) }, ... 412, ) == 0x0 04791 432 NtWaitForSingleObject (412, 0, {-1800000000, -1}, ... ) == 0x0 04792 432 NtClose (412, ... ) == 0x0 04793 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04794 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 412, ) == 0x0 04795 432 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04796 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 04797 432 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1238496, (0xc0100080, {24, 0, 0x40, 0, 1238496, "\??\PIPE\svcctl"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 408, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 408, {status=0x0, info=1}, ) == 0x0 04798 432 NtSetInformationFile (408, 1238552, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 04799 432 NtSetInformationFile (408, 1238544, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 04800 432 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 04801 432 NtWriteFile (408, 261, 0, 0, (408, 261, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\201\273z6D\230\3615\2552\230\3608\0\20\3\2\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 04802 432 NtReadFile (408, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (408, 261, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\201"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x0 04803 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\0\0\0\200", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\201"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 36, 1024, ... {status=0x103, info=68}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\0\0\0\200", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\201"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x103 04804 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\2\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0\0\0\0\0", 64, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 64, 1024, ... {status=0x103, info=48}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\2\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0\0\0\0\0", 64, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 04805 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\3\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\02\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\2\0\0\0X\2\0\0\0\0\0\0@\2\0\0.\2\0\0\22\2\0\0 \0\0\0\4\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\2\0\0\340\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\316\1\0\0\240\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\226\1\0\0~\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0l\1\0\0B\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\1\0\0\32\1\0\0 \0\0\0\4\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\16\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\0R\0S\0v\0c\0\0\0DNS Client\0\0i\0e\0n\0t\0\0\0Dnscache\0\0c\0h\0e\0\0\0Logical Disk Manager\0\0k\0 \0M\0a\0n\0a\0g\0e\0r\0\0\0dmserver\0\0v\0e\0r\0\0\0DHCP Client\0l\0i\0e\0n\0t\0\0\0Dhcp\0\0p\0\0\0Cryptographic Services\0\0c\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0CryptSvc\0\0", ) , 64, 1024, ... {status=0x103, info=624}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\3\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\02\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\2\0\0\0X\2\0\0\0\0\0\0@\2\0\0.\2\0\0\22\2\0\0 \0\0\0\4\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\2\0\0\340\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\316\1\0\0\240\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\226\1\0\0~\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0l\1\0\0B\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\1\0\0\32\1\0\0 \0\0\0\4\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\16\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0E\0R\0S\0v\0c\0\0\0DNS Client\0\0i\0e\0n\0t\0\0\0Dnscache\0\0c\0h\0e\0\0\0Logical Disk Manager\0\0k\0 \0M\0a\0n\0a\0g\0e\0r\0\0\0dmserver\0\0v\0e\0r\0\0\0DHCP Client\0l\0i\0e\0n\0t\0\0\0Dhcp\0\0p\0\0\0Cryptographic