Summary:
NtAddAtom(>) | 1 | NtOpenMutant(>) | 2 | NtUserCallNoParam(>) | 7 | NtUnmapViewOfSection(>) | 36 |
NtCallbackReturn(>) | 1 | NtQueryInformationJobObject(>) | 2 | NtOpenSymbolicLinkObject(>) | 8 | NtOpenSection(>) | 37 |
NtConnectPort(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtQuerySymbolicLinkObject(>) | 8 | NtWaitForSingleObject(>) | 39 |
NtDuplicateToken(>) | 1 | NtQueryPerformanceCounter(>) | 2 | NtWriteFile(>) | 8 | NtProtectVirtualMemory(>) | 40 |
NtGdiCreateBitmap(>) | 1 | NtQueryVirtualMemory(>) | 2 | NtWriteVirtualMemory(>) | 8 | NtSetValueKey(>) | 40 |
NtGdiCreatePatternBrushInternal(>) | 1 | NtResumeThread(>) | 2 | NtFsControlFile(>) | 10 | NtCreateEvent(>) | 41 |
NtGdiInit(>) | 1 | NtUserGetDC(>) | 2 | NtOpenProcessToken(>) | 10 | NtEnumerateKey(>) | 42 |
NtGdiQueryFontAssocInfo(>) | 1 | NtUserGetForegroundWindow(>) | 2 | NtUserGetWindowDC(>) | 10 | NtUserFindExistingCursorIcon(>) | 52 |
NtGdiSelectBitmap(>) | 1 | NtUserGetProcessWindowStation(>) | 2 | NtQueryVolumeInformationFile(>) | 11 | NtSetInformationFile(>) | 54 |
NtOpenKeyedEvent(>) | 1 | NtUserUnregisterClass(>) | 2 | NtReleaseMutant(>) | 11 | NtDeviceIoControlFile(>) | 55 |
NtQueryObject(>) | 1 | NtCreateMutant(>) | 3 | NtUserSystemParametersInfo(>) | 11 | NtUserGetClassInfo(>) | 55 |
NtQuerySystemTime(>) | 1 | NtDuplicateObject(>) | 3 | NtUserCallOneParam(>) | 12 | NtCreateKey(>) | 56 |
NtRegisterThreadTerminatePort(>) | 1 | NtOpenProcess(>) | 3 | NtQuerySection(>) | 13 | NtMapViewOfSection(>) | 56 |
NtSecureConnectPort(>) | 1 | NtUserGetAtomName(>) | 3 | NtRequestWaitReplyPort(>) | 13 | NtQueryInformationProcess(>) | 61 |
NtTestAlert(>) | 1 | NtUserGetObjectInformation(>) | 3 | NtQueryDefaultUILanguage(>) | 14 | NtUserRegisterClassExWOW(>) | 68 |
NtUserGetGUIThreadInfo(>) | 1 | NtUserSetProp(>) | 3 | NtSetInformationThread(>) | 14 | NtAllocateVirtualMemory(>) | 74 |
NtUserGetThreadDesktop(>) | 1 | NtOpenEvent(>) | 4 | NtFreeVirtualMemory(>) | 15 | NtQueryAttributesFile(>) | 84 |
NtAccessCheck(>) | 2 | NtReadVirtualMemory(>) | 4 | NtFlushInstructionCache(>) | 19 | NtQuerySystemInformation(>) | 90 |
NtAdjustPrivilegesToken(>) | 2 | NtUserDestroyWindow(>) | 4 | NtQueryDefaultLocale(>) | 23 | NtOpenFile(>) | 101 |
NtCreateIoCompletion(>) | 2 | NtContinue(>) | 5 | NtNotifyChangeKey(>) | 28 | NtQueryValueKey(>) | 259 |
NtCreateProcessEx(>) | 2 | NtEnumerateValueKey(>) | 5 | NtSetInformationProcess(>) | 28 | NtOpenProcessTokenEx(>) | 282 |
NtCreateSemaphore(>) | 2 | NtGdiCreateCompatibleDC(>) | 5 | NtOpenThreadToken(>) | 30 | NtOpenThreadTokenEx(>) | 282 |
NtCreateThread(>) | 2 | NtGdiGetStockObject(>) | 5 | NtReadFile(>) | 30 | NtQueryInformationToken(>) | 292 |
NtGdiCreateHalftonePalette(>) | 2 | NtSetInformationObject(>) | 5 | NtQueryDebugFilterState(>) | 31 | NtQueryKey(>) | 344 |
NtGdiCreatePaletteInternal(>) | 2 | NtUserRegisterWindowMessage(>) | 5 | NtCreateSection(>) | 32 | NtClose(>) | 878 |
NtGdiCreateSolidBrush(>) | 2 | NtGdiDeleteObjectApp(>) | 6 | NtQueryDirectoryFile(>) | 32 | NtOpenKey(>) | 903 |
NtGdiDoPalette(>) | 2 | NtUserCreateWindowEx(>) | 6 | NtReleaseSemaphore(>) | 32 | ||
NtGdiHfontCreate(>) | 2 | NtUserMessageCall(>) | 6 | NtCreateFile(>) | 33 | ||
NtOpenDirectoryObject(>) | 2 |
