Summary:
NtAccessCheck(>) | 1 | NtOpenMutant(>) | 2 | NtUserCalcMenuBar(>) | 4 | NtQueryKey(>) | 12 |
NtCallbackReturn(>) | 1 | NtOpenProcess(>) | 2 | NtUserFillWindow(>) | 4 | NtCreateFile(>) | 13 |
NtConnectPort(>) | 1 | NtQueryDirectoryFile(>) | 2 | NtUserGetClassName(>) | 4 | NtOpenProcessTokenEx(>) | 13 |
NtCreateMutant(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtUserGetDCEx(>) | 4 | NtOpenThreadToken(>) | 13 |
NtEnumerateValueKey(>) | 1 | NtQueryPerformanceCounter(>) | 2 | NtUserGetTitleBarInfo(>) | 4 | NtOpenThreadTokenEx(>) | 13 |
NtFreeVirtualMemory(>) | 1 | NtQueryVirtualMemory(>) | 2 | NtUserQueryWindow(>) | 4 | NtSetInformationFile(>) | 13 |
NtGdiCreateBitmap(>) | 1 | NtUserDestroyWindow(>) | 2 | NtUserRemoveProp(>) | 4 | NtSetInformationThread(>) | 13 |
NtGdiExtCreateRegion(>) | 1 | NtUserGetForegroundWindow(>) | 2 | NtUserSetWindowFNID(>) | 4 | NtQuerySection(>) | 14 |
NtGdiExtGetObjectW(>) | 1 | NtUserGetThreadDesktop(>) | 2 | NtUserWaitMessage(>) | 4 | NtUnmapViewOfSection(>) | 15 |
NtGdiGetDCDword(>) | 1 | NtUserSetCursor(>) | 2 | NtGdiGetStockObject(>) | 5 | NtFsControlFile(>) | 16 |
NtGdiGetTextExtent(>) | 1 | NtUserSetFocus(>) | 2 | NtUserGetAncestor(>) | 5 | NtGdiIntersectClipRect(>) | 16 |
NtGdiInit(>) | 1 | NtUserSetWindowRgn(>) | 2 | NtUserGetAtomName(>) | 5 | NtDeviceIoControlFile(>) | 17 |
NtGdiOffsetRgn(>) | 1 | NtUserShowWindow(>) | 2 | NtUserRegisterWindowMessage(>) | 5 | NtQueryInformationToken(>) | 17 |
NtGdiQueryFontAssocInfo(>) | 1 | NtAddAtom(>) | 3 | NtUserSetProp(>) | 5 | NtGdiDrawStream(>) | 18 |
NtNotifyChangeKey(>) | 1 | NtDuplicateObject(>) | 3 | NtUserSetWindowLong(>) | 5 | NtFlushInstructionCache(>) | 22 |
NtOpenKeyedEvent(>) | 1 | NtGdiBitBlt(>) | 3 | NtCreateSemaphore(>) | 6 | NtRaiseException(>) | 23 |
NtQueryObject(>) | 1 | NtGdiCreateCompatibleBitmap(>) | 3 | NtGdiCombineRgn(>) | 6 | NtContinue(>) | 24 |
NtQuerySystemTime(>) | 1 | NtGdiExcludeClipRect(>) | 3 | NtGdiCreateRectRgn(>) | 6 | NtReleaseMutant(>) | 24 |
NtRegisterThreadTerminatePort(>) | 1 | NtGdiGetCharSet(>) | 3 | NtQueryDefaultUILanguage(>) | 6 | NtUserGetWindowDC(>) | 24 |
NtSecureConnectPort(>) | 1 | NtGdiGetTextCharsetInfo(>) | 3 | NtUserBeginPaint(>) | 6 | NtCreateSection(>) | 27 |
NtTestAlert(>) | 1 | NtGdiGetTextMetricsW(>) | 3 | NtWriteFile(>) | 6 | NtUserCallOneParam(>) | 30 |
NtUserBuildHwndList(>) | 1 | NtGdiHfontCreate(>) | 3 | NtGdiCreateCompatibleDC(>) | 7 | NtOpenFile(>) | 35 |
NtUserCallHwnd(>) | 1 | NtGdiSetupPublicCFONT(>) | 3 | NtGdiSelectBitmap(>) | 7 | NtUserGetClassInfo(>) | 37 |
NtUserCallHwndParam(>) | 1 | NtOpenEvent(>) | 3 | NtUserCallNoParam(>) | 7 | NtWaitForSingleObject(>) | 37 |
NtUserCallMsgFilter(>) | 1 | NtOpenSymbolicLinkObject(>) | 3 | NtUserInternalGetWindowText(>) | 7 | NtAllocateVirtualMemory(>) | 42 |
NtUserDrawIconEx(>) | 1 | NtQueryInformationFile(>) | 3 | NtGdiDeleteObjectApp(>) | 8 | NtMapViewOfSection(>) | 46 |
NtUserGetCursorFrameInfo(>) | 1 | NtQuerySymbolicLinkObject(>) | 3 | NtQueryDebugFilterState(>) | 8 | NtOpenSection(>) | 48 |
NtUserGetDC(>) | 1 | NtQueryVolumeInformationFile(>) | 3 | NtUserPeekMessage(>) | 9 | NtProtectVirtualMemory(>) | 48 |
NtUserGetGUIThreadInfo(>) | 1 | NtUserCallHwndLock(>) | 3 | NtReleaseSemaphore(>) | 10 | NtQueryAttributesFile(>) | 53 |
NtUserGetIconSize(>) | 1 | NtUserEndPaint(>) | 3 | NtRequestWaitReplyPort(>) | 10 | NtUserFindExistingCursorIcon(>) | 53 |
NtUserGetProcessWindowStation(>) | 1 | NtUserGetControlBrush(>) | 3 | NtUserCreateWindowEx(>) | 10 | NtUserMessageCall(>) | 64 |
NtUserModifyUserStartupInfoFlags(>) | 1 | NtUserGetObjectInformation(>) | 3 | NtQueryInformationProcess(>) | 11 | NtUserRegisterClassExWOW(>) | 64 |
NtUserUnregisterClass(>) | 1 | NtUserSetWindowPos(>) | 3 | NtSetValueKey(>) | 11 | NtReadFile(>) | 70 |
NtCreateIoCompletion(>) | 2 | NtEnumerateKey(>) | 4 | NtUserSystemParametersInfo(>) | 11 | NtQuerySystemInformation(>) | 76 |
NtGdiCreatePatternBrushInternal(>) | 2 | NtOpenProcessToken(>) | 4 | NtCreateEvent(>) | 12 | NtQueryValueKey(>) | 82 |
NtGdiCreateSolidBrush(>) | 2 | NtQueryDefaultLocale(>) | 4 | NtCreateKey(>) | 12 | NtOpenKey(>) | 104 |
NtGdiGetWidthTable(>) | 2 | NtQuerySecurityObject(>) | 4 | NtGdiExtSelectClipRgn(>) | 12 | NtClose(>) | 181 |
NtOpenDirectoryObject(>) | 2 | NtSetInformationObject(>) | 4 | NtGdiGetRandomRgn(>) | 12 |
3
0
\1\0\0\2008\0t\11\200}\350\0t\3\215u\350\200>.u\21\212F\1\204\300tm<.u\6\200", ) \1\0\0\366E\14\2\17\204\30\1\0\0\276\250\270B\0WV\350`\6\0\0\205\333t\15h\0\223@\0V\350m\6\0\0\353\6W\350\235\1\0\0h\20\220@\0W\350Z\6\0\0W\350N\6\0\0\213\330\215\205\270\376\377\377PV\3\337\377\250
310\223@\0\350\252\370\377\377\2008\0u\22V\377\325+\306PVW\350\21\372\377\377W\377\325\213\370V\377\325\213\360\212\6\204\300u\317]\200'\0WS\377\25\320q@\0\213\370\212\7< t\4<\u\7\200'\0;\337r\345_^[\302\4\0SV\2135\4q@\0Wh\1\200\0\0\377\326\277\360\310B\0W\377t$\24\377\250\213\330\377\326\203\373\377t\13S\377\254q@\0\213\307\353\23\300_^[\302\4\0\377t$\4\377\25\10q@\0\205\300u\16\377t$\4\377\25\14q@\0\205\300t\13\377t$\10P\377\25\20q@\0\302\10\0U\213\354\203\354\34V\213u\10W\213=\330q@\0\353\12\215E\344P\377\25\324q@\0j\1VV\215E\344j\0P\377\327\205\300u\346_^\311\302\4\0\203=4\316B\0\0Vu-3\311j\10\213\301^\213\320\200\342\1\366\332\33\322\201\342 \203\270\355\321\3503\302Nu\352\211\4\2150\316B\0A\201\371\0\1\0\0|\325\213T$\20\213D$\10\205\322\367\320v#\213L$\14W\17\2669\213\360\201\346\377\0\0\03\367\301\350\10\2134\2650\316B\03\306AJu\343_\367\320^\302\14\0U\213\354\203\354D\213E\10SVW\213\10\215p\20\213@\4\211M\310\213\216\250\233\0\0\213\236\30\5\0\0\211E\314\213\206\34\5\0\0\211E\300\213\206\244\233\0\0;\310\211M\320s", ) == 0x0 01415 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "+\301\211E\324\351\303\11\0\0\377$\205\10h@\0\203}\314\0\17\204\302\11\0\0\213E\310\377M\314\213\313\17\266\0\323\340\11E\300\377E\310\203\303\10\203\373\3r\333\213E\300\203\353\3\301m\300\3\203\340\7\213\310\200\341\1\366\331\33\311\203\341\7\321\350\203\301\10\203\350\0\211\216\24\5\0\0\17\204.\1\0\0HtVHtHH\17\205]\11\0\0\203\317\377\307\6\21\0\0\0\213E\300\213M\10\211\206\34\5\0\0\213E\314\211\236\30\5\0\0\211A\4\213E\10\213M\310P\211\10\213M\320\211\216\250\233\0\0\350\240\11\0\0\213\307_^[\311\302\4\0\307\6\13\0\0\0\351\21\11\0\0\200=\270\343B\0\0\17\205\240\0\0\0\203e\370\0\2708\322B\0=t\324B\0\261\10~\24=8\326B\0}\4\376\301\353\11=\230\326B\0}\2\261\7\17\276\311\211\10\203\300\4=\270\326B\0|\324\215E\370\2778\322B\0Ph8\333B\0h\370\223@\0h4\322B\0hhs@\0h(s@\0h\1\1\0\0h \1\0\0W\350\200\11\0\0j\36Yj\5X\363\253\215E\370Ph8\333B\0h\374\223@\0h0\322B\0h\344s@\0h\250s@\0j\0j\36h8\322B\0\350M\11\0\0\376\5\270\343B\0\240\370\223@\0\210F\20\240\374\223@\0\210F\21\2414\322B\0\211F\24\2410\322B\0\211F\30\203&\0\351<\10\0\0\213\313\307\6\11\0\0\0\203\341\7\323m\300+\331\351'\10\0\0\203}\314\0\17\204-\10\0\0\213E\310\377M\314\213\313\17\266\0\323\340\11E\300\377E\310\203\303\10\203\373\20r\333\213E\3003\333%\377\377\0\0\211]\300;\303\211F\4\17\204\351\0\0\0j\12X\351\347\0\0\0\203}\314\0\17\204\350\7\0", ) , ) == 0x0 01416 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\213\216\240\233\0\0\213U\320;\321u)\213\206\244\233\0\0\215\276\240\33\0\0;\307t\31\213\327;\320\211U\320s\5+\302H\353\4+\312\213\301\205\300\211E\324ub\377u\10\211\226\250\233\0\0\350\4\10\0\0\213\226\250\233\0\0\213\216\244\233\0\0;\321\211U\320s\7\213\301+\302H\353\10\213\206\240\233\0\0+\302\213\276\240\233\0\0\211E\324;\327u\35\215\226\240\33\0\0;\321t\23\211U\320s\7+\312I\213\301\353\4+\372\213\307\211E\324\205\300\17\204a\7\0\0;E\314r\3\213E\314\213N\4;\310\213\371r\2\213\370W\377u\310\377u\320\350\325\365\377\377\1}\310)}\314\1}\320)}\324)~\4\17\205\1\7\0\0\213\206\24\5\0\0\211\6\351\364\6\0\0\203}\314\0\17\204\372\6\0\0\213E\310\377M\314\213\313\17\266\0\323\340\11E\300\377E\310\203\303\10\203\373\16r\333\213E\300%\377?