Summary:
NtAddAtom(>) | 1 | NtUserGetThreadDesktop(>) | 1 | NtQueryVirtualMemory(>) | 5 | NtQueryInformationProcess(>) | 18 |
NtCallbackReturn(>) | 1 | NtAdjustPrivilegesToken(>) | 2 | NtSetInformationProcess(>) | 5 | NtUserRegisterWindowMessage(>) | 18 |
NtClearEvent(>) | 1 | NtContinue(>) | 2 | NtSetInformationThread(>) | 5 | NtOpenSection(>) | 22 |
NtConnectPort(>) | 1 | NtCreateIoCompletion(>) | 2 | NtOpenThreadToken(>) | 6 | NtQueryAttributesFile(>) | 22 |
NtCreateSemaphore(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtQueryVolumeInformationFile(>) | 6 | NtOpenProcessTokenEx(>) | 27 |
NtEnumerateValueKey(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtFsControlFile(>) | 7 | NtOpenThreadTokenEx(>) | 27 |
NtFreeVirtualMemory(>) | 1 | NtOpenEvent(>) | 2 | NtQueryDefaultLocale(>) | 7 | NtQueryKey(>) | 28 |
NtGdiCreateBitmap(>) | 1 | NtReadFile(>) | 2 | NtQueryDirectoryFile(>) | 7 | NtMapViewOfSection(>) | 31 |
NtGdiInit(>) | 1 | NtSetEvent(>) | 2 | NtQuerySection(>) | 7 | NtQueryInformationToken(>) | 31 |
NtGdiQueryFontAssocInfo(>) | 1 | NtSetThreadExecutionState(>) | 2 | NtOpenProcessToken(>) | 8 | NtDeviceIoControlFile(>) | 42 |
NtGdiSelectBitmap(>) | 1 | NtUserGetDC(>) | 2 | NtQueryDefaultUILanguage(>) | 8 | NtAllocateVirtualMemory(>) | 45 |
NtOpenKeyedEvent(>) | 1 | NtUserQueryWindow(>) | 2 | NtQueryInformationFile(>) | 8 | NtOpenFile(>) | 47 |
NtOpenProcess(>) | 1 | NtWriteFile(>) | 2 | NtUnmapViewOfSection(>) | 8 | NtUserFindExistingCursorIcon(>) | 52 |
NtQueryInstallUILanguage(>) | 1 | NtAccessCheck(>) | 3 | NtCreateFile(>) | 9 | NtUserRegisterClassExWOW(>) | 61 |
NtQueryObject(>) | 1 | NtDuplicateObject(>) | 3 | NtQueryDebugFilterState(>) | 9 | NtQuerySystemInformation(>) | 73 |
NtQuerySystemTime(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtRequestWaitReplyPort(>) | 11 | NtFlushInstructionCache(>) | 78 |
NtRegisterThreadTerminatePort(>) | 1 | NtUserCallOneParam(>) | 3 | NtUserSystemParametersInfo(>) | 11 | NtDelayExecution(>) | 85 |
NtSecureConnectPort(>) | 1 | NtCreateMutant(>) | 4 | NtCreateEvent(>) | 13 | NtQueryValueKey(>) | 98 |
NtTestAlert(>) | 1 | NtSetInformationObject(>) | 4 | NtSetInformationFile(>) | 14 | NtOpenKey(>) | 147 |
NtUserCallNoParam(>) | 1 | NtGdiGetStockObject(>) | 5 | NtCreateKey(>) | 15 | NtProtectVirtualMemory(>) | 158 |
NtUserGetObjectInformation(>) | 1 | NtOpenSymbolicLinkObject(>) | 5 | NtCreateSection(>) | 15 | NtClose(>) | 213 |
NtUserGetProcessWindowStation(>) | 1 | NtQuerySymbolicLinkObject(>) | 5 | NtSetValueKey(>) | 17 |
, ) , ) == 0x0 01217 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\277<\4\311U\355\231\5\223)\354\362\321\206\255"\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... \322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... 01218 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01219 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01220 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01221 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01222 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01223 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01224 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01225 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01226 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\37B;\324Ed\222k\333\352\220\314\376\255H\214\216\27~_t\264\317\373\315\275=Y\0\3344\251\263\330ghc\272\203ypB\252c,\210\5\267g\325\325\257\2b\26\347\372"A;\255\242\20\5f}Zf\226\331_\377\262\205ONxW\245", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\37B;\324Ed\222k\333\352\220\314\376\255H\214\216\27~_t\264\317\373\315\275=Y\0\3344\251\263\330ghc\272\203ypB\252c,\210\5\267g\325\325\257\2b\26\347\372"A;\255\242\20\5f}Zf\226\331_\377\262\205ONxW\245", 80, ... ) A;\255\242\20\5f}Zf\226\331_\377\262\205ONxW\245", 80, ... ) == 0x0 01227 1736 NtClose (-2147482128, ... ) == 0x0 01217 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\370#ef\354\227\305\15F\255m5[\305\263h\366\3273\17\374\307%\312\177\301.\337\343\313\211\335(;\232\301%\323\267\252\362^N>\374v\377\17A\353\363\306\340\321}\3678\17kZ\344\350\347^otM\351m{,M\275#\265\262\230\26}\245\303\15 >\217\347\32G)l\317!:\223\320\352C\253'\245\254\30^\11.\364\231\243Q<\246\14-}r\312n\2\364\311$\333\357\367\327\236\363\307\353\333z\223o\227\350\6\330\270\330\375\2377\210\305\341\342G\270\353\5qm\30\355\240\245>\255+tL\301\241\330\347#\332F\266\6Z\361\347\324\12\343\16]\34\24\202y\254^\177\310\5\204t\360\3\354\274\224\34\222\30-)\237d\17\247\351*\345]G5\33\244\224-\277x\311\21r1\365\177-A}v)MH\323\334\335\304\207\246\34\302\377\273l;[\322\315<\356\227\30&}\333\321\341O\322\310", ) , ) == 0x0 01228 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\277<\4\311U\355\231\5\223)\354\362\321\206\255"\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... \322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... 