# Flog Txt Version 1 # Analyzer Version: 3.2.1 # Analyzer Build Date: Feb 18 2020 07:49:07 # Log Creation Date: 24.02.2020 15:56:34.912 Process: id = "1" image_name = "cscript.exe" filename = "c:\\windows\\system32\\cscript.exe" page_root = "0x4e177000" os_pid = "0x998" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "analysis_target" parent_id = "0" os_parent_pid = "0x454" cmd_line = "\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf\" " cur_dir = "C:\\Windows\\system32\\" os_username = "XDUWTFONO\\5p5NrGJn0jS HALPmcxz" bitness = "32" os_groups = "XDUWTFONO\\Domain Users" [0x7], "Everyone" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000eb41" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Thread: id = 1 os_tid = 0x9a8 [0035.317] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x26fa30 | out: lpSystemTimeAsFileTime=0x26fa30*(dwLowDateTime=0xf323780, dwHighDateTime=0x1d5eb2b)) [0035.317] GetCurrentProcessId () returned 0x998 [0035.317] GetCurrentThreadId () returned 0x9a8 [0035.317] GetTickCount () returned 0x11444ed [0035.317] QueryPerformanceCounter (in: lpPerformanceCount=0x26fa38 | out: lpPerformanceCount=0x26fa38*=15582938804) returned 1 [0035.320] GetModuleHandleA (lpModuleName=0x0) returned 0xff6e0000 [0035.321] GetVersionExA (in: lpVersionInformation=0x26f920*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0x0, dwBuildNumber=0x0, dwPlatformId=0x0, szCSDVersion="") | out: lpVersionInformation=0x26f920*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0035.321] GetUserDefaultLCID () returned 0x409 [0035.323] LoadLibraryW (lpLibFileName="kernel32.dll") returned 0x77940000 [0035.323] GetProcAddress (hModule=0x77940000, lpProcName="SetThreadUILanguage") returned 0x77956d40 [0035.323] SetThreadUILanguage (LangId=0x0) returned 0x7fffffd0409 [0035.323] FreeLibrary (hLibModule=0x77940000) returned 1 [0035.324] GetCommandLineW () returned="\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf\" " [0035.324] lstrlenW (lpString="\"C:\\Windows\\System32\\CScript.exe\" \"C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf\" ") returned 81 [0035.324] GetCurrentThreadId () returned 0x9a8 [0035.324] CoInitialize (pvReserved=0x0) returned 0x0 [0035.915] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26f5e8 | out: phkResult=0x26f5e8*=0x88) returned 0x0 [0035.915] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26f5e0 | out: phkResult=0x26f5e0*=0x8c) returned 0x0 [0035.915] RegQueryValueExW (in: hKey=0x8c, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x26e8e8, lpData=0x26ecf0, lpcbData=0x26e8e0*=0x400 | out: lpType=0x26e8e8*=0x0, lpData=0x26ecf0*=0x1, lpcbData=0x26e8e0*=0x400) returned 0x2 [0035.915] RegQueryValueExW (in: hKey=0x88, lpValueName="Enabled", lpReserved=0x0, lpType=0x26e8e8, lpData=0x26ecf0, lpcbData=0x26e8e0*=0x400 | out: lpType=0x26e8e8*=0x0, lpData=0x26ecf0*=0x1, lpcbData=0x26e8e0*=0x400) returned 0x2 [0035.915] RegQueryValueExW (in: hKey=0x8c, lpValueName="Enabled", lpReserved=0x0, lpType=0x26e8e8, lpData=0x26ecf0, lpcbData=0x26e8e0*=0x400 | out: lpType=0x26e8e8*=0x0, lpData=0x26ecf0*=0x1, lpcbData=0x26e8e0*=0x400) returned 0x2 [0035.915] CoInitializeSecurity (pSecDesc=0x0, cAuthSvc=-1, asAuthSvc=0x0, pReserved1=0x0, dwAuthnLevel=0x0, dwImpLevel=0x3, pAuthList=0x0, dwCapabilities=0x0, pReserved3=0x0) returned 