\0\0\213\310\211F\4\203\341\37\200\371\35\17\207Y\375\377\377%\340\3\0\0=\240\3\0\0\17\207I\375\377\377\301m\300\16\203\353\16\203f\10\0\307\6\14\0\0\0\213F\4\301\350\12\203\300\49F\10si\353 \203}\314\0\17\204\213\6\0\0\213E\310\377M\314\213\313\17\266\0\323\340\11E\300\377E\310\203\303\10\203\373\3r\333\213N\10\213E\300\203\340\7\203\353\3\17\276\211\24s@\0\301m\300\3\211D\216\14\213N\4\377F\10\213F\10\301\351\12\203\301\4;\301r\315\353\22\213F\10\17\276\200\24s@\0\203d\206\14\0\377F\10\203~\10\23r\350\215M\370\215\276\14\5\0\0Q\215\216 \5\0\0Q\215\216\20\5\0\03\300WQP\211E\370Pj\23\215F\14j\23P\307\7\7\0\0\0\350\310\6\0\0\205\300u\229\7t\16!F\10\307", ) , ) == 0x0 01417 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\21\0\0\0\351\304\5\0\0\213\206\14\5\0\0\353 \203}\314\0\17\204\302\5\0\0\213M\310\377M\314\17\266\21\213\313\323\342\11U\300\377E\310\203\303\10;\330r\334\17\267\4E\324\223@\0#E\300\213\216\20\5\0\0\215\4\201\17\266P\1\17\267@\2\203\370\20\211E\354s\26\213\312+\332\323m\300\213N\10\211D\216\14\377F\10\351\254\0\0\0\203\370\22u\14j\7\307E\370\13\0\0\0X\353,\203\300\362\307E\370\3\0\0\0\353 \203}\314\0\17\204G\5\0\0\213M\310\377M\314\17\2669\213\313\323\347\11}\300\377E\310\203\303\10\215\14\20;\331r\331\213\312+\332\323m\300\17\267\14E\324\223@\0#M\300\213U\370+\330\3\321\213\310\213F\4\323m\300\213N\10\213\370\301\357\5\203\347\37\203\340\37\215\204\7\2\1\0\0\215<\12;\370\17\207|\373\377\377\203}\354\20u\17\203\371\1\17\202m\373\377\377\213|\216\10\353\23\377\215D\216\14\2118A\203\300\4Ju\367\211N\10\213F\4\213N\10\213\320\203\340\37\301\352\5\203\342\37\215\204\2\2\1\0\0;\310\17\202\316\376\377\377\213F\4\203\246\20\5\0\0\0\203e\364\0\213\370\301\350\5\203\347\37\271\1\1\0\0\203\340\37\3\371@\215U\364\211E\354\215\206 \5\0\0RP\215E\374\307E\374\11\0\0\0P\215E\350Phhs@\0h(s@\0Q\215F\14WP\307E\360\6\0\0\0\350\33\5\0\0\203}\374\0u\3\203\310\377\205\300\17\205\312\372\377\377\215E\364P\215\206 \5\0\0P\215E\360P\215E\344Ph\344s@\0h\250s@\0j\0\377u\354\215D\276\14P\350\336\4\0\0\205\300\17\205\226\372\377\377\213E\360\205\300u\14\201\377\1\1\0\0\17\217\203\372\377\377\212M\374\203&\0\210", ) , ) == 0x0 01418 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "N\20\211F\30\17\266F\20\211F\14\213F\24\211F\10\307\6\1\0\0\0\213F\14\353 \203}\314\0\17\204\266\3\0\0\213M\310\377M\314\17\266\21\213\313\323\342\11U\300\377E\310\203\303\10;\330r\334\17\267\4E\324\223@\0#E\300\213N\10\215\4\201\17\266H\1\323m\300+\331\17\266\10\205\311u\22\17\267@\2\211F\10\307\6\6\0\0\0\351Y\3\0\0\366\301\20t\30\203\341\17\211N\10\17\267@\2\211F\4\307\6\2\0\0\0\351<\3\0\0\366\301@\17\204\321\0\0\0\366\301 \17\204\315\371\377\377\307\6\7\0\0\0\351\37\3\0\0\213F\10\353 \203}\314\0\17\204 \3\0\0\213M\310\377M\314\17\266\21\213\313\323\342\11U\300\377E\310\203\303\10;\330r\334\17\267\14E\324\223@\0#M\300\1N\4\213\310\323m\300+\330\17\266F\21\211F\14\213F\30\211F\10\307\6\3\0\0\0\213F\14\353 \203}\314\0\17\204\317\2\0\0\213M\310\377M\314\17\266\21\213\313\323\342\11U\300\377E\310\203\303\10;\330r\334\17\267\4E\324\223@\0#E\300\213N\10\215\4\201\17\266H\1\323m\300+\331\17\266\10\366\301\20t\30\203\341\17\211N\10\17\267@\2\211F\14\307\6\4\0\0\0\351k\2\0\0\366\301@\17\205\5\371\377\377\211N\14\17\267H\2\215\4\210\211F\10\351P\2\0\0\213F\10\353 \203}\314\0\17\204Q\2\0\0\213M\310\377M\314\17\266\21\213\313\323\342\11U\300\377E\310\203\303\10;\330r\334\17\267\14E\324\223@\0#M\300\1N\14\213\310\323m\300+\330\307\6\5\0\0\0\213E\320\213V\14\213\310+\316\201\351\240\33\0\0;\312s\23\213\216\240\233\0\0+\312+\316\215\214\1`\344\377\377\353\4\213\310+\312\203~\4\0\211M\340\17", ) , ) == 0x0 01419 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\221\0\0\0\213\276\240\233\0\0;\307u#\213\216\244\233\0\0\215\226\240\33\0\0;\312t\23\213\302;\301s\7+\310I\213\371\353\2+\370\205\377ud\377u\10\211\206\250\233\0\0\350\11\2\0\0\213\206\250\233\0\0\213\216\244\233\0\0;\301\211E\320s\7\213\371+\370O\353\10\213\276\240\233\0\0+\370\213\226\240\233\0\0;\302\211U\370u\37\215\226\240\33\0\0;\312t\25\213\302;\301\211E\320s\7+\310I\213\371\353\5\213}\370+\370\205\377\17\204d\1\0\0\213M\340\212\21\210\20@AO;\216\240\233\0\0\211E\320\211M\340\211}\324u\11\215\216\240\33\0\0\211M\340\377N\4\17\205:\377\377\377\351\302\370\377\377\213E\324\213}\320\205\300\17\205\221\0\0\0\213\216\240\233\0\0;\371u#\213\206\244\233\0\0\215\226\240\33\0\0;\302t\23\213\372;\370s\5+\307H\353\4+\317\213\301\205\300ud\377u\10\211\276\250\233\0\0\3508\1\0\0\213\276\250\233\0\0\213\216\244\233\0\0;\371\211}\320s\7\213\301+\307H\353\10\213\206\240\233\0\0+\307\213\226\240\233\0\0;\372\211U\370u\37\215\226\240\33\0\0;\312t\25\213\372;\371\211}\320s\7+\317I\213\301\353\5\213E\370+\307\205\300\17\204\223\0\0\0\212N\10\210\17GH\211}\320\211E\324\351\21\370\377\377\203\373\7v\11\203\353\10\377E\314\377M\310\213E\320\377u\10\211\206\250\233\0\0\350\261\0\0\0\213\216\250\233\0\0\213\226\244\233\0\0;\312\211M\320s\7\213\302+\301H\353\10\213\206\240\233\0\0+\301;\312\211E\324u9\213\206\24\5\0\0\203\370\10\211\6u3\213\6\203\370\17\17\2062\366\377\377\351\223\366\377\377\213E\3003\377\211\206\34\5\0\0\213E\10\211\236\30\5\0\0\211x\4", ) , ) == 0x0 01420 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "3\377G\351q\366\377\377\5d@\0\30d@\0\256d@\0\377d@\0}e@\0\301e@\0\307f@\0xg@\01^@\0\306_@\0\353_@\0\371`@\08a@\0\33c@\0p^@\0\206g@\0SV\213t$\14W\213\276\264\233\0\0\213\236\270\233\0\0;\373v\6\213\236\260\233\0\0\213F\14+\337;\330r\2\213\330SW\377v\10+\303\211F\14\350\15\356\377\377\1^\10\213\206\260\233\0\0\3\373;\370u\269\206\270\233\0\0\215\276\260\33\0\0u\271\211\276\270\233\0\0\353\261\211\276\264\233\0\0_^[\302\4\0U\213\354\201\354\354\0\0\0SV\213u\14Wj\203\300Y\215}\220\363\253\213M\10\213\326\213\1\203\301\4\215D\205\220\377\0Ju\3629u\220u\23\213E\34\203 \0\213E \203 \03\300\351\360\2\0\0\213u 3\333Cj\17\213>\213\313\211} Z3\3009D\215\220u\5A;\312v\363;\371\211M\374s\3\211M 9D\225\220u\3Ju\3679U \211U\350v\3\211U \213} \211>\323\343\353\15+\\215\220\17\210\237\2\0\0A\3\333;\312r\357\213\362\301\346\2\215L5\220\2139+\337\211]\320\17\210\202\2\0\0\3\373\211\205T\377\377\377\21193\311Jt\233\377\3L=\224\203\307\4J\211\214=T\377\377\377u\357\213]\103\377\213\13\203\303\4;\310t\23\215\214\215P\377\377\377\213\21\211<\225\270\326B\0B\211\21G;}\14r\336\213\2145P\377\377\377\213] \203M\364\377\203e\334\0\211M\14\213M\374\367\333;M\350\211E\370\211\205P\377\377\377\307E\340\270\326B\0\211\205\24\377\377\377\17\217\363\1\0\0\215Q\377\215L\215\220\211U\330\211M\344\213M\344\2131\205", ) , ) == 0x0 01421 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\213M N\3\313\211u\3249M\374\211M\354\17\216\314\0\0\0F\211u\360\213u\350\377E\364+u\354;u v\3\213u \213M\3743\322+M\354B\323\342;U\360v#\213}\344\203\310\377+E\324\3\320;\316s\24\353\15\203\307\4\3\322\213\7;\320v\7+\320A;\316r\356\213U(3\300@\213\22\323\340\211E\334\215<\2\201\377\240\5\0\0\17\207h\1\0\0\213E$\215\4\220\213U\364\215\264\225\24\377\377\377\213U(\211:\213U\364\205\322\211\6t1\213}\370\213v\374\211\274\225P\377\377\377\212U \210U\11\210M\10\213\327\213\313\323\352\213\310+\316\301\371\2+\312f\211M\12\213M\10\211\14\226\353\5\213M\34\211\1\213M\354\213\331\3M 9M\374\211M\354\17\2178\377\377\377\212M\374\213u\340*\313\210M\11\213M\14\215\14\215\270\326B\0;\361r\6\306E\10\300\353C\213\16;M\20s\34\201\371\0\1\0\0\17\222\301\376\311\203\341`\210M\10f\213\16\203\306\4\211u\340\353\34+M\20\213U\30\3\311\212\24\21\200\302P\203E\340\4\210U\10\213U\24f\213\14\21f\211M\12\213M\374\213U\3703\377+\313G\213\367\323\346\213\313\323\352\353\10\213M\10\211\14\220\3\326;U\334r\363\213M\330\213u\370\213\327\323\342\353\43\362\321\352\205\326u\370\213\3173\362\211M\360\213\313\213\327\211u\370\323\342J#\326\213\312\213U\364;\214\225P\377\377\377t\32+] \213\367J\213\313\323\346N#u\370;\264\225P\377\377\377u\351\211U\364\203}\324\0\17\205?