01229 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01230 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01231 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01232 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01233 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01234 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01235 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01236 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01237 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\230\222\325\332\4\231g\35d\377\304X\210i.2\3322\250\347\223\253\363\232\227\311%4\246\333\310\275\250\317\3633\225{\311\26\325K\33\264\265\272TR\237\332\367p\207\353\30R\337$\342\22\262\325rL\220\3710\36\312\320\224M\6U\315-\203\2744", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\230\222\325\332\4\231g\35d\377\304X\210i.2\3322\250\347\223\253\363\232\227\311%4\246\333\310\275\250\317\3633\225{\311\26\325K\33\264\265\272TR\237\332\367p\207\353\30R\337$\342\22\262\325rL\220\3710\36\312\320\224M\6U\315-\203\2744", 80, ... ) , 80, ... ) == 0x0 01238 1736 NtClose (-2147482128, ... ) == 0x0 01228 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "rQ\212\250{f<3$&\205B\226b\353\326h\305w\3613g\306\245,\304\231P\225i\303\317\303Q\13\370R\3151\222Z\356A\316\221\232\244\333\373\363\303\30\323\363\317\6PZ\310\24\177\320\313(C\315\373h\235\257\255o\237g*\264\226:\203\246\232\301\375s\251\2268\370\327x\16/-\7L\237]\340D\221J\307A\2A\15\300\337\14[\313K\370\305\260E\16\267\6\312\340\13:.\304\363\245O\257g\1\262b\205\204\3721\3\226\345\313\256\2648\374\301q\241\372\362h\376\211x E\2509h]G\251\37\303V'\351\332\305\300\253\334\210Y\367\260\222\320}\362\26\205\350\337\352\240\237?\231>Z\311\310\222[\315fy`\215\17\30\223\177\344\267$/Q\342\0\271\240\321\260\223\32\7\33\2^\307\34\214\15\246\232\315-\11\266(r\216S\3270\301\331\210A\220>\15%Tk\12~z\334\313\256\347\314\7", ) , ) == 0x0 01239 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\277<\4\311U\355\231\5\223)\354\362\321\206\255"\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... \322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\250\307\322-\325 \312\336\262m\232H\22G9\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... 01240 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01241 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01242 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01243 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01244 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01245 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01246 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01247 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01248 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "`\255\237"\32\332\351\202\235\1xXXB)\217 n\322TP\20@\207\32F\242l\312\372im/%$\25\270\336_\373=R\26k\37=\223\277g\11S_\317\6\202C\20\250k\\202\323\223\13\211\370\225\205R\2661\262J\312\355\376\263\261\271\211", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "`\255\237"\32\332\351\202\235\1xXXB)\217 n\322TP\20@\207\32F\242l\312\372im/%$\25\270\336_\373=R\26k\37=\223\277g\11S_\317\6\202C\20\250k\\202\323\223\13\211\370\225\205R\2661\262J\312\355\376\263\261\271\211", 80, ... ) \32\332\351\202\235\1xXXB)\217 n\322TP\20@\207\32F\242l\312\372im/%$\25\270\336_\373=R\26k\37=\223\277g\11S_\317\6\202C\20\250k\\202\323\223\13\211\370\225\205R\2661\262J\312\355\376\263\261\271\211", 80, ... ) == 0x0 01249 1736 NtClose (-2147482128, ... ) == 0x0 01239 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\211D~\347\204\20\14.n\344\300\271x\273\203\252\21N\17\207\276>H\24\265U\366\255e@\12\216\3304\251\317\22584\234 \242\303\23h\241\372\21\274A=\230\315w\252\302\10\205\225\200G`\354R\217hy\224\314\227\216\1\243|\371\21\374y\233\354$\22\201&\323\222N\365!\267\364\4p\215\261\210\226\236\14\353\233\361\225{*\353p\2175\3302p\246{\11\274\373\370\21mO\356\253\366\370\302-\17;R\224\363\27\300T\245]\262\334\2\310\235$'\355\322\343roK\206\265\301\307\247hp`\316j`\2513\372\321a\227x\325 \345\275\221\257:M\373\210\363^\307:\246\325r\265o\201\262\325\4\327\313\25v:_[\326!\312\334\25\254\317e\27Q\212\313\263\365\331\11\325\25\321\315\347(h\322\366\362\310\37IQ\346\332%\201\312@\210\22\247\1B\6\326\261\214\231n \375\24\334\203\211\342\332\263\213", ) , ) == 0x0 01250 1736 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 132, ) == 0x0 01251 1736 NtConnectPort ( ("\RPC Control\ntsvcs", {12, 2, 1, 1}, 0x0, 0x0, 1238540, 188, ... 136, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 1}, 0x0, 0x0, 1238540, 188, ... 