9\351\306/\336\200>TY\352%\216\253\335\231\275GS@\253\322!\243\21351\265\25 \340\256L\250\216\316\324\27\276m~J\263;\17\31S64){b\356+_\225omk\310\10\270C{\360x\21e\246Jw\15\17\360\346\355\250\332\376\15\22\30\301vt\2249\232\273\253T\234\3617K\226\214\322\310\373\25\352\257\27\241czW\31\273\367\370M\30\315\33\306\237\255L+\17\241", ) , ) == 0x0 01737 408 NtAllocateVirtualMemory (-1, 1368064, 0, 16384, 4096, 4, ... 1368064, 16384, ) == 0x0 01738 408 NtUserRegisterClassExWOW (1239332, 1239412, 1239396, 1239428, 0, 384, 0, ... ) == 0x810dc038 01739 408 NtUserGetAtomName (49208, 1238096, ... ) == 0x15 01740 408 NtUserCreateWindowEx (0, 49208, 49208, (0, 49208, 49208, "OleMainThreadWndName", -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... , -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... 01741 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1235620, ... ) }, 1235620, ... ) == 0x0 01742 408 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 52, {status=0x0, info=1}, ) }, 5, 96, ... 52, {status=0x0, info=1}, ) == 0x0 01743 408 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 52, ... 76, ) == 0x0 01744 408 NtClose (52, ... ) == 0x0 01745 408 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x390000), 0x0, 204800, ) == 0x0 01746 408 NtClose (76, ... ) == 0x0 01747 408 NtUnmapViewOfSection (-1, 0x390000, ... ) == 0x0 01748 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1235936, ... ) }, 1235936, ... ) == 0x0 01749 408 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 76, {status=0x0, info=1}, ) }, 5, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01750 408 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 76, ... 52, ) == 0x0 01751 408 NtQuerySection (52, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01752 408 NtClose (76, ... ) == 0x0 01753 408 NtMapViewOfSection (52, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 212992, ) == 0x0 01754 408 NtClose (52, ... ) == 0x0 01755 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01756 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01757 408 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01758 408 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 52, ) == 0x0 01759 408 NtQueryInformationToken (52, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01760 408 NtClose (52, ... ) == 0x0 01761 408 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 52, ) }, ... 52, ) == 0x0 01762 408 NtOpenKey (0x1, {24, 52, 0x40, 0, 0, (0x1, {24, 52, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 76, ) }, ... 76, ) == 0x0 01763 408 NtQueryValueKey (76, (76, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01764 408 NtClose (76, ... ) == 0x0 01765 408 NtClose (52, ... ) == 0x0 01766 408 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01767 408 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 52, ) == 0x0 01768 408 NtQueryInformationToken (52, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01769 408 NtClose (52, ... ) == 0x0 01770 408 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 52, ) }, ... 52, ) == 0x0 01771 408 NtOpenKey (0x1, {24, 52, 0x40, 0, 0, (0x1, {24, 52, 0x40, 0, 0, "Control Panel\Desktop"}, ... 76, ) }, ... 76, ) == 0x0 01772 408 NtQueryValueKey (76, (76, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01773 408 NtClose (76, ... ) == 0x0 01774 408 NtClose (52, ... ) == 0x0 01775 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\UxTheme.dll"}, 1235436, ... ) }, 1235436, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01776 408 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "UxTheme.dll"}, 1235436, ... ) }, 1235436, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01777 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\UxTheme.dll"}, 1235436, ... ) }, 1235436, ... ) == 0x0 01778 408 NtUserGetProcessWindowStation (... ) == 0x24 01779 408 NtUserGetObjectInformation (36, 2, 0, 0, 1237732, ... ) == 0x0 01780 408 NtUserGetObjectInformation (36, 2, 1360544, 16, 1237732, ... ) == 0x1 01781 408 NtUserGetGUIThreadInfo (408, 1237688, ... ) == 0x1 01782 408 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1237508, 64, ... 52, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1237508, 64, ... 52, 0x0, 0x0, 0x0, 64, ) == 0x0 01783 408 NtRequestWaitReplyPort (52, {32, 56, new_msg, 0, 0, 0, 0, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1499, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 404, 408, 1499, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1499, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01784 408 NtRequestWaitReplyPort (52, {32, 56, new_msg, 0, 0, 0, 0, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1500, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 404, 408, 1500, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1500, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01785 408 NtUserCallNoParam (29, ... 01786 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1234980, ... ) }, 1234980, ... ) == 0x0 01785 408 NtUserCallNoParam ... ) == 0x0 01787 408 NtUserSystemParametersInfo (41, 0, 1524225160, 0, ... ) == 0x1 01788 408 NtGdiHfontCreate (1237060, 356, 0, 0, 1329232, ... ) == 0x170a040b 01789 408 NtGdiHfontCreate (1237060, 356, 0, 0, 1329224, ... ) == 0x80a03d2 01790 408 NtRequestWaitReplyPort (52, {32, 56, new_msg, 0, 0, 0, 0, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1501, 0} "\0\0\0\0\0\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 404, 408, 1501, 0} (52, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 404, 408, 1501, 0} "\0\0\0\0\0\0\0\0L\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01791 408 NtMapViewOfSection (76, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x390000), {0, 0}, 331776, ) == 0x0 01792 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01793 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01794 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01795 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01796 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01797 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01798 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01799 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01800 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01801 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01802 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01803 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01804 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01805 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01806 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01807 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01808 408 NtAllocateVirtualMemory (-1, 3293184, 0, 4096, 4096, 4, ... 3293184, 4096, ) == 0x0 01809 408 NtUserGetWindowDC (0, ... ) == 0x1010050 01810 408 NtGdiCreatePatternBrushInternal (59048369, 0, 0, ... ) == 0x2b10040d 01811 408 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01812 408 NtUserCallNoParam (29, ... 01813 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1234424, ... ) }, 1234424, ... ) == 0x0 01812 408 NtUserCallNoParam ... ) == 0x0 01814 408 NtUserCallNoParam (29, ... 01815 408 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1234420, ... ) }, 1234420, ... ) == 0x0 01814 408 NtUserCallNoParam ... ) == 0x0 01816 408 NtUserMessageCall (0x200b0, WM_NCCREATE, 0x0, 0x12e3fc, 0, 670, 0, ... ) == 0x1 01817 408 NtUserMessageCall (0x200b0, WM_NCCALCSIZE, 0x0, 0x12e424, 0, 670, 0, ... ) == 0x0 01818 408 NtUserSetProp (131248, 43288, -1, ... ) == 0x1 01740 408 NtUserCreateWindowEx ... ) == 0x200b0 01819 408 NtDeviceIoControlFile (68, 0, 0x0, 0x0, 0x390008, (68, 0, 0x0, 0x0, 0x390008, "\374yu\17\15\0\12|\306#\357V*\324\25^.