\376\377\377\377E\374\203E\344\4\213M\374\377E\330;M\350\17\216\32\376\377\3773\3009E\320t\11\203}\350\1t\3\203\310\377_^[\311\302$\0\314\377%hr@\0\377%", ) , ) == 0x0 01422 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\236\200\0\0\262\200\0\0\220\200\0\0\200\200\0\0\6\201\0\0\366\200\0\0\344\200\0\0\326\200\0\0\304\200\0\0\0\0\0\08\201\0\0$\201\0\0\21\0\0\200N\201\0\0\0\0\0\0\314\177\0\0\274\177\0\0\254\177\0\0\226\177\0\0\200\177\0\0t\177\0\0d\177\0\0T\177\0\0\0\0\0\0.y\0\0y\0\0bz\0\0pz\0\0\202z\0\0\232z\0\0\252z\0\0\266z\0\0\312z\0\0\332z\0\0\350z\0\0\370z\0\0\12{\0\0\36{\0\0,{\0\0@{\0\0L{\0\0X{\0\0\26y\0\0\374x\0\0\340x\0\0\322x\0\0\304x\0\0\256x\0\0\230x\0\0\210x\0\0tx\0\0dx\0\0Rx\0\0Dx\0\0.x\0\0\20x\0\0\364w\0\0\350w\0\0\334w\0\0\204w\0\0\312w\0\0\276w\0\0\256w\0\0\234w\0\0\216w\0\0Vz\0\0\0\0\0\0H\200\0\00\200\0\0\32\200\0\0\10\200\0\0\370\177\0\0\344\177\0\0V\200\0\0\0\0\0\0v}\0\0\210}\0\0\230}\0\0\250}\0\0\272}\0\0\312}\0\0\330}\0\0\352}\0\0\366}\0\0\4~\0\0\26~\0\0&~\0\04~\0\0F~\0\0X~\0\0j~\0\0~~\0\0\220~\0\0j}\0\0\262~\0\0\300~\0\0\322~\0\0\346~\0\0\370~\0\0\12\177\0\0\30\177\0\0$\177\0\08\177\0\0\332|\0\0\312|\0\0\276|\0\0\254|\0\0\232|\0\0\204|\0\0", ) y\0\0bz\0\0pz\0\0\202z\0\0\232z\0\0\252z\0\0\266z\0\0\312z\0\0\332z\0\0\350z\0\0\370z\0\0\12{\0\0\36{\0\0,{\0\0@{\0\0L{\0\0X{\0\0\26y\0\0\374x\0\0\340x\0\0\322x\0\0\304x\0\0\256x\0\0\230x\0\0\210x\0\0tx\0\0dx\0\0Rx\0\0Dx\0\0.x\0\0\20x\0\0\364w\0\0\350w\0\0\334w\0\0\204w\0\0\312w\0\0\276w\0\0\256w\0\0\234w\0\0\216w\0\0Vz\0\0\0\0\0\0H\200\0\00\200\0\0\32\200\0\0\10\200\0\0\370\177\0\0\344\177\0\0V\200\0\0\0\0\0\0v}\0\0\210}\0\0\230}\0\0\250}\0\0\272}\0\0\312}\0\0\330}\0\0\352}\0\0\366}\0\0\4~\0\0\26~\0\0&~\0\04~\0\0F~\0\0X~\0\0j~\0\0~~\0\0\220~\0\0j}\0\0\262~\0\0\300~\0\0\322~\0\0\346~\0\0\370~\0\0\12\177\0\0\30\177\0\0$\177\0\08\177\0\0\332|\0\0\312|\0\0\276|\0\0\254|\0\0\232|\0\0\204|\0\0", ) == 0x0 01423 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "X}\0\0@}\0\0.}\0\0\36}\0\0\14}\0\0\0}\0\0\240~\0\0\360|\0\08|\0\0*|\0\0\30|\0\0\12|\0\0\2|\0\0\362{\0\0\340{\0\0\320{\0\0\276{\0\0\260{\0\0\240{\0\0\224{\0\0\210{\0\0|{\0\0v|\0\0\0\0\0\0\330\201\0\0\302\201\0\0\260\201\0\0\0\0\0\0\226\201\0\0\204\201\0\0p\201\0\0\0\0\0\0shlwapi.dll\0SHAutoComplete\0\0.DEFAULT\Control Panel\International\0\0\0\0Locale\0\0Control Panel\Desktop\ResourceLocale\0\0\0\0GetUserDefaultUILanguage\0\0\0\0%d\0\0\20\21\22\0\10\7\11\6\12\5\13\4\14\3\15\2\16\1\17\0\3\0\4\0\5\0\6\0\7\0\10\0\11\0\12\0\13\0\15\0\17\0\21\0\23\0\27\0\33\0\37\0#\0+\03\0;\0C\0S\0c\0s\0\203\0\243\0\303\0\343\0\2\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\1\0\1\0\2\0\2\0\2\0\2\0\3\0\3\0\3\0\3\0\4\0\4\0\4\0\4\0\5\0\5\0\5\0\5\0\0\0p\0p\0\0\0\1\0\2\0\3\0\4\0\5\0\7\0\11\0\15\0\21\0\31\0!\01\0A\0a\0\201\0\301\0\1\1\201\1\1\2\1\3\1\4\1\6\1\10\1\14\1\20\1\30\1 \10\1@\1`\0\0\0\0\0\0\0\0\1\0\1\0\2\0\2\0", ) , ) == 0x0 01424 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\6\0\6\0\7\0\7\0\10\0\10\0\11\0\11\0\12\0\12\0\13\0\13\0\14\0\14\0\15\0\15\0\356\24\2\0\0\0\0\0\300\0\0\0\0\0\0F\1\24\2\0\0\0\0\0\300\0\0\0\0\0\0F\13\1\0\0\0\0\0\0\300\0\0\0\0\0\0Fdu\0\0\0\0\0\0\0\0\0\0n{\0\0`p\0\0pv\0\0\0\0\0\0\0\0\0\0H\177\0\0lq\0\0@u\0\0\0\0\0\0\0\0\0\0\332\177\0\0 y\0\0bz\0\0pz\0\0\202z\0\0\232z\0\0\252z\0\0\266z\0\0\312z\0\0\332z\0\0\350z\0\0\370z\0\0\12{\0\0\36{\0\0,{\0\0@{\0\0L{\0\0X{\0\0\26y\0\0\374x\0\0", ) y\0\0bz\0\0pz\0\0\202z\0\0\232z\0\0\252z\0\0\266z\0\0\312z\0\0\332z\0\0\350z\0\0\370z\0\0\12{\0\0\36{\0\0,{\0\0@{\0\0L{\0\0X{\0\0\26y\0\0\374x\0\0", ) == 0x0 01425 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\256x\0\0\230x\0\0\210x\0\0tx\0\0dx\0\0Rx\0\0Dx\0\0.x\0\0\20x\0\0\364w\0\0\350w\0\0\334w\0\0\204w\0\0\312w\0\0\276w\0\0\256w\0\0\234w\0\0\216w\0\0Vz\0\0\0\0\0\0H\200\0\00\200\0\0\32\200\0\0\10\200\0\0\370\177\0\0\344\177\0\0V\200\0\0\0\0\0\0v}\0\0\210}\0\0\230}\0\0\250}\0\0\272}\0\0\312}\0\0\330}\0\0\352}\0\0\366}\0\0\4~\0\0\26~\0\0&~\0\04~\0\0F~\0\0X~\0\0j~\0\0~~\0\0\220~\0\0j}\0\0\262~\0\0\300~\0\0\322~\0\0\346~\0\0\370~\0\0\12\177\0\0\30\177\0\0$\177\0\08\177\0\0\332|\0\0\312|\0\0\276|\0\0\254|\0\0\232|\0\0\204|\0\0j|\0\0T|\0\0D|\0\0X}\0\0@}\0\0.}\0\0\36}\0\0\14}\0\0\0}\0\0\240~\0\0\360|\0\08|\0\0*|\0\0\30|\0\0\12|\0\0\2|\0\0\362{\0\0\340{\0\0\320{\0\0\276{\0\0\260{\0\0\240{\0\0\224{\0\0\210{\0\0|{\0\0v|\0\0\0\0\0\0\330\201\0\0\302\201\0\0\260\201\0\0\0\0\0\0\226\201\0\0\204\201\0\0p\201\0\0\0\0\0\0j\2MulDiv\0\0|\0DeleteFileA\0\311\0FindFirstFileA\0\0\323\0FindNextFileA\0\305\0FindClose\0\20\3SetFilePointer\0\0\253\2ReadFile\0\0\227\3WriteFile\0", ) , ) == 0x0 01426 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "ProfileStringA\0\0\234\3WritePrivateProfileStringA\0\0k\2MultiByteToWideChar\0\357\0FreeLibrary\0\230\1GetProcAddress\0\0H\2LoadLibraryA\0\0w\1GetModuleHandleA\0\0\12\3SetErrorMode\0\0R\1GetExitCodeProcess\0\0\205\3WaitForSingleObject\0\356\1GlobalAlloc\0\365\1GlobalFree\0\0\262\0ExpandEnvironmentStringsA\0P\1GetEnvironmentVariableA\0\263\3lstrcmpA\0\0\266\3lstrcmpiA\0.\0CloseHandle\0\24\3SetFileTime\03\0CompareFileTime\0\320\2SearchPathA\0\255\1GetShortPathNameA\0a\1GetFullPathNameA\0\0d\2MoveFileA\0\377\2SetCurrentDirectoryA\0\0V\1GetFileAttributesA\0\0i\1GetLastError\0\0E\0CreateDirectoryA\0\0\16\3Se", ) , ) == 0x0 01427 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "tesA\0\0I\3Sleep\0[\1GetFileSize\0u\1GetModuleFileNameA\0\0\325\1GetTickCount\0\0:\1GetCurrentProcess\0=\0CopyFileA\0\257\0ExitProcess\0\10\1GetCommandLineA\0\351\1GetWindowsDirectoryA\0\0\313\1GetTempPathA\0\0\274\3lstrcpynA\0E\1GetDiskFreeSpaceA\0\0\2GlobalUnlock\0\0\371\1GlobalLock\0\0i\0CreateThread\0\0`\0CreateProcessA\0\0\272\2RemoveDirectoryA\0\0M\0CreateFileA\0\311\1GetTempFileNameA\0\0\277\3lstrlenA\0\0\260\3lstrcatA\0\0\271\1GetSystemDirectoryA\0KERNEL32.dll\0\0\310\0EndPaint\0\0\274\0DrawTextA\0\342\0FillRect\0\0\377\0GetClientRect\0\15\0BeginPaint\0\0\216\0DefWindowProcA\0\0:\2SendMessageA\0\0\223\1InvalidateRect\0\0\304\0", ) , ) == 0x0 01428 