Services\0\0c\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0CryptSvc\0\0", ) , ) == 0x103 04806 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\4\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0>\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\3\0\0\0X\2\0\0\0\0\0\0@\2\0\04\2\0\0\4\2\0\0 \0\0\0\4\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\362\1\0\0\336\1\0\0 \0\0\0\4\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\306\1\0\0\242\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0d\1\0\0 \1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\1\0\0\356\0\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Help and Support\0\0S\0u\0p\0p\0o\0r\0t\0\0\0helpsvc\0s\0v\0c\0\0\0Fast User Switching Compatibility\0n\0g\0 \0C\0o\0m\0p\0a\0t\0i\0b\0i\0l\0i\0t\0y\0\0\0FastUserSwitchingCompatibility\0\0g\0C\0o\0m\0p\0a\0t\0i\0b\0i\0l\0i\0t\0y\0\0\0COM+ Event System\0t\0 \0S\0y\0s\0t\0e\0m\0\0\0EventSystem\0y\0s\0t\0", ) , 64, 1024, ... {status=0x103, info=624}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\4\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0>\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\3\0\0\0X\2\0\0\0\0\0\0@\2\0\04\2\0\0\4\2\0\0 \0\0\0\4\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\362\1\0\0\336\1\0\0 \0\0\0\4\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\306\1\0\0\242\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0d\1\0\0 \1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\1\0\0\356\0\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Help and Support\0\0S\0u\0p\0p\0o\0r\0t\0\0\0helpsvc\0s\0v\0c\0\0\0Fast User Switching Compatibility\0n\0g\0 \0C\0o\0m\0p\0a\0t\0i\0b\0i\0l\0i\0t\0y\0\0\0FastUserSwitchingCompatibility\0\0g\0C\0o\0m\0p\0a\0t\0i\0b\0i\0l\0i\0t\0y\0\0\0COM+ Event System\0t\0 \0S\0y\0s\0t\0e\0m\0\0\0EventSystem\0y\0s\0t\0", ) , ) == 0x103 04807 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\5\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0p\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\4\0\0\0X\2\0\0\0\0\0\0@\2\0\0&\2\0\0\30\2\0\0 \0\0\0\4\0\0\0\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\364\1\0\0\334\1\0\0 \0\0\0\4\0\0\0\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\314\1\0\0\240\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\214\1\0\0x\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0j\1\0\0B\1\0\0 \1\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\1\0\0\370\0\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Network Location Awareness (NLA)\0\0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0\0\0Nla\0a\0\0\0Network Connections\0n\0n\0e\0c\0t\0i\0o\0n\0s\0\0\0Netman\0\0a\0n\0\0\0Messenger\0n\0g\0e\0r\0\0\0Messenger\0n\0g\0e\0r\0\0\0TCP/IP NetBIOS Helper\0I\0O\0S\0 \0H\0e\0l\0p\0e\0r\0\0\0LmHosts\0s\0t\0", ) , 64, 1024, ... {status=0x103, info=624}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\5\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0p\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\4\0\0\0X\2\0\0\0\0\0\0@\2\0\0&\2\0\0\30\2\0\0 \0\0\0\4\0\0\0\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\364\1\0\0\334\1\0\0 \0\0\0\4\0\0\0\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\314\1\0\0\240\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\214\1\0\0x\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0j\1\0\0B\1\0\0 \1\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\1\0\0\370\0\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Network Location Awareness (NLA)\0\0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0\0\0Nla\0a\0\0\0Network Connections\0n\0n\0e\0c\0t\0i\0o\0n\0s\0\0\0Netman\0\0a\0n\0\0\0Messenger\0n\0g\0e\0r\0\0\0Messenger\0n\0g\0e\0r\0\0\0TCP/IP NetBIOS Helper\0I\0O\0S\0 \0H\0e\0l\0p\0e\0r\0\0\0LmHosts\0s\0t\0", ) , ) == 0x103 04808 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\6\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0\242\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\5\0\0\0X\2\0\0\0\0\0\0@\2\0\0.