\256\361\313\276hE\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01820 408 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01821 408 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01822 408 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01823 408 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01824 408 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01825 408 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01826 408 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01827 408 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482208, 2, ) }, 0, 0x0, 0, ... -2147482208, 2, ) == 0x0 01828 408 NtSetValueKey (-2147482208, (-2147482208, "Seed", 0, 3, "dKQ\247\303\274\274\11\5\220G\321\345u\243\225\215\25\370\250\16-\351\7\247\247\357w^\352\3\305?x;\230\314\310O^\227\325\226\243\321KA\245]\177\266\327G\361\300\267\254\325\362\331\325\26HYF\24\255\272{k-q\330R\363$\204\333", 80, ... ) , 0, 3, (-2147482208, "Seed", 0, 3, "dKQ\247\303\274\274\11\5\220G\321\345u\243\225\215\25\370\250\16-\351\7\247\247\357w^\352\3\305?x;\230\314\310O^\227\325\226\243\321KA\245]\177\266\327G\361\300\267\254\325\362\331\325\26HYF\24\255\272{k-q\330R\363$\204\333", 80, ... ) , 80, ... ) == 0x0 01829 408 NtClose (-2147482208, ... ) == 0x0 01819 408 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\326_\263i2P9V\313h\350\223\244\204\260e.\227\35|l\261\236C\207\324l\4u\177\274\261\202\312\232\3320u\231S\31\314\267\36@N\266\177\203X@\346\366'\321\343H\330\2=\17\221t\271\255\207\277\17\23\21\353\213\247\236K\341o\3*\214\227+\306\370\304|x\272\0\236\277\214\10\37I\240\138\221x\214\343\307\246,\210\206\31\320\227\332}\231\311\324\226\337\303\346\355\205\366\335FX\25\13s\224\254N\267\270\323M\340\236\4\363)\225\203\12\267\216\237\300\354\23{n$\2551\207C\230\214A\267r\2\225t^Qn\266g{\375+\344\250i.\5\244bi\305G\311 \264S#G\345\223(B\200E\352\205\350\226\322\203\31\337\303\32\242\371\21\224\314\364\300A\203\330b\242\240\357L\330p\3114\23\327\15\20\215@5\263\266M\344\357$\35_]\253\345\35\247", ) \203\31\337\303\32\242\371\21\224\314\364\300A\203\330b\242\240\357L\330p\3114\23\327\15\20\215@5\263\266M\344\357$\35_]\253\345\35\247", ) == 0x0 01830 408 NtDeviceIoControlFile (68, 0, 0x0, 0x0, 0x390008, (68, 0, 0x0, 0x0, 0x390008, "\374yu\17\15\0\12|\306#\357V*\324\331\253\270\333\273\336\332\225\30.\256\361\313\276hE\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01831 408 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01832 408 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01833 408 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01834 408 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01835 408 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01836 408 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01837 408 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01838 408 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482208, 2, ) }, 0, 0x0, 0, ... -2147482208, 2, ) == 0x0 01839 408 NtSetValueKey (-2147482208, (-2147482208, "Seed", 0, 3, "\357\336\313\342\334[b{t?\10\35\26 \351\242A\340\6??1\312\266\347\7\15\354\315\272\374\244\244\201\217\276jS\03\276\374\210\21\3437sj\215$\352\344\213\311X\3\256]J*I\267\236\321\247z\26E\310I&\263\216\1\271\32Cu\316", 80, ... ) , 0, 3, (-2147482208, "Seed", 0, 3, "\357\336\313\342\334[b{t?\10\35\26 \351\242A\340\6??1\312\266\347\7\15\354\315\272\374\244\244\201\217\276jS\03\276\374\210\21\3437sj\215$\352\344\213\311X\3\256]J*I\267\236\321\247z\26E\310I&\263\216\1\271\32Cu\316", 80, ... ) , 80, ... ) == 0x0 01840 408 NtClose (-2147482208, ... ) == 0x0 01830 408 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\26C\217Y\12\251\#\270\5'\245\327\346\224\276'\265\221\17{B\360\26\371\3735\201\342B\273\371\202\356/\275\275\240\206