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\0\0\14\1GetDC\0\277\1LoadImageA\0\0\177\2SetWindowLongA\0\0\21\1GetDlgItem\0\0\255\1IsWindow\0\0\344\0FindWindowExA\0=\2SendMessageTimeoutA\0\325\2wsprintfA\0\221\2ShowWindow\0\0V\2SetForegroundWindow\0\3\2PostQuitMessage\0\205\2SetWindowTextA\0\0y\2SetTimer\0\0\231\0DestroyWindow\0U\0CreateDialogParamA\0\0\341\0ExitWindowsEx\0*\0CharNextA\0\236\0DialogBoxParamA\0\366\0GetClassInfoA\0`\0CreateWindowExA\0\230\2SystemParametersInfoA\0\25\2RegisterClassA\0\0\306\0EndDialog\00\2ScreenToClient\0\0t\1GetWindowRect\0F\2SetClassLongA\0\256\1IsWindowEnabled\0\202\2SetWindowPos\0\0Z\1GetSysColor\0n\1GetWindowLongA\0\0L\2SetCurso", ) , ) == 0x0 01429 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "orA\08\0CheckDlgButton\0\0<\1GetMessagePos\0\267\1LoadBitmapA\0\33\0CallWindowProcA\0\261\1IsWindowVisible\0B\0CloseClipboard\0\0I\2SetClipboardData\0\0\301\0EmptyClipboard\0\0\365\1OpenClipboard\0\243\2TrackPopupMenu\0\0\10\0AppendMenuA\0^\0CreatePopupMenu\0]\1GetSystemMetrics\0\0R\2SetDlgItemTextA\0\23\1GetDlgItemTextA\0\336\1MessageBoxA\0-\0CharPrevA\0\241\0DispatchMessageA\0\0\377\1PeekMessageA\0\0USER32.dll\0\0\16\2SelectObject\0\0<\2SetTextColor\0\0\26\2SetBkMode\0:\0CreateFontIndirectA\0)\0CreateBrushIndirect\0\217\0DeleteObject\0\0k\1GetDeviceCaps\0\25\2SetBkColor\0\0GDI32.dll\0\232\0SHFileOperatio", ) , ) == 0x0 01430 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "xecuteA\0\254\0SHGetFileInfoA\0\0y\0SHBrowseForFolderA\0\0\274\0SHGetPathFromIDListA\0\0\267\0SHGetMalloc\0\303\0SHGetSpecialFolderLocation\0\0SHELL32.dll\0\331\1RegEnumValueA\0\325\1RegEnumKeyA\0\354\1RegQueryValueExA\0\0\371\1RegSetValueExA\0\0\315\1RegCreateKeyExA\0\311\1RegCloseKey\0\322\1RegDeleteValueA\0\320\1RegDeleteKeyA\0\342\1RegOpenKeyExA\0ADVAPI32.dll\0\08\0ImageList_Destroy\04\0ImageList_AddMasked\07\0ImageList_Create\0\0COMCTL32.dll\0\0\20\0CoCreateInstance\0\0\4\1OleUninitialize\0\355\0OleInitialize\0ole32.dll\0\12\0VerQueryValueA\0\0\0\0GetFileVersionInfoA\0\1\0GetFileVersionInfoSizeA\0VE", ) , ) == 0x0 01431 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\240\364B\0m\23@\0\27\@\0\6\0\0\0\\0\0\0%s %s\0\0\0->\0\0\377\377\377\377\0\0\0\0The installer you are trying to use is corrupted or incomplete.\12This could be the result of a damaged disk, a failed download or a virus.\12\12You may want to contact the author of this installer to obtain a new copy.\12\12It may be possible to skip this check using the /NCRC command line switch\12(NOT RECOMMENDED).\0verifying installer: %d%%\0\0\0Error launching installer\0\0\0... %d%%\0\0\0\0Au_.exe\0SeShutdownPrivilege\0AdjustTokenPrivileges\0\0\0LookupPrivilegeValueA\0\0\0OpenProc", ) , ) == 0x0 01432 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "ADVAPI32.dll\0\0\0\0 _?=\0\0\0\0" \0\0~nsu.tmp\\0\0\0\Temp\0\0\0NSIS Error\0\0\0\0\0\0Error writing temporary file. Make sure your temp folder is valid.\0\0\377\377\377\377\13?@\0\303F@\0\1B@\0\274N@\0\272A@\0\377\377\377\377\6\0\0\0RichEdit20A\0RichEd20.dll\0\0\0\0.exe\0\0\0\0KERNEL32.dll\0\0\0\0open\0\0\0\0GetDiskFreeSpaceExA\0%u.%u%s%s\0\0\0\*.*\0\0\0\0\12[\0\0[Rename]\15\12\0\0\wininit.ini\0\0\0\0%s=%s\15\12\0MoveFileExA\0C:\Program Files\0\0\0\0ProgramFilesDir\0Software\Microsoft\Windows\CurrentVersion\0\0\0CommonFilesDir\0\0\Microsoft\Internet Explorer\Quick Launch\0\0\0*?|<>/":\0\0\0\0\0\0\1\0\3\0\7\0\17\0\37\0?\0\177\0\377\0\377\1\377\3\377\7\377\17\377\37\377?\377\177", ) \0\0~nsu.tmp\\0\0\0\Temp\0\0\0NSIS Error\0\0\0\0\0\0Error writing temporary file. Make sure your temp folder is valid.\0\0\377\377\377\377\13?@\0\303F@\0\1B@\0\274N@\0\272A@\0\377\377\377\377\6\0\0\0RichEdit20A\0RichEd20.dll\0\0\0\0.exe\0\0\0\0KERNEL32.dll\0\0\0\0open\0\0\0\0GetDiskFreeSpaceExA\0%u.%u%s%s\0\0\0\*.*\0\0\0\0\12[\0\0[Rename]\15\12\0\0\wininit.ini\0\0\0\0%s=%s\15\12\0MoveFileExA\0C:\Program Files\0\0\0\0ProgramFilesDir\0Software\Microsoft\Windows\CurrentVersion\0\0\0CommonFilesDir\0\0\Microsoft\Internet Explorer\Quick Launch\0\0\0*?|<>/ (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "ADVAPI32.dll\0\0\0\0 _?=\0\0\0\0" \0\0~nsu.tmp\\0\0\0\Temp\0\0\0NSIS Error\0\0\0\0\0\0Error writing temporary file. Make sure your temp folder is valid.\0\0\377\377\377\377\13?@\0\303F@\0\1B@\0\274N@\0\272A@\0\377\377\377\377\6\0\0\0RichEdit20A\0RichEd20.dll\0\0\0\0.exe\0\0\0\0KERNEL32.dll\0\0\0\0open\0\0\0\0GetDiskFreeSpaceExA\0%u.%u%s%s\0\0\0\*.*\0\0\0\0\12[\0\0[Rename]\15\12\0\0\wininit.ini\0\0\0\0%s=%s\15\12\0MoveFileExA\0C:\Program Files\0\0\0\0ProgramFilesDir\0Software\Microsoft\Windows\CurrentVersion\0\0\0CommonFilesDir\0\0\Microsoft\Internet Explorer\Quick Launch\0\0\0*?|<>/":\0\0\0\0\0\0\1\0\3\0\7\0\17\0\37\0?\0\177\0\377\0\377\1\377\3\377\7\377\17\377\37\377?\377\177", ) , ) == 0x0 01433 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\3\0\0\0(\0\0\200\5\0\0\0@\0\0\200\16\0\0\0h\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\0\0\200\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0i\0\0\0\230\0\0\200j\0\0\0\260\0\0\200o\0\0\0\310\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0g\0\0\0\340\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\370\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\10\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\30\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0(\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\08\1\0\0H\201\3\0\350\2\0\0\0\0\0\0\0\0\0\00\204\3\0\0\1\0\0\0\0\0\0\0\0\0\00\205\3\0\34\1\0\0\0\0\0\0\0\0\0\0P\206\3\0`\0\0\0\0\0\0\0\0\0\0\0\260\206\3\0\24\0\0\0\0\0\0\0\0\0\0\0(\0\0\0 \0\0\0@\0\0\0\1\0\4\0\0\0\0\0\200\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\0\0\200\0\0\0\200\200\0\0\0\0\200\0\0\200\200\0\200\0\200\0\200\200\200\0\300\300\300\0\0\377\0\0\377\0\0\0\377\377\0\0\0\0\377\0\0\377\377\0\377\0\377\0\377\377\377\0\0\0\0\0\0\0\0\7w\0\0\0\0\0\0\0\0\0\0\0\0\0\7x\215\335\220\0\0\0\0\0\0x\370\360\0\0\177\217\210\335\231\220\0\0\0\0\0\177\217\200p\7\207\370\375\331\231\210\0\0\0\0\0x\370\360", ) , ) == 0x0 01434 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\0\177\217\200xw\207\207\370\331\210\213\260\0\0\0\0x\370\360\207xxxp\11\213\273\260\0\0\0\0\177\217\200xw\207\207\0\0\273\270\200\0\0\0\0x\370\360\207x\210\273\0\0xxp\0\0\0\0\177\217\200xx\273\211\260\7\207\207\200\0\0\0\0\177\377\360\207{\270\233\275\377xxp\0\0\0\0\177\377\360xw\211\273\275\370\367\207\0\0\0\0\0\177\377\360\207\207\233\273\335\217\217x\10\210\210\0\0\177\377\360\210\210{\275\335\210\370\360\0\0\210p\0\177\377\360\210\210\7}\335\210\200\7ww\210p\0\177\377\360\210\210\17\367ww\177\377\377\377\377p\0wwp\210\210\7wwwwwwwxp\0wwp\210\210\0\0\0\0\0\0\0\0\0\200\7\377\377\367\10\210\7\210\210\210\210\210\210\210\207\0wwwwp\210\7\377\377\377\377\377\377\377\207\0\0\0\7ww\10\7\360\0\0\0\0\0\17\207\0\0\0\0wwp\7\360\0\0\0\0\0\17\207\0\0\0\0\7\377\377\7\360\0\0\360\17\0\17\207\0\0\0\0\0wwp\360\0\0\360\17\0\17\207\0\0\0\0\0\0\0\7\360\0\0\377\377\360\17\207\0\0\0\0\0\0\0\7\360\0\0\377\377\360\17\207\0\0\0\0\0\0\0\7\360\17\377\360\0\0\17\207\0\0\0\0\0\0\0\7\360\0\377\0\0\0\17\207\0\0\0\0\0\0\0\7\360\0\0\0\0\0\17\207\0\0\0\0\0\0\0\7\360\0\0\0\0\0\17\207\0\0\0\0\0\0\0\7\377\377\377\377\377\377\377\207\0\0\0\0\0\0\0\0wwwwwwww\0\377\376\7\377\300\370\1\377\300p\0\377\300 \0\177\300\0\0\177\300\0\0?\300\0\0?\300\0`?\300\0`?\300\0\0?\300\0\0?