\2\0\0\22\2\0\0 \0\0\0\4\0\0\0\204\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\372\1\0\0\334\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\272\1\0\0\226\1\0\0 \1\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\0\0X\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L\1\0\0\24\1\0\0 \0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0a\0m\0S\0s\0\0\0Remote Procedure Call (RPC)\0r\0e\0 \0C\0a\0l\0l\0 \0(\0R\0P\0C\0)\0\0\0RpcSs\0S\0s\0\0\0Remote Registry\0e\0g\0i\0s\0t\0r\0y\0\0\0RemoteRegistry\0\0g\0i\0s\0t\0r\0y\0\0\0Protected Storage\0 \0S\0t\0o\0r\0a\0g\0e\0\0\0ProtectedStorage\0\0S\0t\0o\0r\0a\0g\0", ) , 64, 1024, ... {status=0x103, info=624}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\6\0\0\0(\0\0\0\0\0\32\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\1\0\0\0@\2\0\0\254\356\22\0\242\0\0\0", 64, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\5\0\0\0X\2\0\0\0\0\0\0@\2\0\0.\2\0\0\22\2\0\0 \0\0\0\4\0\0\0\204\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\372\1\0\0\334\1\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\272\1\0\0\226\1\0\0 \1\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0x\1\0\0X\1\0\0 \0\0\0\4\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L\1\0\0\24\1\0\0 \0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0a\0m\0S\0s\0\0\0Remote Procedure Call (RPC)\0r\0e\0 \0C\0a\0l\0l\0 \0(\0R\0P\0C\0)\0\0\0RpcSs\0S\0s\0\0\0Remote Registry\0e\0g\0i\0s\0t\0r\0y\0\0\0RemoteRegistry\0\0g\0i\0s\0t\0r\0y\0\0\0Protected Storage\0 \0S\0t\0o\0r\0a\0g\0e\0\0\0ProtectedStorage\0\0S\0t\0o\0r\0a\0g\0", ) , ) == 0x103 04809 432 NtFsControlFile (408, 261, 0x0, 0x0, 0x11c017, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\7\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\6\0\0\0X\2\0\0\0\0\0\0@\2\0\04\2\0\0\0\2\0\0 \0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\356\1\0\0\320\1\0\0 \1\0\0\4\0\0\0G\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\276\1\0\0\236\1\0\0 \1\0\0\4\0\0\0\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\1\0\0`\1\0\0 \0\0\0\4\0\0\0A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0>\1\0\0\14\1\0\0 \0\0\0\4\0\0\0\207\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\0\0\0\340\0\0\0\20\1\0\0\4\0\0\0E\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Print Spooler\0p\0o\0o\0l\0e\0r\0\0\0Spooler\0l\0e\0r\0\0\0Shell Hardware Detection\0\0e\0 \0D\0e\0t\0e\0c\0t\0i\0o\0n\0\0\0ShellHWDetection\0\0t\0e\0c\0t\0i\0o\0n\0\0\0System Event Notification\0N\0o\0t\0i\0f\0i\0c\0a\0t\0i\0o\0n\0\0\0SENS\0\0S\0\0\0Secondary Logon\0y\0 \0L\0o\0g\0o\0n\0\0\0seclogon\0\0g\0o\0n\0\0\0Task Sch", ) , 44, 1024, ... {status=0x103, info=624}, (408, 261, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\7\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\271{\2061\344~\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=624}, "\5\0\2\3\20\0\0\0p\2\0\0\6\0\0\0X\2\0\0\0\0\0\0@\2\0\04\2\0\0\0\2\0\0 \0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\356\1\0\0\320\1\0\0 \1\0\0\4\0\0\0G\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\276\1\0\0\236\1\0\0 \1\0\0\4\0\0\0\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\1\0\0`\1\0\0 \0\0\0\4\0\0\0A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0>\1\0\0\14\1\0\0 \0\0\0\4\0\0\0\207\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\374\0\0\0\340\0\0\0\20\1\0\0\4\0\0\0E\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Print Spooler\0p\0o\0o\0l\0e\0r\0\0\0Spooler\0l\0e\0r\0\0\0Shell Hardware Detection\0\0e\0 \0D\0e\0t\0e\0c\0t\0i\0o\0n\0\0\0ShellHWDetection\0\0t\0e\0c\0t\0i\0o\0n\0\0\0System Event Notification\0N\0o\0t\0i\0f\0i\0c\0a\0t\0i\0o\0n\0\0\0SENS\0\0S\0\0\0Secondary Logon\0y\0 \0L\0o\0g\0o\0n\0\0\0seclogon\0\0g\0o\0n\0\0\0Task Sch", ) , ) == 0x103 04810 432 NtClose (412, ... ) == 0x0 04811 432 NtClose (408, ... ) == 0x0 04812 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "sensapi.