136, 0x0, 0x0, 0x0, 188, ) == 0x0 01252 1736 NtRequestWaitReplyPort (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} "\0\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0`\2\24\0\4\0\0\0\2\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\16\326\327c\4\202\311\263`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\350\245\263\237\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1636, 1736, 75512, 0} "\7\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\2\0\0\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\16\326\327c\4\202\311\263`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\350\245\263\237\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ... {200, 224, reply, 0, 1636, 1736, 75512, 0} (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} "\0\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0`\2\24\0\4\0\0\0\2\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\16\326\327c\4\202\311\263`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\350\245\263\237\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1636, 1736, 75512, 0} "\7\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\2\0\0\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\16\326\327c\4\202\311\263`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\350\245\263\237\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 01253 1736 NtRequestWaitReplyPort (136, {112, 136, new_msg, 0, 44, 3, 20, 0} (136, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\245}d@\240\5u8poe8"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1636, 1736, 75513, 0} "\2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 (136, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\245}d@\240\5u8poe8"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1636, 1736, 75513, 0} "\2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) == 0x0 01254 1736 NtAllocateVirtualMemory (-1, 1355776, 0, 4096, 4096, 4, ... 1355776, 4096, ) == 0x0 01255 1736 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 01256 1736 NtOpenProcessToken (-1, 0x20, ... 140, ) == 0x0 01257 1736 NtAdjustPrivilegesToken (140, 0, 1352496, 0, 0, 0, ... ) == 0x0 01258 1736 NtClose (140, ... ) == 0x0 01259 1736 NtRequestWaitReplyPort (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} "\1\0\0\0A\2\26\0<\0\370\0\226\245\335\341\264\311\275\201:\332R\200\377\377\377\377\]\222\201\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1636, 1736, 75514, 0} "\2+\263\341\4\0T\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\274\1\0\0\360>\11\0" ) ... {40, 64, reply, 0, 1636, 1736, 75514, 0} (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} "\1\0\0\0A\2\26\0<\0\370\0\226\245\335\341\264\311\275\201:\332R\200\377\377\377\377\]\222\201\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1636, 1736, 75514, 0} "\2+\263\341\4\0T\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\274\1\0\0\360>\11\0" ) ) == 0x0 01260 1736 NtRequestWaitReplyPort (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ... {64, 88, reply, 56, 1636, 1736, 75515, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ) ... {64, 88, reply, 56, 1636, 1736, 75515, 0} (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ... {64, 88, reply, 56, 1636, 1736, 75515, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ) ) == 0x0 01261 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 140, {status=0x0, info=1}, ) }, 3, 96, ... 140, {status=0x0, info=1}, ) == 0x0 01262 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 144, ) }, ... 144, ) == 0x0 01263 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\FloppyPDO0", 38, ) , 38, ) == 0x0 01264 1736 NtClose (144, ... ) == 0x0 01265 1736 NtQueryVolumeInformationFile (140, 1237816, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01266 1736 NtClose (140, ... ) == 0x0 01267 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 140, {status=0x0, info=1}, ) }, 3, 16, ... 140, {status=0x0, info=1}, ) == 0x0 01268 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, "\36\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", ) , ) == 0x0 01269 1736 NtClose (140, ... ) == 0x0 01270 1736 NtQueryInformationFile (-1, 1238868, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01271 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238820, (0x100080, {24, 0, 0x40, 0, 1238820, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01272 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 32, ... , 54, 32, ... 01273 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01274 1736 NtClose (-2147482128, ... ) == 0x0 01272 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01275 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 374, ... , 54, 374, ... 01276 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01277 1736 NtClose (-2147482128, ... ) == 0x0 01275 1736 NtDeviceIoControlFile ... {status=0x0, info=374}, ... {status=0x0, info=374}, "v\1\0\0\2\0\0\0\372\0\0\0`\0\0\08\0\0\0\244\0\0\0\334\0\0\0\36\0v\0Z\1\0\0\34\0\\08\0\0\0\244\0p\0\334\0\0\0\36\0\0\0\\0?\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0A\0:\0", ) , ) == 0x0 01278 1736 NtClose (140, ... ) == 0x0 01279 1736 NtAllocateVirtualMemory (-1, 1359872, 0, 4096, 4096, 4, ... 1359872, 4096, ) == 0x0 01280 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01281 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01282 1736 NtClose (140, ... ) == 0x0 01283 1736 NtQueryValueKey (144, (144, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01284 1736 NtQueryValueKey (144, (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\6\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\6\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 01285 1736 NtClose (144, ... ) == 0x0 01286 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 144, ) }, ... 144, ) == 0x0 01287 1736 NtOpenKey (0x2000000, {24, 144, 0x40, 0, 0, (0x2000000, {24, 144, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 140, ) }, ... 140, ) == 0x0 01288 1736 NtClose (144, ... ) == 0x0 01289 1736 NtQueryValueKey (140, (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01290 1736 NtClose (140, ... ) == 0x0 01291 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 140, {status=0x0, info=0}, ) }, 3, 96, ... 140, {status=0x0, info=0}, ) == 0x0 01292 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 144, ) }, ... 144, ) == 0x0 01293 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01294 1736 NtClose (144, ... ) == 0x0 01295 1736 NtQueryVolumeInformationFile (140, 1237816, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01296 1736 NtClose (140, ... ) == 0x0 01297 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 140, {status=0x0, info=0}, ) }, 3, 16, ... 140, {status=0x0, info=0}, ) == 0x0 01298 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, ".\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", ) , ) == 0x0 01299 1736 NtClose (140, ... ) == 0x0 01300 1736 NtQueryInformationFile (-1, 1238868, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01301 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238820, (0x100080, {24, 0, 0x40, 0, 1238820, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01302 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 32, ... , 70, 32, ... 01303 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01304 1736 NtClose (-2147482128, ... ) == 0x0 01302 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01305 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 238, ... , 70, 238, ... 01306 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01307 1736 NtClose (-2147482128, ... ) == 0x0 01305 1736 NtDeviceIoControlFile ... {status=0x0, info=238}, ... {status=0x0, info=238}, "\356\0\0\0\2\0\0\0r\0\0\0`\0\0\08\0\0\0\14\0\0\0D\0\0\0.\0v\0\322\0\0\0\34\0\\08\0\0\0\14\0d\0D\0\0\0.\0k\0\310\24\310\24\0~\0\0\0\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0C\0:\0", ) , ) == 0x0 01308 1736 NtClose (140, ... ) == 0x0 01309 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01310 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01311 1736 NtClose (140, ... ) == 0x0 01312 1736 NtQueryValueKey (144, (144, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01313 1736 NtQueryValueKey (144, (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) \5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0 (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 01314 1736 NtClose (144, ... ) == 0x0 01315 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 144, ) }, ... 144, ) == 0x0 01316 1736 NtOpenKey (0x2000000, {24, 144, 0x40, 0, 0, (0x2000000, {24, 144, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 140, ) }, ... 140, ) == 0x0 01317 1736 NtClose (144, ... ) == 0x0 01318 1736 NtQueryValueKey (140, (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01319 1736 NtClose (140, ... ) == 0x0 01320 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01321 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01322 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01323 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01324 1736 NtClose (-2147482128, ... ) == 0x0 01322 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01325 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01326 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01327 1736 NtClose (-2147482128, ... ) == 0x0 01325 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01328 1736 NtClose (140, ... ) == 0x0 01329 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01330 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01331 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01332 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01333 1736 NtClose (-2147482128, ... ) == 0x0 01331 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01334 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01335 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01336 1736 NtClose (-2147482128, ... ) == 0x0 01334 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01337 1736 NtClose (140, ... ) == 0x0 01338 1736 NtCreateKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01339 1736 NtSetValueKey (140, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01340 1736 NtClose (140, ... ) == 0x0 01341 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01342 