\300\0\0\3\300\0\0\1\300\0\0\0\300\0\0\0\300\0\0\0\300\0\0\0", ) , ) == 0x0 01435 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\370\0\0\1\374\0\0\1\376\0\0\1\377\0\0\1\377\370\0\1\377\370\0\1\377\370\0\1\377\370\0\1\377\370\0\1\377\370\0\1\377\370\0\1\377\374\0\3\1\0\377\377\0\0\0\0\0\0\0\0H\10\312\200\6\0\0\0\0\0\30\1\242\0\0\0\0\0\0\0\10\0\0\0\0\1M\0S\0 \0S\0h\0e\0l\0l\0 \0D\0l\0g\0\0\0\0\0\0\0\0\0\0\0\0\0\3@\253\0\216\02\0\16\0\3\0\0\0\377\377\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1P\337\0\216\02\0\16\0\1\0\0\0\377\377\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1P\7\0\216\02\0\16\0\2\0\0\0\377\377\200\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\2P\7\0\212\0\13\1\1\0\377\377\377\377\377\377\202\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\2@\7\0\6\0\12\1\202\0\372\3\0\0\377\377\202\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\2X;\0\221\0l\0\10\0\4\4\0\0\377\377\202\0\0\0\0\0\1\0\377\377\0\0\0\0\0\0\0\0H\4\0@\5\0\0\0\0\0\12\1\202\0\0\0\0\0\0\0\10\0\0\0\0\1M\0S\0 \0S\0h\0e\0l\0l\0 \0D\0l\0g\0\0\0\0\0\0\0\0\0\0\0\0\0\200P\30\0\12\0\361\0\13\0\354\3\0\0m\0s\0c\0t\0l\0s\0_\0p\0r\0o\0g\0r\0e\0s\0s\03\02\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\214\0\0P\30\0\0\0\361\0\10\0\356\3\0\0\377\377\202\0\0\0\0\0\0\0\0\0\0\0\0\0\5@\201@\0\0\31\0\11\1h\0\370\3\0\0S\0y\0s\0L\0i\0s\0", ) , ) == 0x0 01436 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0P\0\0\0\0\26\0\24\0\7\4\0\0\377\377\202\0\377\377g\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0P\0\0\34\0<\0\16\0\3\4\0\0\377\377\200\0\0\0\0\0\0\0\0\0\1\0\377\377\0\0\0\0\0\0\0\0\310\10\0\200\1\0\0\0\0\0\242\0\26\0\0\0\0\0\0\0\10\0\0\0\0\1M\0S\0 \0S\0h\0e\0l\0l\0 \0D\0l\0g\0\0\0\0\0\0\0\0\0\0\0\1\0\2P\7\0\7\0\224\0\10\0\6\4\0\0\377\377\202\0\0\0\0\0\0\0\1\0\1\0 \20\0\1\0\4\0\350\2\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 01437 424 NtReadFile (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, (176, 0, 0, 0, 512, 0x0, 0, ... {status=0x0, info=512}, "\2\0\0\0\357\276\255\336NullsoftInst\360\10\0\0\370-\1\0C\2\0\200\355T1\213\23Q\20\236\23\357\270\313\31T\320\306\352\35x\210r\204;\5\11i$\354\255\30\3416\301DTH\341Kv\222[nw\337\343\355[\223t\301F+Q\301\306F\260\260\25+\261\260\272\342j\253\3m\374\11j#\26g\234\315f\2755\230\323\316\302|0\373\315\233\331\371fv\31\336}\0`30D\304\221\233\237\5\310\20W\346\342\2705\37\307?\315\303\371H!\16\0<'\372<\370{\300?\306{\232a\364K`v\304\311y\201\354\25L1\305\24\3773\26\311\216\247\356\205\361\334\311\11uG\310\226 \276_\17\217\345N\220=\246+'\237\4n\337x\350=};\363\201\356\243$g\20\227\17\321\343u\361\353\366\275\235_r\26q\347\34=>\276{p\372Y\\27\315rk\302\234I\35\22_Y\2447^\34\335\355l\307\232g)\26N\370\206\231\203~\314\367\345e\330(\226\254\252i\324Je\13\366\236\364\301(\324k\350\311zC\251\264_\257p\245=\231sE\336\252%\313\254\345\326\315J\342\212&O\334\262q3\322\2557V/^\266\257#\214xm5\177!\207]L\347\352\3439+t\335@\2644+\371\201\346\256\313\252\275@\243\307\356\234\317\255\345ap\267\317\252\250C\11\6\367\317h\326Q\216\306\2\3C!\327\310Z\302\265Q\321\331TJ(fcSxRa\208~\233\331\\363%f\10\245B\251\321fN\334\0\325%0\273\330\14\207BfW+\336\324i\17\207ZQ\247HE\13\326r\dP\16\265\14\365~\313\352\226#%\332\3210B\366\330:j\356\270\1\253\11f\270\216l\10\256\354\321XB\242\37I\15uZ\373\332\5\226", ) , ) == 0x0 01438 424 NtClose (176, ... ) == 0x0 01439 424 NtUserDestroyWindow (131250, ... 01440 424 NtUserRemoveProp (131250, 43288, ... ) == 0xffffffff 01441 424 NtUserRemoveProp (131250, 43282, ... ) == 0x0 01442 424 NtUserRemoveProp (131250, 43287, ... ) == 0x0 01439 424 NtUserDestroyWindow ... ) == 0x1 01443 424 NtUserUnregisterClass (1244636, 1998258176, 1244624, ... ) == 0x1 01444 424 NtUserModifyUserStartupInfoFlags (1, 0, ... ) == 0x810d4da8 01445 424 NtUserGetDCEx (0, 0, 3, ... ) == 0x1010050 01446 424 NtGdiSetupPublicCFONT (16842832, 0, 0, ... ) == 0x100 01447 424 NtGdiGetTextExtent (16842832, 1351816, 10, 1244068, 1, ... ) == 0x1 01448 424 NtUserGetForegroundWindow (... ) == 0x20064 01449 424 NtUserQueryWindow (131172, 0, ... ) == 0x7f4 01450 424 NtUserQueryWindow (131172, 1, ... ) == 0x7f8 01451 424 NtGdiSetupPublicCFONT (16842832, 0, 0, ... ) == 0x100 01452 424 NtGdiGetTextMetricsW (16842832, 1242988, 68, ... ) == 0x1 01453 424 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 01454 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x60403f0 01455 424 NtGdiGetRandomRgn (16842832, 100926448, 1, ... ) == 0x0 01456 424 NtGdiIntersectClipRect (16842832, 0, 0, 565, 738, ... ) == 0x3 01457 424 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x2 01458 424 NtGdiSetupPublicCFONT (0, 50987263, 6, ... ) == 0x3 01459 424 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 01460 424 NtGdiGetRandomRgn (16842832, 117703664, 1, ... ) == 0x0 01461 424 NtGdiIntersectClipRect (16842832, 0, 0, 355, 738, ... ) == 0x3 01462 424 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x2 01463 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01464 424 NtUserFindExistingCursorIcon (1242856, 1242872, 1243440, ... ) == 0x10011 01465 424 NtUserSetCursor (65553, ... ) == 0x10015 01466 424 NtUserCallOneParam (1, 49, ... ) == 0x1 01467 424 NtUserFindExistingCursorIcon (1242808, 1242824, 1243392, ... ) == 0x10015 01468 424 NtUserSetCursor (65557, ... ) == 0x10011 01469 424 NtGdiCreateCompatibleDC (0, ... ) == 0x70103ea 01470 424 NtGdiExtGetObjectW (50987263, 92, 1243136, ... ) == 0x5c 01471 424 NtGdiHfontCreate (1242572, 356, 0, 0, 1329216, ... ) == 0x60a03e9 01472 424 NtGdiGetTextMetricsW (117507050, 1243076, 68, ... ) == 0x1 01473 424 NtGdiGetWidthTable (117507050, 52, 1407432, 308, 1408048, 1406800, 1406816, ... ) == 0x1 01474 424 NtGdiDeleteObjectApp (117507050, ... ) == 0x1 01475 424 NtUserGetForegroundWindow (... ) == 0x20064 01476 424 NtUserQueryWindow (131172, 0, ... ) == 0x7f4 01477 424 NtUserQueryWindow (131172, 1, ... ) == 0x7f8 01478 424 NtUserGetAtomName (32770, 1242012, ... ) == 0x6 01479 424 NtUserCreateWindowEx (65793, 32770, 32770, (65793, 32770, 32770, "NSIS Error", -2134375995, 300, 306, 431, 185, 0, 0, 2010382336, 0, 1073742848, 0, ... , -2134375995, 300, 306, 431, 185, 0, 0, 2010382336, 0, 1073742848, 0, ... 01480 424 NtUserSetWindowFNID (196786, 676, ... ) == 0x1 01481 424 NtUserCallHwndParam (196786, 1353564, 78, ... ) == 0x14a75c 01482 424 NtUserMessageCall (0x300b2, WM_NCCREATE, 0x0, 0x12f348, 0, 670, 0, ... ) == 0x1 01483 424 NtUserMessageCall (0x300b2, WM_NCCALCSIZE, 0x0, 0x12f370, 0, 670, 0, ... ) == 0x0 01484 424 NtUserGetClassName (196786, 0, 1241136, ... ) == 0x6 01485 424 NtUserRemoveProp (196786, 43282, ... ) == 0x0 01486 424 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 0, 0, 0, 0} (24, {24, 52, new_msg, 0, 0, 0, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\250\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 420, 424, 1532, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\250\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 420, 424, 1532, 0} (24, {24, 52, new_msg, 0, 0, 0, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\250\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 420, 424, 1532, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\0\0\0\0\250\1\0\0\0\0\0\0" ) ) == 0x0 01487 424 NtUserGetThreadDesktop (424, 0, ... ) == 0x2c 01488 424 NtUserGetObjectInformation (44, 2, 1240812, 520, 0, ... ) == 0x1 01489 424 NtGdiDeleteObjectApp (101712879, ... ) == 0x1 01490 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01491 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01492 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01493 