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04813 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\sensapi.dll"}, 1238756, ... ) }, 1238756, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04814 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "sensapi.dll"}, 1238756, ... ) }, 1238756, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04815 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\sensapi.dll"}, 1238756, ... ) }, 1238756, ... ) == 0x0 04816 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\sensapi.dll"}, 5, 96, ... 408, {status=0x0, info=1}, ) }, 5, 96, ... 408, {status=0x0, info=1}, ) == 0x0 04817 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 408, ... 412, ) == 0x0 04818 432 NtQuerySection (412, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04819 432 NtClose (408, ... ) == 0x0 04820 432 NtMapViewOfSection (412, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x722b0000), 0x0, 20480, ) == 0x0 04821 432 NtClose (412, ... ) == 0x0 04822 432 NtOpenSection (0x4, {24, 52, 0x0, 0, 0, (0x4, {24, 52, 0x0, 0, 0, "SENS Information Cache"}, ... 412, ) }, ... 412, ) == 0x0 04823 432 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xb40000), {0, 0}, 4096, ) == 0x0 04824 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 408, ) == 0x0 04825 432 NtConnectPort ( ("\RPC Control\senssvc", {12, 2, 1, 1}, 0x0, 0x0, 1239220, 112, ... 416, 0x0, 0x0, 0x0, 112, ) , {12, 2, 1, 1}, 0x0, 0x0, 1239220, 112, ... 416, 0x0, 0x0, 0x0, 112, ) == 0x0 04826 432 NtRequestWaitReplyPort (416, {128, 152, new_msg, 0, 1310720, 124552, 1310720, 1238984} (416, {128, 152, new_msg, 0, 1310720, 124552, 1310720, 1238984} "\0$\370wx\356\22\0\2$\370w$\344\373c) \321\21\215\270\0\252\0J\275^\1\0\0\0\1\0\0\0\30P\26\0\4\0\0\0\30P\26\0\20\344\314w\30P\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\0\0\212\0\0\300\3304$\0\0\0+r\0\0+\0\370b\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1543, 0} "\7$\370wx\356\22\0\2$\370w$\344\373c) \321\21\215\270\0\252\0J\275^\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\30P\26\0\377\377\377\377\30P\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\0\0\212\0\0\300\3304$\0\0\0+r\0\0+\0\370b\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\5\0\0\0" ) ... {128, 152, reply, 0, 424, 432, 1543, 0} (416, {128, 152, new_msg, 0, 1310720, 124552, 1310720, 1238984} "\0$\370wx\356\22\0\2$\370w$\344\373c) \321\21\215\270\0\252\0J\275^\1\0\0\0\1\0\0\0\30P\26\0\4\0\0\0\30P\26\0\20\344\314w\30P\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\0\0\212\0\0\300\3304$\0\0\0+r\0\0+\0\370b\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\5\0\0\0" ... {128, 152, reply, 0, 424, 432, 1543, 0} "\7$\370wx\356\22\0\2$\370w$\344\373c) \321\21\215\270\0\252\0J\275^\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\30P\26\0\377\377\377\377\30P\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\0\0\212\0\0\300\3304$\0\0\0+r\0\0+\0\370b\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\5\0\0\0" ) ) == 0x0 04827 432 NtRequestWaitReplyPort (416, {32, 56, new_msg, 0, 44, 7, 20, 0} (416, {32, 56, new_msg, 0, 44, 7, 20, 0} "\1\0\0\0A\2\0\0\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\377\377\377\377@\2\0\0" ... {124, 148, reply, 0, 424, 432, 1544, 0} "\2\0\372\177\1\00\300\0\0\0\0\227\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\304\13\11\370X\5O\200\0\0\372\177\0\0\0\0\0\0\0\0\330Z\26\201\230\303\34\201\1\304\34\201\0\0\0\0\200\376\37\300\230\303\34\201\0\0\0\0\0\0\334\0\377\377\333\0\0\0\0\0\0\0\334\0\0\0\0\0\230\303\34\201<\13\11\370" ) ... {124, 148, reply, 0, 424, 432, 1544, 0} (416, {32, 56, new_msg, 0, 44, 7, 20, 0} "\1\0\0\0A\2\0\0\344~\334\21\261\310\0\14)\371\246\3050\0\0\0\377\377\377\377@\2\0\0" ... {124, 148, reply, 0, 424, 432, 1544, 0} "\2\0\372\177\1\00\300\0\0\0\0\227\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\304\13\11\370X\5O\200\0\0\372\177\0\0\0\0\0\0\0\0\330Z\26\201\230\303\34\201\1\304\34\201\0\0\0\0\200\376\37\300\230\303\34\201\0\0\0\0\0\0\334\0\377\377\333\0\0\0\0\0\0\0\334\0\0\0\0\0\230\303\34\201<\13\11\370" ) ) == 0x0 04828 432 NtWaitForSingleObject (380, 0, {0, 0}, ... ) == 0x102 04829 432 NtWaitForSingleObject (380, 0, {0, 0}, ... ) == 0x102 04830 432 NtWaitForSingleObject (380, 0, {0, 0}, ... ) == 0x102 04831 432 NtWaitForSingleObject (392, 0, {0, 0}, ... ) == 0x102 04832 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 420, ) == 0x0 04833 432 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 1}, 0x0, 0x0, 1236960, 112, ... 