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01343 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01344 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01345 1736 NtClose (-2147482128, ... ) == 0x0 01343 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01346 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01347 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01348 1736 NtClose (-2147482128, ... ) == 0x0 01346 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01349 1736 NtClose (140, ... ) == 0x0 01350 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01351 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01352 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01353 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01354 1736 NtClose (-2147482128, ... ) == 0x0 01352 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01355 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01356 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01357 1736 NtClose (-2147482128, ... ) == 0x0 01355 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01358 1736 NtClose (140, ... ) == 0x0 01359 1736 NtCreateKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01360 1736 NtSetValueKey (140, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01361 1736 NtClose (140, ... ) == 0x0 01362 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01363 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01364 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 140, {status=0x0, info=1}, ) }, 3, 96, ... 140, {status=0x0, info=1}, ) == 0x0 01365 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 144, ) }, ... 144, ) == 0x0 01366 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 01367 1736 NtClose (144, ... ) == 0x0 01368 1736 NtQueryVolumeInformationFile (140, 1239204, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01369 1736 NtClose (140, ... ) == 0x0 01370 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01371 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01372 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01373 1736 NtClose (140, ... ) == 0x0 01374 1736 NtQueryValueKey (144, (144, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (144, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01375 1736 NtClose (144, ... ) == 0x0 01376 1736 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, 1240336, ... ) }, 1240336, ... ) == 0x0 01377 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01378 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 144, {status=0x0, info=1}, ) }, 3, 96, ... 144, {status=0x0, info=1}, ) == 0x0 01379 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 140, ) }, ... 140, ) == 0x0 01380 1736 NtQuerySymbolicLinkObject (140, ... (140, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 01381 1736 NtClose (140, ... ) == 0x0 01382 1736 NtQueryVolumeInformationFile (144, 1241076, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01383 1736 NtClose (144, ... ) == 0x0 01384 1736 NtCreateEvent (0x1f0003, {24, 48, 0x80, 1339720, 0, (0x1f0003, {24, 48, 0x80, 1339720, 0, "ShellCopyEngineFinished"}, 0, 0, ... 144, ) }, 0, 0, ... 144, ) == 0x0 01385 1736 NtSetEvent (144, ... 0x0, ) == 0x0 01386 1736 NtClose (144, ... ) == 0x0 01387 1736 NtClearEvent (68, ... ) == 0x0 01388 1736 NtClose (68, ... ) == 0x0 01389 1736 NtSetThreadExecutionState (-2147483648, 1244004, ... ) == 0x0 01390 1736 NtDelayExecution (0, {-1010000, -1}, ... ) == 0x0 01391 1736 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion"}, ... 68, ) }, ... 68, ) == 0x0 01392 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01393 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01394 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01395 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01396 1736 NtClose (68, ... ) == 0x0 01397 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01398 1736 NtDelayExecution (0, {-1010000, -1}, ... ) == 0x0 01399 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01400 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01401 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01402 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01403 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01404 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01405 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01406 1736 NtClose (144, ... ) == 0x0 01407 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01408 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01409 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01410 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01411 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01412 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01413 1736 NtClose (144, ... ) == 0x0 01414 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01415 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01416 1736 NtClose (70, ... ) == 0x0 01417 1736 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion"}, ... 