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01494 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01495 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01496 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01497 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01498 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01499 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01500 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01501 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01502 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01503 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01504 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01505 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01506 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01507 424 NtGdiCreatePatternBrushInternal (59048369, 0, 0, ... ) == 0x71003ef 01508 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01509 424 NtUserSetProp (196786, 43288, 8801104, ... ) == 0x1 01479 424 NtUserCreateWindowEx ... ) == 0x300b2 01510 424 NtUserCallHwndLock (196786, 89, ... ) == 0x1 01511 424 NtUserGetAtomName (49175, 1242012, ... ) == 0x6 01512 424 NtUserCreateWindowEx (4, 49175, 49175, (4, 49175, 49175, "OK", 1342373889, 174, 119, 75, 23, 196786, 1, 2010382336, 0, 1073742848, 0, ... , 1342373889, 174, 119, 75, 23, 196786, 1, 2010382336, 0, 1073742848, 0, ... 01513 424 NtUserSetWindowFNID (65750, 673, ... ) == 0x1 01514 424 NtUserSetWindowLong (65750, 0, 1407580, 0, ... ) == 0x0 01515 424 NtUserMessageCall (0x100d6, WM_NCCREATE, 0x0, 0x12f348, 0, 670, 0, ... ) == 0x1 01516 424 NtUserMessageCall (0x100d6, WM_NCCALCSIZE, 0x0, 0x12f370, 0, 670, 0, ... ) == 0x0 01517 424 NtUserSetProp (65750, 43288, -1, ... ) == 0x1 01512 424 NtUserCreateWindowEx ... ) == 0x100d6 01518 424 NtUserGetAtomName (49177, 1242012, ... ) == 0x6 01519 424 NtUserCreateWindowEx (4, 49177, 49177, "1342308355, 11, 11, 0, 0, 196786, 20, 2010382336, 0, 1073742848, 0, ... 01520 424 NtUserSetWindowFNID (65752, 680, ... ) == 0x1 01521 424 NtUserSetWindowLong (65752, 0, 1403640, 0, ... ) == 0x0 01522 424 NtUserMessageCall (0x100d8, WM_NCCREATE, 0x0, 0x12f348, 0, 670, 0, ... ) == 0x1 01523 424 NtUserMessageCall (0x100d8, WM_NCCALCSIZE, 0x0, 0x12f370, 0, 670, 0, ... ) == 0x0 01524 424 NtUserSetProp (65752, 43288, -1, ... ) == 0x1 01525 424 NtUserFindExistingCursorIcon (1240800, 1240816, 1241384, ... ) == 0x0 01526 424 NtUserFindExistingCursorIcon (1240800, 1240816, 1241384, ... ) == 0x0 01527 424 NtUserFindExistingCursorIcon (1240800, 1240816, 1241384, ... ) == 0x10009 01528 424 NtUserGetIconSize (65545, 0, 1241404, 1241408, ... ) == 0x1 01529 424 NtUserGetCursorFrameInfo (65545, 0, 1241440, 1241416, ... ) == 0x10009 01530 424 NtUserSetWindowPos (65752, 0, 0, 0, 32, 32, 22, ... 01531 424 NtUserMessageCall (0x100d8, WM_WINDOWPOSCHANGING, 0x0, 0x12f0b8, 0, 670, 0, ... ) == 0x0 01532 424 NtUserMessageCall (0x100d8, WM_NCCALCSIZE, 0x1, 0x12f08c, 0, 670, 0, ... ) == 0x0 01530 424 NtUserSetWindowPos ... ) == 0x1 01519 424 NtUserCreateWindowEx ... ) == 0x100d8 01533 424 NtUserGetAtomName (49177, 1242012, ... ) == 0x6 01534 424 NtUserCreateWindowEx (4, 49177, 49177, "The installer you are trying to use is corrupted or incomplete. 01535 424 NtUserSetWindowFNID (65754, 680, ... ) == 0x1 01536 424 NtUserSetWindowLong (65754, 0, 1403616, 0, ... ) == 0x0 01537 424 NtUserMessageCall (0x100da, WM_NCCREATE, 0x0, 0x12f348, 0, 670, 0, ... 01538 424 NtAllocateVirtualMemory (-1, 5677056, 0, 4096, 4096, 32, ... 5677056, 4096, ) == 0x0 01537 424 NtUserMessageCall ... ) == 0x1 01539 424 NtUserMessageCall (0x100da, WM_NCCALCSIZE, 0x0, 0x12f370, 0, 670, 0, ... ) == 0x0 01540 424 NtUserSetProp (65754, 43288, -1, ... ) == 0x1 01534 424 NtUserCreateWindowEx ... ) == 0x100da 01541 424 NtUserSetWindowLong (196786, -21, 1244512, 0, ... ) == 0x0 01542 424 NtUserCallHwnd (196786, 72, ... ) == 0xbc649cb0 01543 424 NtAllocateVirtualMemory (-1, 0, 0, 131064, 8192, 4, ... 10027008, 131072, ) == 0x0 01544 424 NtAllocateVirtualMemory (-1, 10027008, 0, 4096, 4096, 4, ... 10027008, 4096, ) == 0x0 01545 424 NtUserSetFocus (65750, ... 01546 424 NtUserMessageCall (0x300b2, WM_NCACTIVATE, 0x1, 0xffffffff, 0, 670, 0, ... ) == 0x1 01547 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01548 424 NtUserGetWindowDC (196786, ... ) == 0x1010051 01549 424 NtGdiGetTextMetricsW (16842833, 1241072, 68, ... ) == 0x1 01550 424 NtGdiGetRandomRgn (16842833, 134480880, 1, ... ) == 0x0 01551 424 NtGdiIntersectClipRect (16842833, 0, 0, 0, 0, ... ) == 0x3 01552 424 NtGdiGetWidthTable (16842833, 10, 1334336, 266, 1334868, 1407664, 1407680, ... ) == 0x1 01553 424 NtGdiExtSelectClipRgn (16842833, 0, 5, ... ) == 0x1 01554 424 NtUserCallOneParam (16842833, 56, ... ) == 0x1 01555 424 NtUserCalcMenuBar (196786, 3, 3, 29, 8801288, ... ) == 0x0 01556 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 1241040, 690, 0, ... 01557 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01556 424 NtUserMessageCall ... ) == 0x0 01558 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 1241040, 690, 0, ... 01559 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01558 424 NtUserMessageCall ... ) == 0x0 01560 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 1241040, 690, 0, ... 01561 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01560 424 NtUserMessageCall ... ) == 0x0 01562 424 NtUserGetTitleBarInfo (196786, 1241668, ... ) == 0x1 01563 424 NtUserGetDCEx (196786, 0, 66561, ... ) == 0x1010053 01564 424 NtGdiExcludeClipRect (16842835, 3, 29, 428, 182, ... ) == 0x3 01565 424 NtGdiDrawStream (16842835, 96, 1241072, ... ) == 0x1 01566 424 NtGdiDrawStream (16842835, 96, 1241072, ... ) == 0x1 01567 424 NtGdiDrawStream (16842835, 96, 1241072, ... ) == 0x1 01568 424 NtGdiCreateCompatibleBitmap (16842835, 431, 29, ... ) == 0xc0503ea 01569 424 NtGdiCreateCompatibleDC (16842835, ... ) == 0x70103ec 01570 424 NtGdiSelectBitmap (117507052, 201655274, ... ) == 0x185000f 01571 424 NtGdiDrawStream (117507052, 96, 1240964, ... ) == 0x1 01572 424 NtGdiDrawStream (117507052, 96, 1240920, ... ) == 0x1 01573 424 NtGdiDrawStream (117507052, 96, 1240920, ... ) == 0x1 01574 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01575 424 NtGdiGetRandomRgn (117507052, 151258096, 1, ... ) == 0x0 01576 424 NtGdiIntersectClipRect (117507052, 8, 8, 403, 25, ... ) == 0x3 01577 424 NtGdiExtSelectClipRgn (117507052, 0, 5, ... ) == 0x2 01578 424 NtGdiGetRandomRgn (117507052, 168035312, 1, ... ) == 0x0 01579 424 NtGdiIntersectClipRect (117507052, 7, 7, 402, 25, ... ) == 0x3 01580 424 NtGdiExtSelectClipRgn (117507052, 0, 5, ... ) == 0x2 01581 424 NtGdiBitBlt (16842835, 0, 0, 431, 29, 117507052, 0, 0, 13369376, -1, 0, ... ) == 0x1 01582 424 NtGdiSelectBitmap (117507052, 25493519, ... ) == 0xc0503ea 01583 424 NtGdiDeleteObjectApp (117507052, ... ) == 0x1 01584 424 NtGdiDeleteObjectApp (201655274, ... ) == 0x1 01585 424 NtUserCallOneParam (16842835, 56, ... ) == 0x1 01545 424 NtUserSetFocus ... ) == 0x0 01586 424 NtUserSetWindowLong (65750, -12, 2, 0, ... ) == 0x1 01587 424 NtUserGetClassName (65750, 0, 1242556, ... ) == 0x6 01588 424 NtUserGetClassName (65752, 0, 1242556, ... ) == 0x6 01589 424 NtUserGetClassName (65754, 0, 1242556, ... ) == 0x6 01590 424 NtUserGetAncestor (196786, 1, ... ) == 0x10014 01591 424 NtUserSetWindowPos (196786, 0, 300, 306, 431, 185, 1047, ... ) == 0x1 01592 424 NtUserMessageCall (0x300b2, 0x128, 0x30001, 0x0, 0, 670, 0, ... 