424, 0x0, 0x0, 0x0, 112, ) , {12, 2, 1, 1}, 0x0, 0x0, 1236960, 112, ... 424, 0x0, 0x0, 0x0, 112, ) == 0x0 04834 432 NtRequestWaitReplyPort (424, {128, 152, new_msg, 0, 122292, 1310720, 1236724, 2012750850} (424, {128, 152, new_msg, 0, 122292, 1310720, 1236724, 2012750850} "\0\345\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\6\0\0\0\0\0x\1\24\0\0\0\0\0 i\26\0\210g\26\0\370h\26\0\0\0\0\0\0\0\0\0\0\0\0\0 i\26\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {128, 152, reply, 0, 424, 432, 1546, 0} "\7\345\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\6\0\0\0\0\0x\1\24\0\0\0\0\0 i\26\0\210g\26\0\370h\26\0\0\0\0\0\0\0\0\0\0\0\0\0 i\26\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {128, 152, reply, 0, 424, 432, 1546, 0} (424, {128, 152, new_msg, 0, 122292, 1310720, 1236724, 2012750850} "\0\345\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0k\23\314w\4\0\0\0\20\344\314w\360^\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\6\0\0\0\0\0x\1\24\0\0\0\0\0 i\26\0\210g\26\0\370h\26\0\0\0\0\0\0\0\0\0\0\0\0\0 i\26\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {128, 152, reply, 0, 424, 432, 1546, 0} "\7\345\22\0\2$\370w\370T\367w\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\20\344\314w\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\6\0\0\0\0\0x\1\24\0\0\0\0\0 i\26\0\210g\26\0\370h\26\0\0\0\0\0\0\0\0\0\0\0\0\0 i\26\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 04835 432 NtRequestWaitReplyPort (424, {112, 136, new_msg, 0, 6029401, 5439573, 5374021, 5439580} (424, {112, 136, new_msg, 0, 6029401, 5439573, 5374021, 5439580} "\1\0\0\0A\2\11\0-\02\01\0-\01\00\07\08\0\377\377\377\3771\05\0\0\0\0\0\224\221\25\0\26\0\0\0\0\0\0\0\26\0\0\0p\0r\0s\0.\0p\0a\0y\0p\0e\0r\0d\0o\0w\0n\0l\0o\0a\0d\0.\0n\0l\0\0\0\1\0e\0\0\0\0\0D\0r\0i\0v\0" ... {44, 68, reply, 0, 424, 432, 1547, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\0\0\0\0\264\5\0\0\1\0\0\0" ) ... {44, 68, reply, 0, 424, 432, 1547, 0} (424, {112, 136, new_msg, 0, 6029401, 5439573, 5374021, 5439580} "\1\0\0\0A\2\11\0-\02\01\0-\01\00\07\08\0\377\377\377\3771\05\0\0\0\0\0\224\221\25\0\26\0\0\0\0\0\0\0\26\0\0\0p\0r\0s\0.\0p\0a\0y\0p\0e\0r\0d\0o\0w\0n\0l\0o\0a\0d\0.\0n\0l\0\0\0\1\0e\0\0\0\0\0D\0r\0i\0v\0" ... {44, 68, reply, 0, 424, 432, 1547, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\322\2\307w\322\2\307w\200\2\307w\0\0\0\0\264\5\0\0\1\0\0\0" ) ) == 0x0 04836 432 NtClose (420, ... ) == 0x0 04837 432 NtClose (424, ... ) == 0x0 04838 432 NtOpenKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "System\CurrentControlSet\Services\WinSock2\Parameters"}, ... 424, ) }, ... 424, ) == 0x0 04839 432 NtQueryValueKey (424, (424, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (424, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 04840 432 NtQueryValueKey (424, (424, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (424, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 04841 432 NtQueryValueKey (424, (424, "AutodialDLL", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04842 432 NtClose (424, ... ) == 0x0 04843 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "rasadhlp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04844 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\rasadhlp.dll"}, 1237720, ... ) }, 1237720, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04845 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "rasadhlp.dll"}, 1237720, ... ) }, 1237720, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04846 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasadhlp.dll"}, 1237720, ... ) }, 1237720, ... ) == 0x0 04847 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasadhlp.dll"}, 5, 96, ... 424, {status=0x0, info=1}, ) }, 5, 96, ... 