68, ) }, ... 68, ) == 0x0 01418 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01419 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01420 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01421 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01422 1736 NtClose (68, ... ) == 0x0 01423 1736 NtDelayExecution (0, {-430000, -1}, ... ) == 0x0 01424 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01425 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01426 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01427 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01428 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01429 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01430 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01431 1736 NtClose (144, ... ) == 0x0 01432 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01433 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01434 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01435 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01436 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01437 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01438 1736 NtClose (144, ... ) == 0x0 01439 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01440 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01441 1736 NtClose (70, ... ) == 0x0 01442 1736 NtQueryKey (66, Name, 382, ... {Name= (66, Name, 382, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01443 1736 NtOpenKey (0x2000000, {24, 66, 0x40, 0, 0, (0x2000000, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01444 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes"}, ... 68, ) }, ... 68, ) == 0x0 01445 1736 NtCreateKey (0x20006, {24, 68, 0x40, 0, 0, (0x20006, {24, 68, 0x40, 0, 0, "WR"}, 0, "", 0, ... 144, 2, ) }, 0, "", 0, ... 144, 2, ) == 0x0 01446 1736 NtClose (68, ... ) == 0x0 01447 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01448 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01449 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01450 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01451 1736 NtClose (68, ... ) == 0x0 01452 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01453 1736 NtSetValueKey (146, (146, "version", 0, 1, "7\02\0\0\0", 6, ... , 0, 1, (146, "version", 0, 1, "7\02\0\0\0", 6, ... , 6, ... 01454 1736 NtSetInformationFile (-2147482448, -139348624, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 01453 1736 NtSetValueKey ... ) == 0x0 01455 1736 NtClose (146, ... ) == 0x0 01456 1736 NtDelayExecution (0, {-350000, -1}, ... ) == 0x0 01457 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01458 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01459 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01460 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01461 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01462 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01463 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 144, ) }, ... 144, ) == 0x0 01464 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01465 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01466 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01467 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01468 1736 NtClose (68, ... ) == 0x0 01469 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01470 1736 NtQueryValueKey (146, (146, "nextupdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01471 1736 NtClose (146, ... ) == 0x0 01472 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01473 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01474 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 144, ) }, ... 144, ) == 0x0 01475 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01476 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01477 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01478 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01479 1736 NtClose (68, ... ) == 0x0 01480 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01481 1736 NtQueryValueKey (146, (146, "nextupdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01482 1736 NtClose (146, ... ) == 0x0 01483 1736 NtQueryKey (66, Name, 382, ... {Name= (66, Name, 382, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01484 1736 NtOpenKey (0x2000000, {24, 66, 0x40, 0, 0, (0x2000000, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01485 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes"}, ... 144, ) }, ... 144, ) == 0x0 01486 1736 NtCreateKey (0x20006, {24, 144, 0x40, 0, 0, (0x20006, {24, 144, 0x40, 0, 0, "WR"}, 0, "", 0, ... 68, 2, ) }, 0, "", 0, ... 