01593 424 NtUserMessageCall (0x100d6, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 01594 424 NtUserMessageCall (0x100d8, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 01595 424 NtUserMessageCall (0x100da, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 01592 424 NtUserMessageCall ... ) == 0x0 01596 424 NtUserShowWindow (196786, 1, ... 01597 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01598 424 NtUserGetWindowDC (196786, ... ) == 0x1010053 01599 424 NtGdiGetRandomRgn (16842835, 184812528, 1, ... ) == 0x0 01600 424 NtGdiIntersectClipRect (16842835, 0, 0, 0, 0, ... ) == 0x3 01601 424 NtGdiGetCharSet (16842835, ... ) == 0x4e4 01602 424 NtGdiExtSelectClipRgn (16842835, 0, 5, ... ) == 0x2 01603 424 NtUserCallOneParam (16842835, 56, ... ) == 0x1 01604 424 NtUserCalcMenuBar (196786, 3, 3, 29, 8801288, ... ) == 0x0 01605 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 1241656, 690, 0, ... 01606 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01605 424 NtUserMessageCall ... ) == 0x0 01607 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 1241656, 690, 0, ... 01608 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01607 424 NtUserMessageCall ... ) == 0x0 01609 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 1241656, 690, 0, ... 01610 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01609 424 NtUserMessageCall ... ) == 0x0 01611 424 NtUserGetTitleBarInfo (196786, 1242284, ... ) == 0x1 01612 424 NtUserGetDCEx (196786, 0, 66561, ... ) == 0x1010051 01613 424 NtGdiExcludeClipRect (16842833, 3, 29, 428, 182, ... ) == 0x3 01614 424 NtGdiDrawStream (16842833, 96, 1241688, ... ) == 0x1 01615 424 NtGdiDrawStream (16842833, 96, 1241688, ... ) == 0x1 01616 424 NtGdiDrawStream (16842833, 96, 1241688, ... ) == 0x1 01617 424 NtGdiCreateCompatibleBitmap (16842833, 431, 29, ... ) == 0x100503ea 01618 424 NtGdiCreateCompatibleDC (16842833, ... ) == 0x70103e7 01619 424 NtGdiSelectBitmap (117507047, 268764138, ... ) == 0x185000f 01620 424 NtGdiDrawStream (117507047, 96, 1241580, ... ) == 0x1 01621 424 NtGdiDrawStream (117507047, 96, 1241536, ... ) == 0x1 01622 424 NtGdiDrawStream (117507047, 96, 1241536, ... ) == 0x1 01623 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01624 424 NtGdiGetRandomRgn (117507047, 201589744, 1, ... ) == 0x0 01625 424 NtGdiIntersectClipRect (117507047, 8, 8, 403, 25, ... ) == 0x3 01626 424 NtGdiExtSelectClipRgn (117507047, 0, 5, ... ) == 0x2 01627 424 NtGdiGetRandomRgn (117507047, 218366960, 1, ... ) == 0x0 01628 424 NtGdiIntersectClipRect (117507047, 7, 7, 402, 25, ... ) == 0x3 01629 424 NtGdiExtSelectClipRgn (117507047, 0, 5, ... ) == 0x2 01630 424 NtGdiBitBlt (16842833, 0, 0, 431, 29, 117507047, 0, 0, 13369376, -1, 0, ... ) == 0x1 01631 424 NtGdiSelectBitmap (117507047, 25493519, ... ) == 0x100503ea 01632 424 NtGdiDeleteObjectApp (117507047, ... ) == 0x1 01633 424 NtGdiDeleteObjectApp (268764138, ... ) == 0x1 01634 424 NtUserCallOneParam (16842833, 56, ... ) == 0x1 01635 424 NtUserFillWindow (196786, 196786, 16842834, 4, ... 01636 424 NtUserGetAncestor (196786, 1, ... ) == 0x10014 01637 424 NtUserGetAncestor (65556, 1, ... ) == 0x0 01635 424 NtUserFillWindow ... ) == 0x1 01638 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01639 424 NtUserGetWindowDC (196786, ... ) == 0x1010053 01640 424 NtGdiGetRandomRgn (16842835, 235144176, 1, ... ) == 0x0 01641 424 NtGdiIntersectClipRect (16842835, 0, 0, 0, 0, ... ) == 0x3 01642 424 NtGdiGetCharSet (16842835, ... ) == 0x4e4 01643 424 NtGdiExtSelectClipRgn (16842835, 0, 5, ... ) == 0x2 01644 424 NtUserCallOneParam (16842835, 56, ... ) == 0x1 01645 424 NtUserCalcMenuBar (196786, 3, 3, 29, 8801288, ... ) == 0x0 01646 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 1241940, 690, 0, ... 01647 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01646 424 NtUserMessageCall ... ) == 0x0 01648 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 1241940, 690, 0, ... 01649 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01648 424 NtUserMessageCall ... ) == 0x0 01650 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 1241940, 690, 0, ... 01651 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01650 424 NtUserMessageCall ... ) == 0x0 01652 424 NtUserGetTitleBarInfo (196786, 1242568, ... ) == 0x1 01653 424 NtUserBuildHwndList (0, 196786, 1, 0, 64, ... (0x100d6, 0x100d8, 0x100da, 0x1, ), 4, ) == 0x0 01654 424 NtUserGetWindowDC (0, ... ) == 0x1010054 01655 424 NtUserCallOneParam (16842836, 56, ... ) == 0x1 01656 424 NtGdiExtCreateRegion (0, 112, 8799840, ... ) == 0x120403ea 01657 424 NtGdiOffsetRgn (302253034, 0, 0, ... ) == 0x3 01658 424 NtGdiCombineRgn (251921392, 302253034, 251921392, 5, ... ) == 0x3 01659 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x80403e7 01660 424 NtGdiCombineRgn (251921392, 134480871, 251921392, 2, ... ) == 0x3 01661 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x30403ed 01662 424 NtGdiCombineRgn (251921392, 50594797, 251921392, 2, ... ) == 0x3 01663 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x604040d 01664 424 NtGdiCombineRgn (251921392, 100926477, 251921392, 2, ... ) == 0x3 01665 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0xa040407 01666 424 NtGdiCombineRgn (251921392, 168035335, 251921392, 2, ... ) == 0x3 01667 424 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x704040f 01668 424 NtGdiCombineRgn (117703695, 251921392, 0, 5, ... ) == 0x3 01669 424 NtUserSetWindowRgn (196786, 251921392, 1, ... 01670 424 NtUserMessageCall (0x300b2, WM_NCCALCSIZE, 0x1, 0x12f50c, 0, 670, 0, ... ) == 0x0 01671 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01672 424 NtUserGetWindowDC (196786, ... ) == 0x1010053 01673 424 NtGdiGetRandomRgn (16842835, 184812551, 1, ... ) == 0x0 01674 424 NtGdiIntersectClipRect (16842835, 0, 0, 0, 0, ... ) == 0x3 01675 424 NtGdiGetCharSet (16842835, ... ) == 0x4e4 01676 424 NtGdiExtSelectClipRgn (16842835, 0, 5, ... ) == 0x3 01677 424 NtUserCallOneParam (16842835, 56, ... ) == 0x1 01678 424 NtUserCalcMenuBar (196786, 3, 3, 29, 8801288, ... ) == 0x0 01679 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 1240740, 690, 0, ... 01680 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01679 424 NtUserMessageCall ... ) == 0x0 01681 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 1240740, 690, 0, ... 01682 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01681 424 NtUserMessageCall ... ) == 0x0 01683 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 1240740, 690, 0, ... 