0x0 [0036.405] RegCloseKey (hKey=0x8c) returned 0x0 [0036.405] RegCloseKey (hKey=0x88) returned 0x0 [0036.405] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26f300 | out: phkResult=0x26f300*=0x88) returned 0x0 [0036.405] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26f2f8 | out: phkResult=0x26f2f8*=0x8c) returned 0x0 [0036.405] RegQueryValueExW (in: hKey=0x8c, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x26e608, lpData=0x26ea10, lpcbData=0x26e600*=0x400 | out: lpType=0x26e608*=0x0, lpData=0x26ea10*=0x0, lpcbData=0x26e600*=0x400) returned 0x2 [0036.405] RegQueryValueExW (in: hKey=0x88, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x26e608, lpData=0x26ea10, lpcbData=0x26e600*=0x400 | out: lpType=0x26e608*=0x0, lpData=0x26ea10*=0x0, lpcbData=0x26e600*=0x400) returned 0x2 [0036.405] RegQueryValueExW (in: hKey=0x8c, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x26e608, lpData=0x26ea10, lpcbData=0x26e600*=0x400 | out: lpType=0x26e608*=0x0, lpData=0x26ea10*=0x0, lpcbData=0x26e600*=0x400) returned 0x2 [0036.405] RegCloseKey (hKey=0x8c) returned 0x0 [0036.405] RegCloseKey (hKey=0x88) returned 0x0 [0036.405] GetACP () returned 0x4e4 [0036.405] LoadLibraryA (lpLibFileName="kernel32.dll") returned 0x77940000 [0036.406] GetProcAddress (hModule=0x77940000, lpProcName="HeapSetInformation") returned 0x7795c4a0 [0036.406] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0036.406] FreeLibrary (hLibModule=0x77940000) returned 1 [0036.406] ??2@YAPEAX_K@Z () returned 0x3ddf90 [0036.406] CoRegisterMessageFilter (in: lpMessageFilter=0x3ddf90, lplpMessageFilter=0x3ddfa0 | out: lplpMessageFilter=0x3ddfa0*=0x0) returned 0x0 [0036.406] IUnknown:AddRef (This=0x3ddf90) returned 0x2 [0036.406] GetModuleFileNameW (in: hModule=0xff6e0000, lpFilename=0x26f640, nSize=0x105 | out: lpFilename="C:\\Windows\\System32\\CScript.exe" (normalized: "c:\\windows\\system32\\cscript.exe")) returned 0x1f [0036.406] GetFileVersionInfoSizeW (in: lptstrFilename="C:\\Windows\\System32\\CScript.exe", lpdwHandle=0x26ef90 | out: lpdwHandle=0x26ef90) returned 0x704 [0036.406] GetFileVersionInfoW (in: lptstrFilename="C:\\Windows\\System32\\CScript.exe", dwHandle=0x0, dwLen=0x704, lpData=0x26e880 | out: lpData=0x26e880) returned 1 [0036.407] VerQueryValueW (in: pBlock=0x26e880, lpSubBlock="\\", lplpBuffer=0x26ef98, puLen=0x26ef94 | out: lplpBuffer=0x26ef98*=0x26e8a8, puLen=0x26ef94) returned 1 [0036.407] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26efe8 | out: phkResult=0x26efe8*=0x88) returned 0x0 [0036.407] RegQueryValueExW (in: hKey=0x88, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x26e338, lpData=0x26e740, lpcbData=0x26e330*=0x400 | out: lpType=0x26e338*=0x0, lpData=0x26e740*=0x0, lpcbData=0x26e330*=0x400) returned 0x2 [0036.407] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x26efa0 | out: phkResult=0x26efa0*=0x8c) returned 0x0 [0036.407] RegQueryValueExW (in: hKey=0x8c, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x26ef64, lpData=0x26efe0, lpcbData=0x26ef60*=0x4 | out: lpType=0x26ef64*=0x0, lpData=0x26efe0*=0x10, lpcbData=0x26ef60*=0x4) returned 0x2 [0036.407] RegQueryValueExW (in: hKey=0x8c, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x26e338, lpData=0x26e740, lpcbData=0x26e330*=0x400 | out: lpType=0x26e338*=0x0, lpData=0x26e740*=0x0, lpcbData=0x26e330*=0x400) returned 