68, 2, ) == 0x0 01487 1736 NtClose (144, ... ) == 0x0 01488 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01489 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01490 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01491 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01492 1736 NtClose (144, ... ) == 0x0 01493 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01494 1736 NtSetValueKey (70, (70, "nextupdate", 0, 4, "\364\371\16H", 4, ... ) , 0, 4, (70, "nextupdate", 0, 4, "\364\371\16H", 4, ... ) , 4, ... ) == 0x0 01495 1736 NtClose (70, ... ) == 0x0 01496 1736 NtDelayExecution (0, {-340000, -1}, ... ) == 0x0 01497 1736 NtDelayExecution (0, {-350000, -1}, ... ) == 0x0 01498 1736 NtDelayExecution (0, {-350000, -1}, ... ) == 0x0 01499 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01500 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01501 1736 NtDelayExecution (0, {-330000, -1}, ... ) == 0x0 01502 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01503 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01504 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01505 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01506 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01507 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01508 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01509 1736 NtClose (144, ... ) == 0x0 01510 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01511 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01512 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01513 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01514 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01515 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01516 1736 NtClose (144, ... ) == 0x0 01517 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01518 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01519 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01520 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01521 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01522 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01523 1736 NtClose (144, ... ) == 0x0 01524 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01525 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01526 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01527 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01528 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01529 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01530 1736 NtClose (144, ... ) == 0x0 01531 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01532 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01533 1736 NtClose (70, ... ) == 0x0 01534 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01535 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01536 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01537 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01538 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01539 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01540 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01541 1736 NtClose (144, ... ) == 0x0 01542 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01543 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01544 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01545 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01546 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01547 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01548 1736 NtClose (144, ... ) == 0x0 01549 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01550 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01551 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01552 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01553 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01554 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01555 1736 NtClose (144, ... ) == 0x0 01556 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01557 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01558 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01559 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01560 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01561 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01562 1736 NtClose (144, ... ) == 0x0 01563 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01564 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01565 1736 NtClose (70, ... ) == 0x0 01566 1736 NtDelayExecution (0, {-1010000, -1}, ... ) == 0x0 01567 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01568 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01569 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01570 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01571 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01572 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01573 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01574 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01575 1736 NtDelayExecution (0, {-21350000, -1}, ... ) == 0x0 01576 1736 NtDelayExecution (0, {-21350000, -1}, ...