424, {status=0x0, info=1}, ) == 0x0 04848 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 424, ... 420, ) == 0x0 04849 432 NtQuerySection (420, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04850 432 NtClose (424, ... ) == 0x0 04851 432 NtMapViewOfSection (420, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76fc0000), 0x0, 20480, ) == 0x0 04852 432 NtClose (420, ... ) == 0x0 04853 432 NtCreateFile (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Device\RasAcd"}, 0x0, 128, 3, 3, 0, 0, 0, ... 420, {status=0x0, info=0}, ) }, 0x0, 128, 3, 3, 0, 0, 0, ... 420, {status=0x0, info=0}, ) == 0x0 04854 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 424, ) == 0x0 04855 432 NtDeviceIoControlFile (420, 424, 0x0, 0x0, 0xf14014, (420, 424, 0x0, 0x0, 0xf14014, "\3\0\0\0prs.payperdownload.nl\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1552, 0, ... ) , 1552, 0, ... ) == STATUS_UNSUCCESSFUL 04856 432 NtClose (424, ... ) == 0x0 04857 432 NtClose (420, ... ) == 0x0 04858 432 NtWaitForSingleObject (364, 0, 0x0, ... ) == 0x0 04859 432 NtWaitForSingleObject (368, 0, 0x0, ... ) == 0x0 04860 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RASAPI32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04861 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\RASAPI32.DLL"}, 1237236, ... ) }, 1237236, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04862 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "RASAPI32.DLL"}, 1237236, ... ) }, 1237236, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04863 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\RASAPI32.DLL"}, 1237236, ... ) }, 1237236, ... ) == 0x0 04864 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\RASAPI32.DLL"}, 5, 96, ... 420, {status=0x0, info=1}, ) }, 5, 96, ... 420, {status=0x0, info=1}, ) == 0x0 04865 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 420, ... 424, ) == 0x0 04866 432 NtQuerySection (424, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04867 432 NtClose (420, ... ) == 0x0 04868 432 NtMapViewOfSection (424, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76ee0000), 0x0, 225280, ) == 0x0 04869 432 NtClose (424, ... ) == 0x0 04870 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "rasman.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04871 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\rasman.dll"}, 1236432, ... ) }, 1236432, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04872 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "rasman.dll"}, 1236432, ... ) }, 1236432, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04873 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasman.dll"}, 1236432, ... ) }, 1236432, ... ) == 0x0 04874 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasman.dll"}, 5, 96, ... 424, {status=0x0, info=1}, ) }, 5, 96, ... 424, {status=0x0, info=1}, ) == 0x0 04875 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 424, ... 420, ) == 0x0 04876 432 NtQuerySection (420, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04877 432 NtClose (424, ... ) == 0x0 04878 432 NtMapViewOfSection (420, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e90000), 0x0, 69632, ) == 0x0 04879 432 NtClose (420, ... ) == 0x0 04880 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "TAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04881 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\TAPI32.dll"}, 1236432, ... ) }, 1236432, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04882 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "TAPI32.dll"}, 1236432, ... ) }, 1236432, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04883 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll"}, 1236432, ... ) }, 1236432, ... ) == 0x0 04884 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll"}, 5, 96, ... 420, {status=0x0, info=1}, ) }, 5, 96, ... 420, {status=0x0, info=1}, ) == 0x0 04885 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 420, ... 