01684 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01683 424 NtUserMessageCall ... ) == 0x0 01685 424 NtUserGetTitleBarInfo (196786, 1241368, ... ) == 0x1 01686 424 NtUserGetDCEx (196786, 0, 66561, ... ) == 0x1010052 01687 424 NtGdiExcludeClipRect (16842834, 3, 29, 428, 182, ... ) == 0x3 01688 424 NtGdiDrawStream (16842834, 96, 1240772, ... ) == 0x1 01689 424 NtGdiDrawStream (16842834, 96, 1240772, ... ) == 0x1 01690 424 NtGdiDrawStream (16842834, 96, 1240772, ... ) == 0x1 01691 424 NtGdiCreateCompatibleBitmap (16842834, 431, 29, ... ) == 0x60503e4 01692 424 NtGdiCreateCompatibleDC (16842834, ... ) == 0x80103bb 01693 424 NtGdiSelectBitmap (134284219, 100991972, ... ) == 0x185000f 01694 424 NtGdiDrawStream (134284219, 96, 1240664, ... ) == 0x1 01695 424 NtGdiDrawStream (134284219, 96, 1240620, ... ) == 0x1 01696 424 NtGdiDrawStream (134284219, 96, 1240620, ... ) == 0x1 01697 424 NtUserInternalGetWindowText (0x300b2, 260, ... (0x300b2, 260, ... "NSIS Error", ) , ) == 0xa 01698 424 NtGdiGetRandomRgn (134284219, 201589767, 1, ... ) == 0x0 01699 424 NtGdiIntersectClipRect (134284219, 8, 8, 403, 25, ... ) == 0x3 01700 424 NtGdiExtSelectClipRgn (134284219, 0, 5, ... ) == 0x2 01701 424 NtGdiGetRandomRgn (134284219, 218366983, 1, ... ) == 0x0 01702 424 NtGdiIntersectClipRect (134284219, 7, 7, 402, 25, ... ) == 0x3 01703 424 NtGdiExtSelectClipRgn (134284219, 0, 5, ... ) == 0x2 01704 424 NtGdiBitBlt (16842834, 0, 0, 431, 29, 134284219, 0, 0, 13369376, -1, 0, ... ) == 0x1 01705 424 NtGdiSelectBitmap (134284219, 25493519, ... ) == 0x60503e4 01706 424 NtGdiDeleteObjectApp (134284219, ... ) == 0x1 01707 424 NtGdiDeleteObjectApp (100991972, ... ) == 0x1 01708 424 NtUserCallOneParam (16842834, 56, ... ) == 0x1 01709 424 NtUserFillWindow (196786, 196786, 16842833, 4, ... 01710 424 NtUserGetAncestor (196786, 1, ... ) == 0x10014 01711 424 NtUserGetAncestor (65556, 1, ... ) == 0x0 01709 424 NtUserFillWindow ... ) == 0x1 01669 424 NtUserSetWindowRgn ... ) == 0x1 01596 424 NtUserShowWindow ... ) == 0x0 01712 424 NtUserCallHwndLock (196786, 93, ... 01713 424 NtUserMessageCall (0x300b2, WM_PAINT, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01714 424 NtUserBeginPaint (0x100d6, 1242940, ... 01715 424 NtUserMessageCall (0x100d6, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01714 424 NtUserBeginPaint ... ) == 0x1010051 01716 424 NtUserGetControlBrush (0x100d6, 16842833, 309, ... ) == 0x1100056 01717 424 NtGdiIntersectClipRect (16842833, 0, 0, 75, 23, ... ) == 0x3 01718 424 NtGdiIntersectClipRect (16842833, 3, 3, 72, 20, ... ) == 0x3 01719 424 NtUserEndPaint (0x100d6, 1242940, ... ) == 0x1 01720 424 NtUserBeginPaint (0x100d8, 1242952, ... 01721 424 NtUserMessageCall (0x100d8, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01720 424 NtUserBeginPaint ... ) == 0x1010051 01722 424 NtGdiIntersectClipRect (16842833, 0, 0, 32, 32, ... ) == 0x3 01723 424 NtUserGetControlBrush (0x100d8, 16842833, 312, ... ) == 0x1100056 01724 424 NtGdiGetDCDword (16842833, 7, 1242672, ... ) == 0x1 01725 424 NtUserDrawIconEx (16842833, 0, 0, 65545, 32, 32, 0, 17825878, 3, 0, 1242716, ... ) == 0x1 01726 424 NtUserEndPaint (0x100d8, 1242952, ... ) == 0x1 01727 424 NtUserBeginPaint (0x100da, 1242952, ... 01728 424 NtUserMessageCall (0x100da, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01727 424 NtUserBeginPaint ... ) == 0x1010051 01729 424 NtGdiIntersectClipRect (16842833, 0, 0, 357, 93, ... ) == 0x3 01730 424 NtUserGetControlBrush (0x100da, 16842833, 312, ... ) == 0x1100056 01731 424 NtGdiGetTextCharsetInfo (16842833, 0, 0, ... ) == 0x0 01732 424 NtUserEndPaint (0x100da, 1242952, ... ) == 0x1 01712 424 NtUserCallHwndLock ... ) == 0x1 01733 424 NtUserPeekMessage (0, 0, 0, 1, ... 01734 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\VMware\VMware Tools\hook.dll"}, 1240804, ... ) }, 1240804, ... ) == 0x0 01735 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\VMware\VMware Tools\hook.dll"}, 5, 96, ... 176, {status=0x0, info=1}, ) }, 5, 96, ... 176, {status=0x0, info=1}, ) == 0x0 01736 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 176, ... 172, ) == 0x0 01737 424 NtClose (176, ... ) == 0x0 01738 424 NtMapViewOfSection (172, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x9b0000), 0x0, 45056, ) == 0x0 01739 424 NtClose (172, ... ) == 0x0 01740 424 NtUnmapViewOfSection (-1, 0x9b0000, ... ) == 0x0 01741 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\VMware\VMware Tools\hook.dll"}, 1241120, ... ) }, 1241120, ... ) == 0x0 01742 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Program Files\VMware\VMware Tools\hook.dll"}, 1241120, ... ) }, 1241120, ... ) == 0x0 01743 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\Program Files\VMware\VMware Tools\hook.dll"}, 5, 96, ... 172, {status=0x0, info=1}, ) }, 5, 96, ... 172, {status=0x0, info=1}, ) == 0x0 01744 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 172, ... 176, ) == 0x0 01745 424 NtQuerySection (176, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01746 424 NtClose (172, ... ) == 0x0 01747 424 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x9b0000), 0x0, 49152, ) == STATUS_IMAGE_NOT_AT_BASE 01748 424 NtProtectVirtualMemory (-1, (0x9b1000), 20480, 4, ... (0x9b1000), 20480, 32, ) == 0x0 01749 424 NtProtectVirtualMemory (-1, (0x9b6000), 8192, 4, ... (0x9b6000), 8192, 2, ) == 0x0 01750 424 NtProtectVirtualMemory (-1, (0x9bb000), 4096, 4, ... (0x9bb000), 4096, 2, ) == 0x0 01751 424 NtMapViewOfSection (176, -1, (0x9b0000), 0, 0, 0x0, 49152, 1, 0, 4, ... ) == STATUS_CONFLICTING_ADDRESSES 01752 424 NtProtectVirtualMemory (-1, (0x9b1000), 20480, 16, ... (0x9b1000), 20480, 4, ) == 0x0 01753 424 NtProtectVirtualMemory (-1, (0x9b6000), 8192, 2, ... (0x9b6000), 8192, 4, ) == 0x0 01754 424 NtProtectVirtualMemory (-1, (0x9bb000), 4096, 2, ... (0x9bb000), 4096, 8, ) == 0x0 01755 424 NtFlushInstructionCache (-1, 0, 0, ... ) == 0x0 01756 424 NtClose (176, ... ) == 0x0 01757 424 NtProtectVirtualMemory (-1, (0x9b6000), 256, 4, ... (0x9b6000), 4096, 2, ) == 0x0 01758 424 NtProtectVirtualMemory (-1, (0x9b6000), 4096, 2, ... (0x9b6000), 4096, 4, ) == 0x0 01759 424 NtFlushInstructionCache (-1, 10182656, 256, ... ) == 0x0 01760 424 NtProtectVirtualMemory (-1, (0x9b6000), 256, 4, ... (0x9b6000), 4096, 2, ) == 0x0 01761 424 NtProtectVirtualMemory (-1, (0x9b6000), 4096, 2, ... (0x9b6000), 4096, 4, ) == 0x0 01762 424 NtFlushInstructionCache (-1, 10182656, 256, ... ) == 0x0 01763 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01764 424 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 10223616, 65536, ) == 0x0 01765 424 NtAllocateVirtualMemory (-1, 10223616, 0, 4096, 4096, 4, ... 10223616, 4096, ) == 0x0 01766 424 NtAllocateVirtualMemory (-1, 10227712, 0, 8192, 4096, 4, ... 10227712, 8192, ) == 0x0 01767 424 NtQueryPerformanceCounter (... {106682781, 0}, {3579545, 0}, ) == 0x0 01768 424 NtUserMessageCall (0x300b2, WM_SETCURSOR, 0x300b2, 0x2000001, 0, 670, 0, ... ) == 0x0 01733 424 NtUserPeekMessage ... {0x300b2, WM_MOUSEFIRST, 0x0, 0x3100d1, 0x6c66, {512, 384}}, ) == 0x1 01769 424 NtUserCallMsgFilter (1243308, 0, ... ) == 0x0 01770 424 NtUserPeekMessage (0, 0, 0, 1, ... {0x300b2, WM_MOUSEFIRST, 0x0, 0x3100d1, 0x6c66, {512, 384}}, ) == 0x0 01771 424 NtUserWaitMessage (... ) == 0x1 01772 424 NtUserPeekMessage (0, 0, 0, 1, ... 01773 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01772 424 NtUserPeekMessage ... {0x300b2, WM_MOUSEFIRST, 0x0, 0x3100d1, 0x6c66, {512, 384}}, ) == 0x0 01774 424 NtUserWaitMessage (... ) == 0x1 01775 424 NtUserPeekMessage (0, 0, 0, 1, ... 01776 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01775 424 NtUserPeekMessage ... {0x300b2, WM_MOUSEFIRST, 0x0, 0x3100d1, 0x6c66, {512, 384}}, ) == 0x0 01777 424 NtUserWaitMessage (... ) == 0x1 01778 424 NtUserPeekMessage (0, 0, 0, 1, ... 01779 424 NtUserMessageCall (0x300b2, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01778 424 NtUserPeekMessage ... {0x300b2, WM_MOUSEFIRST, 0x0, 0x3100d1, 0x6c66, {512, 384}}, ) == 0x0 01780 424 NtUserWaitMessage (...