0x2 [0036.407] RegQueryValueExW (in: hKey=0x88, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x26ef64, lpData=0x26efe0, lpcbData=0x26ef60*=0x4 | out: lpType=0x26ef64*=0x0, lpData=0x26efe0*=0x10, lpcbData=0x26ef60*=0x4) returned 0x2 [0036.407] RegQueryValueExW (in: hKey=0x88, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x26e338, lpData=0x26e740, lpcbData=0x26e330*=0x400 | out: lpType=0x26e338*=0x1, lpData="1", lpcbData=0x26e330*=0x4) returned 0x0 [0036.407] lstrlenW (lpString="1") returned 1 [0036.407] lstrlenW (lpString="0") returned 1 [0036.407] lstrlenW (lpString="1") returned 1 [0036.407] lstrlenW (lpString="no") returned 2 [0036.407] lstrlenW (lpString="1") returned 1 [0036.407] lstrlenW (lpString="false") returned 5 [0036.407] RegCloseKey (hKey=0x8c) returned 0x0 [0036.407] RegCloseKey (hKey=0x88) returned 0x0 [0036.407] RegCreateKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x26efe8, lpdwDisposition=0x0 | out: phkResult=0x26efe8*=0x88, lpdwDisposition=0x0) returned 0x0 [0036.407] RegQueryValueExW (in: hKey=0x88, lpValueName="Timeout", lpReserved=0x0, lpType=0x26ef84, lpData=0x26efe0, lpcbData=0x26ef80*=0x4 | out: lpType=0x26ef84*=0x0, lpData=0x26efe0*=0x10, lpcbData=0x26ef80*=0x4) returned 0x2 [0036.408] RegQueryValueExW (in: hKey=0x88, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x26e358, lpData=0x26e760, lpcbData=0x26e350*=0x400 | out: lpType=0x26e358*=0x1, lpData="1", lpcbData=0x26e350*=0x4) returned 0x0 [0036.408] lstrlenW (lpString="1") returned 1 [0036.408] lstrlenW (lpString="0") returned 1 [0036.408] lstrlenW (lpString="1") returned 1 [0036.408] lstrlenW (lpString="no") returned 2 [0036.408] lstrlenW (lpString="1") returned 1 [0036.408] lstrlenW (lpString="false") returned 5 [0036.408] RegCloseKey (hKey=0x88) returned 0x0 [0036.408] RegCreateKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x26efe8, lpdwDisposition=0x0 | out: phkResult=0x26efe8*=0x88, lpdwDisposition=0x0) returned 0x0 [0036.408] RegQueryValueExW (in: hKey=0x88, lpValueName="Timeout", lpReserved=0x0, lpType=0x26ef84, lpData=0x26efe0, lpcbData=0x26ef80*=0x4 | out: lpType=0x26ef84*=0x0, lpData=0x26efe0*=0x10, lpcbData=0x26ef80*=0x4) returned 0x2 [0036.408] RegQueryValueExW (in: hKey=0x88, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x26e358, lpData=0x26e760, lpcbData=0x26e350*=0x400 | out: lpType=0x26e358*=0x0, lpData=0x26e760*=0x31, lpcbData=0x26e350*=0x400) returned 0x2 [0036.408] RegCloseKey (hKey=0x88) returned 0x0 [0036.408] lstrlenW (lpString="C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf") returned 43 [0036.408] lstrlenW (lpString="wsf") returned 3 [0036.408] lstrlenW (lpString="WSH") returned 3 [0036.408] LoadStringW (in: hInstance=0xff6e0000, uID=0x834, lpBuffer=0x26dee0, cchBufferMax=2048 | out: lpBuffer="Microsoft (R) Windows Script Host Version %1!u!.%2!u!\nCopyright (C) Microsoft Corporation. All rights reserved.\n") returned 0x70 [0036.408] FormatMessageW (in: dwFlags=0x500, lpSource=0x6fe48, dwMessageId=0x0, dwLanguageId=0x0, lpBuffer=0x26eec8, nSize=0x0, Arguments=0x26ef38 | out: lpBuffer="\x06") returned 0x6a [0036.409] LocalFree (hMem=0x6ecb0) returned 0x0 [0036.409] GetStdHandle (nStdHandle=0xfffffff5) returned 0x7 [0036.409] lstrlenW (lpString="Microsoft (R) Windows Script Host Version 5.8\r\nCopyright (C) Microsoft Corporation. All rights reserved.\r\n") returned 106 [0036.409] GetProcessHeap () returned 0x40000 [0036.409] RtlAllocateHeap (HeapHandle=0x40000, Flags=0x0, Size=0xe8) returned 0x5f340 [0036.411] GetConsoleMode (in: hConsoleHandle=0x7, lpMode=0x26ec98 | out: lpMode=0x26ec98) returned 1 [0036.412] WriteConsoleW (in: hConsoleOutput=0x7, lpBuffer=0x5f340*, nNumberOfCharsToWrite=0x6c, lpNumberOfCharsWritten=0x26ec90, lpReserved=0x0 | out: lpBuffer=0x5f340*, lpNumberOfCharsWritten=0x26ec90*=0x6c) returned 1 [0036.412] GetProcessHeap () returned 0x40000 [0036.412] HeapFree (in: hHeap=0x40000, dwFlags=0x0, lpMem=0x5f340 | out: hHeap=0x40000) returned 1 [0036.412] ??2@YAPEAX_K@Z () returned 0x3c5f30 [0036.413] LoadStringW (in: hInstance=0xff6e0000, uID=0x7d1, lpBuffer=0x26da50, cchBufferMax=2048 | out: lpBuffer="Windows Script Host") returned 0x13 [0036.413] LoadTypeLib (in: szFile="C:\\Windows\\System32\\CScript.exe", pptlib=0x26ea90*=0x0 | out: pptlib=0x26ea90*=0x6f040) returned 0x0 [0036.419] ITypeLib:GetTypeInfoOfGuid (in: This=0x6f040, GUID=0xff6f49b0*(Data1=0x91afbd1b, Data2=0x5feb, Data3=0x43f5, Data4=([0]=0xb0, [1]=0x28, [2]=0xe2, [3]=0xca, [4]=0x96, [5]=0x6, [6]=0x17, [7]=0xec)), ppTInfo=0x26ea78 | out: ppTInfo=0x26ea78*=0x70428) returned 0x0 [0036.623] ITypeInfo:GetRefTypeOfImplType (in: This=0x70428, index=0xffffffff, pRefType=0x26ea70 | out: pRefType=0x26ea70*=0xfffffffe) returned 0x0 [0036.623] ITypeInfo:GetRefTypeInfo (in: This=0x70428, hreftype=0xfffffffe, ppTInfo=0xff6fd638 | out: ppTInfo=0xff6fd638*=0x70480) returned 0x0 [0036.624] IUnknown:Release (This=0x70428) returned 0x1 [0036.624] ??2@YAPEAX_K@Z () returned 0x3c57b0 [0036.624] ??2@YAPEAX_K@Z () returned 0x3c5850 [0036.624] ??2@YAPEAX_K@Z () returned 0x3c58b0 [0036.624] ITypeLib:GetTypeInfoOfGuid (in: This=0x6f040, GUID=0xff6f4f50*(Data1=0x2cc5a9d0, Data2=0xb1e5, Data3=0x11d3, Data4=([0]=0xa2, [1]=0x86, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppTInfo=0x26ea78 | out: ppTInfo=0x26ea78*=0x704d8) returned 0x0 [0036.624] ITypeInfo:GetRefTypeOfImplType (in: This=0x704d8, index=0xffffffff, pRefType=0x26ea70 | out: pRefType=0x26ea70*=0xfffffffe) returned 0x0 [0036.624] ITypeInfo:GetRefTypeInfo (in: This=0x704d8, hreftype=0xfffffffe, ppTInfo=0xff6fd6b8 | out: ppTInfo=0xff6fd6b8*=0x70530) returned 0x0 [0036.624] IUnknown:Release (This=0x704d8) returned 0x1 [0036.624] ITypeLib:GetTypeInfoOfGuid (in: This=0x6f040, GUID=0xff6f4f60*(Data1=0xbf64faf0, Data2=0x5906, Data3=0x426c, Data4=([0]=0xb4, [1]=0xbc, [2]=0x7b, [3]=0x75, [4]=0x3c, [5]=0xbe, [6]=0x81, [7]=0x9f)), ppTInfo=0x26ea78 | out: ppTInfo=0x26ea78*=0x70588) returned 0x0 [0036.624] ITypeInfo:GetRefTypeOfImplType (in: This=0x70588, index=0xffffffff, pRefType=0x26ea70 | out: pRefType=0x26ea70*=0xfffffffe) returned 0x0 [0036.624] ITypeInfo:GetRefTypeInfo (in: This=0x70588, hreftype=0xfffffffe, ppTInfo=0xff6fd6f8 | out: ppTInfo=0xff6fd6f8*=0x705e0) returned 0x0 [0036.625] IUnknown:Release (This=0x70588) returned 0x1 [0036.625] ITypeLib:GetTypeInfoOfGuid (in: This=0x6f040, GUID=0xff6f4e20*(Data1=0x2cc5a9d1, Data2=0xb1e5, Data3=0x11d3, Data4=([0]=0xa2, [1]=0x86, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppTInfo=0x26ea78 | out: ppTInfo=0x26ea78*=0x70638) returned 0x0 [0036.625] ITypeInfo:GetRefTypeOfImplType (in: This=0x70638, index=0xffffffff, pRefType=0x26ea70 | out: pRefType=0x26ea70*=0xfffffffe) returned 0x0 [0036.625] ITypeInfo:GetRefTypeInfo (in: This=0x70638, hreftype=0xfffffffe, ppTInfo=0xff6fd678 | out: ppTInfo=0xff6fd678*=0x70690) returned 0x0 [0036.625] IUnknown:Release (This=0x70638) returned 0x1 [0036.625] IUnknown:Release (This=0x6f040) returned 0x4 [0036.625] ??2@YAPEAX_K@Z () returned 0x3c5910 [0036.625] GetCurrentThreadId () returned 0x9a8 [0036.625] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0xd8 [0036.625] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0xff6e23e8, lpParameter=0x3c5910, dwCreationFlags=0x0, lpThreadId=0x3c5938 | out: lpThreadId=0x3c5938*=0xb40) returned 0xe0 [0036.626] MsgWaitForMultipleObjects (nCount=0x1, pHandles=0x26ecd0*=0xd8, fWaitAll=0, dwMilliseconds=0xffffffff, dwWakeMask=0xff) returned 0x0 [0036.777] CloseHandle (hObject=0xd8) returned 1 [0036.777] GetFullPathNameW (in: lpFileName="C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf", nBufferLength=0x104, lpBuffer=0x26ed60, lpFilePart=0x26ed50 | out: lpBuffer="C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf", lpFilePart=0x26ed50*="documeynt4565.wsf") returned 0x2b [0036.778] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey=".wsf", ulOptions=0x0, samDesired=0x20019, phkResult=0x26e270 | out: phkResult=0x26e270*=0xf2) returned 0x0 [0036.778] RegQueryValueExW (in: hKey=0xf2, lpValueName=0x0, lpReserved=0x0, lpType=0x26e220, lpData=0x26e280, lpcbData=0x26e224*=0x800 | out: lpType=0x26e220*=0x1, lpData="WSFFile", lpcbData=0x26e224*=0x10) returned 0x0 [0036.778] RegCloseKey (hKey=0xf2) returned 0x0 [0036.778] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey="WSFFile\\ScriptEngine", ulOptions=0x0, samDesired=0x20019, phkResult=0x26e270 | out: phkResult=0x26e270*=0x0) returned 0x2 [0036.779] lstrlenW (lpString=".wsf") returned 4 [0036.779] lstrlenW (lpString=".wsf") returned 4 [0036.779] LoadLibraryA (lpLibFileName="urlmon.dll") returned 0x7feff760000 [0039.887] GetProcAddress (hModule=0x7feff760000, lpProcName="CreateURLMonikerEx") returned 0x7feff77f3e0 [0039.887] CreateURLMonikerEx (in: pMkCtx=0x0, szURL="C:\\Users\\5P5NRG~1\\Desktop\\documeynt4565.wsf", ppmk=0x26ed48*=0x0, dwFlags=0x1 | out: ppmk=0x26ed48*=0x82910) returned 0x0 [0039.893] CoCreateInstance (in: rclsid=0xff6f5218*(Data1=0x6290bd6, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), pUnkOuter=0x0, dwClsContext=0x1, riid=0xff6f5238*(Data1=0x6290bea, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppv=0x26f898 | out: ppv=0x26f898*=0x0) returned 0x80040154 [0040.247] CoCreateInstance (in: rclsid=0xff6f5208*(Data1=0x6290bd0, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), pUnkOuter=0x0, dwClsContext=0x1, riid=0xff6f5238*(Data1=0x6290bea, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppv=0x26f898 | out: ppv=0x26f898*=0x3c70b8) returned 0x0 [0040.480] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x26ce80 | out: lpSystemTimeAsFileTime=0x26ce80*(dwLowDateTime=0xfbea8a0, dwHighDateTime=0x1d5eb2b)) [0040.480] GetCurrentProcessId () returned 0x998 [0040.480] GetCurrentThreadId () returned 0x9a8 [0040.480] GetTickCount () returned 0x1144885 [0040.480] QueryPerformanceCounter (in: lpPerformanceCount=0x26ce88 | out: lpPerformanceCount=0x26ce88*=16099266019) returned 1 [0040.480] malloc (_Size=0x100) returned 0x3c6cd0 [0040.481] __dllonexit () returned 0x7fef92c14c0 [0040.481] __dllonexit () returned 0x7fef92c14e8 [0040.481] GetVersionExA (in: lpVersionInformation=0x26cc60*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x7fe, dwMinorVersion=0xf92c2dc9, dwBuildNumber=0x7fe, dwPlatformId=0xf92c14e8, szCSDVersion="þ\x07") | out: lpVersionInformation=0x26cc60*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0040.481] GetProcessWindowStation () returned 0x2c [0040.481] GetUserObjectInformationA (in: hObj=0x2c, nIndex=1, pvInfo=0x26cc48, nLength=0xc, lpnLengthNeeded=0x26cc40 | out: pvInfo=0x26cc48, lpnLengthNeeded=0x26cc40) returned 1 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c5a60 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c5ab0 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6de0 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6e20 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6e60 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6ea0 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6ee0 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6f20 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6f60 [0040.481] ??2@YAPEAX_K@Z () returned 0x3c6fa0 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c6fe0 [0040.482] ??3@YAXPEAX@Z () returned 0x3c3df301 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c7030 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c7070 [0040.482] DllGetClassObject (in: rclsid=0x8c950*(Data1=0x6290bd0, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), riid=0x7feff426cd0*(Data1=0x1, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x26d950 | out: ppv=0x26d950*=0x3c5ab0) returned 0x0 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c5ab0 [0040.482] IClassFactory:CreateInstance (in: This=0x3c5ab0, pUnkOuter=0x0, riid=0x26e730*(Data1=0x6290bea, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppvObject=0x26d970 | out: ppvObject=0x26d970*=0x3c70b8) returned 0x0 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c70b0 [0040.482] ??2@YAPEAX_K@Z () returned 0x3c7110 [0040.483] IUnknown:AddRef (This=0x3c70b8) returned 0x2 [0040.483] IUnknown:Release (This=0x3c70b8) returned 0x1 [0040.483] IUnknown:Release (This=0x3c5ab0) returned 0x0 [0040.483] ??3@YAXPEAX@Z () returned 0x3c3df301 [0040.483] IUnknown:QueryInterface (in: This=0x3c70b8, riid=0xff6f5238*(Data1=0x6290bea, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppvObject=0x26ebb8 | out: ppvObject=0x26ebb8*=0x3c70b8) returned 0x0 [0040.483] IUnknown:Release (This=0x3c70b8) returned 0x1 [0040.483] GetUserDefaultLCID () returned 0x409 [0040.483] ??2@YAPEAX_K@Z () returned 0x3c5ab0 [0040.483] ??2@YAPEAX_K@Z () returned 0x3c7140 [0040.484] CoGetClassObject (in: rclsid=0xff6f5228*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), dwClsContext=0x1, pvReserved=0x0, riid=0xff6f5268*(Data1=0x342d1ea0, Data2=0xae25, Data3=0x11d1, Data4=([0]=0x89, [1]=0xc5, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppv=0x26ec90 | out: ppv=0x26ec90*=0x3c7180) returned 0x0 [0040.485] DllGetClassObject (in: rclsid=0x8c9a0*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), riid=0x26e720*(Data1=0x342d1ea0, Data2=0xae25, Data3=0x11d1, Data4=([0]=0x89, [1]=0xc5, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppv=0x26da20 | out: ppv=0x26da20*=0x3c7180) returned 0x0 [0040.485] ??2@YAPEAX_K@Z () returned 0x3c7180 [0040.485] IUnknown:AddRef (This=0x3c7180) returned 0x2 [0040.485] IUnknown:Release (This=0x3c7180) returned 0x1 [0040.485] IUnknown:QueryInterface (in: This=0x3c7180, riid=0xff6f5268*(Data1=0x342d1ea0, Data2=0xae25, Data3=0x11d1, Data4=([0]=0x89, [1]=0xc5, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), ppvObject=0x26e9a0 | out: ppvObject=0x26e9a0*=0x3c7180) returned 0x0 [0040.485] IUnknown:Release (This=0x3c7180) returned 0x1 [0040.486] ??2@YAPEAX_K@Z () returned 0x3c71a0 [0040.486] ??2@YAPEAX_K@Z () returned 0x3c7250 [0040.486] ??2@YAPEAX_K@Z () returned 0x3c7270 [0040.486] ??2@YAPEAX_K@Z () returned 0x3c72b0 [0040.486] CreateBindCtx (in: reserved=0x0, ppbc=0x26ed28 | out: ppbc=0x26ed28*=0x85290) returned 0x0 [0040.486] IBindCtx:RemoteSetBindOptions (This=0x85290, pbindopts=0x26eca0) returned 0x0 [0040.486] IMoniker:RemoteBindToStorage (in: This=0x82910, pbc=0x85290, pmkToLeft=0x0, riid=0x7fef92e7db0*(Data1=0xc, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppvObj=0x26eb28 | out: ppvObj=0x26eb28*=0x85530) returned 0x0 [0040.508] malloc (_Size=0x57b2) returned 0x3c72e0 [0040.508] ??2@YAPEAX_K@Z () returned 0x3ccaa0 [0040.509] IUnknown:QueryInterface (in: This=0x82910, riid=0x7fef92e8440*(Data1=0xf29f6bc0, Data2=0x5021, Data3=0x11ce, Data4=([0]=0xaa, [1]=0x15, [2]=0x0, [3]=0x0, [4]=0x69, [5]=0x1, [6]=0x29, [7]=0x3f)), ppvObject=0x26e2b8 | out: ppvObject=0x26e2b8*=0x82918) returned 0x0 [0040.509] IROTData:GetComparisonData (in: This=0x82918, pbData=0x26e2c0, cbMax=0x800, pcbData=0x26e2b0 | out: pbData=0x26e2c0*=0x66, pcbData=0x26e2b0*=0x68) returned 0x0 [0040.509] IUnknown:Release (This=0x82918) returned 0x1 [0040.509] ??2@YAPEAX_K@Z () returned 0x3ccad0 [0040.509] IUnknown:AddRef (This=0x82910) returned 0x2 [0040.509] _strnicmp (_Str1="", _MaxCount=0xd) returned 47 [0044.971] wcsncmp (_String1="?xml version=", _String2="\r\n", _MaxCount=0xd) returned 50 [0044.971] wcsncmp (_String1="xml version='", _String2="\r\n", _MaxCount=0xd) returned 107 [0044.971] wcsncmp (_String1="ml version='1", _String2="\r\n", _MaxCount=0xd) returned 96 [0044.971] wcsncmp (_String1="l version='1.", _String2="\r\n", _MaxCount=0xd) returned 95 [0044.971] wcsncmp (_String1=" version='1.0", _String2="\r\n", _MaxCount=0xd) returned 19 [0044.971] wcsncmp (_String1="version='1.0'", _String2="\r\n", _MaxCount=0xd) returned 105 [0044.971] wcsncmp (_String1="ersion='1.0' ", _String2="\r\n", _MaxCount=0xd) returned 88 [0044.971] wcsncmp (_String1="rsion='1.0' e", _String2="\r\n", _MaxCount=0xd) returned 101 [0044.971] wcsncmp (_String1="sion='1.0' en", _String2="\r\n", _MaxCount=0xd) returned 102 [0044.971] wcsncmp (_String1="ion='1.0' enc", _String2="\r\n", _MaxCount=0xd) returned 92 [0044.971] wcsncmp (_String1="on='1.0' enco", _String2="\r\n", _MaxCount=0xd) returned 98 [0044.971] wcsncmp (_String1="n='1.0' encod", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.971] wcsncmp (_String1="='1.0' encodi", _String2="\r\n", _MaxCount=0xd) returned 48 [0044.971] wcsncmp (_String1="'1.0' encodin", _String2="\r\n", _MaxCount=0xd) returned 26 [0044.971] wcsncmp (_String1="1.0' encoding", _String2="\r\n", _MaxCount=0xd) returned 36 [0044.971] wcsncmp (_String1=".0' encoding=", _String2="\r\n", _MaxCount=0xd) returned 33 [0044.971] wcsncmp (_String1="0' encoding='", _String2="\r\n", _MaxCount=0xd) returned 35 [0044.971] wcsncmp (_String1="' encoding='w", _String2="\r\n", _MaxCount=0xd) returned 26 [0044.971] wcsncmp (_String1=" encoding='wi", _String2="\r\n", _MaxCount=0xd) returned 19 [0044.971] wcsncmp (_String1="encoding='win", _String2="\r\n", _MaxCount=0xd) returned 88 [0044.971] wcsncmp (_String1="ncoding='wind", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.971] wcsncmp (_String1="coding='windo", _String2="\r\n", _MaxCount=0xd) returned 86 [0044.971] wcsncmp (_String1="oding='window", _String2="\r\n", _MaxCount=0xd) returned 98 [0044.971] wcsncmp (_String1="ding='windows", _String2="\r\n", _MaxCount=0xd) returned 87 [0044.971] wcsncmp (_String1="ing='windows-", _String2="\r\n", _MaxCount=0xd) returned 92 [0044.971] wcsncmp (_String1="ng='windows-1", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.972] wcsncmp (_String1="g='windows-12", _String2="\r\n", _MaxCount=0xd) returned 90 [0044.972] wcsncmp (_String1="='windows-125", _String2="\r\n", _MaxCount=0xd) returned 48 [0044.972] wcsncmp (_String1="'windows-1251", _String2="\r\n", _MaxCount=0xd) returned 26 [0044.972] wcsncmp (_String1="windows-1251'", _String2="\r\n", _MaxCount=0xd) returned 106 [0044.972] wcsncmp (_String1="indows-1251' ", _String2="\r\n", _MaxCount=0xd) returned 92 [0044.972] wcsncmp (_String1="ndows-1251' s", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.972] wcsncmp (_String1="dows-1251' st", _String2="\r\n", _MaxCount=0xd) returned 87 [0044.972] wcsncmp (_String1="ows-1251' sta", _String2="\r\n", _MaxCount=0xd) returned 98 [0044.972] wcsncmp (_String1="ws-1251' stan", _String2="\r\n", _MaxCount=0xd) returned 106 [0044.972] wcsncmp (_String1="s-1251' stand", _String2="\r\n", _MaxCount=0xd) returned 102 [0044.972] wcsncmp (_String1="-1251' standa", _String2="\r\n", _MaxCount=0xd) returned 32 [0044.972] wcsncmp (_String1="1251' standal", _String2="\r\n", _MaxCount=0xd) returned 36 [0044.972] wcsncmp (_String1="251' standalo", _String2="\r\n", _MaxCount=0xd) returned 37 [0044.972] wcsncmp (_String1="51' standalon", _String2="\r\n", _MaxCount=0xd) returned 40 [0044.972] wcsncmp (_String1="1' standalone", _String2="\r\n", _MaxCount=0xd) returned 36 [0044.972] wcsncmp (_String1="' standalone=", _String2="\r\n", _MaxCount=0xd) returned 26 [0044.972] wcsncmp (_String1=" standalone='", _String2="\r\n", _MaxCount=0xd) returned 19 [0044.972] wcsncmp (_String1="standalone='y", _String2="\r\n", _MaxCount=0xd) returned 102 [0044.972] wcsncmp (_String1="tandalone='ye", _String2="\r\n", _MaxCount=0xd) returned 103 [0044.972] wcsncmp (_String1="andalone='yes", _String2="\r\n", _MaxCount=0xd) returned 84 [0044.972] wcsncmp (_String1="ndalone='yes'", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.972] wcsncmp (_String1="dalone='yes'?", _String2="\r\n", _MaxCount=0xd) returned 87 [0044.972] wcsncmp (_String1="alone='yes'?>", _String2="\r\n", _MaxCount=0xd) returned 84 [0044.972] wcsncmp (_String1="lone='yes'?>\r", _String2="\r\n", _MaxCount=0xd) returned 95 [0044.972] wcsncmp (_String1="one='yes'?>\r\n", _String2="\r\n", _MaxCount=0xd) returned 98 [0044.972] wcsncmp (_String1="ne='yes'?>\r\n<", _String2="\r\n", _MaxCount=0xd) returned 97 [0044.972] wcsncmp (_String1="e='yes'?>\r\n