424, ) == 0x0 04886 432 NtQuerySection (424, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04887 432 NtClose (420, ... ) == 0x0 04888 432 NtMapViewOfSection (424, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76eb0000), 0x0, 172032, ) == 0x0 04889 432 NtClose (424, ... ) == 0x0 04890 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "rtutils.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04891 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\rtutils.dll"}, 1235628, ... ) }, 1235628, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04892 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "rtutils.dll"}, 1235628, ... ) }, 1235628, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04893 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rtutils.dll"}, 1235628, ... ) }, 1235628, ... ) == 0x0 04894 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rtutils.dll"}, 5, 96, ... 424, {status=0x0, info=1}, ) }, 5, 96, ... 424, {status=0x0, info=1}, ) == 0x0 04895 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 424, ... 420, ) == 0x0 04896 432 NtQuerySection (420, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04897 432 NtClose (424, ... ) == 0x0 04898 432 NtMapViewOfSection (420, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e80000), 0x0, 53248, ) == 0x0 04899 432 NtClose (420, ... ) == 0x0 04900 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WINMM.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04901 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WINMM.dll"}, 1235628, ... ) }, 1235628, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04902 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WINMM.dll"}, 1235628, ... ) }, 1235628, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04903 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINMM.dll"}, 1235628, ... ) }, 1235628, ... ) == 0x0 04904 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINMM.dll"}, 5, 96, ... 420, {status=0x0, info=1}, ) }, 5, 96, ... 420, {status=0x0, info=1}, ) == 0x0 04905 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 420, ... 424, ) == 0x0 04906 432 NtQuerySection (424, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04907 432 NtClose (420, ... ) == 0x0 04908 432 NtMapViewOfSection (424, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76b40000), 0x0, 180224, ) == 0x0 04909 432 NtClose (424, ... ) == 0x0 04910 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 424, ) == 0x0 04911 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 420, ) == 0x0 04912 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 428, ) == 0x0 04913 432 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32"}, ... 432, ) }, ... 432, ) == 0x0 04914 432 NtQueryValueKey (432, (432, "wave", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04915 432 NtQueryValueKey (432, (432, "wave1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04916 432 NtQueryValueKey (432, (432, "wave2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04917 432 NtQueryValueKey (432, (432, "wave3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04918 432 NtQueryValueKey (432, (432, "wave4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04919 432 NtQueryValueKey (432, (432, "wave5", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04920 432 NtQueryValueKey (432, (432, "wave6", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04921 432 NtQueryValueKey (432, (432, "wave7", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04922 432 NtQueryValueKey (432, (432, "wave8", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04923 432 NtQueryValueKey (432, (432, "wave9", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04924 432 NtQueryValueKey (432, (432, "midi", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04925 432 NtQueryValueKey (432, (432, "midi1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04926 432 NtQueryValueKey (432, (432, "midi2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04927 432 NtQueryValueKey (432, (432, "midi3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04928 432 NtQueryValueKey (432, (432, "midi4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND